
OTL:
http://wklej.eu/index.php?id=584520b6ba
http://www.wklej.eu/index.php?id=be530adac7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.17) Gecko/20110420 Firefox/3.6.17
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
MOD - [2011-12-03 13:59:06 | 000,192,512 | ---- | M] () -- C:\Users\media\AppData\Local\Temp\sfamcc00001.dll
MOD - [2011-12-03 13:59:06 | 000,172,032 | ---- | M] () -- C:\Users\media\AppData\Local\Temp\sfareca00001.dll
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=83&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=83&bd=Pavilion&pf=cnnb
IE - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=83&bd=Pavilion&pf=cnnb
IE - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2.0185
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=UT2V5&o=15158&locale=en_US&apn_uid=E2713A6C-A361-4094-B535-D8B4D085C724&apn_ptnrs=UG&apn_sauid=06FAB986-2209-4DD5-83FF-04EC4185BEDC&apn_dtid=&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2010-05-12 20:30:29 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\media\AppData\Roaming\mozilla\Firefox\Profiles\h5d0wi5t.default\extensions\[email protected]
[2010-12-15 19:41:12 | 000,002,559 | ---- | M] () -- C:\Users\media\AppData\Roaming\Mozilla\Firefox\Profiles\h5d0wi5t.default\searchplugins\askcom.xml
[2010-05-12 20:30:08 | 000,002,059 | ---- | M] () -- C:\Users\media\AppData\Roaming\Mozilla\Firefox\Profiles\h5d0wi5t.default\searchplugins\daemon-search.xml
[2009-10-04 22:36:04 | 000,001,632 | ---- | M] () -- C:\Users\media\AppData\Roaming\Mozilla\Firefox\Profiles\h5d0wi5t.default\searchplugins\weathercom.xml
[2009-04-07 17:51:15 | 000,000,000 | ---D | M] (G DATA WebFilter) -- C:\Program Files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
[2011-01-04 16:15:26 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O8 - Extra context menu item: &Wyszukiwarka na pasku narzędzi AOL - C:\ProgramData\AOL\ieToolbar\resources\pl-PL\local\search.html ()
O20 - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000 Winlogon: Shell - (C:\Users\media\AppData\Roaming\sjlp.exe) - File not found
@Alternate Data Stream - 64 bytes -> C:\Users\media\Desktop\091208_Marseille-Real_1-3_.avi:TOC.WMV
:Files
C:\Users\media\AppData\Local\Temp*.html
C:\Program Files\Lavasoft
C:\ProgramData\Lavasoft
C:\Users\media\AppData\Roaming\Malwarebytes
C:\Program Files\Trend Micro
C:\ProgramData\Malwarebytes
C:\Windows\tasks\HPCeeScheduleFormedia.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Health Check Scheduler"=-
"StartCCC"=-
"SysTrayApp"=-
"Windows Defender"=-
"Windows Mobile-based device management"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
'WindowsWelcomeCenter"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
'WindowsWelcomeCenter"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.17) Gecko/20110420 Firefox/3.6.17
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
DRV - [2008-01-29 09:38:08 | 000,039,544 | ---- | M] (G DATA Software Sp. z o.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\GLogin.sys -- (GLogin)
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.0
O3 - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1331116099-1105675598-2705616807-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
:Files
C:\Windows\System32\drivers\GLogin.sys
C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\[email protected]
C:\Users\media\AppData\Roaming\QuickStoresToolbar
C:\Windows\tasks\Ad-Aware Update (Weekly).job
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.17) Gecko/20110420 Firefox/3.6.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
Wypadałoby przede wszystkim podać brakujący log z Gmerotl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p88736
Nie można tego tak po prostu "olewać", bo w OTL ewentualnych rootkitów nie zobaczymy.
:OTL
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
:Reg
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
mati8898 napisał(a):To autor tematu ma dosyć dziwne podejście do sprawy, skoro połowę sprawy załatwia tu, a połowę gdzieś na PW. Już nie wspomnę o pkt. 7 regulaminu działu. Tak się po prostu nie robi, nikt tu w zgadywanki się bawił nie będzie.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:8.0.1) Gecko/20100101 Firefox/8.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
Zarejestrowani użytkownicy: Bing [Bot]