Gdy skończy
Gmer:
W OTL w Custom Scan/Fixes:
Kod:
:OTL
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - [2009-07-20 20:16:15 | 00,223,744 | ---- | M] () -- C:\WINDOWS\system32\dlg.exe
MOD - [2009-11-02 20:53:00 | 00,076,264 | RHS- | M] () -- C:\Documents and Settings\M&P\Ustawienia lokalne\Temp\cvasds0.dll
SRV - [2009-07-20 20:16:15 | 00,223,744 | ---- | M] () -- C:\WINDOWS\system32\dlg.exe -- (dlgx1)
IE - HKU\S-1-5-21-329068152-1715567821-839522115-1003\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll (Conduit Ltd.)
O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-329068152-1715567821-839522115-1003\..\Toolbar\ShellBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfre1.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-329068152-1715567821-839522115-1003\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfre1.dll (Conduit Ltd.)
O4 - HKU\S-1-5-21-329068152-1715567821-839522115-1003..\Run: [cdoosoft] C:\Documents and Settings\M&P\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2009-11-02 22:55:31 | 00,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-11-02 22:55:31 | 00,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{d0295a2f-843c-11de-9c9e-001485df1c5d}\Shell\AutoRun\command - "" = se12ydam.exe
O33 - MountPoints2\{d0295a2f-843c-11de-9c9e-001485df1c5d}\Shell\open\Command - "" = se12ydam.exe
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:D06A4C76
:Files
c:\windows\system32\dlg.dll
c:\windows\system32\dlg.exe
C:\9b9w3.exe
D:\9b9w3.exe
D:\b00ijwpu.exe
D:\hjvjte.exe
D:\nds0q.exe
D:\rg9g9bgq.exe
D:\se12ydam.exe
D:\wcgswa.exe
C:\Program Files\free-downloads.net
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[purity]
[clearrestorepoints]
[emptytemp]
[start explorer]
[reboot]
I klikasz Run Fix.
Potem pokaż nowe logi.