mwav log-poradte co smáznout
Napsal: 05 pro 2008 17:01
poslední dobou se můj systém chová divne ,mezi otevrenými procesy jsem objevil podezřelý soubor na který můj avast nereaguje ale po projetí teho souboru na netu jsem zjistil že nektré antiviry ho označili za vir či cosi podobného jedná se o soubor C:\DOCUME~1\grebi\grebi.exe
zajímavé je že má stejný název jako uživatel pod kterým se přihlašuji -grebi
pravdepodobne je to nejaký trojan který potom natahuje další smejd do počítače-možná ,nevím
tady je log s MWAV skenu už trochu pročištený poradte co mám smáznout díky moc, za pomoc
(jo ješte neco:mám Os- win xp, antivir avast)
Fri Dec 05 16:24:22 2008 => File C:\DOCUME~1\grebi\grebi.exe infected by "Backdoor.Win32.Small.gtw" Virus!
Action Taken: No Action Taken.
Fri Dec 05 16:24:27 2008 => System found infected with yahoospymon Spyware/Adware
({4340df8e-d7a3-4675-be74-80077b2b3e81})! Action taken: No Action Taken.
Fri Dec 05 16:24:29 2008 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\p3p\history\gator.com !!!
Fri Dec 05 16:24:29 2008 => Object "gain.gator Spyware/Adware" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:29 2008 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\p3p\history\gator.com !!!
Fri Dec 05 16:24:29 2008 => Object "gain.gator Spyware/Adware" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:30 2008 => Offending Folder found: C:\Documents and Settings\grebi\Data
aplikací\icq\bart\1024
Fri Dec 05 16:24:30 2008 => Object "smitfraud Browser Hijacker" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:34 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:34 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:38 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:38 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:39 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:39 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:40 2008 => Offending Registry Entry found: hkcu\software\mirabilis
Fri Dec 05 16:24:40 2008 => System found infected with personalantispy Corrupted Adware/Spyware
(hkcu\software\mirabilis)! Action taken: No Action Taken.
Fri Dec 05 16:24:40 2008 => Offending Registry Entry found: hkcu\software\avs
Fri Dec 05 16:24:40 2008 => System found infected with antivirus sentry Corrupted Adware/Spyware
(hkcu\software\avs)! Action taken: No Action Taken.
Fri Dec 05 16:24:43 2008 => Checking MountPoints2 Registry Key...
Fri Dec 05 16:24:43 2008 => Checking CLSID Reference Entries...
Fri Dec 05 16:24:43 2008 => Entry "HKCR\AcroExch.Document.7" refers to invalid object
"{B801CA65-A1FC-11D0-85AD-444553540000}". Action Taken: No Action Taken.
Fri Dec 05 16:24:43 2008 => Entry "HKCR\AcroExch.XDPDoc" refers to invalid object
"{B801CA65-A1FC-11D0-85AD-444553540000}". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Entry "HKCR\MSInfo.Document" refers to invalid object
"{45ac8c63-23e2-11d1-a696-00c04fd58bc3}". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Checking Module Usage Entries...
Fri Dec 05 16:24:44 2008 => Checking User Trusted External App Entries...
Fri Dec 05 16:24:44 2008 => Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External
Applications" refers to invalid object ""E:\data\cdw32.exe"". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Checking Shared DLL Entries...
Fri Dec 05 16:24:47 2008 => Checking Installer Entries...
Fri Dec 05 16:24:47 2008 => Checking Shared Tools Entries...
Fri Dec 05 16:24:47 2008 => Checking File Extension Entries...
Fri Dec 05 16:24:47 2008 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts"
refers to invalid object ".pf". Action Taken: No Action Taken.
Fri Dec 05 16:24:47 2008 => Checking Application Cache Entries...
Fri Dec 05 16:24:47 2008 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache"
refers to invalid object "{7B63B2922B174135AFC0E1377DD81EC2}". Action Taken: No Action Taken.
