Antivirus XP 2008 - log HijackThis

Niech skanuję dalej, wklej log na wklejto.pl jak naciskam na ten link komp mi sie wiesza.

==============

K.

to raport kasperskiego na wklejto http://wklejto.pl/8883

Wklej log na http://up.wklej.org/

:slight_smile:

===============

K.

Wyłącz przywracanie systemu na wszystkich dyskach. Instrukcja

Podłącz wszystkie pendrives

Pobierz Combofix ale nie uruchamiaj wklej do notatnika:

File::

C:\1dg.exe 

C:\2.bat 

C:\22wcb21o.exe

C:\32e2.com

C:\3wcxx91.cmd

C:\6l6w8.com

C:\8.bat

C:\9n1k0g6t.cmd

C:\a3g3.bat

C:\cayfq2.cmd

C:\cl.bat

C:\d6fagcs8.cmd

C:\Documents and Settings\Ludcatchme.zip

C:\Documents and Settings\Ludż\Dane aplikacji\Gadu-Gadu\backup\_cache\banner.htm

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\0D168724d01

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\21DFC4EEd01

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\D6FEE92Dd01

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\F48D3461d01

C:\jfvkcsy.bat

C:\kxax.cmd 

C:\lkxcqdb.bat

C:\m9j.com

C:\mgjpcfdg.cmd 

C:\mug0sd.cmd

C:\nlblkhq.com 

C:\okqa2g.com 

C:\oq.cmd 

C:\qa8sywva.cmd

C:\qwc.exe

C:\SDFix\backups_old\backups.zip

C:\ser.com 

C:\stw1ojde.bat

C:\ta2.cmd

C:\tknn6.bat

C:\u2.cmd 

C:\uq9peya.bat

C:\v.com

C:\vqv.exe

C:\x6.bat

C:\xp19.com 

D:\0.com 

D:\00hoeav.com

D:\0gjn3yw.exe

D:\0n.bat

D:\1dg.exe

D:\2.bat

D:\22wcb21o.exe

D:\32e2.com

D:\3wcxx91.cmd

D:\6l6w8.com

D:\8.bat

D:\83fgj.com

D:\9n1k0g6t.cmd

D:\a3g3.bat

D:\Avenger\Autorun.Inf

D:\bpu.exe

D:\cayfq2.cmd

D:\cl.bat

D:\d6fagcs8.cmd

D:\dwvo.cmd

D:\e.com

D:\e9ehn1m8.com

D:\fppg1.exe

D:\g2pfnid.com

D:\gumkrhf.bat

D:\gy.cmd

D:\jfvkcsy.bat

D:\k.com

D:\klp8j6i.com

D:\kxax.cmd

D:\lkxcqdb.bat 

D:\m88coaim.exe

D:\m9j.com

D:\mgjpcfdg.cmd

D:\mug0sd.cmd

D:\n.com

D:\nlblkhq.com

D:\okqa2g.com

D:\oq.cmd 

D:\p83gjy.exe

D:\qa8sywva.cmd

D:\qwc.exe

D:\ser.com

D:\stw1ojde.bat

D:\t1ypkh.exe

D:\t9peum02.exe

D:\ta2.cmd

D:\tknn6.bat

D:\u2.cmd 

D:\uq9peya.bat

D:\v.com

D:\vqv.exe 

D:\x6.bat

D:\xp19.com 

D:\xqf.com 

D:\xvlyb.exe 

D:\ybj8df.exe

E:\0.com

E:\00hoeav.com

E:\0gjn3yw.exe

E:\0n.bat

E:\1dg.exe

E:\2.bat

E:\22wcb21o.exe

E:\32e2.com 

E:\3wcxx91.cmd 

E:\6l6w8.com 

E:\8.bat 

E:\83fgj.com 

E:\9n1k0g6t.cmd

E:\a3g3.bat

E:\Avenger\Autorun.Inf

E:\bpu.exe 

E:\cayfq2.cmd 

E:\cl.bat

E:\d6fagcs8.cmd

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\0D4LOL4H\fillmemadv588[1].htm 

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\0D4LOL4H\fillmemadv588[2].htm 

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\0D4LOL4H\fillmemadv588[3].htm

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\1JRJ9DSE\index[1].htm  

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\34SH3228\fillmemadv588[1].htm

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\34SH3228\fillmemadv588[2].htm

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\34SH3228\fillmemadv588[3].htm

