Uruchom
OTL w oknie
Własne opcje skanowania/skrypt wklej:
:Processes
killallprocesses
:OTL
MOD - [2011-10-30 21:48:41 | 000,344,576 | ---- | M] () -- C:\WINDOWS\update.5.0\svchost.exe
MOD - [2011-10-30 21:47:10 | 001,942,528 | ---- | M] () -- C:\WINDOWS\update.2\svchost.exe
MOD - [2011-10-30 21:44:12 | 000,258,048 | ---- | M] () -- C:\WINDOWS\sysdriver32.exe
SRV - [2011-10-30 21:48:41 | 000,344,576 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.5.0\svchost.exe -- (srvbtcclient)
SRV - [2011-10-30 21:47:10 | 001,942,528 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.2\svchost.exe -- (srviecheck)
SRV - [2011-10-30 21:44:12 | 000,258,048 | ---- | M] () [Auto | Running] -- C:\WINDOWS\sysdriver32.exe -- (srvsysdriver32)
SRV - [2011-10-30 21:26:27 | 001,204,736 | -H-- | M] (Cronosoft) [Auto | Running] -- C:\WINDOWS\update.1\svchost.exe -- (wxpdrivers)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll File not found
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O4 - HKLM..\Run: [3339107.exe] C:\Documents and Settings\User\Ustawienia lokalne\Temp\3339107.exe ()
O4 - HKLM..\Run: [5621382.exe] C:\WINDOWS\TEMP\5621382.exe ()
O4 - HKLM..\Run: [6298131.exe] C:\WINDOWS\TEMP\6298131.exe ()
O4 - HKLM..\Run: [7906872.exe] C:\WINDOWS\TEMP\7906872.exe ()
O4 - HKLM..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe File not found
O4 - HKLM..\Run: [sysdriver32.exe] C:\WINDOWS\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\WINDOWS\sysdriver32_.exe ()
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico0] C:\WINDOWS\update.tray-12-0\svchost.exe (Cronosoft)
O4 - HKLM..\Run: [tray_ico1] C:\WINDOWS\update.tray-7-0\svchost.exe (Cronosoft)
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKLM..\Run: [wxpdrv] C:\WINDOWS\services32.exe (Cronosoft)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll File not found
[2011-11-01 11:31:05 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-7-0-lnk
[2011-11-01 11:31:05 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-7-0
[2011-10-30 21:50:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011-10-30 21:50:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\rpcminer
[2011-10-30 21:50:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\phoenix
[2011-10-30 21:48:42 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.5.0
[2011-10-30 21:47:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.2
[2011-10-30 21:43:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\av_ico
[2011-10-30 21:42:33 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.1
[2011-10-30 21:42:14 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-12-0-lnk
[2011-10-30 21:42:14 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-12-0
[2011-11-01 11:46:49 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011-10-30 21:50:25 | 005,589,370 | ---- | M] () -- C:\WINDOWS\phoenix.rar
[2011-10-30 21:50:25 | 000,246,272 | ---- | M] () -- C:\WINDOWS\unrar.exe
[2011-10-30 21:50:25 | 000,182,617 | ---- | M] () -- C:\WINDOWS\ufa.rar
[2011-10-30 21:50:24 | 001,075,284 | ---- | M] () -- C:\WINDOWS\rpcminer.rar
[2011-10-30 21:50:11 | 000,000,113 | ---- | M] () -- C:\WINDOWS\info1
[2011-10-30 21:47:11 | 000,904,792 | ---- | M] () -- C:\WINDOWS\geoiplist.rar
[2011-10-30 21:46:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
:Files
C:\WINDOWS\update.2
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\User\Moje dokumenty\Pobieranie\Flash-Player.exe"=-
"C:\WINDOWS\update.1\svchost.exe"=-
"C:\WINDOWS\update.1\svchost.exe" = C:\WINDOWS\update.1\svchost.exe:*:Enabled:C:\WINDOWS\update.1\svchost.exe -- (Cronosoft)
"C:\WINDOWS\update.tray-12-0\svchost.exe"=-
"C:\WINDOWS\update.2\svchost.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt. Następnie usuń resztki po AVG i Avaście, gdyż wyglądają na "uwalone", posłuż się tymi narzędziami:
Avast
http://www.instalki.pl/programy/downloa ... ility.html (uruchamiasz w trybie awaryjnym)
AVG
http://download.avg.com/filedir/util/av ... 2_1796.exePo wykonaniu powyższych podaj nowe logi z OTL robione opcją
Skanuj.