UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UWAGA Jeżeli posiadamy oprogramowanie emulujące napędy takie jak Alkohol, Daemon Tools, AstroBurn itp. przed uruchomieniem narzędzia należy koniecznie wyłączyć ich sterowniki za pomocą Defoggera otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p111852.
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.1.25378/26.1023; U; pl) Presto/2.8.119 Version/10.54
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
IE - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = astroburn-search.com
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2011/07/09 20:08:37 | 000,001,583 | ---- | M] () -- C:\Users\Błaszko\AppData\Roaming\Mozilla\Firefox\Profiles\35ghawhy.default\searchplugins\web-search.xml
O3 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [e-Kiosk] "C:\Program Files\e-Kiosk Reader\eGazetaST.exe" File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun File not found
:Commands
[emptytemp]
sfc /scannow
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
O4 - Startup: C:\Users\Błaszko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KatMouse.lnk = C:\Program Files\KatMouse\KatMouse.exe ()
:OTL
IE - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=smsn
IE - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
FF - prefs.js..browser.startup.homepage: "about:blanck"
[2011/10/25 16:53:14 | 000,001,036 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/25 16:30:01 | 000,001,066 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-604524677-2708395862-3557633927-1000UA.job
[2011/10/25 15:56:07 | 000,001,032 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/25 15:55:53 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2011/10/25 15:33:25 | 000,001,014 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-604524677-2708395862-3557633927-1000Core.job
@Alternate Data Stream - 129 bytes C:\ProgramData\Temp:63238B95
@Alternate Data Stream - 128 bytes C:\ProgramData\Temp:4CF61E54
:Files
C:\Program Files\trend micro
C:\rsit
C:\SDFix
C:\Users\Błaszko\Desktop\RSIT.exe
C:\Users\Błaszko\Desktop\gmer.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Gmail Notifier"=-
"Bonus.SSR.FR10"=-
"NokiaMServer"=-
[HKEY_USERS\S-1-5-21-604524677-2708395862-3557633927-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"NokiaOviSuite2"=-
"OscarEditor"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
blazej_zg napisał(a):Czy ten admuncher tak bardzo przeszkadza?
Bardzo się zżyłem z nim
;]?
Start w wyszukiwarce wpisz cmd.exe i uruchom przez prawoklik - Uruchom jako administrator wpisz polecenie:
sfc /scannow
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
[2011/10/25 20:04:00 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
:Files
C:\Program Files\Astroburn Toolbar
C:\ProgramData\Astroburn Lite
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników