05 Kwi 2012, 10:58
05 Kwi 2012, 13:58
URUCHOM
i wpisz tam
"c:\users\Damian\Downloads\ComboFix.exe" /uninstall . Następnie podaj logi z OTL
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p107754.
05 Kwi 2012, 15:59
05 Kwi 2012, 17:55
http://www.instalki.pl/programy/downloa ... boFix.html do lokalizacji
C:\Users\Damian\Desktop, a następnie wejdź w START
URUCHOM
i wklej tam
"C:\Users\Damian\Desktop\Combofix.exe" /uninstall
Microsoft Antimalware i Akamai NetSession Interface.
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-824699806-1959797451-325210591-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-824699806-1959797451-325210591-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-824699806-1959797451-325210591-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Damian\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Damian\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
O8:[b]64bit:[/b] - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8:[b]64bit:[/b] - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
:Files
C:\Users\Damian\AppData\Local\Google\Update
$RECYCLE.BIN /alldrives
c:\users\UpdatusUser\AppData\Local\temp
c:\users\Gość\AppData\Local\temp
c:\users\Default\AppData\Local\temp
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk
C:\Windows\tasks\*.job
:Commands
[clearallrestorepoints]
[emptytemp]
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p138589.
05 Kwi 2012, 20:41
06 Kwi 2012, 19:39
AmIcoSinglun64, BCSSync, ETDWare, IgfxTray, Persistence, ATKMEDIA, ATKOSD2, HControlUser HControlUser, NUSB3MON, SunJavaUpdateSched, FancyStart daemon.lnk, Microsoft Wndows, Microsoft Windows, AlcoholAutomount, Sony Ericsson PC Companion, NvCplDesktopContext, Groove GFS Browser Helper, Adobe PDF Link Helper, Groove GFS Browser Helper, Java(tm) Plug-In 2 SSV Helper, Java(tm) Plug-In SSV Helper, wszystko z zakładki
Task Scheduler, nvsvc, nvUpdatusService, WinDefend, catchme, NPPTNT2, PortTalk, qkm, Tosrfcom i X6va003.
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O4 - HKU\S-1-5-21-824699806-1959797451-325210591-1006..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
:Files
$RECYCLE.BIN /alldrives
C:\ComboFix
C:\Windows\ERDNT
C:\Users\Damian\AppData\Roaming\Malwarebytes
C:\ProgramData\Malwarebytes
C:\Users\Damian\Desktop\AutoRuns.arn
:Commands
[clearallrestorepoints]
[emptytemp]07 Kwi 2012, 10:21
07 Kwi 2012, 18:59
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O2:[b]64bit:[/b] - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - Startup: C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2012-04-07 10:07:22 | 000,000,000 | -H-D | M]
:Files
$RECYCLE.BIN /alldrives
C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
:Commands
[clearallrestorepoints]
[emptytemp]
Sprzątanie.
Java(TM) 6 Update 30 i zainstaluj najnowszą
http://www.instalki.pl/programy/downloa ... /Java.html.
Adobe Reader X i zainstaluj najnowszą
http://www.instalki.pl/programy/downloa ... eader.html.
https://www.instalki.pl/download/programy/windows/multimedia/kodeki/k-lite-codec-pack-full/.
https://www.instalki.pl/download/programy/windows/narzedzia/narzedzia-systemowe/ccleaner/.
https://www.instalki.pl/download/programy/windows/bezpieczenstwo/antyspyware/malwarebytes/, jeśli coś znajdzie usuń i daj raport.
08 Kwi 2012, 10:41
08 Kwi 2012, 19:44
:OTL
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O4 - HKU\S-1-5-21-824699806-1959797451-325210591-1007..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
[2012-04-07 19:42:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\v9Soft
:Files
C:\ProgramData\nvwiz.exe