
Niestetey mojego kompa pierwszy raz dopadł wirus.
zainstalowałm OTL
raport
Extras
http://wklej.to/Nc91t
OTL
http://wklej.to/lE6gR
Z góry dzieki
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Kuba\USTAWI~1\Temp\__Samsung_Update\ADDMEM.SYS -- (ADDMEM)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=10
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms}
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=10
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Program Files\TVersitybar\prxtbTVe0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2548838
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms}
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O4 - HKLM..\Run: [rsevnrzylssedzj] C:\Documents and Settings\All Users\Dane aplikacji\rsevnrzy.exe ()
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [rsevnrzylssedzj] C:\Documents and Settings\All Users\Dane aplikacji\rsevnrzy.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [] File not found
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - Startup: C:\Documents and Settings\Kuba\Menu Start\Programy\Autostart\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
[2012-07-29 23:00:25 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4289377953-1970212417-366036058-1005.job
[2012-07-29 23:00:23 | 000,001,028 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-07-27 22:45:48 | 000,000,051 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\txuuonjldeuejwq
[2012-07-27 22:45:33 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\rsevnrzy.exe
[2012-07-27 22:45:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\qfydvihglnldkvi
[2012-07-13 18:32:34 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Kuba.job
[2012-07-07 22:20:04 | 000,308,621 | ---- | C] () -- C:\WINDOWS\System32\autorun.inf
:Commands
[emptytemp]
:OTL
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=10
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - No CLSID value found
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2548838
IE - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaultthis.engineName: "TVersitybar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com/?crg=3.1010000&st=10"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: fe_3.6@nokia.com:1.7.110.333
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145
FF - prefs.js..extensions.enabledItems: {66bd2442-241b-44cd-8c7a-b51037053cdb}:3.2.1.3
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2548838&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2548838&SearchSource=3&q={searchTerms}"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "TVersitybar Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2548838&SearchSource=13"
[2012-07-20 14:30:20 | 000,000,000 | ---D | M] (TVersitybar Community Toolbar) -- C:\Documents and Settings\Kuba\Dane aplikacji\Mozilla\Firefox\Profiles\9s4qdtsg.default\extensions\{66bd2442-241b-44cd-8c7a-b51037053cdb}
[2010-10-14 20:05:16 | 000,000,925 | ---- | M] () -- C:\Documents and Settings\Kuba\Dane aplikacji\Mozilla\Firefox\Profiles\9s4qdtsg.default\searchplugins\conduit.xml
[2012-07-12 10:24:25 | 000,003,948 | ---- | M] () -- C:\Documents and Settings\Kuba\Dane aplikacji\Mozilla\Firefox\Profiles\9s4qdtsg.default\searchplugins\sweetim.xml
O3 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005\..\Toolbar\WebBrowser: (no name) - {66BD2442-241B-44CD-8C7A-B51037053CDB} - No CLSID value found.
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [] File not found
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [rsevnrzylssedzj] C:\Documents and Settings\All Users\Dane aplikacji\rsevnrzy.exe File not found
O4 - HKU\S-1-5-21-4289377953-1970212417-366036058-1005..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O33 - MountPoints2\{a9b8c9a0-67a2-11e0-9778-002163aa97ed}\Shell - "" = AutoRun
O33 - MountPoints2\{a9b8c9a0-67a2-11e0-9778-002163aa97ed}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{bc683d04-b9cb-11e0-979e-001377d195e6}\Shell - "" = AutoRun
O33 - MountPoints2\{bc683d04-b9cb-11e0-979e-001377d195e6}\Shell\AutoRun\command - "" = E:\iStudio.exe
[2012-07-27 22:45:33 | 000,061,440 | ---- | C] () -- C:\Documents and Settings\Kuba\ms.exe
[2012-07-29 21:16:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kuba\Dane aplikacji\SpeedyPC Software
[2012-07-29 21:16:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kuba\Dane aplikacji\DriverCure
[2012-07-29 21:16:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kuba\Menu Start\Programy\SpeedyPC Software
[2012-07-29 21:16:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\SpeedyPC Software
[2012-07-29 21:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\HitmanPro
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości