23 Lis 2011, 21:13
23 Lis 2011, 21:36
:OTL
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab (MainControl Class)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:7E95B6FD
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2BE9FEFC
:Files
C:\WINDOWS\ERUNT
C:\SDFix
C:\Program Files\Trend Micro
C:\Documents and Settings\User01\Ustawienia lokalne\Dane aplikacji\Symantec_Corporation
C:\Documents and Settings\User01\Dane aplikacji\Symantec
C:\WINDOWS\System32\drivers\vproeventmonitor.sys
C:\WINDOWS\System32\drivers\v2imount.sys
C:\Documents and Settings\User01\Pulpit\SDFix1.240.exe
C:\WINDOWS\System32\4234089482.sys
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ControlCenter2.0"=-
:Commands
[clearallrestorepoints]
[emptytemp]
23 Lis 2011, 22:11
23 Lis 2011, 22:15
:OTL
IE - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
O3 - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-1417289158-2933258430-3330087080-1005\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
:Files
C:\Documents and Settings\User01\Ustawienia lokalne\Dane aplikacji\Symantec_Corporation
C:\Documents and Settings\User01\Dane aplikacji\Symantec
C:\WINDOWS\System32\drivers\vproeventmonitor.sys
C:\WINDOWS\System32\drivers\v2imount.sys
:Commands
[clearallrestorepoints]
[emptytemp]
23 Lis 2011, 22:17
23 Lis 2011, 22:18
23 Lis 2011, 22:21
23 Lis 2011, 22:37
24 Lis 2011, 17:56
mati8898 napisał(a):No teraz już nie. Wyciągnij plik 4234089482.sys z kwarantanny OTL (czyli z folderu C:\_OTL ) i wrzuć do folderu C:\WINDOWS\System32
24 Lis 2011, 18:00
24 Lis 2011, 18:36