Fri Dec 05 16:26:14 2008 => ***** Checking for specific ITW Viruses *****
Fri Dec 05 16:26:14 2008 => Checking for Welchia Virus...
Fri Dec 05 16:26:14 2008 => Checking for LovGate Virus...
Fri Dec 05 16:26:14 2008 => Checking for CodeRed Virus...
Fri Dec 05 16:26:14 2008 => Checking for OpaServ Virus...
Fri Dec 05 16:26:14 2008 => Checking for Sobig.e Virus...
Fri Dec 05 16:26:14 2008 => Checking for Winupie Virus...
Fri Dec 05 16:26:14 2008 => Checking for Swen Virus...
Fri Dec 05 16:26:14 2008 => Checking for JS.Fortnight Virus...
Fri Dec 05 16:26:14 2008 => Checking for Novarg Virus...
Fri Dec 05 16:26:14 2008 => Checking for Pagabot Virus...
Fri Dec 05 16:26:14 2008 => Checking for Parite.b Virus...
Fri Dec 05 16:26:14 2008 => Checking for Parite.a Virus...
Fri Dec 05 16:26:14 2008 => Checking for Adware.SeekSeek Virus...
Fri Dec 05 16:26:14 2008 => ***** Scanning complete. *****
Fri Dec 05 16:26:14 2008 => Total Objects Scanned: 64776
Fri Dec 05 16:26:14 2008 => Total Critical Objects: 10
Fri Dec 05 16:26:14 2008 => Total Disinfected Objects: 0
Fri Dec 05 16:26:14 2008 => Total Objects Renamed: 0
Fri Dec 05 16:26:14 2008 => Total Deleted Objects: 0
Fri Dec 05 16:26:14 2008 => Total Errors: 15
Fri Dec 05 16:26:14 2008 => Time Elapsed: 00:02:17
Fri Dec 05 16:26:14 2008 => Virus Database Date: 12/5/2008
Fri Dec 05 16:26:14 2008 => Virus Database Count: 1438362
Fri Dec 05 16:26:14 2008 => Scan Completed.
zajímavé je že má stejný název jako uživatel pod kterým se přihlašuji -grebi
pravdepodobne je to nejaký trojan který potom natahuje další smejd do počítače-možná ,nevím
tady je log s MWAV skenu už trochu pročištený poradte co mám smáznout díky moc, za pomoc
(jo ješte neco:mám Os- win xp, antivir avast)
Fri Dec 05 16:24:22 2008 => File C:\DOCUME~1\grebi\grebi.exe infected by "Backdoor.Win32.Small.gtw" Virus!
Action Taken: No Action Taken.
Fri Dec 05 16:24:27 2008 => System found infected with yahoospymon Spyware/Adware
({4340df8e-d7a3-4675-be74-80077b2b3e81})! Action taken: No Action Taken.
Fri Dec 05 16:24:29 2008 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\p3p\history\gator.com !!!
Fri Dec 05 16:24:29 2008 => Object "gain.gator Spyware/Adware" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:29 2008 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\p3p\history\gator.com !!!
Fri Dec 05 16:24:29 2008 => Object "gain.gator Spyware/Adware" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:30 2008 => Offending Folder found: C:\Documents and Settings\grebi\Data
aplikací\icq\bart\1024
Fri Dec 05 16:24:30 2008 => Object "smitfraud Browser Hijacker" found in File System! Action Taken: No
Action Taken.
Fri Dec 05 16:24:34 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:34 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:38 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:38 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:39 2008 => Offending file found: C:\WINNT\system32\win.com
Fri Dec 05 16:24:39 2008 => System found infected with combo Spyware/Adware (C:\WINNT\system32\win.com)!
Action taken: No Action Taken.
Fri Dec 05 16:24:40 2008 => Offending Registry Entry found: hkcu\software\mirabilis
Fri Dec 05 16:24:40 2008 => System found infected with personalantispy Corrupted Adware/Spyware
(hkcu\software\mirabilis)! Action taken: No Action Taken.
