Sporo nawalone w autostarcie i prawdopodobnie w usługach.
Wklej ten skrypt do OTL, kliknij
Run Fix i po restarcie na
wklej.org wklej log, który wyskoczy:
Kod:
:OTL
SRV - File not found [Auto | Stopped] -- -- (sp_rssrv)
DRV - [2009-03-21 10:37:11 | 000,141,312 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
IE - HKU\S-1-5-21-1176470751-1127595548-3999700639-1000\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
FF - prefs.js..extensions.enabledItems: {12e4c684-c03e-4e4d-85bc-0c065e7a9489}:5.23.2.10
O3 - HKLM\..\Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-1176470751-1127595548-3999700639-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O8 - Extra context menu item: &SHOUTcast Search - C:\ProgramData\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
@Alternate Data Stream - 64 bytes -> C:\Users\Domownicy\Desktop\Loty krolewo malborskie.mp4:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Domownicy\Desktop\clip0001.avi:TOC.WMV
@Alternate Data Stream - 524 bytes -> C:\ProgramData\TEMP:05EE1EEF
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:6BE50C2B
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
:Files
C:\Windows\tasks\Norton Internet Security - Uruchom pełne skanowanie systemu - Domownicy.job
C:\Windows\tasks\User_Feed_Synchronization-{7228B9EE-6BC3-48CB-B27F-24A1522CCE16}.job
C:\Users\Domownicy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Domownicy\AppData\Local\Temp*.html
C:\Users\Domownicy\AppData\Roaming\Spyware Terminator
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"AppleSyncNotifier"=-
"ccApp"=-
"hpsysdrv"=-
"KBD"=-
"Malwarebytes Anti-Malware (reboot)"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"NvSvc"=-
"OsdMaestro"=-
"RtHDVCpl"=-
"SpywareTerminator"=-
"SunJavaUpdateReg"=-
"TkBellExe"=-
"WinampAgent"=-
[HKU\S-1-5-21-1176470751-1127595548-3999700639-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Shockwave Updater"=-
[HKEY_CURRENT_USER\Control Panel\Desktop]
"AutoEndTasks"="1"
"WaitToKillAppTimeout"="5000"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control]
"WaitToKillServiceTimeout"="5000"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cisvc]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMonLog]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc]
"Start"=dword:00000003
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
Odinstaluj programy przez "Dodaj-usuń programy":
- Google Toolbar for Internet Explorer
- Wszystko co ma w nazwie Java - po tym zainstaluj najnowszą wersję: link
- Norton Internet Security (o ile jest na liście)
- Dealio Toolbar 3.4
- Gameztar Toolbar
- Adobe Reader 8.1.0 - po tym zainstaluj najnowszą wersję: link
- DAEMON Tools Toolbar
- SHOUTcast Radio Toolbar
- Winamp Toolbar for Firefox
Po drugie ściągnij i uruchom narzędzie
Norton Removal Tool, żeby usunąć resztki od Symanteca:
ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exeStwórz nowe logi przez OTL (z ustawieniami jak poprzednio).
Podsumowując:Na wklej.org wklejasz logi z czyszczenia (po uruchomieniu skryptu) i nowe z OTL.