UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") -C:\WINDOWS\System32\sysdm.cpl (cr1t1cal)
:Processes
killallprocesses
:OTL
MOD - [2011-08-09 23:18:20 | 001,018,880 | ---- | M] () -- C:\Documents and Settings\All Users\My applications\lua8.exe
O4 - HKU\S-1-5-21-343818398-2049760794-1644491937-1001..\Run: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\My applications\lua8.exe ()
O8 - Extra context menu item: ????3?? - Reg Error: Value error. File not found
O8 - Extra context menu item: ????3?????? - Reg Error: Value error. File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
@Alternate Data Stream - 111 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:010ADD2C
:Files
C:\WINDOWS\System32\secustat.dat
C:\WINDOWS\System32\secushr.dat
C:\dk2.mem
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
c:\documents and settings\SysOp\Pulpit\mexiliamt2\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\documents and settings\SysOp\Pulpit\mexiliamt2\pack\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\documents and settings\SysOp\Pulpit\Rozne\metin5.s2.07.02.2011\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\documents and settings\SysOp\Pulpit\Rozne\metin5.s2.07.02.2011\pack\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\documents and settings\SysOp\Pulpit\Rozne\mexiliamt2\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\documents and settings\SysOp\Pulpit\Rozne\mexiliamt2\pack\metin2.bin (Trojan.Agent) Quarantined and deleted successfully.
c:\program files\counter-strike\platform\Admin\adminserver.dll (Malware.Packer.Gen) Quarantined and deleted successfully.
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
Powtórz usuwanie skryptem w trybie awaryjnym
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
kominekl napisał(a):Uruchom OTL w oknie Własne opcje skanowania/skrypt wklej::Processes
killallprocesses
:OTL
O4 - HKU\S-1-5-21-343818398-2049760794-1644491937-1001..\Run: [] File not found
O8 - Extra context menu item: ????3?? - Reg Error: Value error. File not found
O8 - Extra context menu item: ????3?????? - Reg Error: Value error. File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
@Alternate Data Stream - 111 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:010ADD2C
:Files
C:\WINDOWS\System32\secustat.dat
C:\WINDOWS\System32\secushr.dat
C:\dk2.mem
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podajesz nowe logi z OTL.
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
:OTL
O4 - HKLM..\RunOnce: [InnoSetupRegFile.0000000001] C:\WINDOWS\is-GCC1S.exe ()
:Files
C:\WINDOWS\is-GCC1S.msg
C:\WINDOWS\is-GCC1S.lst
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20100101 Firefox/7.0
[HKEY_USERS\S-1-5-21-343818398-2049760794-1644491937-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=-
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]