UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
File::
c:\windows\system32\lsdelete.exe
c:\windows\system32\edacded0_x.dat
Folder::
c:\windows\system32\BDD55D
c:\windows\system32\A01FDB
c:\windows\system32\ED162B
c:\windows\system32\2C079A
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"=-
"SunJavaUpdateSched"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^8E48A3.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microtek Scanner Finder.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Adobe Gamma.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^OpenOffice.org 2.4.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^PowerReg Scheduler.exe]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Ubisoft register.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^winsys.exe.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^winword.exe.lnk]
[HKLM\~\startupfolde\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Xfire.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000000
"FirewallOverride"=dword:00000000
Driver::
avm
ATE_PROCMON
DarkSpy
HwIOctl
c:\\windows\\system32\\CMStarterCore.exe
c:\\windows\\iun6002.exe
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
2009-06-15 21:34:38 Anna 1816 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\system volume information\_restore{7b5a35f0-c8dc-48ed-868b-e56225e1fb8d}\rp670\A0403825.exe" file.
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
File::
c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-00531102}.dat
c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-00531102}.dat
C:\drmHeader.bin
[HKLM\\~\\startupfolder\\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microtek Scanner Finder.lnk]
path=c:\\documents and settings\\All Users\\Menu Start\\Programy\\Autostart\\Microtek Scanner Finder.lnk
backup=c:\\windows\\pss\\Microtek Scanner Finder.lnkCommon Startup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^8E48A3.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\8E48A3.lnk
backup=c:\\windows\\pss\\8E48A3.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Adobe Gamma.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\Adobe Gamma.lnk
backup=c:\\windows\\pss\\Adobe Gamma.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^OpenOffice.org 2.4.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\OpenOffice.org 2.4.lnk
backup=c:\\windows\\pss\\OpenOffice.org 2.4.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^PowerReg Scheduler.exe]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\PowerReg Scheduler.exe
backup=c:\\windows\\pss\\PowerReg Scheduler.exeStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Ubisoft register.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\Ubisoft register.lnk
backup=c:\\windows\\pss\\Ubisoft register.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^winsys.exe.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\winsys.exe.lnk
backup=c:\\windows\\pss\\winsys.exe.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^winword.exe.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\winword.exe.lnk
backup=c:\\windows\\pss\\winword.exe.lnkStartup
[HKLM\\~\\startupfolder\\C:^Documents and Settings^Anna^Menu Start^Programy^Autostart^Xfire.lnk]
path=c:\\documents and settings\\Anna\\Menu Start\\Programy\\Autostart\\Xfire.lnk
backup=c:\\windows\\pss\\Xfire.lnkStartup
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
Michael Parker napisał(a):Zastanawiają mnie niektóre z tych wpisów. Usuń skróty znajdujące się w Start Wszystkie programy Autostart.
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
File::
c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-00531102}.dat
c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-00531102}.dat
C:\drmHeader.bin
c:\documents and settings\Anna\Menu Start\Programy\Autostart\8E48A3.lnk
c:\windows\pss\8E48A3.lnk
c:\documents and settings\Anna\Menu Start\Programy\Autostart\PowerReg Scheduler.exe
c:\windows\pss\PowerReg Scheduler.exe
c:\documents and settings\Anna\Menu Start\Programy\Autostart\Ubisoft register.lnk
c:\documents and settings\Anna\Menu Start\Programy\Autostart\winsys.exe.lnk
c:\\windows\pss\winword.exe.lnk
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
W trakcie tych działań mój Firewall gdzieś zniknął, czy po zakończeniu będę mógł go uruchomić ponownie? Czy będzie działał jak poprzednio czy może powinienem ściągnąć i zainstalować od nowa?
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
Zarejestrowani użytkownicy: Google [Bot]