18 Cze 2009, 16:35
>>> Danger - possible CPU address substitution[1].IDT[06] = [F3AF916D] C:\WINDOWS\system32\drivers\Haspnt.sys, driver recognized as trusted
>>> Danger - possible CPU address substitution[1].IDT[0E] = [F3AF8FC2] C:\WINDOWS\system32\drivers\Haspnt.sys, driver recognized as trusted
8. Searching for vulnerabilities:
>> Services: potentially dangerous service allowed: RemoteRegistry (Rejestr zdalny)
>> Services: potentially dangerous service allowed: TermService (Usługi terminalowe)
>> Services: potentially dangerous service allowed: SSDPSRV (Usługa odnajdywania SSDP)
>> Services: potentially dangerous service allowed: Schedule (Harmonogram zadań)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Menedżer sesji pomocy pulpitu zdalnego)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
18 Cze 2009, 18:11
19 Cze 2009, 11:36
>> Danger - possible CPU address substitution[1].IDT[06] = [F3AF916D] C:\WINDOWS\system32\drivers\Haspnt.sys, driver recognized as trusted
>>> Danger - possible CPU address substitution[1].IDT[0E] = [F3AF8FC2] C:\WINDOWS\system32\drivers\Haspnt.sys, driver recognized as trusted
8. Searching for vulnerabilities:
>> Services: potentially dangerous service allowed: RemoteRegistry (Rejestr zdalny)
>> Services: potentially dangerous service allowed: TermService (Usługi terminalowe)
>> Services: potentially dangerous service allowed: SSDPSRV (Usługa odnajdywania SSDP)
>> Services: potentially dangerous service allowed: Schedule (Harmonogram zadań)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Menedżer sesji pomocy pulpitu zdalnego)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
19 Cze 2009, 18:05
Drivers to delete:
SASDIFSV
SASKUTIL
FirebirdServerDefaultInstance
mpr_freader
SASENUM
19 Cze 2009, 23:06
20 Cze 2009, 10:05
Drivers to delete:
SASDIFSV
SASKUTIL
mpr_freader
SASENUM
20 Cze 2009, 12:12
20 Cze 2009, 12:18
21 Cze 2009, 09:15
C:\Windows\system32\ShowErrMsg.dll;5;Suspicion for Keylogger or Trojan DLL
C:\Windows\system32\sysenv.dll;5;Suspicion for Keylogger or Trojan DLL
21 Cze 2009, 13:25
21 Cze 2009, 14:12
log AVZ Antiviral Toolkit_csv: (Tylko zarażone pliki pokazuje)
C:\Windows\system32\ShowErrMsg.dll;5;Suspicion for Keylogger or Trojan DLL
C:\Windows\system32\sysenv.dll;5;Suspicion for Keylogger or Trojan DLL
21 Cze 2009, 14:41
File::
c:\program files\Global.sw
C:\Windows\system32\ShowErrMsg.dll
C:\Windows\system32\sysenv.dll
Folder::
c:\users\user\AppData\Local\temp
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
21 Cze 2009, 15:48
21 Cze 2009, 15:58
c:\windows\system32\novamnp6.dll
c:\windows\system32\novamip6.dll
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000
c:\users\user\AppData\Local\Temp
22 Cze 2009, 06:26
Statystyki
-----------------------------------------------------------------------------
Przetestowane obiekty: 20553
Zainfekowane obiekty: 0
Zmodyfikowane obiekty: 0
Podejrzane obiekty: 0
Programy Adware: 0
Programy Dialer: 0
Programy Joke: 0
Programy Riskware: 0
Programy Hacktool: 0
Wyleczone obiekty: 0
Usunięte obiekty: 0
Przemianowane obiekty: 0
Przeniesione obiekty: 0
Pominięte obiekty: 0
Prędkość testu: 2723 Kb/s
Czas testu: 00:15:32