28 Lis 2010, 19:00
28 Lis 2010, 19:19
Dodam też że USBfix nie działa (error).
:OTL
MOD - [2010-11-28 16:57:15 | 000,118,272 | RHS- | M] () -- C:\WINDOWS\system32\arking0.dll
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\ZDCndis5.SYS -- (ZDCndis5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PCANDIS5.SYS -- (PCANDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MediaCoder\SysInfo.sys -- (CrystalSysInfo)
O4 - HKU\S-1-5-21-1757981266-507921405-1801674531-1003..\Run: [api32] C:\DOCUME~1\JESTEM~1\USTAWI~1\Temp\apiqq.exe File not found
O4 - HKU\S-1-5-21-1757981266-507921405-1801674531-1003..\Run: [dso32] C:\DOCUME~1\JESTEM~1\USTAWI~1\Temp\dsoqq.exe File not found
O4 - HKU\S-1-5-21-1757981266-507921405-1801674531-1003..\Run: [King_ar] C:\WINDOWS\system32\arking.exe ()
O4 - HKU\S-1-5-21-1757981266-507921405-1801674531-1003..\Run: [king_mg] C:\WINDOWS\system32\mgking.exe ()
O4 - HKLM..\RunOnce: [] File not found
O32 - AutoRun File - [2010-11-28 16:43:18 | 000,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-11-28 16:43:18 | 000,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-11-28 16:43:18 | 000,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{08af5004-9bb3-11df-bc11-0060b304c8f2}\Shell\AutoRun\command - "" = H:\wyskq6lt.exe -- File not found
O33 - MountPoints2\{08af5004-9bb3-11df-bc11-0060b304c8f2}\Shell\open\Command - "" = H:\wyskq6lt.exe -- File not found
O33 - MountPoints2\{1fafc8da-9008-11df-bbe9-0060b304c8f2}\Shell\AutoRun\command - "" = H:\12gn6id2.exe -- File not found
O33 - MountPoints2\{1fafc8da-9008-11df-bbe9-0060b304c8f2}\Shell\open\Command - "" = H:\12gn6id2.exe -- File not found
O33 - MountPoints2\{4d48b144-de19-11df-bcce-0060b304c8f2}\Shell\AutoRun\command - "" = H:\apqpm.exe -- File not found
O33 - MountPoints2\{4d48b144-de19-11df-bcce-0060b304c8f2}\Shell\open\Command - "" = H:\apqpm.exe -- File not found
O33 - MountPoints2\{610ea5d0-88f1-11df-bbd1-000ae6085c84}\Shell\AutoRun\command - "" = w9.exe
O33 - MountPoints2\{610ea5d0-88f1-11df-bbd1-000ae6085c84}\Shell\open\Command - "" = w9.exe
O33 - MountPoints2\{64ec4178-8b3d-11df-bbdc-0060b304c8f2}\Shell\AutoRun\command - "" = H:\i00dvoym.exe -- File not found
O33 - MountPoints2\{64ec4178-8b3d-11df-bbdc-0060b304c8f2}\Shell\open\Command - "" = H:\i00dvoym.exe -- File not found
O33 - MountPoints2\{9a1b487a-891f-11df-bbd4-0060b304c8f2}\Shell\AutoRun\command - "" = I:\i8gcgmg.exe -- File not found
O33 - MountPoints2\{9a1b487a-891f-11df-bbd4-0060b304c8f2}\Shell\open\Command - "" = I:\i8gcgmg.exe -- File not found
O33 - MountPoints2\{9c7e5009-e2a7-11df-bcd8-0060b304c8f2}\Shell\AutoRun\command - "" = H:\b9v.exe -- File not found
O33 - MountPoints2\{9c7e5009-e2a7-11df-bcd8-0060b304c8f2}\Shell\open\Command - "" = H:\b9v.exe -- File not found
O33 - MountPoints2\{c162e49e-a090-11d7-bc06-0060b304c8f2}\Shell\AutoRun\command - "" = H:\b9v.exe -- File not found
O33 - MountPoints2\{c162e49e-a090-11d7-bc06-0060b304c8f2}\Shell\open\Command - "" = H:\b9v.exe -- File not found
O33 - MountPoints2\{d650354e-be74-11df-bc71-0060b304c8f2}\Shell\AutoRun\command - "" = H:\12gn6id2.exe -- File not found
O33 - MountPoints2\{d650354e-be74-11df-bc71-0060b304c8f2}\Shell\open\Command - "" = H:\12gn6id2.exe -- File not found
O33 - MountPoints2\{d8b1a366-e4be-11df-bcdd-0060b304c8f2}\Shell\AutoRun\command - "" = I:\egmjjb.exe -- File not found
O33 - MountPoints2\{d8b1a366-e4be-11df-bcdd-0060b304c8f2}\Shell\open\Command - "" = I:\egmjjb.exe -- File not found
O33 - MountPoints2\{d8b1a369-e4be-11df-bcdd-0060b304c8f2}\Shell\AutoRun\command - "" = H:\cbbw88s.exe -- File not found
O33 - MountPoints2\{d8b1a369-e4be-11df-bcdd-0060b304c8f2}\Shell\open\Command - "" = H:\cbbw88s.exe -- File not found
O33 - MountPoints2\{ed6ca306-f020-11df-bd01-0060b304c8f2}\Shell\AutoRun\command - "" = H:\et3ypes.exe -- File not found
O33 - MountPoints2\{ed6ca306-f020-11df-bd01-0060b304c8f2}\Shell\open\Command - "" = H:\et3ypes.exe -- File not found
O33 - MountPoints2\C\Shell\AutoRun\command - "" = C:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O33 - MountPoints2\C\Shell\open\Command - "" = C:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O33 - MountPoints2\D\Shell\open\Command - "" = D:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O33 - MountPoints2\E\Shell\open\Command - "" = E:\w9.exe -- [2010-11-27 20:49:26 | 000,182,272 | RHS- | M] ()
O37 - HKU\S-1-5-21-1757981266-507921405-1801674531-1003\...exe [@ = exefile] -- Reg Error: Key error. File not found
[2010-11-28 16:57:15 | 000,118,272 | RHS- | M] () -- C:\WINDOWS\System32\arking0.dll
[2010-11-28 16:43:27 | 000,182,272 | RHS- | M] () -- C:\WINDOWS\System32\arking.exe
[2010-11-28 16:42:52 | 000,118,784 | RHS- | M] () -- C:\WINDOWS\System32\mgking0.dll
[2010-11-28 16:06:31 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\HPpromotions journeysoftware.job
[2010-11-27 20:49:26 | 000,182,272 | RHS- | M] () -- C:\WINDOWS\System32\mgking.exe
[2010-11-27 20:49:26 | 000,118,784 | RHS- | M] () -- C:\WINDOWS\System32\mgking1.dll
:Files
C:\WINDOWS\system32\arking0.dll
w9.exe /alldrives
:Commands
[emptytemp]
28 Lis 2010, 19:40
28 Lis 2010, 19:58
PS. zapomniałem dodać (o ile to ważne) że ten wirus jest na wszystkich dyskach i nawet na moim pendrivie;/
28 Lis 2010, 20:22
28 Lis 2010, 21:05
problem w tym że pożyczyłem drugiego pendriva koledze;/ i teraz nie moge dodać loga.
:OTL
:Files
H:\RECYCLER
H:\autorun.inf
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"Adobe Reader Speed Launcher"=-
"AdobeCS4ServiceManager"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"E:\PES.2010-KaOs\pes2010.exe"=-
28 Lis 2010, 21:20
28 Lis 2010, 21:34
:OTL
O4 - HKLM..\RunOnce: [] File not found
:Commands
[clearallrestorepoints]
jak wchodzę na strony to często jest awaria wtyczki adobe, często wyskakuje jakiś problem z dźwiękiem i zamiast dźwięków alertu komp pipczy (wiecie o co chodzi) Ale po chwili jest ok.
a co z systemem? bo czasem nieźle zamula;/
28 Lis 2010, 22:05
28 Lis 2010, 22:07
Jak odzyskam pendriva to użyć Flash Disinfector i poprzednie polecenie w cmd i dać loga?
28 Lis 2010, 22:49
28 Lis 2010, 23:15
Not selected for removal.
Wersja bazy: 4052
29 Lis 2010, 19:03
29 Lis 2010, 19:17
:OTL
:Files
H:\yveqsh93.exe
H:\autorun.inf
H:\i00dvoym.exe
29 Lis 2010, 19:49