UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
--------------------------------------------------------------------------------
RAPORT KASPERSKY ONLINE SCANNER 7.0
poniedziałek, 17 listopad 2008
System operacyjny: Microsoft Windows XP Professional Dodatek Service Pack 2 (build 2600)
Wersja Kaspersky Online Scanner: 7.0.26.12
Data ostatniej aktualizacji bazy danych: Monday, November 17, 2008 13:29:42
Liczba wpisów: 1389818
--------------------------------------------------------------------------------
Ustawienia skanowania:
Typ bazy danych użytej do skanowania: rozszerzona
Skanuj archiwa: tak
Skanuj pocztowe bazy danych: tak
Obszar skanowania - Mój komputer:
C:\
E:\
Statystyki skanowania:
Przeskanowanych plików: 19301
Nazwa zagrożenia: 2
Zainfekowanych obiektów: 3
Podejrzanych obiektów: 0
Czas skanowania: 00:44:51
Nazwa pliku / Nazwa zagrożenia / Liczba zagrożeń
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP9\A0007287.inf Zainfekowany: Trojan-GameThief.Win32.OnLineGames.ttcr 1
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP10\A0007504.dll Zainfekowany: Trojan-GameThief.Win32.Magania.akll 1
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP10\A0007505.dll Zainfekowany: Trojan-GameThief.Win32.Magania.akll 1
Wybrany obszar został przeskanowany.
;dSCJ9r3knL3fld81ifssDa0kD2paaX2Kr1srlskol0rac5kqww4K7iaq2kofqjKj2AL7k3siSrlsDwI4di3jiwoJaDk3AA4KlifpwqaiwKk40eK632dik9
[AutoRun]
;l2Zr3lisa3O74a2swoF13kfw4wkwqpjoK70slL372
open=yannh.cmd
;jd4plDl4i3LA3c2LLo5DAkawk0Kqdjaq54Oa8kZarLi9LUwklDsr2fq1i3s1Sso4or9l
shell\open\Command=yannh.cmd
;3X7K42aso8qofHki14asAKdsAaiKidF0swkaokwqZ2w5p04Oa73lDwkclKiJr40Llwd5
shell\open\Default=1
;lLXj0i3wKS8d4Jl4sokALkwwDriADo1aAaSa432sC91k7i082ai5adlO3psKw34rrf149mkfw0wLZkqD1lsaslKo90isKs7I2
shell\explore\Command=yannh.cmd
;A2jX4li558aaikn4wIJZ35c2dKisKr03j26qKisDkjiaraaLlkasrL54kKdeCo3ls0k1OaaJfkd
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
Folder::
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP9
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
Files to delete:
C:\Autorun.inf
Folders to delete:
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP9
C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\Autorun.inf" deleted successfully.
File "C:\yannh.cmd" deleted successfully.
Error: could not open file "E:\Autorun.inf"
Deletion of file "E:\Autorun.inf" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: could not open file "E:\yannh.cmd"
Deletion of file "E:\yannh.cmd" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Folder "C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP9" deleted successfully.
Folder "C:\System Volume Information\_restore{1E5269AD-D30F-407C-A293-34B28FCF0B9B}\RP10" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników