UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
"DiskMax" = DiskMax 4.56
"Evonsoft Computer Repair_is1" = Evonsoft Computer Repair 1.0
"IObit Security 360_is1" = IObit Security 360
Paket WinMend
Autoruns.
Logi.
:OTL
SRV - File not found [On_Demand | Stopped] -- -- (Uniblue.MaxiDiskSvc)
SRV - File not found [Auto | Stopped] -- -- (Skype C2C Service)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-2025429265-839522115-1708537768-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
[2006-09-26 11:29:29 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\oeef77ys.default\searchplugins\map24_m1.gif
[2006-09-26 11:29:29 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\oeef77ys.default\searchplugins\map24_m1.src
O2 - BHO: (no name) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No CLSID value found.
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:07BF512B
:Files
C:\Documents and Settings\All Users\Dane aplikacji\TEMP
C:\Documents and Settings\user\Dane aplikacji\KoshyJohn.com
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Autoruns.
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Autoruns.
Logi.
:OTL
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
:Files
C:\Documents and Settings\user\Moje dokumenty\AutoRuns.rar
C:\Documents and Settings\user\Moje dokumenty\AutoRuns.arn
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
"{8F45A7FB-2178-41A8-8ECC-1A11589A2DF9}" = ArcaBit Prerequistes
[2012-07-04 12:44:45 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
Logi.
"{AC76BA86-7AD7-1045-7B44-A93000000001}" = Adobe Reader 9.3 - Polish
Kroki Finalizujące.
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
kominekl napisał(a):[2012-07-04 12:44:45 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
Możesz przywrócić. Potem usuń folder.
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
marcos_777 napisał(a):Nie widzę opcji "przywróć". Usunąć po prostu cały folder? Wszystko dobrze działa.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
marcos_777 napisał(a):Ale w kwarantannie te pliki są jakoś zakodowane - inne nazwy i formaty , nie widać tych plików w normalnej postaci, takiej jak w logu wymienione. Zrobiłem nawet ponowne skanowanie i też nie ma dojścia do kwarantanny i opcji opróżnij, przywróć itp.
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Utworzyłem PPS i kasuję ten folder.
UA: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
Zarejestrowani użytkownicy: Bing [Bot]