jak w temacie. przekopałem już chyba każdy temat związany z tym problemem, ale rozwiązania dla siebie nie znalazłem. proponuję loga z hijack. proces ten zajmuje 50% z procka więc zabawne to dla mnie nie jest.
Czy wolisz polską wersję strony elektroda?
Nie, dziękuję Przekieruj mnie tamCytat:ComboFix 11-02-09.05 - SysOp 2011-02-10 14:41:08.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.1022.324 [GMT 1:00]
Uruchomiony z: e:\pobrane\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\SysOp\goykvkva.exe
c:\windows\system32\msconfig.exe
c:\windows\regedit.exe . . . jest zainfekowany!!
c:\windows\system32\midimap.dll . . . jest zainfekowany!!
Zainfekowana kopia c:\windows\system32\drivers\ndis.sys została znaleziona. Problem naprawiono
Plik odzyskano z - c:\system volume information\_restore{5337D05E-D6C8-4B25-9477-74E8A5560A82}\RP36\A0026072.sys
.
((((((((((((((((((((((((( Pliki utworzone od 2011-01-10 do 2011-02-10 )))))))))))))))))))))))))))))))
.
2011-02-10 13:46 . 2011-02-10 13:46 -------- d-----w- c:\windows\system32\xircom
2011-02-10 13:46 . 2011-02-10 13:46 -------- d-----w- c:\windows\system32\wbem\snmp
2011-02-10 13:46 . 2011-02-10 13:46 -------- d-----w- c:\windows\system32\oobe
2011-02-10 13:46 . 2011-02-10 13:46 -------- d-----w- c:\windows\srchasst
2011-02-10 13:32 . 2011-02-10 13:32 -------- d-----w- C:\UsbFix
2011-02-09 20:27 . 2011-02-09 20:28 -------- d-----w- c:\documents and settings\SysOp\DoctorWeb
2011-02-09 15:37 . 2011-02-09 15:37 -------- d-----w- c:\program files\Unlocker
2011-02-07 15:28 . 2011-02-07 15:28 -------- d-sh--w- c:\documents and settings\SysOp\IECompatCache
2011-02-05 22:50 . 2011-02-09 16:12 -------- d-----w- c:\program files\trend micro
2011-02-01 21:09 . 2011-02-01 21:09 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\RegistryKeys
2011-02-01 13:42 . 2011-02-01 13:42 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\Smart PC Solutions
2011-02-01 13:42 . 2011-02-05 22:49 -------- d---a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
2011-02-01 13:42 . 2011-02-01 13:42 -------- d-----w- c:\program files\Smart PC Solutions
2011-02-01 13:41 . 2011-02-01 13:41 22 --sha-w- c:\windows\Sys3390 SettingsCollection.bin
2011-02-01 13:41 . 2011-02-01 13:41 22 --sha-w- c:\documents and settings\SysOp\Dane aplikacji\Sys6925.Config Collection.sys
2011-02-01 13:38 . 2011-02-01 13:47 -------- d-----w- c:\program files\jv16 PowerTools 2010
2011-01-31 21:33 . 2011-01-31 21:44 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\Uniblue
2011-01-31 21:32 . 2011-01-31 21:32 -------- d-----w- c:\documents and settings\SysOp\Ustawienia lokalne\Dane aplikacji\PackageAware
2011-01-31 21:25 . 2011-01-31 21:29 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\SecTaskMan
2011-01-31 21:25 . 2011-02-10 13:28 -------- d-----w- c:\program files\Security Task Manager
2011-01-31 20:23 . 2011-02-03 21:27 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\HP
2011-01-31 20:21 . 2006-04-13 00:04 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2011-01-31 20:20 . 2006-04-13 00:04 49664 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2011-01-31 20:17 . 2006-01-04 09:12 77824 ----a-r- c:\windows\system32\HPZIDS01.dll
2011-01-31 20:17 . 2006-04-10 13:02 74240 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp054.dll
2011-01-31 20:17 . 2006-04-10 13:03 38400 ----a-w- c:\windows\system32\hpz3l054.dll
2011-01-31 20:17 . 2009-07-12 10:33 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-01-31 20:09 . 2011-01-31 20:09 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\HP
2011-01-31 20:07 . 2011-01-31 20:08 -------- d-----w- c:\program files\Common Files\HP
2011-01-31 20:05 . 2011-01-31 20:05 -------- d-----w- c:\program files\Hewlett-Packard
2011-01-31 20:04 . 2011-01-31 20:04 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2011-01-31 20:01 . 2006-03-03 20:03 282680 ----a-w- c:\windows\system32\HPZidr12.dll
2011-01-31 20:01 . 2006-03-03 20:03 65536 ----a-w- c:\windows\system32\HPZinw12.exe
2011-01-31 20:01 . 2006-03-03 20:03 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2011-01-31 20:01 . 2006-03-03 20:02 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2011-01-31 20:01 . 2006-03-03 20:02 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2011-01-31 20:01 . 2006-03-03 20:02 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2011-01-31 20:00 . 2011-01-31 20:08 -------- d-----w- c:\program files\HP
