ja polecam kaspersky internet security:0 sciągałem se keygeny ale to był błąd połowa to trojany:) i troche mi wykrylo... zwłaszcza ze dalem scan calego systemu a dopiero co zainstalowalem ten antywir. wczesniej byl mc afee ale za duzo nie wykryl... a dokładnie nic! mialem tez avg, awasta ale na 98 i tez nic nie wykrywaly... nie mozliwe:( wiec nie radze instalowac lepiej niech komp wolniej chodzi ale bezpiecznie. przy okazji mam tu fajnego loga;)
Logfile of HijackThis v1.99.1
Scan saved at 12:41:13, on 2006-06-02
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\Aston\aston.exe
F:\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\System32\GEARSec.exe
F:\In cd\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
F:\Aston\XP\internat.exe
F:\A4Tech\Mouse\Amoumain.exe
F:\In cd\InCD\InCD.exe
F:\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\NoAds\NoAds.exe
F:\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
F:\Firefox\firefox.exe
F:\TC PowerPack\totalcmd.exe
F:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kurnik.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: Shell=F:\Aston\aston.exe ,svchost.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WheelMouse] f:\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [systemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [inCD] F:\In cd\InCD\InCD.exe
O4 - HKLM\..\Run: [kis] "F:\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKCU\..\Run: [NoAds] "F:\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [AWMON] "F:\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [Norton SystemWorks] "F:\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - F:\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Download all by Free Download Manager - file://f:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://f:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://f:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://f:\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://F:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Pasek Narzędzi RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Personalizuj Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Wypełnij Pola - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Zapisz Pola - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - F:\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Wypełnij pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Wypełnij Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Zapisz - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Zapisz Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Pasek Narzędzi RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145868103000
O17 - HKLM\System\CCS\Services\Tcpip\..\{F521DCF1-2CA0-4EF5-B764-00807C6B548B}: NameServer = 194.204.159.1,194.204.152.34
O20 - AppInit_DLLs: interceptor.dll,,F:\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - F:\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - F:\In cd\InCD\InCDsrv.exe
O23 - Service: Norton Ghost - Symantec Corporation - F:\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - f:\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
a to zasady z firewala to na koncu to trojan nie wiem czy wiecej nie zostalo ciekaw jestem co usunąc
musze wogule je przeczyscic i zeby od nowa moze sie potworzyly bo maja pewnie jeszcze cos wspólnego z trojanami;0
svchost.exe C:\WINDOWS\system32\ 13
alg.exe C:\WINDOWS\system32\ 3
dwwin.exe C:\WINDOWS\system32\ 2
regwiz.exe C:\WINDOWS\system32\ 2
rdpclip.exe C:\WINDOWS\system32\ 3
mstsc.exe C:\WINDOWS\system32\ 3
sessmgr.exe C:\WINDOWS\system32\ 2
mobsync.exe C:\WINDOWS\system32\ 2
wuauclt.exe C:\WINDOWS\system32\ 2
rundll32.exe C:\WINDOWS\system32\ 6
spoolsv.exe C:\WINDOWS\system32\ 2
msimn.exe C:\Program Files\Outlook Express\ 8
explorer.exe C:\WINDOWS\ 5
IEXPLORE.EXE C:\Program Files\Internet Explorer\ 11
firefox.exe F:\Firefox\ 8
