UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )
2010-09-06 09:02:35
Ochrona systemu plików w czasie rzeczywistym.
Plik:
C:\System Volume Information\_restore{EFCEEB96-A8DD-4FDF-9E02-F0F58AAC7FBF}\RP199\A0034624.dll
prawdopodobnie odmiana wirusa Win32/Genetik koń trojański
wyleczony przez usunięcie - poddany kwarantannie - ZARZĄDZANIE NT\SYSTEM
Zdarzenie wystąpiło podczas modyfikowania pliku przez aplikację: C:\WINDOWS\system32\svchost.exe. 13:53:15 -> Loading definitions-list...
[b]13:56:18 -> Deleting: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net[/b]
13:56:34 -> End of the scan process.
----- \TypeLib\{fe666755-7db5-47b5-9f9e-abc3d730af26} ---- Registry
Rogue.BulletProofSoftware
----- \Interface\{39625f3a-a770-4d43-878b-b776f7881742} ---- Registry
Rogue.BulletProofSoftware
----- \Interface\{8d36f049-ced6-48f5-8604-86279e6516f9} ---- Registry
Rogue.BulletProofSoftware
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
Ale dziś rano ESET zneutralizował trojana w Svchost:
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\user\USTAWI~1\Temp\esihdrv.sys -- (esihdrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\user\USTAWI~1\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )
========== OTL ==========
Service esihdrv stopped successfully!
Service esihdrv deleted successfully!
File C:\DOCUME~1\user\USTAWI~1\Temp\esihdrv.sys not found.
Service cpuz132 stopped successfully!
Service cpuz132 deleted successfully!
File C:\DOCUME~1\user\USTAWI~1\Temp\cpuz132\cpuz132_x32.sys not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
OTL by OldTimer - Version 3.2.11.0 log created on 09062010_153926
----- \TypeLib\{fe666755-7db5-47b5-9f9e-abc3d730af26} ---- Registry
Rogue.BulletProofSoftware
----- \Interface\{39625f3a-a770-4d43-878b-b776f7881742} ---- Registry
Rogue.BulletProofSoftware
----- \Interface\{8d36f049-ced6-48f5-8604-86279e6516f9} ---- Registry
Rogue.BulletProofSoftware
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )


UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8 ( )


Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]