26 Gru 2012, 21:52
26 Gru 2012, 22:14
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=110824&tt=4212_5&babsrc=HP_ss&mntrId=b01c0588000000000000000bcd467543
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110824&tt=4212_5&babsrc=SP_ss&mntrId=b01c0588000000000000000bcd467543
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=3F9B06C7-2564-46EC-B933-C647DCDC82CF&apn_sauid=2242D6B7-37DB-4357-94B1-9EE545D2C303
SRV - [2008-04-14 21:50:36 | 000,161,768 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\mlgrfi.dll -- (ddczwg)
O4 - HKU\S-1-5-21-1957994488-573735546-842925246-1003..\Run: [MSConfig] C:\Documents and Settings\Biały\emog.exe (TODO: <Название компании>)
:Files
RECYCLER /alldrives
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3250:TCP"=-
:Commands
[clearallrestorepoints]
[emptytemp]
netsvcs
26 Gru 2012, 22:26
26 Gru 2012, 22:31
:OTL
O4 - HKCU..\Run: [MSConfig] C:\Documents and Settings\Biały\emog.exe (TODO: <Название компании>)
:Commands
[reboot]
26 Gru 2012, 22:45
26 Gru 2012, 22:58
Files to delete:
C:\Documents and Settings\Biały\emog.exe
Potwierdzasz i zgadzasz się na restart klikając OK.:OTL
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-
26 Gru 2012, 23:11
26 Gru 2012, 23:17
Sprzątanie
http://www.instalki.pl/programy/downloa ... _8_XP.html27 Gru 2012, 00:11
27 Gru 2012, 00:28
http://www.instalki.pl/programy/downloa ... virus.html
http://www.instalki.pl/programy/downloa ... virus.html
http://www.instalki.pl/programy/downloa ... virus.html