ftp.exe C:\WINDOWS\system32\ 3
telnet.exe C:\WINDOWS\system32\ 3
conf.exe C:\Program Files\NetMeeting\ 5
CCAPP.EXE C:\Program Files\Common Files\Symantec Shared\ 2
hijackthis.exe F:\ 2
ping.exe C:\WINDOWS\system32\ 1
tracert.exe C:\WINDOWS\system32\ 1
nslookup.exe C:\WINDOWS\system32\ 1
finger.exe C:\WINDOWS\system32\ 2
rcp.exe C:\WINDOWS\system32\ 2
rexec.exe C:\WINDOWS\system32\ 0
lpq.exe C:\WINDOWS\system32\ 2
rsh.exe C:\WINDOWS\system32\ 2
lpr.exe C:\WINDOWS\system32\ 2
tftp.exe C:\WINDOWS\system32\ 2
mplayer2.exe C:\Program Files\Windows Media Player\ 3
wmplayer.exe C:\Program Files\Windows Media Player\ 3
EXCEL.EXE F:\Microsoft Office\OFFICE11\ 7
WINWORD.EXE F:\Microsoft Office\OFFICE11\ 6
lsass.exe C:\WINDOWS\system32\ 6
services.exe C:\WINDOWS\system32\ 6
winlogon.exe C:\WINDOWS\system32\ 2
userinit.exe C:\WINDOWS\system32\ 3
system system 1
SysMech6.exe F:\SYSTEM MECHANIC PROFESSIONAL 6\ 8
fdm.exe F:\Free Download Manager\ 26
setup_wm.exe C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\ 2
IDENTITIES.EXE F:\AI_ROBO_FORM\ 2
XPINSTALL.EXE E:\Temp\ 8
msiexec.exe C:\WINDOWS\system32\ 4
javaw.exe F:\JRE1.5.0_06\bin\ 2
oodcnt.exe F:\DEFRAG PROFESSIONAL\ 2
Aston.exe F:\Aston\ 2
jucheck.exe F:\JRE1.5.0_06\bin\ 4
LuComServer_2_7.EXE C:\Program Files\Symantec\LiveUpdate\ 8
SEARCHANDRECOVER.EXE F:\SYSTEM MECHANIC PROFESSIONAL 6\SEARCH AND RECOVER\ 6
is-8OOK9.tmp E:\Temp\is-JNOMI.tmp\ 2
WIN12.TMP.EXE E:\Temp\ 2
a teraz przeglad trojanków z ostatniego dnia;0
detected: Trojan program Trojan-Downloader.Win32.Tiny.bw URL: http://installare.net/a412/an.php?m=0&b=779
detected: Trojan program Trojan-Downloader.Win32.IstBar.ff URL: http://installare.net/a412/pop.php/UPX
deleted: Trojan program Trojan-Dropper.Win32.VB.kk File: C:\Program Files\Yazzle Sudoku\Sudoku.exe
deleted: adware not-a-virus:AdWare.Win32.SaveNow.bo File: E:\ Ściągane\fdminst.exe
deleted: adware not-a-virus:AdWare.Win32.SaveNow.bo File: E:\ Ściągane\fdmlpinst.exe
not found: Trojan program Trojan-Downloader.Win32.Zlob.pz File: E:\ Ściągane\lz04oq01.exe/run.exe/PE_Patch.UPX/UPX/data0008/PE_Patch/UPack
deleted: adware not-a-virus:AdWare.Win32.Doza.a File: E:\ Ściągane\tleninst55032.exe/UPX/data0020/UPX
deleted: Trojan program Trojan-Downloader.Win32.Zlob.pz File: E:\RECYCLER\S-1-5-21-606747145-1482476501-725345543-1003\De1.exe/run.exe/PE_Patch.UPX/UPX/data0008/PE_Patch/UPack
deleted: Trojan program Trojan.Win32.Dialer.oy File: E:\Temp\win12.tmp.exe/UPX
deleted: Trojan program Trojan-Dropper.Win32.VB.kk File: E:\Temp\win1B.tmp.exe/data0002/data0006
deleted: Trojan program Trojan-Dropper.Win32.VB.kk File: E:\Temporary Internet Files\Content.IE5\AZH3J8A3\winz32[1].exe
deleted: Trojan program Trojan-Dropper.Win32.VB.kk File: E:\Temporary Internet Files\Content.IE5\AZH3J8A3\winz32[1].exe/data0002/data0006
deleted: Trojan program Trojan.Win32.Dialer.oy File: E:\Temporary Internet Files\Content.IE5\S9UZ85IB\mulbin32[1].exe/UPX
deleted: Trojan program Trojan-Downloader.Win32.Zlob.pz File: H:\RECYCLER\S-1-5-21-606747145-1482476501-725345543-1003\Dh6\run.exe/PE_Patch.UPX/UPX/data0008/PE_Patch/UPack
deleted: Trojan program Trojan.Win32.Agent.qt File: C:\WINDOWS\SYSTEM32\winzdn32.dll/NSPack
deleted: Trojan program Trojan.Win32.Agent.qt File: E:\Temp\cliE.tmp/NSPack
deleted: Trojan program Trojan-Downloader.Win32.Zlob.pz File: E:\RECYCLER\S-1-5-21-606747145-1482476501-725345543-1003\De1.exe/PE_Patch.UPX/UPX/data0008/PE_Patch/UPack
kaspersky ma fajny dysk ratunkowy haha to taki mini windows xp no i częste aktualizacje ... bo zlapalem jakiegos trojana co zostal wykryty pare dni temu i wkrotce potem powstala szczepionka:)
no i na koniec co to takiego??????????? wyskakuje czesto:( numerki sie zmieniają ale nic mi nie wykrywa
2006-06-02 12:16:19 Process (PID 3980) tried to access Kaspersky Internet Security 6.0 process (PID 660), but it has been blocked. This is Self-Defense monitoring, and you do not need to do anything.