spandaupol napisał(a):katiqq, Jak podajesz logi to proszę czekać na ich analizę Masz rootkita zeroaccess sama szczepionka to tutaj nie pomoże. Proszę pobrać i użyć Combofixa zgodnie z instrukcją http://www.fixitpc.pl/topic/7-dezynfekc ... -combofix/ Jak wszystko pójdzie dobrze i narzędzie skończy pracę powstanie raport który podasz na forum
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"netsvcs"=hex(7):36,00,74,00,6f,00,34,00,00,00,41,00,70,00,70,00,4d,00,67,00,\
6d,00,74,00,00,00,41,00,75,00,64,00,69,00,6f,00,53,00,72,00,76,00,00,00,42,\
00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,43,00,72,00,79,00,70,00,74,00,\
53,00,76,00,63,00,00,00,44,00,4d,00,53,00,65,00,72,00,76,00,65,00,72,00,00,\
00,44,00,48,00,43,00,50,00,00,00,45,00,52,00,53,00,76,00,63,00,00,00,45,00,\
76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,46,00,61,\
00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,\
69,00,6e,00,67,00,43,00,6f,00,6d,00,70,00,61,00,74,00,69,00,62,00,69,00,6c,\
00,69,00,74,00,79,00,00,00,48,00,69,00,64,00,53,00,65,00,72,00,76,00,00,00,\
49,00,61,00,73,00,00,00,49,00,70,00,72,00,69,00,70,00,00,00,49,00,72,00,6d,\
00,6f,00,6e,00,00,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,53,00,65,00,72,00,\
76,00,65,00,72,00,00,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,\
00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,00,00,4d,00,65,00,73,00,\
73,00,65,00,6e,00,67,00,65,00,72,00,00,00,4e,00,65,00,74,00,6d,00,61,00,6e,\
00,00,00,4e,00,6c,00,61,00,00,00,4e,00,74,00,6d,00,73,00,73,00,76,00,63,00,\
00,00,4e,00,57,00,43,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,4e,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6e,00,\
74,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6f,00,00,00,52,00,61,00,73,\
00,6d,00,61,00,6e,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,61,00,63,00,\
63,00,65,00,73,00,73,00,00,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,\
00,00,00,53,00,65,00,63,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00,53,00,45,00,\
4e,00,53,00,00,00,53,00,68,00,61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,\
00,73,00,73,00,00,00,53,00,52,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,\
00,00,54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,54,00,68,00,65,00,6d,\
00,65,00,73,00,00,00,54,00,72,00,6b,00,57,00,6b,00,73,00,00,00,57,00,33,00,\
32,00,54,00,69,00,6d,00,65,00,00,00,57,00,5a,00,43,00,53,00,56,00,43,00,00,\
00,57,00,6d,00,69,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,70,00,\
00,00,77,00,69,00,6e,00,6d,00,67,00,6d,00,74,00,00,00,77,00,73,00,63,00,73,\
00,76,00,63,00,00,00,78,00,6d,00,6c,00,70,00,72,00,6f,00,76,00,00,00,6e,00,\
61,00,70,00,61,00,67,00,65,00,6e,00,74,00,00,00,68,00,6b,00,6d,00,73,00,76,\
00,63,00,00,00,42,00,49,00,54,00,53,00,00,00,77,00,75,00,61,00,75,00,73,00,\
65,00,72,00,76,00,00,00,53,00,68,00,65,00,6c,00,6c,00,48,00,57,00,44,00,65,\
00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,68,00,65,00,6c,00,70,00,\
73,00,76,00,63,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,00,00,\
00,00,00
:OTL
:Files
c:\documents and settings\1\Ustawienia lokalne\Dane aplikacji\5e5e0692
C:\WINDOWS\System32\dds_log_trash.cmd
C:\WINDOWS\System32\ApjohxuHqulx.dll
:Services
SirefefRemover
:Reg
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SirefefRemover]
:Commands
[emptytemp]
powtarzam link do obrazka http://imageshack.us/photo/my-images/109/xxxad.jpg/
DRV - [2008-04-14 17:11:05 | 000,065,280 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\serial.sys -- (Serial)
:Files
C:\WINDOWS\system32\drivers\serial.sys|C:\Plik\serial.sys /replace
:Commands
[emptytemp]
Powtórzyłam czynności, ale bez podmieniania plików, bo nie chcę się narażać "władzy". Może tym razem będzie ok
Hello jest tam kto? Nadal eset wyrzuca mi powiadomienia o znalezionych szkodnikach.
Jeśli tylko uda się podmienić
W okno Własne opcje skanowania / skrypt w OTL wklej::Files
C:\WINDOWS\system32\drivers\serial.sys|C:\Plik\serial.sys /replace
:Commands
[emptytemp]
Klikasz na Wykonaj skrypt. Zgadzasz się na restart komputera. Log z usuwania na forum
Następnie ponownie uruchamiasz OTL klikasz raz jeszcze Skanuj i dajesz nowy log na forum Czyli dwa logi jeden z usuwania drugi z nowego skanowania po usuwaniu.
Czy raport GMER mogłabym wysłać na priva?
:OTL
SRV - File not found [Auto | Stopped] -- -- (wpshelper)
SRV - File not found [Auto | Stopped] -- -- (WavxDMgr)
SRV - File not found [Auto | Stopped] -- -- (vc5secs)
SRV - File not found [Auto | Stopped] -- -- (USBVCD)
SRV - File not found [Auto | Stopped] -- -- (slave)
SRV - File not found [Auto | Stopped] -- -- (SE27obex)
SRV - File not found [Auto | Stopped] -- -- (rxmssync)
SRV - File not found [Auto | Stopped] -- -- (rt2500)
SRV - File not found [Auto | Stopped] -- -- (razerusb)
SRV - File not found [Auto | Stopped] -- -- (purgeieservice)
SRV - File not found [Auto | Stopped] -- -- (ppmoucls)
SRV - File not found [Auto | Stopped] -- -- (pmsveh)
SRV - File not found [Auto | Stopped] -- -- (pdfcreatormessages)
SRV - File not found [Auto | Stopped] -- -- (nvmd)
SRV - File not found [Auto | Stopped] -- -- (netrcacm)
SRV - File not found [Auto | Stopped] -- -- (mskservice)
SRV - File not found [Auto | Stopped] -- -- (mpservice)
SRV - File not found [Auto | Stopped] -- -- (iSMBIOS)
SRV - File not found [Auto | Stopped] -- -- (G400DH)
SRV - File not found [Auto | Stopped] -- -- (aspi32)
[2012-02-24 08:11:38 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012-02-24 08:11:38 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012-02-24 08:11:38 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012-02-24 08:11:38 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012-02-24 08:11:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012-02-24 08:11:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-02-24 08:10:34 | 004,418,150 | R--- | C] (Swearware) -- C:\Documents and Settings\1\Pulpit\ComboFix.exe
[2012-02-24 08:11:38 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012-02-24 08:11:38 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012-02-24 08:11:38 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012-02-24 08:11:38 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012-02-24 08:11:38 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
:Files
C:\Documents and Settings\1\Pulpit\fix.reg
:Commands
[emptytemp]
Zidentyfikowani użytkownicy: ADR1991, alfinho, Bing [Bot], Cristian, Dimatheus, dzikiwiepsz, edek112, Google [Bot], Google Adsense [Bot], itsave, jadrekk, JNJN, kosti1, misza_88, p19koz, passat112243, pawel403, ponton.z, sebcioseb, stach1691, strumyk17, woodz, Yahoo [Bot]