
http://wklej.org/id/395979/
http://wklej.org/id/395980/
Win32:Sality napisał(a):Zalecam instalowanie Konsoli Odzyskiwania (XP, 2000)
(...)
Mimo wszystko ComboFix nie jest doskonały.
ComboFix napisał(a):UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
netsvcs
C:\*.*
D:\*.*
E:\*.*
F:\*.*
G:\*.*
H:\*.*
%ALLUSERSPROFILE%\Application Data\*.
%APPDATA%\*.
%SYSTEMDRIVE%\*. /mp /s
/md5start
atapi.sys
iaStor.sys
jraid.sys
nvata.sys
ndis.sys
beep.sys
ntfs.sys
explorer.exe
svchost.exe
userinit.exe
winlogon.exe
/md5stop
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\kernel32.dll /md5
%systemroot%\system32\user32.dll /md5
%systemroot%\Tasks\*.job /lockedfiles
CREATERESTOREPOINT
restorepoints
C:\WINDOWS\System32\wmimgr32.dll
C:\WINDOWS\system32\ctfmon.exe
[Kill All Processes]
[Unregister Dlls]
[Driver Services - Safe List]
YN -> (catchme) catchme [Kernel | On_Demand | Stopped] -> C:\ComboFix\catchme.sys -> File not found
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
YY -> {043C5167-00BB-4324-AF7E-62013FAEDACF} [HKLM] -> C:\Program Files\vShare\vshare_toolbar.dll [vShare Plugin] -> [2010-09-06 13:06:10 | 000,432,008 | ---- | M] ()
YY -> {D4027C7F-154A-4066-A1AD-4243D8127440} [HKLM] -> C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask Toolbar] -> [2009-09-02 14:56:30 | 001,175,944 | ---- | M] (Ask.com)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
YY -> "{043C5167-00BB-4324-AF7E-62013FAEDACF}" [HKLM] -> C:\Program Files\vShare\vshare_toolbar.dll [vShare Plugin] -> [2010-09-06 13:06:10 | 000,432,008 | ---- | M] ()
YY -> "{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask Toolbar] -> [2009-09-02 14:56:30 | 001,175,944 | ---- | M] (Ask.com)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1085031214-1659004503-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1085031214-1659004503-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ ->
YY -> WebBrowser\\"{043C5167-00BB-4324-AF7E-62013FAEDACF}" [HKLM] -> C:\Program Files\vShare\vshare_toolbar.dll [vShare Plugin] -> [2010-09-06 13:06:10 | 000,432,008 | ---- | M] ()
YY -> WebBrowser\\"{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask Toolbar] -> [2009-09-02 14:56:30 | 001,175,944 | ---- | M] (Ask.com)
[Custom Items]
:files
C:\Documents and Settings\ŚLIMOK\Dane aplikacji\Mozilla\Firefox\Profiles\9fe3e1x8.default\searchplugins\askcom.xml
C:\Documents and Settings\ŚLIMOK\Dane aplikacji\Mozilla\Firefox\Profiles\9fe3e1x8.default\extensions\toolbar@ask.com
:end
[Empty Temp Folders]
[Emptyflash]
[Start Explorer]
[Reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 8 gości