20 Kwi 2013, 20:01
20 Kwi 2013, 20:27
infekcje-plikow-wykonywalnych-t20698.html
http://www.speedyshare.com/yyCZ5/salitykiller.zip
20 Kwi 2013, 20:29
Hej, spokojnie. Dołącz brakujące logi z OTL Extras oraz GMER. Wszystko masz dokładnie wyjaśnione w tych linkach:
-OTLhttp://forum.instalki.pl/otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p107754
-GMERhttp://forum.instalki.pl/otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p88736
Po prostu przeczytaj całe opisy tych programów, i postępuj krok po kroku.
20 Kwi 2013, 21:38
20 Kwi 2013, 21:41
20 Kwi 2013, 22:20
20 Kwi 2013, 22:47
21 Kwi 2013, 12:29
21 Kwi 2013, 13:13
w oknie Własne opcje skanowania/skrypt wklej::OTL
DRV - [2013-04-20 22:35:53 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\utmymtcy.sys -- (utmymtcy)
DRV - [2013-04-20 12:15:05 | 000,475,736 | ---- | M] () [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\7621573drv.sys -- (7621573drv)
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=D83100112FBF3589
FF - prefs.js..browser.search.order.1: "Delta Search"
FF - prefs.js..browser.search.selectedEngine: "Search Here"
FF - prefs.js..browser.startup.homepage: "http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589"
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll File not found
[2013-04-20 12:12:08 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\extensions\[email protected]
[2013-04-20 12:44:06 | 000,006,470 | ---- | M] () -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\searchplugins\BrowserProtect.xml
[2013-04-20 12:45:00 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\searchplugins\delta.xml
[2013-04-20 12:44:06 | 000,006,470 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Java SATARaid.lnk = C:\Program Files\Silicon Image\Java SATARaid\run.bat ()
[2013-04-20 22:07:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Doctor Web
[2013-04-20 12:12:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Menu Start\Programy\BrowserProtect
[2013-04-20 12:12:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BrowserProtect
[2013-04-20 12:11:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2013-04-20 12:11:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Dane aplikacji\Babylon
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\INSTALLO\78.03_XP\setup.exe"=-
"C:\WINDOWS\Explorer.EXE"=-
"D:\INSTALLO\Silverlight.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\fmcn.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\jedsq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\wingeteig.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winywpxc.exe"=-
"D:\INSTALLO\NET\Firefox Setup 9.0.1.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\bnrnla.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\tupkso.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\clovii.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winisqk.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winkqami.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\mtvt.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\qbttf.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\chfsl.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\pfxkc.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\rtbo.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\jtcs.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winwdrse.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winvahayq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\wintncs.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winkqnck.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winlmve.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\mqyvq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\lysw.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\ommhq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\uedhl.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winmryavv.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winkmedkq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winiiwqi.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\vetnax.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winlrilaf.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\oggv.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winyrfro.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\dibeo.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winhgmk.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\mlnmv.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\wineyeg.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winfkxteu.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winreiwjk.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winorufv.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winoqgde.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winwvmhn.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\dtdpuq.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\qsiaof.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\winoumsm.exe"=-
"C:\DOCUME~1\dk\USTAWI~1\Temp\eodj.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
http://forum.instalki.pl/otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p88736
21 Kwi 2013, 13:36
21 Kwi 2013, 13:58
21 Kwi 2013, 14:14
. Będzie się wtedy łatwiej w tym połapać. Teraz już za późno bo, już chyba nie jesteś w stanie tych wiadomości usunąć, ale to tak na przyszłość.
,21 Kwi 2013, 18:36
:OTL
DRV - [2013-04-20 22:35:53 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\utmymtcy.sys -- (utmymtcy)
DRV - [2013-04-20 12:15:05 | 000,475,736 | ---- | M] () [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\7621573drv.sys -- (7621573drv)
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589
IE - HKU\S-1-5-21-1220945662-1580818891-839522115-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=D83100112FBF3589
FF - prefs.js..browser.search.order.1: "Delta Search"
FF - prefs.js..browser.search.selectedEngine: "Search Here"
FF - prefs.js..browser.startup.homepage: "http://www1.delta-search.com/?affID=119370&babsrc=HP_ss&mntrId=D83100112FBF3589"
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll File not found
[2013-04-20 12:12:08 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\extensions\[email protected]
[2013-04-20 12:44:06 | 000,006,470 | ---- | M] () -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\searchplugins\BrowserProtect.xml
[2013-04-20 12:45:00 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\dk\Dane aplikacji\Mozilla\Firefox\Profiles\illgn7mh.default\searchplugins\delta.xml
[2013-04-20 12:44:06 | 000,006,470 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Java SATARaid.lnk = C:\Program Files\Silicon Image\Java SATARaid\run.bat ()
[2013-04-20 22:07:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Doctor Web
[2013-04-20 12:12:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Menu Start\Programy\BrowserProtect
[2013-04-20 12:12:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BrowserProtect
[2013-04-20 12:11:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2013-04-20 12:11:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\dk\Dane aplikacji\Babylon
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.16.16\deltaTlbr.dll (Delta-search.com)
:Files
C:\Program Files\Delta
:Commands
[reboot]
21 Kwi 2013, 19:33
21 Kwi 2013, 20:06
otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p139531 z opcji Usuń i podaj utworzony log.