
Poniżej logi:
OTLhttp://wklej.to/ALj9a
OTL Extra http://wklej.to/VWA9J
Gmer 1http://wklej.to/xFGY1
Gmer 2http://wklej.to/HDXdN
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fpggl.sys -- (amsint32)
:OTL
[2016-01-11 22:26:25 | 000,407,471 | -HS- | C] () -- C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Svchost.exe
O4 - HKCU..\Run: [Svchost.exe] C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Svchost.exe ()
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fpggl.sys -- (amsint32)
:Files
C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Mrdkdw.exe
:Commands
[emptytemp]
D:\aomdaa.exe
D:\aomdaa.exe
C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Svchost.exe
R3 amsint32; \??\C:\WINDOWS\system32\drivers\fpggl.sys [X]
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
S2 XAudioService; %SystemRoot%\system32\DRIVERS\xaudio.exe [X]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-796845957-1532298954-682003330-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-796845957-1532298954-682003330-1003\...\Run: [Svchost.exe] => C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Mrdkdw.exe [0 ] ()
HKU\S-1-5-21-796845957-1532298954-682003330-1003\...\Policies\system: [DisableTaskMgr] 1
HKU\S-1-5-21-796845957-1532298954-682003330-1003\...\Policies\system: [DisableRegistryTools] 1
AlternateShell:
C:\Documents and Settings\EWA PAWEŁ\Dane aplikacji\Mrdkdw.exe
DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Svchost.exe
StandardProfile\AuthorizedApplications: [C:\WINDOWS\SOUNDMAN.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\ALCMTR.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\RTHDCPL.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [D:\aomdaa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\PLFSetL.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\Atiptaxx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\EWA PAWEŁ\Pulpit\OTL.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\EWA PAWEŁ\Pulpit\rkill.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\explorer.exe] => C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\ntvdm.exe] => Enabled:ipsec
EmptyTemp:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości