04 Paź 2011, 18:12
:Processes
killallprocesses
:OTL
MOD - [2007-09-20 12:11:04 | 000,135,168 | ---- | M] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\svchost.exe
IE - HKU\S-1-5-21-839522115-2025429265-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2786678
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found
O3 - HKU\S-1-5-21-839522115-2025429265-1606980848-500\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [SoundMax] C:\Documents and Settings\Administrator\userinit.exe ()
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6CC69D3C
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Office Update.lnk
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
04 Paź 2011, 19:56
05 Paź 2011, 18:06
Java(TM) 6 Update 24
Adobe Reader 9.4.0 - Polish
01 Lis 2011, 23:09
01 Lis 2011, 23:24
01 Lis 2011, 23:25
02 Lis 2011, 18:43
:OTL
SRV - File not found [On_Demand | Stopped] -- -- (ALG)
IE - HKU\.DEFAULT\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-20\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-682003330-1592454029-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.xpblackedition.ubf.pl/
IE - HKU\S-1-5-21-682003330-1592454029-1417001333-500\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
O32 - AutoRun File - [2011-11-01 20:33:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
:Services
ALG
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-
:Commands
[clearallrestorepoints]
[emptytemp]
02 Lis 2011, 20:33
:OTL
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-20\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-682003330-1592454029-1417001333-500\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
O32 - AutoRun File - [2011-07-20 23:45:09 | 000,000,301 | RH-- | M] () - D:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\AutoPlay\Command - "" = autoply.exe OPEN
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\AutoRun\command - "" = autoply.exe OPEN
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\explore\Command - "" = autoply.exe EXPLORE
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\open\Command - "" = autoply.exe OPEN
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-
:Commands
[clearallrestorepoints]
[emptytemp]
02 Lis 2011, 20:59
mati8898 napisał(a):Źle, źle i jeszcze raz ŹLE. Powyższy skrypt usuwa prawidłowe wpisy i pliki, a nie usuwa tego co szkodliwe.
Skrypt powinien wyglądać tak::OTL
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-20\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-682003330-1592454029-1417001333-500\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
O32 - AutoRun File - [2011-07-20 23:45:09 | 000,000,301 | RH-- | M] () - D:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\AutoPlay\Command - "" = autoply.exe OPEN
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\AutoRun\command - "" = autoply.exe OPEN
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\explore\Command - "" = autoply.exe EXPLORE
O33 - MountPoints2\{b3b663f1-04c5-11e1-835a-806d6172696f}\Shell\open\Command - "" = autoply.exe OPEN
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Dodatkowo pobierz ten plikhttp://hotfile.com/dl/111489395/f30c1a1/alg.exe.html i wrzuć do folderu C:\WINDOWS\System32
Z podłączonymi pamięciami przenośnymi użyj UsbFix z opcji Listing i podaj utworzony log.
02 Lis 2011, 23:03
03 Lis 2011, 16:16