CoinMincer - Pomocy.

Wszystko co dotyczy bezpieczeństwa systemów oraz walki z malware, w szczególności analiza logów
maczoszym12

Użytkownik
Posty: 2
Rejestracja: 19 gru 2012, 17:20

CoinMincer - Pomocy.

Post19 gru 2012, 21:33

Witam mam wirusa CoinMiner oto Log z OTL:
Dostępne tylko dla zarejestrowanych użytkowników
Dostępne tylko dla zarejestrowanych użytkowników

Proszę o dalsze porady :)

-- 19 gru 2012, 22:33 --

Pomoże ktoś :>?

Awatar użytkownika
kominekl

Ekspert
Posty: 5855
Rejestracja: 27 lis 2011, 14:25
Kontaktowanie:

CoinMincer - Pomocy.

Post19 gru 2012, 22:05

"McAfee Security Scan" = McAfee Security Scan Plus
"Xfire_New Toolbar" = Xfire New Toolbar


Odinstaluj.

Logi.


Uruchom OTL -> w oknie Własne opcje skanowania/skrypt wklej:

:OTL

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {113342cd-3031-4ee9-9288-2c58857d3a3d} - C:\Program Files (x86)\Xfire_New\prxtbXfir.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&SearchSource=4&ctid=CT3248869
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Dostępne tylko dla zarejestrowanych użytkowników
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {113342cd-3031-4ee9-9288-2c58857d3a3d} - C:\Program Files (x86)\Xfire_New\prxtbXfir.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{352E595E-66B4-490D-8368-D159E38F8242}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=35F8A19F-B2F0-4ED9-B4F4-35BD6EF213D7&apn_sauid=667D5472-0274-4AF4-9D64-B8E5CB553509
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&SearchSource=4&ctid=CT3248869
FF - prefs.js..browser.search.defaultengine: "Ask.com Search"
FF - prefs.js..browser.search.defaultenginename: "Ask.com Search"
FF - prefs.js..browser.search.order.1: "Ask.com Search"
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3248869&SearchSource=2&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
[2012-11-29 21:12:25 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Maciek\AppData\Roaming\mozilla\Firefox\Profiles\54m9ukx1.default\extensions\toolbar@ask.com
[2012-10-17 00:44:04 | 000,002,333 | ---- | M] () -- C:\Users\Maciek\AppData\Roaming\mozilla\firefox\profiles\54m9ukx1.default\searchplugins\askcom.xml
[2012-11-29 21:11:40 | 000,002,306 | ---- | M] () -- C:\Users\Maciek\AppData\Roaming\mozilla\firefox\profiles\54m9ukx1.default\searchplugins\askcomsearch.xml
[2012-10-16 21:37:42 | 000,001,018 | ---- | M] () -- C:\Users\Maciek\AppData\Roaming\mozilla\firefox\profiles\54m9ukx1.default\searchplugins\xfire-new-customized-web-search.xml
[2012-12-06 00:12:13 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
CHR - Extension: Xfire New = C:\Users\Maciek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jadmiphpbpjbfngipbjmjaajaeiflhkc\10.13.1.89_0\
CHR - Extension: Skype Click to Call = C:\Users\Maciek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Mexplorer] C:\Users\Maciek\AppData\Roaming\9DF0.exe (Avira GmbH)
O4 - HKCU..\Run: [dhfh22] C:\Users\Maciek\AppData\Local\Temp\sample.exe ()
O4 - HKCU..\Run: [Gxtatg] C:\Users\Maciek\AppData\Roaming\Gxtatg.exe ()
O4 - HKCU..\Run: [Mexplorer] C:\Users\Maciek\AppData\Roaming\5428.exe (Avira GmbH)
O4 - HKCU..\Run: [PCSpeedUp] C:\Program Files (x86)\Przyspiesz Komputer\PCSpeedUp.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O4 - HKCU..\Run: [Facebook Update] C:\Users\Maciek\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
[2012-12-19 16:28:48 | 000,135,168 | -H-- | C] () -- C:\Users\Maciek\AppData\Roaming\Gxtatg.exe
[2012-12-14 14:53:31 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\35D5.exe
[2012-12-14 14:53:28 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\28BA.exe
[2012-12-14 11:22:51 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\55CD.exe
[2012-12-14 11:22:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\421E.exe
[2012-12-13 22:36:17 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\14E1.exe
[2012-12-13 22:36:13 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\797.exe
[2012-12-13 16:01:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7050.exe
[2012-12-13 16:01:11 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5BD5.exe
[2012-12-12 19:13:14 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5CD5.exe
[2012-12-12 19:13:10 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4FBA.exe
[2012-12-12 16:20:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7945.exe
[2012-12-12 16:20:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6BFB.exe
[2012-12-11 16:38:30 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\52E2.exe
[2012-12-11 16:38:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4615.exe
[2012-12-11 16:38:22 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3265.exe
[2012-12-10 20:14:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\55.exe
[2012-12-10 20:14:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\F32A.exe
[2012-12-10 20:14:13 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\E63E.exe
[2012-12-10 17:58:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3C94.exe
[2012-12-10 17:58:08 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2EED.exe
[2012-12-10 17:58:02 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1747.exe
[2012-12-09 23:05:45 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\AEF.exe
[2012-12-09 23:05:42 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\FDD3.exe
[2012-12-09 23:05:39 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\F309.exe
[2012-12-09 20:30:55 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\46FD.exe
[2012-12-09 20:30:51 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3946.exe
[2012-12-09 10:14:49 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3978.exe
[2012-12-09 10:14:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2CDA.exe
[2012-12-09 10:14:40 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\16DA.exe
[2012-12-09 00:45:45 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1A9D.exe
[2012-12-09 00:45:42 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\DE0.exe
[2012-12-09 00:45:39 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B5.exe
[2012-12-08 11:33:26 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B42B.exe
[2012-12-08 11:33:22 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\A730.exe
[2012-12-08 11:33:20 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9D5F.exe
[2012-12-08 10:16:21 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2189.exe
[2012-12-08 10:16:17 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\147E.exe
[2012-12-08 10:16:14 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7DF.exe
