log z Gmera robiony w nieodpowiednich warunkach :
[Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
poczytaj
programy emulujące napędypamiętać o tym prosze, i log dajemy nie w formie screena tylko tak jak inne do tematu
w dodaj usuń programy odinstaluj śmiecia :
DAEMON Tools ToolbarUruchom OTL i w oknie Custom Scans/Fixes wklej :
:OTL
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\QBAQ.QBAQ-1514A32D52\Ustawienia lokalne\Temp\herss.exe ()
O4 - HKCU..\Run: [dso32] C:\Documents and Settings\QBAQ.QBAQ-1514A32D52\Ustawienia lokalne\Temp\dsoqq.exe ()
O4 - HKCU..\Run: [Steam] D:\GRY\CS\Steam.exe File not found
O20 - HKLM Winlogon: Shell - (%WINDIR%\system32\drivers\btwdins.exe) - C:\WINDOWS\System32\drivers\btwdins.exe File not found
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-6330451624-1477560941-457882538-9807\nissan.exe) - C:\RECYCLER\S-1-5-21-6330451624-1477560941-457882538-9807\nissan.exe File not found
O32 - AutoRun File - [2010-05-20 12:04:27 | 000,000,055 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-05-20 12:04:27 | 000,000,055 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-05-20 12:04:28 | 000,000,055 | RHS- | M] () - H:\autorun.inf -- [ FAT ]
O33 - MountPoints2\{23288d4b-f3c8-11de-9711-4d6564696130}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\runshell.exe -- [2009-11-01 15:51:24 | 000,076,800 | RHS- | M] ()
O33 - MountPoints2\{23288d4b-f3c8-11de-9711-4d6564696130}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\runshell.exe -- [2009-11-01 15:51:24 | 000,076,800 | RHS- | M] ()
O33 - MountPoints2\{444a2805-d91a-11de-8b11-806d6172696f}\Shell\AutoRun\command - "" = C:\k8jc.exe -- [2009-12-06 13:38:56 | 000,115,688 | RHS- | M] ()
O33 - MountPoints2\{444a2805-d91a-11de-8b11-806d6172696f}\Shell\open\Command - "" = C:\k8jc.exe -- [2009-12-06 13:38:56 | 000,115,688 | RHS- | M] ()
O33 - MountPoints2\{444a2806-d91a-11de-8b11-806d6172696f}\Shell\AutoRun\command - "" = D:\k8jc.exe -- [2009-12-06 13:38:56 | 000,115,688 | RHS- | M] ()
O33 - MountPoints2\{444a2806-d91a-11de-8b11-806d6172696f}\Shell\open\Command - "" = D:\k8jc.exe -- [2009-12-06 13:38:56 | 000,115,688 | RHS- | M] ()
O33 - MountPoints2\{5e062353-e979-11de-96e5-4d6564696130}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\runshell.exe -- [2009-11-01 15:51:24 | 000,076,800 | RHS- | M] ()
O33 - MountPoints2\{5e062353-e979-11de-96e5-4d6564696130}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\runshell.exe -- [2009-11-01 15:51:24 | 000,076,800 | RHS- | M] ()
O33 - MountPoints2\{7332030b-ee33-11de-96f7-4d6564696130}\Shell\AutoRun\command - "" = H:\KLIZAVI/sapun.exe -- [2009-12-18 13:51:14 | 000,145,408 | RHS- | M] ()
O33 - MountPoints2\{7332030b-ee33-11de-96f7-4d6564696130}\Shell\explore\command - "" = H:\KLIZAVI/sapun.exe -- [2009-12-18 13:51:14 | 000,145,408 | RHS- | M] ()
O33 - MountPoints2\{7332030b-ee33-11de-96f7-4d6564696130}\Shell\open\command - "" = H:\KLIZAVI/sapun.exe -- [2009-12-18 13:51:14 | 000,145,408 | RHS- | M] ()
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:C74D7A47
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:436DEE1E
:Files
C:\autorun.inf
C:\k8jc.exe
C:\p9rs.exe
C:\RECYCLER
D:\autorun.inf
D:\k8jc.exe
D:\p9rs.exe
D:\RECYCLER
H:\k8jc.exe
H:\autorun.inf
H:\KLIZAVI
H:\RECYCLER
C:\Documents and Settings\QBAQ.QBAQ-1514A32D52\Dane aplikacji\Mozilla\Firefox\Profiles\5obc5jm4.default\extensions\DTToolbar@toolbarnet.com
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
Kliknij w Run Fix. I potwierdź reset kompa .
Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia komputera + log z Gmera (poprawnie) + ten plik :
C:\WINDOWS\System32\ftp.exe
przeskanuj tu
http://virusscan.jotti.org/
http://www.virustotal.com/
i daj raporty ze skanow