2011-01-31 19:46 . 2009-07-12 10:33 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-01-31 19:46 . 2008-04-13 21:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-01-31 13:52 . 2011-01-31 13:52 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\Malwarebytes
2011-01-31 13:52 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-31 13:52 . 2011-01-31 13:52 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2011-01-31 13:51 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-31 13:51 . 2011-02-09 19:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-31 13:43 . 2011-01-31 14:01 -------- d-----w- c:\program files\SkanerOnline
2011-01-28 13:38 . 2011-01-28 13:38 -------- d-----w- c:\program files\CCleaner
2011-01-27 14:07 . 2011-01-27 14:55 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2011-01-27 14:07 . 2011-01-27 14:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-27 13:24 . 2011-01-27 13:24 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-01-25 20:19 . 2011-01-25 20:19 214400 ----a-w- c:\windows\system32\dllcache\ndis.sys
2011-01-25 20:19 . 2011-01-25 20:19 43008 ----a-w- c:\windows\system32\goykvkva.exe
2011-01-20 17:00 . 2011-01-20 17:00 -------- d-----w- C:\ProgramData
2011-01-20 16:57 . 2008-09-04 18:17 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-20 16:57 . 2011-01-20 16:57 -------- d-----w- c:\program files\Microsoft WSE
2011-01-20 16:44 . 2011-01-20 16:59 -------- d-----w- c:\program files\Electronic Arts
2011-01-15 13:47 . 2011-01-15 13:47 -------- d-----w- c:\documents and settings\SysOp\Dane aplikacji\Creative
2011-01-12 19:57 . 2011-01-12 19:57 -------- d-----w- c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-28 22:43 . 2010-12-04 22:35 196608 ----a-w- c:\windows\system32\drivers\aStandard.bin
2010-12-17 13:51 . 2010-12-16 14:05 138056 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-12-17 13:51 . 2010-12-16 14:05 138056 ----a-w- c:\documents and settings\SysOp\Dane aplikacji\PnkBstrK.sys
2010-12-17 13:51 . 2010-12-16 14:05 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-12-17 13:50 . 2010-12-16 14:05 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-17 13:50 . 2010-12-16 14:05 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-12-16 20:50 . 2010-12-16 14:05 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-12-16 20:50 . 2010-12-16 20:31 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-12-09 15:36 . 2010-12-09 15:36 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2010-12-09 15:36 . 2010-12-09 15:36 1060864 ----a-w- c:\windows\system32\mfc71.dll
2010-12-04 22:26 . 2010-12-04 22:26 315392 ----a-w- c:\windows\HideWin.exe
.
------- Sigcheck -------
[-] 2009-07-12 . DF70435F3D17C40D5CB15E6DC918342E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-07-12 12:19 . 4678172D19476FA7D539682FCA42C942 . 1420800 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
[-] 2009-07-12 . 335813EACD16E84F3047A3326F6E5473 . 549888 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-07-12 . 37ED43F3DEC4400586554D61C3129478 . 112128 . . [5.4.3790.5512] . . c:\windows\system32\wuauclt.exe
[-] 2009-07-12 . E6C1811BA05F4E4BD4DA437778630489 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-14 . 737739FACEAD60683AA8D7FF7602FD14 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[7] 2001-08-18 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2009-07-12 . BE84B4FE25D1965661172432A6426CDC . 6160896 . . [8.00.6001.22873] . . c:\windows\system32\mshtml.dll
[-] 2009-07-03 . 991C8CDC4C34B65FFC780F49936358FB . 652288 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2009-07-12 . B62213934FDC8B5DC9E6360218043E59 . 1016832 . . [8.00.6001.22873] . . c:\windows\system32\wininet.dll
[-] 2009-03-17 . 36F8D0529ACD765F9A9672A154930997 . 1739776 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2009-07-12 . EB3B4771498DD3FFD97E123643A26D91 . 1312256 . . [5.1.2600.5512] . . c:\windows\system32\ole32.dll
[-] 2009-07-12 . 572B0A653990AFE6B71D38D7DD2F202D . 370688 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
[-] 2009-03-21 . D3B530DD991CD66B97BDC4F5B30CBA00 . 2027520 . . [5.1.2600.5657] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-03-21 . 1350B4234A59717691AAEAF717A46DA5 . 2148864 . . [5.1.2600.5657] . . c:\windows\system32\ntoskrnl.exe
c:\windows\System32\wscntfy.exe ... - brak elementu !!
c:\windows\System32\ctfmon.exe ... - brak elementu !!
c:\windows\System32\regsvc.dll ... - brak elementu !!
