UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) Not selected for removal.
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) Not selected for removal.
e:\metin2_connect_changer1.7.2\metin2_connect_changer\m2.bin (Trojan.Downloader) Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) Bad: (1) Good: (0) Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) Bad: (1) Good: (0) Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) Bad: (1) Good: (0) Quarantined and deleted successfully.
c:\Ghost.bat (Worm.Wukill) Quarantined and deleted successfully.
d:\Ghost.bat (Worm.Wukill) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP148\A0040896.exe (Trojan.Downloader) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP148\A0040922.exe (Trojan.Downloader) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP148\A0040953.exe (Trojan.Downloader) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP162\A0044609.exe (Trojan.Downloader) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP162\A0045062.exe (Trojan.Downloader) Quarantined and deleted successfully.
d:\system volume information\_restore{d03c5659-f535-4196-b3f8-0cc2f7819b53}\RP162\A0045098.exe (Malware.Packer.Gen) Quarantined and deleted successfully.
e:\Ghost.bat (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Kufel\Kufel.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Murzyny\Murzyny.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Murzyny\car audio\car audio.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Muza\Muza.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\nowe\nowe.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Nuta\Nuta.exe (Worm.Wukill) Quarantined and deleted successfully.
e:\Muzyka\abc\Różne\Różne.exe (Worm.Wukill) Quarantined and deleted successfully.
c:\WINDOWS\system32\d3d10_1.dll (Trojan.FakeAlert) Quarantined and deleted successfully.
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
powod dlaczego wyłaczylem malware ? prawie wszystko mi blokuje, np na internecie to nawet to forum mi blokuje.
znowu wszystkie te pliki co były GY to wróciły, nie tylko w steam ale tez tak gdzie były, np starcraft na pulpicie to z photoscape itp.
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
a i nie wiem czego ale co jakis czas mi sie OTL.exe usuwa i GMER tez
chciałem rozpakować to oczywiscie instalka winrara tez sie zamieniła w .gy ...
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
[2011-10-12 10:29:04 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Documents and Settings\aa\Dane aplikacji\Mozilla\Firefox\Profiles\107oomwh.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=100842&mntrId=187e4142000000000000001bfcc56918
O4 - HKLM..\Run: [TempCom] C:\WINDOWS\Fonts\CEF2D.com (gy)
[2009-04-28 09:48:53 | 000,057,344 | -H-- | C] (gy) -- C:\Program Files\Program Files.exe
[2009-04-28 09:48:53 | 000,057,344 | -H-- | C] (gy) -- C:\Program Files\Common Files\Common Files.exe
[2011-10-14 12:14:57 | 000,000,943 | -HS- | M] () -- C:\Program Files\folder.htt
[2011-10-14 12:14:57 | 000,000,937 | -HS- | M] () -- C:\folder.htt
[2011-10-14 12:14:57 | 000,000,937 | ---- | M] () -- C:\NetHood.htm
[2011-10-14 08:27:43 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1214440339-1078081533-725345543-1004.job
[2011-10-12 10:29:09 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1214440339-1078081533-725345543-1004.job
[2011-10-05 20:32:29 | 1811,792,527 | ---- | M] () -- C:\UsbFix_Upload_Me_AA-C2B3FBFFC6AD.zip
:Files
D:\Steam\steamapps\koszula7\koszula7.exe
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]