
http://wklej.org/id/287015/
Files to delete:
C:\RECYCLER\S-1-5-21-6248679652-4298819628-633608275-2398\nissan.exe
Folders to delete:
C:\recycler
Registry Values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|TaskMan
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\RECYCLER\S-1-5-21-6248679652-4298819628-633608275-2398\nissan.exe" deleted successfully.
Folder "C:\recycler" deleted successfully.
Registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|TaskMan" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
:OTL
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-8242209300-6795786203-078664026-2935\nissan.exe) - C:\RECYCLER\S-1-5-21-8242209300-6795786203-078664026-2935\nissan.exe ()
O32 - AutoRun File - [2010-02-27 18:12:40 | 000,000,584 | ---- | M] () - G:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{080bc89c-23a6-11df-98c1-000acd02d28f}\Shell\AutoRun\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{080bc89c-23a6-11df-98c1-000acd02d28f}\Shell\explore\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{080bc89c-23a6-11df-98c1-000acd02d28f}\Shell\open\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{0dec0307-1644-11df-98b5-000acd02d28f}\Shell\AutoRun\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{0dec0307-1644-11df-98b5-000acd02d28f}\Shell\explore\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{0dec0307-1644-11df-98b5-000acd02d28f}\Shell\open\command - "" = G:\BEJBI///tatinamaza.exe -- [2010-02-02 19:09:52 | 000,284,160 | RHS- | M] ()
O33 - MountPoints2\{270c7a0d-0fca-11df-98a0-000acd02d28f}\Shell\AutoRun\command - "" = G:\TRAZEME\\nonstopbre.exe -- File not found
O33 - MountPoints2\{270c7a0d-0fca-11df-98a0-000acd02d28f}\Shell\explore\command - "" = G:\TRAZEME\\nonstopbre.exe -- File not found
O33 - MountPoints2\{270c7a0d-0fca-11df-98a0-000acd02d28f}\Shell\open\command - "" = G:\TRAZEME\\nonstopbre.exe -- File not found
O33 - MountPoints2\{998cb849-1498-11df-98b1-000acd02d28f}\Shell - "" = AutoRun
O33 - MountPoints2\{998cb849-1498-11df-98b1-000acd02d28f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{c54d56fe-10c4-11df-98a6-000acd02d28f}\Shell - "" = AutoRun
O33 - MountPoints2\{c54d56fe-10c4-11df-98a6-000acd02d28f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O33 - MountPoints2\{c54d56ff-10c4-11df-98a6-000acd02d28f}\Shell\AutoRun\command - "" = H:\BEJBI\\tatinamaza.exe -- File not found
O33 - MountPoints2\{c54d56ff-10c4-11df-98a6-000acd02d28f}\Shell\explore\command - "" = H:\BEJBI\\tatinamaza.exe -- File not found
O33 - MountPoints2\{c54d56ff-10c4-11df-98a6-000acd02d28f}\Shell\open\command - "" = H:\BEJBI\\tatinamaza.exe -- File not found
:Files
C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\RECYCLER
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
Malwarebytes' Anti-Malware 1.44
Wersja bazy definicji: 3805
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 7.0.5730.13
2010-02-28 14:24:05
mbam-log-2010-02-28 (14-24-05).txt
Typ skanowania: Pełne skanowanie (C:\|D:\|G:\|)
Przeskanowane obiekty: 188331
Upłynęło: 42 minute(s), 11 second(s)
Zainfekowane procesy w pamięci: 0
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 0
Zainfekowane wartości rejestru: 0
Zainfekowane pliki rejestru: 0
Zainfekowane foldery: 0
Zainfekowane pliki: 3
Zainfekowane procesy w pamięci:
(Nie wykryto groźnych plików)
Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)
Zainfekowane klucze rejestru:
(Nie wykryto groźnych plików)
Zainfekowane wartości rejestru:
(Nie wykryto groźnych plików)
Zainfekowane pliki rejestru:
(Nie wykryto groźnych plików)
Zainfekowane foldery:
(Nie wykryto groźnych plików)
Zainfekowane pliki:
C:\System Volume Information\_restore{ACFE450B-A0A5-4735-BDAF-B50971140F6E}\RP59\A0025205.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Aga\Dane aplikacji\wiaservg.log (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Aga\Dane aplikacji\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości