UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
na koniec użyłem combofixa
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\DOCUME~1\Gadoms\USTAWI~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (afj47j4l)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-06-20 18:16:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\bfcbpmhrqtvnyms
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"NvMediaCenter"=-
"nwiz"=-
:Commands
[clearallrestorepoints]
[emptytemp]
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Gadom\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a6qicsl1)
IE - HKLM\..\SearchScopes\{A2074458-380E-47E0-AFB9-CE17DCDF728E}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=1cf3a220-1391-11e1-b8c8-00241d64dbf3&q={searchTerms}
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=PV&apn_dtid=YYYYYYYYPL&apn_uid=AEAE3388-0931-414D-B554-89065D429FF0&apn_sauid=29A8834D-6306-4F89-AAE3-85A87284C762
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{98DDD4C2-082D-48D3-BE73-8B5253DB207C}: "URL" = http://www3.iamwired.net/websearch.php?src=tops&search={SearchTerms}
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{A2074458-380E-47E0-AFB9-CE17DCDF728E}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=1cf3a220-1391-11e1-b8c8-00241d64dbf3&q={searchTerms}
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1235542836-933740508-3956609943-1001\..\SearchScopes\{DA497415-AA98-4A5A-B897-F76D380E0ADE}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=382950&p={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=382950&p="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-03-03 17:18:56 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM
[2012-03-03 17:18:56 | 000,000,000 | ---D | M] (IObit Toolbar) -- C:\PROGRAM FILES\IOBIT TOOLBAR\FF
[2012-02-12 22:46:57 | 000,275,540 | ---- | M] () (No name found) --
[2011-10-03 11:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-01-23 15:01:17 | 000,000,000 | ---D | M] -- C:\Users\Gadom\AppData\Roaming\x2svyttytzmcvie1hkmbmha3marmk3lc2
[2011-01-26 16:57:08 | 000,000,000 | ---D | M] -- C:\Users\Gadom\AppData\Roaming\xuqyyxmeupaed2giruqghf2udd1dmsha2
[2011-04-28 00:22:16 | 000,000,000 | ---D | M] -- C:\Users\Gadom\AppData\Roaming\zrksqj3k1wfwuqgmcynrgc1gemtu1pc2
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\Gadom\AppData\Roaming\x2svyttytzmcvie1hkmbmha3marmk3lc2\svcnost.exe"=-
"C:\Users\Gadom\AppData\Roaming\xuqyyxmeupaed2giruqghf2udd1dmsha2\svcnost.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
Radze się zapoznać z tym otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967.html#p73687
Pobierz ten plik http://www.dlldump.com/dllfiles/W/wuauserv.dll i wrzuć do folderu C:\WINDOWS\system32
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
Mam pytanie co do DAEMON Tools Toolbar, bo w końcu to program który umożliwia uruchamianie wirtualnych dysków a jednak miałem go usunąć czemu ?
Java(TM) 6 Update 22
Adobe Reader 9.1 - Polish
Java(TM) 6 Update 29
Adobe Reader 9.4.5 - Polish
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników