
Jak się tego pozbyć ?
Xavdas napisał(a):Jak się tego pozbyć ?
:processes
killallprocesses
:services
srviecheck
srvbtcclient
ddservice
srvsysdriver32
wxpdrivers
:files
C:\Windows\phoenix.rar
C:\Windows\rpcminer.rar
C:\Windows\ufa.rar
C:\Windows\l1rezerv.exe
C:\Windows\geoiplist
C:\Windows\geoiplist.rar
C:\Windows\unrar.exe
C:\Windows\info1
C:\Windows\loader2.exe_ok
C:\Windows\sysdriver32_.exe
C:\Windows\sysdriver32.exe
C:\Windows\services32.exe
C:\Windows\systemup.exe
:otl
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (no name) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - Reg Error: Value error. File not found
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (no name) - {64182481-4F71-486b-A045-B233BD0DA8FC} - No CLSID value found.
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [16845284-loader2.exe] C:\Windows\Temp\16845284-loader2.exe ()
O4 - HKLM..\Run: [3599606.exe] C:\Windows\Temp\3599606.exe ()
O4 - HKLM..\Run: [4944203.exe] C:\Windows\Temp\4944203.exe ()
O4 - HKLM..\Run: [9912574.exe] C:\Users\Xavdas\AppData\Local\Temp\9912574.exe ()
O4 - HKLM..\Run: [egui] File not found
O4 - HKLM..\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe ()
O4 - HKLM..\Run: [systemup] C:\Windows\systemup.exe ()
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico0] C:\Windows\update.tray-2-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico1] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKLM..\Run: [w_distrib.exe] C:\Windows\update.3\svchost.exe ()
O4 - HKLM..\Run: [WinampAgent] E:\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [wxpdrv] C:\Windows\services32.exe ()
O4 - HKCU..\Run: [HKCU] C:\Users\Xavdas\AppData\Roaming\system32\Windows Updater.exe ()
O4 - HKCU..\Run: [RDReminder] File not found
O31 - SafeBoot: AlternateShell - services32.exe
O33 - MountPoints2\{28cbeed4-3102-11e0-a954-00241d5b95e0}\Shell - "" = AutoRun
O33 - MountPoints2\{28cbeed4-3102-11e0-a954-00241d5b95e0}\Shell\AutoRun\command - "" = K:\Autorun.exe
O33 - MountPoints2\{a06ae1af-3e5b-11e0-b849-00241d5b95e0}\Shell - "" = AutoRun
O33 - MountPoints2\{a06ae1af-3e5b-11e0-b849-00241d5b95e0}\Shell\AutoRun\command - "" = L:\setup.exe
O33 - MountPoints2\{a06ae1af-3e5b-11e0-b849-00241d5b95e0}\Shell\dinstall\command - "" = Quake3\directx7\dxsetup.exe
[2011-08-21 19:17:23 | 000,000,000 | -H-D | C] -- C:\Windows\update.3
[2011-08-21 12:12:35 | 000,000,000 | ---D | C] -- C:\Windows\ufa
[2011-08-21 12:12:35 | 000,000,000 | ---D | C] -- C:\Windows\rpcminer
[2011-08-21 12:12:35 | 000,000,000 | ---D | C] -- C:\Windows\phoenix
[2011-08-21 12:10:52 | 000,000,000 | -H-D | C] -- C:\Windows\update.5.0
[2011-08-21 12:09:25 | 000,000,000 | -H-D | C] -- C:\Windows\update.2
[2011-08-21 12:09:02 | 000,000,000 | -H-D | C] -- C:\Windows\update.7.1
[2011-08-21 12:07:39 | 000,000,000 | ---D | C] -- C:\Windows\av_ico
[2011-08-21 12:06:16 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0-lnk
[2011-08-21 12:06:16 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0
[2011-08-21 12:06:16 | 000,000,000 | -H-D | C] -- C:\Windows\update.1
[2011-08-23 15:36:45 | 000,000,224 | ---- | M] () -- C:\Windows\info1
[2011-08-21 12:12:34 | 005,589,370 | ---- | M] () -- C:\Windows\phoenix.rar
[2011-08-21 12:12:34 | 001,075,284 | ---- | M] () -- C:\Windows\rpcminer.rar
[2011-08-21 12:12:34 | 000,246,272 | ---- | M] () -- C:\Windows\unrar.exe
[2011-08-21 12:12:34 | 000,182,617 | ---- | M] () -- C:\Windows\ufa.rar
[2011-08-21 12:11:44 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
[2011-08-21 12:09:30 | 000,904,792 | ---- | M] () -- C:\Windows\geoiplist.rar
[2011-08-21 12:08:27 | 000,000,000 | ---- | M] () -- C:\Windows\loader2.exe_ok
[2011-08-21 12:07:56 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32_.exe
[2011-08-21 12:07:56 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32.exe
[2011-08-21 11:51:09 | 001,216,000 | ---- | M] () -- C:\Windows\services32.exe
[2011-08-22 17:59:47 | 000,137,728 | ---- | M] () -- C:\Windows\systemup.exe
[2006-04-09 05:09:25 | 000,000,000 | RHSD | M] -- C:\Users\Xavdas\AppData\Roaming\system32
:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"
:commands
[resethosts]
[emptytemp]
[emptyflash]
:Files
C:\Windows\System32\drivers\etc\hîsts
C:\AnalysisLog.sr0
:OTL
[2011-08-24 14:55:50 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-08-24 14:55:50 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
:Processes
killallprocesses
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=bf&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - Reg Error: Value error. File not found
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@Webzen.com/NPGameWebStarter: C:\Program Files\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll File not found
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
[2011-08-25 11:34:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1001UA.job
[2011-08-25 11:19:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1007UA.job
[2011-08-25 11:19:00 | 000,001,010 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1007Core.job
[2011-08-25 11:09:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1003UA.job
[2011-08-25 11:03:00 | 000,001,038 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-08-25 07:11:31 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-08-23 14:09:00 | 000,001,014 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1003Core.job
[2011-08-21 22:34:00 | 000,001,014 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-609054657-900459892-2953646686-1001Core.job
[2011-08-17 14:26:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
[2011-08-05 14:26:02 | 000,000,262 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
:Files
C:\Windows\System32\unrar.dll
:Services
gupdate
gupdatem
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Malwarebytes' Anti-Malware"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
:Commands
[clearallrestorepoints]
[emptytemp]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="E:\Adobe\Reader\Reader_sl.exe"
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"="E:\ALLPlayer\ALLUpdate.exe"
Win32:Sality napisał(a):czekaj czekaj, musimy odkręcić co napsuł kominek. wyrzucił jeden poprawny plik.
Wejdź do katalogu C:\_OTL
potem do MovedFiles
potem do C_Windows
potem do System 32
znajdziesz tam plik unrar.dll, musisz go skopiować do katalogu C:\Windows\System32\.
Potem otwórz notatnik (notepad.exe)
wklej do niego następującą zawartość:[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="E:\Adobe\Reader\Reader_sl.exe"
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"="E:\ALLPlayer\ALLUpdate.exe"
Plik -> zapisz jako -> wszystkie pliki -> fix.reg i zapisz na pulpicie.
Odpal plik fix.reg i potwierdź dodanie do rejestru. zresetuj komputer.
@Kominekl - jeszcze jeden taki skrypt i porozmawiasz sobie z administracją!
Windows Registry Editor Version 5.00
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="E:\Adobe\Reader\Reader_sl.exe"
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"="E:\ALLPlayer\ALLUpdate.exe"
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 17 gości