26 Wrz 2012, 22:08
poniżej zamieszczam logi wykonane w OTL i bardzo proszę o ich interpretacje i wskazówki w razie problemu . 27 Wrz 2012, 14:40
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p120292
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1001\..\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}: "URL" = http://badoo.com/startpage/?source=bsb&q={searchTerms}
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O4 - HKU\S-1-5-21-2334474722-1604631244-297283752-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:A42BB95A2423B939
:Commands
[emptytemp]27 Wrz 2012, 20:57
tutaj podaje nowe logi http://wklej.eu/index.php?id=b83ec9b7f6 oraz http://wklej.eu/index.php?id=aa28001c86 niestety do combofixa nie mam już
wczoraj w południe miałem go zamiar uruchomić ale wersja była nie aktualna xd z jednej strony dobrze bo faktycznie to jest zbyt potężne narzędzie dla laika ... pozdrawiam i jeszcze raz dziękuję
28 Wrz 2012, 12:36
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p138589
30 Wrz 2012, 10:29
30 Wrz 2012, 13:49
Autoruns.
rdpclip
BTMTrayAgent
DellStage
IgfxTray
Persistence
Adobe Reader Speed Launcher
Dell Registration
IAStorIcon
NUSB3MON
RoxWatchTray
Wszystko.
Wszystko.
Wszystko.
Wszystko.
Wszystko.
Wszystko.
Wszystko.
AESTFilters
Bluetooth Device Monitor
Bluetooth Media Service
Bluetooth OBEX Service
cvhsvc
EvtEng
IAStorDataMgrSvc
LMS
NVSvc
nvUpdatusService
ose
osppsvc
RegSrvc
sftlist
SftService
sftvsa
SkypeUpdate
Stereo Service
stllssvr
UNS
WinDefend
wlidsvc
WMPNetworkSvc
Wszystko.
Wszystko.
Wszystko.
Wszystko.
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
Logi.
w oknie Własne opcje skanowania/skrypt wklej::OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1001\..\SearchScopes,DefaultScope = {8A244612-A1F7-11E0-95C0-E71F4824019B}
IE - HKU\S-1-5-21-2334474722-1604631244-297283752-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\ghost\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\ghost\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:A42BB95A2423B939
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:E965A533
:Files
C:\Users\ghost\AppData\Local\Google\Update
C:\Program Files (x86)\TrendMicro
C:\ComboFix
C:\Qoobox
C:\Windows\erdnt
C:\Windows\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]