Log z Malwarebytes
Malwarebytes’ Anti-Malware 1.46
http://www.malwarebytes.org
Wersja bazy: 4069
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 7.0.5730.13
2010-05-05 21:22:21
mbam-log-2010-05-05 (21-22-21).txt
Typ skanowania: Pełne skanowanie (C:|)
Przeskanowano obiektów: 216333
Upłynęło: 1 godzin(y), 17 minut(y), 59 sekund(y)
Zainfekowanych procesów w pamięci: 0
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 5
Zainfekowanych wartości rejestru: 0
Zainfekowane informacje rejestru systemowego: 0
Zainfekowanych folderów: 0
Zainfekowanych plików: 16
Zainfekowanych procesów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)
Zainfekowanych kluczy rejestru:
HKEY_CLASSES_ROOT\CLSID{b03a4be6-5e5a-b9b3-483e-c484d4b20b72} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{c5f43bef-ce2f-afe6-46d8-a647bacd1f09} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\NOD32KVBIT (Trojan.Frethog) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\MADOWN (Worm.Magania) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XP antiVirus (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
Zainfekowanych wartości rejestru:
(Nie znaleziono zagrożeń)
Zainfekowane informacje rejestru systemowego:
(Nie znaleziono zagrożeń)
Zainfekowanych folderów:
(Nie znaleziono zagrożeń)
Zainfekowanych plików:
C:\System Volume Information_restore{EBE851C6-D750-49E9-B3FF-CC24FF052C6A}\RP50\A0015063.exe (HackTool.Snadboy) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025313.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025333.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025359.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025374.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025393.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025347.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025364.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025449.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025419.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025440.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025458.com (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025488.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marian\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Marian\Dane aplikacji\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
– Dodane 05.05.2010 (Śr) 21:42 –
Log z Malware
Malware’ Anti-Malware 1.46 http://www.malwarebytes.org Wersja bazy: 4069 Windows 5.1.2600 Dodatek Service Pack 3 Internet Explorer 7.0.5730.13 2010-05-05 21:22:21 mbam-log-2010-05-05 (21-22-21).txt Typ skanowania: Pełne skanowanie (C:|) Przeskanowano obiektów: 216333 Upłynęło: 1 godzin(y), 17 minut(y), 59 sekund(y) Zainfekowanych procesów w pamięci: 0 Zainfekowanych modułów w pamięci: 0 Zainfekowanych kluczy rejestru: 5 Zainfekowanych wartości rejestru: 0 Zainfekowane informacje rejestru systemowego: 0 Zainfekowanych folderów: 0 Zainfekowanych plików: 16 Zainfekowanych procesów w pamięci: (Nie znaleziono zagrożeń) Zainfekowanych modułów w pamięci: (Nie znaleziono zagrożeń) Zainfekowanych kluczy rejestru: HKEY_CLASSES_ROOT\CLSID{b03a4be6-5e5a-b9b3-483e-c484d4b20b72} (Spyware.OnlineGames) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID{c5f43bef-ce2f-afe6-46d8-a647bacd1f09} (Spyware.OnlineGames) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\NOD32KVBIT (Trojan.Frethog) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\MADOWN (Worm.Magania) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XP antiVirus (Rogue.XPantiVirus) -> Quarantined and deleted successfully. Zainfekowanych wartości rejestru: (Nie znaleziono zagrożeń) Zainfekowane informacje rejestru systemowego: (Nie znaleziono zagrożeń) Zainfekowanych folderów: (Nie znaleziono zagrożeń) Zainfekowanych plików: C:\System Volume Information_restore{EBE851C6-D750-49E9-B3FF-CC24FF052C6A}\RP50\A0015063.exe (HackTool.Snadboy) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025313.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025333.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025359.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025374.com (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025393.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025347.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025364.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025449.com (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025419.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025440.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025458.com (Trojan.Downloader) -> Quarantined and deleted successfully. C:\System Volume Information_restore{ECDED79B-5399-4362-8584-EC683D21B1CD}\RP226\A0025488.dll (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Documents and Settings\Marian\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\Marian\Dane aplikacji\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.