Fri Dec 05 16:24:40 2008 => Offending Registry Entry found: hkcu\software\avs
Fri Dec 05 16:24:40 2008 => System found infected with antivirus sentry Corrupted Adware/Spyware
(hkcu\software\avs)! Action taken: No Action Taken.
Fri Dec 05 16:24:43 2008 => Checking MountPoints2 Registry Key...
Fri Dec 05 16:24:43 2008 => Checking CLSID Reference Entries...
Fri Dec 05 16:24:43 2008 => Entry "HKCR\AcroExch.Document.7" refers to invalid object
"{B801CA65-A1FC-11D0-85AD-444553540000}". Action Taken: No Action Taken.
Fri Dec 05 16:24:43 2008 => Entry "HKCR\AcroExch.XDPDoc" refers to invalid object
"{B801CA65-A1FC-11D0-85AD-444553540000}". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Entry "HKCR\MSInfo.Document" refers to invalid object
"{45ac8c63-23e2-11d1-a696-00c04fd58bc3}". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Checking Module Usage Entries...
Fri Dec 05 16:24:44 2008 => Checking User Trusted External App Entries...
Fri Dec 05 16:24:44 2008 => Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External
Applications" refers to invalid object ""E:\data\cdw32.exe"". Action Taken: No Action Taken.
Fri Dec 05 16:24:44 2008 => Checking Shared DLL Entries...
Fri Dec 05 16:24:47 2008 => Checking Installer Entries...
Fri Dec 05 16:24:47 2008 => Checking Shared Tools Entries...
Fri Dec 05 16:24:47 2008 => Checking File Extension Entries...
Fri Dec 05 16:24:47 2008 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts"
refers to invalid object ".pf". Action Taken: No Action Taken.
Fri Dec 05 16:24:47 2008 => Checking Application Cache Entries...
Fri Dec 05 16:24:47 2008 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache"
refers to invalid object "{7B63B2922B174135AFC0E1377DD81EC2}". Action Taken: No Action Taken.
Fri Dec 05 16:26:14 2008 => ***** Checking for specific ITW Viruses *****
Fri Dec 05 16:26:14 2008 => Checking for Welchia Virus...
Fri Dec 05 16:26:14 2008 => Checking for LovGate Virus...
Fri Dec 05 16:26:14 2008 => Checking for CodeRed Virus...
Fri Dec 05 16:26:14 2008 => Checking for OpaServ Virus...
Fri Dec 05 16:26:14 2008 => Checking for Sobig.e Virus...
Fri Dec 05 16:26:14 2008 => Checking for Winupie Virus...
Fri Dec 05 16:26:14 2008 => Checking for Swen Virus...
Fri Dec 05 16:26:14 2008 => Checking for JS.Fortnight Virus...
Fri Dec 05 16:26:14 2008 => Checking for Novarg Virus...
Fri Dec 05 16:26:14 2008 => Checking for Pagabot Virus...
Fri Dec 05 16:26:14 2008 => Checking for Parite.b Virus...
Fri Dec 05 16:26:14 2008 => Checking for Parite.a Virus...
Fri Dec 05 16:26:14 2008 => Checking for Adware.SeekSeek Virus...
Fri Dec 05 16:26:14 2008 => ***** Scanning complete. *****
Fri Dec 05 16:26:14 2008 => Total Objects Scanned: 64776
Fri Dec 05 16:26:14 2008 => Total Critical Objects: 10
Fri Dec 05 16:26:14 2008 => Total Disinfected Objects: 0
Fri Dec 05 16:26:14 2008 => Total Objects Renamed: 0
Fri Dec 05 16:26:14 2008 => Total Deleted Objects: 0
Fri Dec 05 16:26:14 2008 => Total Errors: 15
Fri Dec 05 16:26:14 2008 => Time Elapsed: 00:02:17
Fri Dec 05 16:26:14 2008 => Virus Database Date: 12/5/2008
Fri Dec 05 16:26:14 2008 => Virus Database Count: 1438362
Fri Dec 05 16:26:14 2008 => Scan Completed.