24 Lut 2011, 20:57
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Folder "C:\Documents and Settings\Administrator\Dane aplikacji\xbbe2wmufenpjvefqxgmb1nbpflgwuvp2" deleted successfully.
Folder "C:\Documents and Settings\Administrator\Dane aplikacji\ivwjdfbkm3j2vdudzxswdyf1mhyuvxu2" deleted successfully.
Folder "C:\Documents and Settings\Administrator\Dane aplikacji\xw3ppoqujsbdhetswbwl1xu3x1c3r3ns2" deleted successfully.
Folder "C:\Documents and Settings\Administrator\Dane aplikacji\xxn1vhpdtiqpdlfvhne2d1paplmhhzvo2" deleted successfully.
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\7202.12" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\7202.12" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: "C:\Documents and Settings\Administrator\Dane aplikacji\340C.224" is not a folder! It may instead be a file.
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\340C.224" failed!
Status: 0xc0000103 (STATUS_NOT_A_DIRECTORY)
--> use "Files to delete:" instead of "Folders to delete:" to delete an ordinary file
File "C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\csrss.exe" deleted successfully.
File "C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\conhost.exe" deleted successfully.
File "C:\Documents and Settings\Administrator\Dane aplikacji\dwm.exe" deleted successfully.
Program "C:\FIX.reg" successfully queued to run on reboot.
Completed script processing.
*******************
Finished! Terminate.
24 Lut 2011, 21:01
wywaliło mi neta
24 Lut 2011, 21:08
24 Lut 2011, 21:18
:OTL
IE - HKU\S-1-5-21-1390067357-1085031214-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-1390067357-1085031214-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:52808
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 173.192.105.217 173.193.227.124
24 Lut 2011, 21:44
========== OTL ==========
HKU\S-1-5-21-1390067357-1085031214-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-21-1390067357-1085031214-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
OTL by OldTimer - Version 3.2.21.0 log created on 02242011_202956
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\xbbe2wmufenpjvefqxgmb1nbpflgwuvp2" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\xbbe2wmufenpjvefqxgmb1nbpflgwuvp2" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\ivwjdfbkm3j2vdudzxswdyf1mhyuvxu2" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\ivwjdfbkm3j2vdudzxswdyf1mhyuvxu2" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\xw3ppoqujsbdhetswbwl1xu3x1c3r3ns2" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\xw3ppoqujsbdhetswbwl1xu3x1c3r3ns2" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\xxn1vhpdtiqpdlfvhne2d1paplmhhzvo2" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\xxn1vhpdtiqpdlfvhne2d1paplmhhzvo2" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\Documents and Settings\Administrator\Dane aplikacji\7202.12" not found!
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\7202.12" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: "C:\Documents and Settings\Administrator\Dane aplikacji\340C.224" is not a folder! It may instead be a file.
Deletion of folder "C:\Documents and Settings\Administrator\Dane aplikacji\340C.224" failed!
Status: 0xc0000103 (STATUS_NOT_A_DIRECTORY)
--> use "Files to delete:" instead of "Folders to delete:" to delete an ordinary file
File "C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\csrss.exe" deleted successfully.
File "C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\conhost.exe" deleted successfully.
File "C:\Documents and Settings\Administrator\Dane aplikacji\dwm.exe" deleted successfully.
Program "C:\FIX.reg" successfully queued to run on reboot.
Completed script processing.
*******************
Finished! Terminate.
24 Lut 2011, 21:53
:OTL
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O4 - HKU\S-1-5-21-1390067357-1085031214-1801674531-500..\Run: [mssend] File not found
F3 - HKU\S-1-5-21-1390067357-1085031214-1801674531-500 WinNT: Load - (C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\csrss.exe) - File not found
[2011-02-17 13:53:33 | 000,005,014 | ---- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\340C.224
[2011-02-17 12:32:11 | 000,013,672 | ---- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\7202.12E
:Commands
[clearallrestorepoints]
[emptytemp]
24 Lut 2011, 22:09
24 Lut 2011, 22:50
:OTL
O3 - HKU\S-1-5-21-1390067357-1085031214-1801674531-500\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 173.192.105.217 173.193.227.124
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\0.3261719558617614.exe"=-
"C:\Documents and Settings\Administrator\Dane aplikacji\xbbe2wmufenpjvefqxgmb1nbpflgwuvp2\svcnost.exe"=-
"C:\Documents and Settings\Administrator\Dane aplikacji\xw3ppoqujsbdhetswbwl1xu3x1c3r3ns2\svcnost.exe"=-
"C:\Documents and Settings\Administrator\Dane aplikacji\xxn1vhpdtiqpdlfvhne2d1paplmhhzvo2\svcnost.exe"=-
"C:\Documents and Settings\Administrator\Dane aplikacji\ivwjdfbkm3j2vdudzxswdyf1mhyuvxu2\csrss.exe"=-
Java(TM) 6 Update 17
Java(TM) 6 Update 7
Adobe Reader 9 Lite
25 Lut 2011, 00:12
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Wersja bazy: 5873
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 7.0.5730.13
2011-02-24 23:02:14
mbam-log-2011-02-24 (23-02-01).txt
Typ skanowania: Pełne skanowanie (C:\|E:\|F:\|)
Przeskanowano obiektów: 227914
Upłynęło: 21 minut(y), 53 sekund(y)
Zainfekowanych procesów w pamięci: 0
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 3
Zainfekowanych wartości rejestru: 2
Zainfekowane informacje rejestru systemowego: 2
Zainfekowanych folderów: 0
Zainfekowanych plików: 5
Zainfekowanych procesów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych kluczy rejestru:
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) No action taken.
HKEY_CURRENT_USER\SOFTWARE\TOY5KNQ8OC (Trojan.FakeAlert) No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) No action taken.
Zainfekowanych wartości rejestru:
HKEY_CURRENT_USER\Software\Microsoft\setiasworld (Malware.Trace) Value: setiasworld No action taken.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) Value: bk No action taken.
Zainfekowane informacje rejestru systemowego:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) Bad: (0) Good: (1) No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (PUM.Hijack.Help) Bad: (1) Good: (0) No action taken.
Zainfekowanych folderów:
(Nie znaleziono zagrożeń)
Zainfekowanych plików:
c:\documents and settings\administrator\moje dokumenty\Paweł\windows.genuine.advantage.validation_wga\sprawdzanie kluczy systemu\produkey 1.01\ProduKey.exe (PUP.PSWTool.ProductKey) No action taken.
c:\documents and settings\administrator\Pulpit\Moje\perfectdisk11_keygen-crd\keygen-crd\kg.exe (Trojan.Agent.CK) No action taken.
c:\program files\Opera\update.exe (Spyware.Passwords.XGen) No action taken.
c:\program files\WinRAR\default_eng.sfx (Trojan.PWS) No action taken.
e:\skarabeusz\skarabeusz 1\skarabeusz_v.2.5_kgn.exe (Riskware.Tool.CK) No action taken.
25 Lut 2011, 10:06
No action taken.
8.8.8.8
8.8.4.4
25 Lut 2011, 20:03