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv588[1].htm

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv588[2].htm

E:\dwvo.cmd 

E:\e.com

E:\e9ehn1m8.com

E:\fppg1.exe

E:\g2pfnid.com

E:\gumkrhf.bat

E:\gy.cmd

E:\jfvkcsy.bat

E:\k.com

E:\klp8j6i.com

E:\kxax.cmd

E:\lkxcqdb.bat

E:\m88coaim.exe

E:\m9j.com

E:\mgjpcfdg.cmd

E:\mug0sd.cmd

E:\n.com

E:\nlblkhq.com

E:\okqa2g.com

E:\oq.cmd

E:\p83gjy.exe

E:\qa8sywva.cmd

E:\qwc.exe

E:\ser.com 

E:\stw1ojde.bat

E:\t1ypkh.exe

E:\t9peum02.exe 

E:\ta2.cmd

E:\tknn6.bat

E:\u2.cmd

E:\uq9peya.bat

E:\v.com

E:\vqv.exe

E:\x6.bat

E:\xp19.com

E:\xqf.com

E:\xvlyb.exe

E:\ybj8df.exe

F:\0.com 

F:\00hoeav.com

F:\0gjn3yw.exe

F:\0n.bat

F:\1dg.exe 

F:\2.bat

F:\22wcb21o.exe

F:\32e2.com

F:\3wcxx91.cmd

F:\6l6w8.com 

F:\8.bat

F:\83fgj.com

F:\9n1k0g6t.cmd

F:\a3g3.bat

F:\Avenger\Autorun.Inf

F:\bpu.exe

F:\cayfq2.cmd

F:\cl.bat

F:\d6fagcs8.cmd

F:\dwvo.cmd 

F:\e.com 

F:\e9ehn1m8.com

F:\fppg1.exe 

F:\g2pfnid.com 

F:\gumkrhf.bat

F:\gy.cmd 

F:\jfvkcsy.bat

F:\k.com

F:\klp8j6i.com

F:\kxax.cmd 

F:\lkxcqdb.bat 

F:\m88coaim.exe

F:\m9j.com

F:\mgjpcfdg.cmd

F:\mug0sd.cmd 

F:\n.com 

F:\nlblkhq.com

F:\okqa2g.com 

F:\oq.cmd 

F:\p83gjy.exe 

F:\qa8sywva.cmd 

F:\qwc.exe 

F:\ser.com 

F:\stw1ojde.bat

F:\t1ypkh.exe

F:\t9peum02.exe

F:\ta2.cmd

F:\tknn6.bat

F:\u2.cmd  

F:\uq9peya.bat

F:\v.com  

F:\vqv.exe 

F:\x6.bat 

F:\xp19.com

F:\xqf.com

F:\xvlyb.exe 

F:\ybj8df.exe

Zapisz plik jako CFScript.txt najlepiej aby ikonka tego pliku znajdowała się obok ikonki ComboFix.exe

Przeciągnij i upuść plik CFScript.txt na ikonkę ComboFix.exe powinno rozpocząć się usuwanie po tym daj log na forum.

Usuń ręcznie folder C:\Qoobox , usuń instalkę Combofix z dysku.

Następnie przeskanuj raz jeszcze obszar Mój komputer Kaspersky Online Scanner i daj raport na forum

raport kasperkiego: http://up.wklej.org/download.php?id=b05 … 0dfc08abfa (sprzed wykonania czynnosci z ostatniego postu! !!

Masz w poście powyżej co robić.

:slight_smile:

logi z comofixa:

ComboFix 08-08-26.03 - Ludż 2008-08-27 17:54:48.3 - NTFSx86

Log wyglada na czysty

usuń ręcznie folder C: \Qoobox , usuń instalkę Combofix z dysku.

Przeczyść komputer Ccleanerem

Wykonaj optymalizację autostartu

Wyłącz i włącz przywracanie systemu na wszystkich dyskach. Instrukcja

Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum

lub

Dr.WEB CureIt!

raport z kasperskiego: http://up.wklej.org/download.php?id=f65 … 39259acffa

czym jeszcze przeskanowac? combofixem, hijacksem czy czym?

Pobierz The Avenger

wklej do niego ten tekst:

Files to delete:

C:\Documents and Settings\Ludcatchme.zip

C:\SDFix\backups_old\backups.zip

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\0D168724d01 

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\21DFC4EEd01 

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\D6FEE92Dd01 

C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\F48D3461d01

D:\83fgj.com 

D:\Avenger\Autorun.Inf

E:\0.com

E:\00hoeav.com 

E:\0gjn3yw.exe 

E:\0n.bat 

E:\1dg.exe 

E:\2.bat 

E:\22wcb21o.exe

E:\32e2.com 

E:\3wcxx91.cmd 

E:\6l6w8.com 

E:\8.bat 

E:\83fgj.com 

E:\9n1k0g6t.cmd 

E:\a3g3.bat 

E:\Avenger\Autorun.Inf 

E:\bpu.exe 

E:\cayfq2.cmd 

E:\cl.bat 

E:\d6fagcs8.cmd

E:\dwvo.cmd 

E:\e.com

E:\e9ehn1m8.com 

E:\fppg1.exe 

E:\g2pfnid.com 

E:\gumkrhf.bat 

E:\gy.cmd 

E:\jfvkcsy.bat

E:\k.com 

E:\klp8j6i.com

E:\kxax.cmd 

E:\lkxcqdb.bat

E:\m88coaim.exe 

E:\m9j.com 

E:\mgjpcfdg.cmd 

E:\mug0sd.cmd

E:\n.com 

E:\nlblkhq.com

E:\okqa2g.com

E:\oq.cmd 

E:\p83gjy.exe 

E:\qa8sywva.cmd 

E:\qwc.exe 

E:\ser.com 

E:\stw1ojde.bat 

E:\t1ypkh.exe

E:\t9peum02.exe 

E:\ta2.cmd 

E:\tknn6.bat 

E:\u2.cmd 

E:\uq9peya.bat 

E:\v.com 

E:\vqv.exe 

E:\x6.bat 

E:\xp19.com 

E:\xqf.com 

E:\xvlyb.exe 	

E:\ybj8df.exe 

F:\0.com 

F:\00hoeav.com 

F:\0gjn3yw.exe 

F:\0n.bat 

F:\1dg.exe 

F:\2.bat 

F:\22wcb21o.exe 

F:\32e2.com 	

F:\3wcxx91.cmd 

F:\6l6w8.com 

F:\8.bat 

F:\83fgj.com 

F:\9n1k0g6t.cmd 

F:\a3g3.bat 

F:\Avenger\Autorun.Inf

F:\bpu.exe 

F:\cayfq2.cmd 	

F:\cl.bat 

F:\d6fagcs8.cmd 

F:\dwvo.cmd 

F:\e.com 

F:\e9ehn1m8.com 

F:\fppg1.exe 

F:\g2pfnid.com

F:\gumkrhf.bat

F:\gy.cmd 

F:\jfvkcsy.bat 

F:\k.com 

F:\klp8j6i.com 

F:\kxax.cmd 

F:\lkxcqdb.bat 

F:\m88coaim.exe 

F:\m9j.com 

F:\mgjpcfdg.cmd 

F:\mug0sd.cmd 	

F:\n.com 

F:\nlblkhq.com 	

F:\okqa2g.com 

F:\oq.cmd 

F:\p83gjy.exe 

F:\qa8sywva.cmd 

F:\qwc.exe

F:\ser.com 

F:\stw1ojde.bat 

F:\t9peum02.exe 

F:\ta2.cmd 

F:\tknn6.bat

F:\u2.cmd 

F:\uq9peya.bat 

F:\v.com 	

F:\vqv.exe 	

F:\x6.bat 

F:\xp19.com 

F:\xqf.com 	

F:\xvlyb.exe 

F:\ybj8df.exe


Folders to delete:

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\34SH3228

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\1JRJ9DSE

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\0D4LOL4H

kopiuj to i klikasz na Paste Script from Clipboard wybierasz Execute oraz Potwierdzasz i zgadzasz się na restart klikając OK.

Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt

Usuń wszystkie pliki z tego folderu:

log z avengera:

Logfile of The Avenger Version 2.0, (c) by Swandog46

http://swandog46.geekstogo.com


Platform: Windows XP


*******************


Script file opened successfully.

Script file read successfully.


Backups directory opened successfully at C:\Avenger


*******************


Beginning to process script file:


Rootkit scan active.

No rootkits found!


File "C:\Documents and Settings\Ludcatchme.zip" deleted successfully.

File "C:\SDFix\backups_old\backups.zip" deleted successfully.

File "C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\0D168724d01" deleted successfully.

File "C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\21DFC4EEd01" deleted successfully.

File "C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\D6FEE92Dd01" deleted successfully.

File "C:\Documents and Settings\Olędzki\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\lrm9irk0.default\Cache\F48D3461d01" deleted successfully.

File "D:\83fgj.com" deleted successfully.

File "D:\Avenger\Autorun.Inf" deleted successfully.

File "E:\0.com" deleted successfully.

File "E:\00hoeav.com" deleted successfully.

File "E:\0gjn3yw.exe" deleted successfully.