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu 10"="c:\program files\Gadu-Gadu 10\gg.exe" [2010-10-07 12661344]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-03 15028104]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-07-12 128512]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu 10\\gg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Program Files\\OGPlanet\\Zone4\\Zone4_NA.exe"=
R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [2002-09-27 22912]
R2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [2002-03-19 36864]
R3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [2010-12-11 178913]
R4 atidgllk;atidgllk;c:\windows\atidgllk.sys [2010-12-04 5376]
S2 eyozxya4ayyteuqi;Crypkey License;c:\windows\system32\woquanno.exe --> c:\windows\system32\woquanno.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-08 136176]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-01-31 38224]
S3 PRISM_USB;D-Link Air Wireless USB Adapter Driver;c:\windows\system32\drivers\PRISMUSB.sys [2003-10-02 666624]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - HELPSVC
.
Zawartość folderu 'Zaplanowane zadania'
2011-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-08 07:43]
2011-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-08 07:43]
2011-02-10 c:\windows\Tasks\User_Feed_Synchronization-{67DDD7E3-2B40-47B3-82F4-D3A5AFE1C362}.job
- c:\windows\system32\msfeedssync.exe [2001-07-22 11:57]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://fullarticles.net
IE: &Winamp Search - c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
FF - ProfilePath - c:\documents and settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar
.
- - - - USUNIĘTO PUSTE WPISY - - - -
URLSearchHooks-{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
HKCU-Run-goykvkva - c:\documents and settings\SysOp\goykvkva.exe
HKCU-Run-PKTray - c:\program files\Przyspiesz Komputer\PKTray.exe
SafeBoot-mkuxabgx.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-10 14:46
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@DenieD: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DenieD: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscui.dll
c:\windows\system32\COMRes.dll
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\setupapi.dll
c:\windows\system32\scecli.dll
c:\windows\system32\psbase.dll
- - - - - - - > 'explorer.exe'(1828)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\LINKINFO.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\ATKKBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\HPZipm12.exe
.
**************************************************************************
.
Czas ukończenia: 2011-02-10 14:49:02 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2011-02-10 13:49
Przed: 23 179 714 560 bajtów wolnych
Po: 23 217 233 920 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
- - End Of File - - 1B40CE8848F37AE8023B4BAD1E689E3C
Cytat:========== OTL ==========
Service eyozxya4ayyteuqi stopped successfully!
Service eyozxya4ayyteuqi deleted successfully!
Error: No service named DwProt was found to stop!
Service\Driver key DwProt not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ not found.
Prefs.js: "Winamp Search" removed from browser.search.defaultenginename
Prefs.js: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" removed from browser.search.defaulturl
Prefs.js: "Winamp Search" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: vshare@toolbar:1.0.0 removed from extensions.enabledItems
Prefs.js: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" removed from keyword.URL
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar\modules folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar\locale\en-US folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar\locale folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar\components folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar\chrome folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\extensions\vshare@toolbar folder moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\g4rr6vmt.default\searchplugins\winamp-search.xml moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\chrome\icons\default folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\chrome\icons folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\goykvkva not found.
File C:\Documents and Settings\SysOp\goykvkva.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\PKTray not found.
Starting removal of ActiveX control {68282C51-9459-467B-95BF-3C0E89627E55}
C:\WINDOWS\Downloaded Program Files\SkanerOnline.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{68282C51-9459-467B-95BF-3C0E89627E55}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55}\ not found.
Starting removal of ActiveX control {D27CDB6E-AE6D-11CF-96B8-444553540000}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Folder move failed. C:\Autorun.inf scheduled to be moved on reboot.
File D:\autorun.inf not found.
File E:\autorun.inf not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c229c7d-fff7-11df-b464-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c229c7d-fff7-11df-b464-806d6172696f}\ not found.
File lpl.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c229c7d-fff7-11df-b464-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c229c7d-fff7-11df-b464-806d6172696f}\ not found.
File lpl.exe not found.
C:\Documents and Settings\SysOp\Dane aplikacji\HhdFJl61DD.txt moved successfully.
C:\WINDOWS\system32\goykvkva.exe moved successfully.
File C:\Documents and Settings\SysOp\goykvkva.exe not found.
C:\Documents and Settings\SysOp\Dane aplikacji\Bgm7fGCGHJ.txt moved successfully.
C:\Documents and Settings\SysOp\Dane aplikacji\IK6fDMGl71.txt moved successfully.
Unable to delete ADS C:\WINDOWS\Temp:temp .
========== COMMANDS ==========
Error: Unable to interpret <[emtytemp] > in the current context!
OTL by OldTimer - Version 3.2.20.6 log created on 02102011_145119
Files\Folders moved on Reboot...
Folder move failed. C:\Autorun.inf scheduled to be moved on reboot.
Registry entries deleted on Reboot...
qrzepa napisał:
Panie moderatorze. w tym momencie nie mam jak zrobić załącznika, usunąłem logi z komputera/ na drugi raz zrobie poprawnie.