UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
SRV - File not found [Auto | Running] -- -- (HWDeviceService.exe)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
IE - HKU\S-1-5-21-796845957-362288127-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66017
IE - HKU\S-1-5-21-796845957-362288127-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.www.daemon-search.com/default
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2008-02-15 21:50:15 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\uojif8nn.default\searchplugins\daemon-search.xml
O3 - HKU\S-1-5-21-796845957-362288127-725345543-500\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKU\S-1-5-21-796845957-362288127-725345543-500..\Run: [TomTomHOME.exe] "d:\TomTom HOME 2\TomTomHOMERunner.exe" File not found
O33 - MountPoints2\{10f0e0c8-c3e4-11de-b4c0-0013ce7fa646}\Shell\AutoRun\command - "" = F:\q3kku.exe
O33 - MountPoints2\{10f0e0c8-c3e4-11de-b4c0-0013ce7fa646}\Shell\open\Command - "" = F:\q3kku.exe
O33 - MountPoints2\{59856dc6-4b85-11de-b45e-0013ce7fa646}\Shell\AutoRun\command - "" = F:\n68mqcra.exe
O33 - MountPoints2\{59856dc6-4b85-11de-b45e-0013ce7fa646}\Shell\open\Command - "" = F:\n68mqcra.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"KernelFaultCheck"=-
"NeroFilterCheck"=-
"SoundMan"=-
"Media Codec Update Service"=-
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
1. Uruchamiam OTL i wklejam to co dostałem wyżej w odpowiedzi od mati8898 uzyskuje log w formacie OTL.txt oraz Extras.txt
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
mati8898 napisał(a):Dajesz log z usuwania + nowe logi z OTL (wykonaj je wg. tej instrukcjiotl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p107754 i nie zapomnij o Extras.txt) + brakujący log z Gmer
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p88736
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-11-13 21:55:19
Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_HM100JC rev.YN100-08
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pwliqpow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xA9420D5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xA9420BC5]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdePort0 8A3DF1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 8A3DF1F8
Device \Driver\atapi \Device\Ide\IdePort1 8A3DF1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 8A3DF1F8
Device \Driver\ahp0cd13 \Device\Scsi\ahp0cd131 89EE5500
Device \Driver\ahp0cd13 \Device\Scsi\ahp0cd131Port2Path0Target0Lun0 89EE5500
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Ntfs \Ntfs 8A3DE1F8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
---- EOF - GMER 1.0.15 ----
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
W instrucji jest zapis że " może się zdarzyć że zostaniemi poproszeni o wprowadzenie skryptu!
:OTL
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.20110508
[2007-07-26 12:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
O16 - DPF: {3553FF81-A19A-4486-873E-3105287E6975} file://E:\WebPlayer.cab (BackupPlayer Control)
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
:Files
C:\Documents and Settings\All Users\Dane aplikacji\.zreglib
:Reg
[HKEY_USERS\S-1-5-21-796845957-362288127-725345543-500\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników