UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:Processes
killallprocesses
:OTL
MOD - [2011-10-18 15:30:39 | 000,167,424 | ---- | M] () -- C:\Users\Dzeweta\AppData\Local\Temp\tmp39.exe
MOD - [2011-10-08 02:17:30 | 000,153,600 | -HS- | M] () -- C:\Users\Dzeweta\Network\igfxck32.exe
O4 - HKU\S-1-5-21-980011144-3180161312-1642646373-1000..\Run: [Intel Device Display] C:\Users\Dzeweta\Network\igfxck32.exe ()
O4 - HKU\S-1-5-21-980011144-3180161312-1642646373-1000..\Run: [MSConfig] C:\Users\Dzeweta\tuhar.exe ()
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
[2011-10-18 21:05:58 | 000,000,000 | ---D | C] -- C:\Users\Dzeweta\Desktop\happysad
[2011-10-14 16:17:02 | 000,333,312 | ---- | C] (YourCompany) -- C:\Users\Dzeweta\bm.exe
[2011-10-08 23:13:32 | 000,000,000 | -HSD | C] -- C:\Users\Dzeweta\Network
[2011-10-14 16:15:42 | 000,047,109 | -H-- | M] () -- C:\Users\Dzeweta\userdiff.sav
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.1.25378/26.984; U; pl) Presto/2.8.119 Version/10.54
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
z tego co wiem tdsskiller moze zastapic gmer
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx? ... 909&m=e525
IE - HKU\S-1-5-21-980011144-3180161312-1642646373-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx? ... 909&m=e525
IE - HKU\S-1-5-21-980011144-3180161312-1642646373-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACEW
[2011-10-18 20:42:26 | 000,000,462 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6BBE4691-059D-431A-B0E0-2B3145A0FBBD}.job
:Files
C:\Windows\UA000088.DLL
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WarReg_PopUp"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
kominekl napisał(a):z tego co wiem tdsskiller moze zastapic gmer
Może .
kominekl napisał(a)::Files
C:\Windows\UA000088.DLL
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
mati8898 napisał(a):kominekl napisał(a):z tego co wiem tdsskiller moze zastapic gmer
Może .
No nie do końca, tylko w określonych przypadkach (np. systemy 64-bit, na których Gmer nie działa lub wtedy, gdy są z nim problemy). TDSSKiller nie podaje tylu informacji co Gmer.kominekl napisał(a)::Files
C:\Windows\UA000088.DLL
Ten plik nie jest szkodliwy.
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"="credssp.dll"
:Commands
[reboot]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]