
Od wczoraj mam jakąś infekcję PC, proszę o pomoc w pozbyciu się jej. Na początku nie mogłem zrobić loga w OTL ale to już samemu naprawiłem, ale dalej już nie umiem.
[Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
:OTL
SRV - [2012-09-20 11:55:13 | 000,154,624 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\bikuvuwe.exe -- (ae6y8oiehkakq)
IE - HKU\S-1-5-21-1614895754-1606980848-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112542&tt=2912_4&babsrc=HP_ss&mntrId=7cd2b93c000000000000001e8c274b66
IE - HKU\S-1-5-21-1614895754-1606980848-725345543-1003\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1614895754-1606980848-725345543-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112542&tt=2912_4&babsrc=SP_ss&mntrId=7cd2b93c000000000000001e8c274b66
IE - HKU\S-1-5-21-1614895754-1606980848-725345543-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=112542&tt=2912_4&babsrc=KW_ss&mntrId=7cd2b93c000000000000001e8c274b66&q="
[2012-09-02 18:46:54 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\o8kpdujh.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2012-07-16 08:47:15 | 000,000,000 | ---D | M] (DealPly) -- C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\o8kpdujh.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012-07-16 20:42:30 | 000,002,349 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
DRV - [2009-06-30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)
O4 - HKU\S-1-5-21-1614895754-1606980848-725345543-1003..\Run: [H/PC Connection Agent] D:\wcescomm.exe File not found
O4 - HKU\S-1-5-21-1614895754-1606980848-725345543-1003..\Run: [RDReminder] C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe (Dll-FIles.Com)
O4 - HKLM..\Run: [voottiz] C:\WINDOWS\system32\soumowazor.exe ()
[2012-09-02 18:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2012-09-20 11:55:13 | 000,154,624 | ---- | M] () -- C:\WINDOWS\System32\soumowazor.exe
[2012-09-20 11:55:13 | 000,154,624 | ---- | M] () -- C:\WINDOWS\System32\bikuvuwe.exe
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1038:TCP"=-
"5000:UDP"=-
:Services
ae6y8oiehkakq
:Commands
[emptytemp]
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\AmdTools.sys -- (AmdTools)
O4 - HKU\S-1-5-21-1614895754-1606980848-725345543-1003..\Run: [Akamai NetSession Interface] "C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe" File not found
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 16 gości