01 Lip 2012, 22:37
01 Lip 2012, 23:09
:OTL
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [c4dU5nsvHkbsaiW] C:\Documents and Settings\rgolebiowski\Dane aplikacji\43euyh45wsuw.exe ()
O4 - HKLM..\Run: [eAgent PrintMonitor] File not found
O4 - HKU\administrator.RMIZOMAR_ON_C..\Run: [] File not found
O4 - HKU\Administrator_ON_C..\Run: [] File not found
O4 - HKU\rgolebiowski_ON_C..\Run: [] File not found
O4 - HKU\rgolebiowski_ON_C..\Run: [c4dU5nsvHkbsaiW] C:\Documents and Settings\rgolebiowski\Dane aplikacji\43euyh45wsuw.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\hpzrcv01.LNK = File not found
O7 - HKU\rgolebiowski_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\rgolebiowski_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O32 - AutoRun File - [2004/04/30 11:01:00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ]
[2012/07/01 13:24:42 | 000,114,688 | ---- | C] (SoftThinks) -- C:\WINDOWS\System32\chg.exe
[2012/07/01 13:24:57 | 000,034,576 | ---- | M] () -- C:\WINDOWS\System32\drivers\WPRO_41_1879.sys
[2012/06/29 05:46:03 | 000,208,384 | ---- | M] () -- C:\Documents and Settings\rgolebiowski\Dane aplikacji\43euyh45wsuw.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
"Shell"="explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"=-
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\administrator.RMIZOMAR_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
"Shell"=-
[HKEY_USERS\rgolebiowski_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\rgolebiowski_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"=-
:Commands
[clearallrestorepoints]
[emptytemp]
03 Lip 2012, 17:48
03 Lip 2012, 19:43
:OTL
SRV - File not found [Auto | Running] -- C:\Program Files\Btc\eAudytor\eAgent\Bin\eAgentInternal.exe )##'Az'@F2.0sM# -- (agent2)
DRV - File not found [Kernel | Disabled | Stopped] -- a -- (vsdatant)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\TEMP\cpuz132\cpuz132_x32.sys -- (cpuz132)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\Software\MozillaPlugins\@vividas.com/npVividasPlayer: C:\Program Files\Vividas\Player\npVividasPlayer.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\rgolebiowski\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\rgolebiowski\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
O4 - HKLM..\Run: [eAgent PrintMonitor] "C:\Program Files\Btc\eAudytor\eAgent\Bin\eAgentPm.exe" 0.05 "C:\Program Files\Btc\eAudytor\eAgent\Bin\params.ini" File not found
O15 - HKCU\..Trusted Domains: epm ([]http in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199378103843 (MUWebControl Class)
O16 - DPF: {E3089160-E8AD-4C5B-B47C-ADDF3DF660DD} http://epm/PWA/_layouts/pwa/objects/pjclient.cab (PjAdoInfo4 Class)
O16 - DPF: {EBC0768D-D8D6-40F4-A100-C28D36FB00A5} http://epm/PWA/_layouts/pwa/objects/1045/pjcintl.cab (PJ12plkC Class)
:Files
C:\Program Files\Vividas
C:\Documents and Settings\rgolebiowski\Ustawienia lokalne\Dane aplikacji\Google\Update
C:\Documents and Settings\rgolebiowski\Dane aplikacji\Malwarebytes
C:\WINDOWS\TEMP
C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
C:\WINDOWS\System32\drivers\mbam.sys
C:\Program Files\Malwarebytes' Anti-Malware
C:\WINDOWS\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[-
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{69333A04-5134-40A5-A055-9166A7AA1EC8}]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
03 Lip 2012, 21:38
:OTL
SRV - File not found [Auto | Running] -- C:\Program Files\Btc\eAudytor\eAgent\Bin\eAgentInternal.exe )##'Az'@F2.0sM# -- (agent2)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\TEMP\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | Disabled | Stopped] -- a -- (vsdatant)
O4 - HKLM..\Run: [eAgent PrintMonitor] "C:\Program Files\Btc\eAudytor\eAgent\Bin\eAgentPm.exe" 0.05 "C:\Program Files\Btc\eAudytor\eAgent\Bin\params.ini" File not found
[2012-07-02 22:12:35 | 000,034,576 | ---- | M] () -- C:\WINDOWS\System32\drivers\WPRO_41_1879.sys
[2012-07-02 22:12:21 | 000,114,688 | ---- | M] (SoftThinks) -- C:\WINDOWS\System32\chg.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
:Commands
[emptytemp]
[clearallrestorepoints]
03 Lip 2012, 21:53
W powyższym skrypcie są błędy.
03 Lip 2012, 22:07
03 Lip 2012, 22:10
03 Lip 2012, 23:08
03 Lip 2012, 23:15
03 Lip 2012, 23:24
04 Lip 2012, 17:29
:OTL
:Services
WPRO_41_1879
Java(TM) SE Runtime Environment 6
Adobe Reader 6.0.2 CE
09 Lip 2012, 10:00