Skocz do zawartości

bialy437

Użytkownicy
  • Postów

    8
  • Dołączył

  • Ostatnia wizyta

  1. prawie 1,5 dnia skanowało i teraz pokazało 3 zainfekowane ale nie można było usunąć, więc zaznaczyłem w programie i usunęło. po skanowaniu nic nie było. Tryb awaryjny się otwiera bez problemu Nodem skanowałem to jeszcze wykryło 98 plików. program wyleczył to (podobno) OTL.Txt UsbFix.txt
  2. Wyniki z SalityKiller: infected files : 856 infected process : 6 infected theards : 70 cured files : 856 will be cured on reboot: 0 executed registry scripts: 1 i tu dane z olt po restarcie systemu: All processes killed ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf\\""|"@SYS:DoesNotExist" /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\\EnableLUA not found. ========== FILES ========== File move failed. C:\autorun.inf scheduled to be moved on reboot. File move failed. D:\autorun.inf scheduled to be moved on reboot. File move failed. E:\autorun.inf scheduled to be moved on reboot. File move failed. F:\autorun.inf scheduled to be moved on reboot. File move failed. G:\autorun.inf scheduled to be moved on reboot. File move failed. K:\autorun.inf scheduled to be moved on reboot. File move failed. L:\autorun.inf scheduled to be moved on reboot. File move failed. M:\AUTORUN.INF scheduled to be moved on reboot. File move failed. N:\autorun.inf scheduled to be moved on reboot. File move failed. O:\autorun.inf scheduled to be moved on reboot. C:\opyjra.exe moved successfully. D:\yhfux.exe moved successfully. E:\npuvph.pif moved successfully. F:\bmwyn.pif moved successfully. G:\vlemp.exe moved successfully. File\Folder K:\cutn.pif not found. File\Folder L:\kxhw.exe not found. File\Folder N:\lovul.pif not found. File\Folder O:\lcmyc.exe not found. < netsh firewall reset /C > Ok. E:\Downloads\cmd.bat deleted successfully. E:\Downloads\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Bia ->Temp folder emptied: 1328297 bytes ->Temporary Internet Files folder emptied: 372817 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 15565243 bytes ->Google Chrome cache emptied: 32478497 bytes ->Flash cache emptied: 497 bytes User: CURRENT_USER User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 22048768 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1662807 bytes RecycleBin emptied: 548877 bytes Total Files Cleaned = 71,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 03162013_152031 Files\Folders moved on Reboot... C:\autorun.inf moved successfully. D:\autorun.inf moved successfully. E:\autorun.inf moved successfully. F:\autorun.inf moved successfully. G:\autorun.inf moved successfully. K:\autorun.inf moved successfully. L:\autorun.inf moved successfully. File\Folder M:\AUTORUN.INF not found! N:\autorun.inf moved successfully. O:\autorun.inf moved successfully. C:\WINDOWS\temp\Perflib_Perfdata_7d8.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... OTL.Txt UsbFix.txt
  3. BlitzBlank 1.0.0.32 File/Registry Modification Engine native application MoveFileOnReboot: sourceFile = "\??\c:\documents and settings\bia\dane aplikacji\qmrcrs.exe", destinationFile = "(null)", replaceWithDummy = 0 skrótów nie mam już na dysku. dziękuję ślicznie UsbFix.txt OTL.Txt
  4. przepraszam. Już poprawiam sie checkup.txt GMER.txt OTL.Txt Extras.Txt
  5. Tylko ten plik mi się pojawił więc jakie jeszcze? Gdzie mogę je znaleźć?
  6. Witam, Bardzo proszę o pomoc, na dysku zewnętrznym i pendrivach zamiast normalnych folderów są skróty. Wiem, że to sprawka wirusa, bo czytałem o tym i posłużyłem się ComboFix zgodnie z instrukcją. Na każdej partycji jest folder : RECYCLER. Wirus pewnie dobrze Państwu znany także pewnie nie będzie problemu. Z góry dziękuję za pomoc Pozdrawiam ComboFix.txt
×
×
  • Dodaj nową pozycję...