File "E:\0n.bat" deleted successfully.

File "E:\1dg.exe" deleted successfully.

File "E:\2.bat" deleted successfully.

File "E:\22wcb21o.exe" deleted successfully.

File "E:\32e2.com" deleted successfully.

File "E:\3wcxx91.cmd" deleted successfully.

File "E:\6l6w8.com" deleted successfully.

File "E:\8.bat" deleted successfully.

File "E:\83fgj.com" deleted successfully.

File "E:\9n1k0g6t.cmd" deleted successfully.

File "E:\a3g3.bat" deleted successfully.

File "E:\Avenger\Autorun.Inf" deleted successfully.

File "E:\bpu.exe" deleted successfully.

File "E:\cayfq2.cmd" deleted successfully.

File "E:\cl.bat" deleted successfully.

File "E:\d6fagcs8.cmd" deleted successfully.

File "E:\dwvo.cmd" deleted successfully.

File "E:\e.com" deleted successfully.

File "E:\e9ehn1m8.com" deleted successfully.

File "E:\fppg1.exe" deleted successfully.

File "E:\g2pfnid.com" deleted successfully.

File "E:\gumkrhf.bat" deleted successfully.

File "E:\gy.cmd" deleted successfully.

File "E:\jfvkcsy.bat" deleted successfully.

File "E:\k.com" deleted successfully.

File "E:\klp8j6i.com" deleted successfully.

File "E:\kxax.cmd" deleted successfully.

File "E:\lkxcqdb.bat" deleted successfully.

File "E:\m88coaim.exe" deleted successfully.

File "E:\m9j.com" deleted successfully.

File "E:\mgjpcfdg.cmd" deleted successfully.

File "E:\mug0sd.cmd" deleted successfully.

File "E:\n.com" deleted successfully.

File "E:\nlblkhq.com" deleted successfully.

File "E:\okqa2g.com" deleted successfully.

File "E:\oq.cmd" deleted successfully.

File "E:\p83gjy.exe" deleted successfully.

File "E:\qa8sywva.cmd" deleted successfully.

File "E:\qwc.exe" deleted successfully.

File "E:\ser.com" deleted successfully.

File "E:\stw1ojde.bat" deleted successfully.

File "E:\t1ypkh.exe" deleted successfully.

File "E:\t9peum02.exe" deleted successfully.

File "E:\ta2.cmd" deleted successfully.

File "E:\tknn6.bat" deleted successfully.

File "E:\u2.cmd" deleted successfully.

File "E:\uq9peya.bat" deleted successfully.

File "E:\v.com" deleted successfully.

File "E:\vqv.exe" deleted successfully.

File "E:\x6.bat" deleted successfully.

File "E:\xp19.com" deleted successfully.

File "E:\xqf.com" deleted successfully.

File "E:\xvlyb.exe" deleted successfully.

File "E:\ybj8df.exe" deleted successfully.

File "F:\0.com" deleted successfully.

File "F:\00hoeav.com" deleted successfully.

File "F:\0gjn3yw.exe" deleted successfully.

File "F:\0n.bat" deleted successfully.

File "F:\1dg.exe" deleted successfully.

File "F:\2.bat" deleted successfully.

File "F:\22wcb21o.exe" deleted successfully.

File "F:\32e2.com" deleted successfully.

File "F:\3wcxx91.cmd" deleted successfully.

File "F:\6l6w8.com" deleted successfully.

File "F:\8.bat" deleted successfully.

File "F:\83fgj.com" deleted successfully.

File "F:\9n1k0g6t.cmd" deleted successfully.

File "F:\a3g3.bat" deleted successfully.

File "F:\Avenger\Autorun.Inf" deleted successfully.

File "F:\bpu.exe" deleted successfully.

File "F:\cayfq2.cmd" deleted successfully.

File "F:\cl.bat" deleted successfully.

File "F:\d6fagcs8.cmd" deleted successfully.

File "F:\dwvo.cmd" deleted successfully.

File "F:\e.com" deleted successfully.

File "F:\e9ehn1m8.com" deleted successfully.

File "F:\fppg1.exe" deleted successfully.

File "F:\g2pfnid.com" deleted successfully.

File "F:\gumkrhf.bat" deleted successfully.

File "F:\gy.cmd" deleted successfully.

File "F:\jfvkcsy.bat" deleted successfully.

File "F:\k.com" deleted successfully.

File "F:\klp8j6i.com" deleted successfully.

File "F:\kxax.cmd" deleted successfully.

File "F:\lkxcqdb.bat" deleted successfully.

File "F:\m88coaim.exe" deleted successfully.

File "F:\m9j.com" deleted successfully.

File "F:\mgjpcfdg.cmd" deleted successfully.

File "F:\mug0sd.cmd" deleted successfully.

File "F:\n.com" deleted successfully.

File "F:\nlblkhq.com" deleted successfully.

File "F:\okqa2g.com" deleted successfully.

File "F:\oq.cmd" deleted successfully.

File "F:\p83gjy.exe" deleted successfully.

File "F:\qa8sywva.cmd" deleted successfully.

File "F:\qwc.exe" deleted successfully.

File "F:\ser.com" deleted successfully.

File "F:\stw1ojde.bat" deleted successfully.

File "F:\t9peum02.exe" deleted successfully.

File "F:\ta2.cmd" deleted successfully.

File "F:\tknn6.bat" deleted successfully.

File "F:\u2.cmd" deleted successfully.

File "F:\uq9peya.bat" deleted successfully.

File "F:\v.com" deleted successfully.

File "F:\vqv.exe" deleted successfully.

File "F:\x6.bat" deleted successfully.

File "F:\xp19.com" deleted successfully.

File "F:\xqf.com" deleted successfully.

File "F:\xvlyb.exe" deleted successfully.

File "F:\ybj8df.exe" deleted successfully.

Folder "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\34SH3228" deleted successfully.

Folder "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\1JRJ9DSE" deleted successfully.

Folder "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\0D4LOL4H" deleted successfully.


Completed script processing.


*******************


Finished! Terminate.

Wszystko zostało usunięte

Przeskanuj ponownie Kasperskim

:slight_smile:

to log z kasperskiego, chyba rzeczywiscie jest czysty ^^ http://up.wklej.org/download.php?id=cf3 … e2d4fafdcc mam jeszcze cos robic?

Pobierz The Avenger

wklej do niego ten tekst:

Files to delete:

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5881.htm 	

E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5882.htm

F:\t1ypkh.exe

kopiuj to i klikasz na Paste Script from Clipboard wybierasz Execute oraz Potwierdzasz i zgadzasz się na restart klikając OK.

Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt

Usuń koniecznie to:

Opróżnij kosz

:slight_smile:

Pobierz i uruchom narzędzie The Avenger Zaznaczasz tekst podany do usunięcia na forum

kopiuj >> klikasz na Paste Script from Clipboard >> Execute >> Potwierdzasz i zgadzasz się na restart klikając OK.

Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt

:slight_smile:

pierwszy log z avengera:

Logfile of The Avenger Version 2.0, (c) by Swandog46

http://swandog46.geekstogo.com


Platform: Windows XP


*******************


Script file opened successfully.

Script file read successfully.


Backups directory opened successfully at C:\Avenger


*******************


Beginning to process script file:


Rootkit scan active.

No rootkits found!



Error: file "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5881.htm" not found!

Deletion of file "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5881.htm" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5882.htm" not found!

Deletion of file "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv5882.htm" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist


File "F:\t1ypkh.exe" deleted successfully.


Completed script processing.


*******************


Finished! Terminate.

i drugi log z avengera:

Logfile of The Avenger Version 2.0, (c) by Swandog46

http://swandog46.geekstogo.com


Platform: Windows XP


*******************


Script file opened successfully.

Script file read successfully.


Backups directory opened successfully at C:\Avenger


*******************


Beginning to process script file:


Rootkit scan active.

No rootkits found!


File "C:\Avenger\backups.zip" deleted successfully.


Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc10.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc10.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc11.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc11.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc12.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc12.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc13.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc13.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc2.cmd" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc2.cmd" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc3.cmd" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc3.cmd" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc6.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc6.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc8.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc8.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Error: file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc9.com" not found!

Deletion of file "C:\RECYCLER\S-1-5-21-789336058-1659004503-682003330-1007\Dc9.com" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist


File "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv588[1].htm" deleted successfully.

File "E:\dane z dysku 20GB\KOCUR\Kocur\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KDC5I1U1\fillmemadv588[2].htm" deleted successfully.


Error: file "F:\t1ypkh.exe" not found!

Deletion of file "F:\t1ypkh.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

  --> the object does not exist



Completed script processing.


*******************


Finished! Terminate.

czy mam usunac C:\Avenger\backups.zip? uwaga, nie backup, tylko backups!

wszystko usunięte powinno być OK

:slight_smile:

backups.zip nadal jest na dysku, wewnatrz sa pliki o nazwach na oko takich samych jak jakies pliki tego wirusa

Usuń ten plik