mam tai problem pomozcie plizzzz
formatowalem partycje systemowa, ale i to nie pomoglo, bo jak sie okazalo trojan jest takze na drugiej patycji oraz dysku zewnetznym. w raporcie z AVIRA AntiVir jest cos takiego :
Avira AntiVir Personal
Report file date: 28 września 2008 19:34
Scanning for 1646460 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Dodatek Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: JACEK-63C412C8F
Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 2008-08-12 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 2008-06-26 08:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-05-26 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-05-26 07:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 2008-06-24 13:54:15
ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 2008-09-26 17:08:19
ANTIVIR3.VDF : 7.0.6.220 16384 Bytes 2008-09-28 17:08:19
Engineversion : 8.1.1.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 09:58:21
AESCRIPT.DLL : 8.1.0.76 319867 Bytes 2008-09-28 17:08:34
AESCN.DLL : 8.1.0.23 119156 Bytes 2008-07-10 12:44:49
AERDL.DLL : 8.1.1.2 438644 Bytes 2008-09-28 17:08:33
AEPACK.DLL : 8.1.2.3 364918 Bytes 2008-09-28 17:08:31
AEOFFICE.DLL : 8.1.0.25 196986 Bytes 2008-09-28 17:08:29
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 2008-09-28 17:08:28
AEHELP.DLL : 8.1.0.15 115063 Bytes 2008-07-10 12:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 2008-09-28 17:08:22
AEEMU.DLL : 8.1.0.7 430452 Bytes 2008-07-31 08:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 2008-09-28 17:08:21
AEBB.DLL : 8.1.0.1 53617 Bytes 2008-07-10 12:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 2008-09-28 17:08:20
AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-06-12 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-06-27 13:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:, F:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: 28 września 2008 19:34
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'skypePM.exe' - '1' Module(s) have been scanned
Scan process 'HPQTOA~1.EXE' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
Scan process 'Skype.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'QLBCTRL.exe' - '1' Module(s) have been scanned
Scan process 'HP Wireless Assistant.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
34 processes with 34 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'F:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '52' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
D:\Gry\magwoj\Graphics.exe
[0] Archive type: CAB SFX (self extracting)
--> Graphics\Animations\002-Action02.png
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP102\A0034128.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc437.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP102\A0034650.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e9f08.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP103\A0034654.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc438.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP103\A0034791.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc439.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP103\A0034811.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e9f0a.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP103\A0034832.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc43a.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP104\A0034885.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e9f0b.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034920.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc43c.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034941.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e9f0d.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034954.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc43b.qua'!
D:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0035967.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e9f0c.qua'!
D:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP16\A0000448.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc43e.qua'!
Begin scan in 'F:\' <Twardziel jesteeee>
F:\jopnqbe2.com
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '494fc47f.qua'!
F:\Gry\Capoeira Fighter\=shockwave.com.capoeira.fighter.2.cracked.exe-rev.zip
[0] Archive type: ZIP
--> cracked.rar
[1] Archive type: RAR
--> Capoeira Fighter 2.exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Bot.33783 back-door program
[NOTE] The file was moved to '4947c617.qua'!
F:\Gry\Capoeira Fighter\cracked.rar
[0] Archive type: RAR
--> Capoeira Fighter 2.exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Bot.33783 back-door program
[NOTE] The file was moved to '4940c619.qua'!
F:\RECYCLER\S-1-5-21-1028082712-3752474381-643496382-1006\Dg1.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '4910c950.qua'!
F:\RECYCLER\S-1-5-21-1028082712-3752474381-643496382-1006\Dg2.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '4911c951.qua'!
F:\RECYCLER\S-1-5-21-3755838163-4144160231-277544596-1006\Di1.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '4910c957.qua'!
F:\RECYCLER\S-1-5-21-3755838163-4144160231-277544596-1006\Di2.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '4911c958.qua'!
F:\RECYCLER\S-1-5-21-3755838163-4144160231-277544596-1006\Di4.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '4913c958.qua'!
F:\RECYCLER\S-1-5-21-3755838163-4144160231-277544596-1006\Di5.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '4914c958.qua'!
F:\System Volume Information\_restore{4FFBD7F9-1A35-4864-A549-AD3AB4133A92}\RP433\A0199618.exe
[DETECTION] Contains recognition pattern of the W32/Perlovga.A.1 Windows virus
[NOTE] The file was moved to '4910c92b.qua'!
F:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP102\A0034130.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc92c.qua'!
F:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP104\A0034887.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc92d.qua'!
F:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034922.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e921e.qua'!
F:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034943.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc92e.qua'!
F:\System Volume Information\_restore{76155CF2-CAF3-43A4-A227-2CD4ACD043EE}\RP105\A0034956.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '487e921f.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP14\A0000281.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc941.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000486.com
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '490fc942.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000489.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '487e9273.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000490.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '490fc944.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000491.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '490fc943.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000492.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '487e9274.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000493.inf
[DETECTION] Contains recognition pattern of the WORM/Autorun.IR.3 worm
[NOTE] The file was moved to '490fc945.qua'!
F:\System Volume Information\_restore{CBA33605-81F2-479B-96A9-C10EC5602FDB}\RP17\A0000494.exe
[DETECTION] Contains recognition pattern of the WORM/Agent.129368 worm
[NOTE] The file was moved to '487e9275.qua'!
End of the scan: 28 września 2008 20:25
Used time: 50:52 Minute(s)
The scan has been done completely.
5581 Scanning directories
214946 Files were scanned
35 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
35 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
214909 Files not concerned
1104 Archives were scanned
3 Warnings
35 Notes
na dodatek jak klikam na dysku to pokazuje mi sie cos w rodzaju: otwórz za pomoca...
prosze o pomoc i z gory dzieki