witam,
mam problem z wirusami. Podaje logi:
malware: http://wklej.to/WNFj
otl: http://wklej.to/PuOR i http://wklej.to/cnDY
gmer sie nie uruchamia...
antywirus co jakis czas wykrywa wirusy od dluzszego czasu.
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
PRC - [2004-08-03 23:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
SRV - File not found [On_Demand | Stopped] -- -- (aspnet_state)
O4 - HKLM..\Run: [MSRegInfo] C:\WINDOWS\pagefile.sys.vbs ()
O4 - HKLM..\Run: [restorer32_a] C:\WINDOWS\System32\restorer32_a.exe File not found
O4 - HKU\S-1-5-21-861567501-152049171-725345543-1003..\Run: [restorer32_a] C:\Documents and Settings\Wlasciciel\restorer32_a.exe File not found
O4 - HKU\S-1-5-21-861567501-152049171-725345543-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe File not found
O32 - AutoRun File - [2009-08-21 13:52:30 | 00,000,353 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-08-21 13:52:30 | 00,000,353 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
:Files
C:\Documents and Settings\Wlasciciel\Menu Start\Programy\Autostart\Adobe Gamma.lnk
C:\bd3q0qix.exe
D:\bd3q0qix.exe
C:\WINDOWS\pagefile.sys.vbs
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"IAAnotif"=-
"RTHDCPL"=-
:Commands
[emptytemp]
[start explorer]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Wlasciciel\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found
O3 - HKU\S-1-5-21-861567501-152049171-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
Zarejestrowani użytkownicy: Bing [Bot]