[2012-12-08 09:50:11 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2F2C.exe
[2012-12-08 09:50:08 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\21A4.exe
[2012-12-08 09:50:02 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\AE8.exe
[2012-12-07 23:23:48 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\834D.exe
[2012-12-07 23:23:44 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7622.exe
[2012-12-07 23:23:41 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\68E8.exe
[2012-12-07 18:17:41 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\41C2.exe
[2012-12-07 18:17:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\34B7.exe
[2012-12-07 18:17:32 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\201D.exe
[2012-12-07 12:28:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5810.exe
[2012-12-07 12:28:21 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4B23.exe
[2012-12-07 12:28:15 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\33AC.exe
[2012-12-06 21:31:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\E876.exe
[2012-12-06 21:31:21 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\DB7A.exe
[2012-12-06 21:31:18 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\CE5F.exe
[2012-12-06 15:20:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4922.exe
[2012-12-06 15:20:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3C35.exe
[2012-12-06 15:20:20 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2EDC.exe
[2012-12-05 20:43:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\36C3.exe
[2012-12-05 20:43:40 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2989.exe
[2012-12-05 20:43:36 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1BB3.exe
[2012-12-05 15:37:56 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\42DB.exe
[2012-12-05 15:37:53 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\34D6.exe
[2012-12-05 15:37:49 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\276D.exe
[2012-12-04 21:12:37 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\F2D.exe
[2012-12-04 21:12:34 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\212.exe
[2012-12-04 21:12:30 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\F3EE.exe
[2012-12-04 15:46:23 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6290.exe
[2012-12-04 15:46:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\548B.exe
[2012-12-04 15:46:16 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4761.exe
[2012-12-04 13:26:26 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4107.exe
[2012-12-04 13:26:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\319B.exe
[2012-12-04 13:26:14 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1303.exe
[2012-12-03 17:49:59 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\52C2.exe
[2012-12-03 17:49:56 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\44FC.exe
[2012-12-03 17:49:49 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\29AE.exe
[2012-12-02 20:41:42 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\C95A.exe
[2012-12-02 20:41:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BAD9.exe
[2012-12-02 20:41:35 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\AD9E.exe
[2012-12-02 20:11:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\FAD2.exe
[2012-12-02 20:11:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\ED2B.exe
[2012-12-02 20:11:12 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\DCE4.exe
[2012-12-02 10:02:40 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\A48A.exe
[2012-12-02 10:02:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9AF8.exe
[2012-12-02 10:02:15 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\42D9.exe
[2012-12-02 00:37:56 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\77DF.exe
[2012-12-02 00:37:52 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6A76.exe
[2012-12-02 00:37:47 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\563A.exe
[2012-12-01 23:58:49 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2117.exe
[2012-12-01 23:58:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\13AE.exe
[2012-12-01 23:58:42 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5A9.exe
[2012-12-01 13:50:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\65A6.exe
[2012-12-01 13:50:40 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\58F9.exe
[2012-12-01 13:50:36 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\47A9.exe
[2012-11-30 12:18:59 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5A32.exe
[2012-11-30 12:18:55 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4B04.exe
[2012-11-30 12:18:47 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2EBD.exe
[2012-11-29 22:26:41 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BC81.exe
[2012-11-29 22:26:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\ADFF.exe
[2012-11-29 22:26:34 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9E93.exe
[2012-11-29 21:11:56 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4CD9.exe
[2012-11-29 21:11:53 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3EA5.exe
[2012-11-29 21:11:47 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\297F.exe
[2012-11-28 16:16:04 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2FB8.exe
[2012-11-28 16:16:00 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1FDF.exe
[2012-11-28 16:15:55 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\ECE.exe
[2012-11-27 20:32:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\ABA3.exe
[2012-11-27 20:32:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9DBE.exe
[2012-11-27 20:32:40 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\90C2.exe
[2012-11-27 15:59:09 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2740.exe
[2012-11-27 15:59:05 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1AB1.exe
[2012-11-27 15:59:00 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\646.exe
[2012-11-26 18:18:59 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4726.exe
[2012-11-26 18:18:49 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\22F2.exe
[2012-11-26 18:18:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\156A.exe
[2012-11-26 15:00:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\517A.exe
[2012-11-26 15:00:17 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5F02.exe
[2012-11-26 15:00:14 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\312D.exe
[2012-11-26 00:18:08 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\43EB.exe
[2012-11-26 00:18:05 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\36A1.exe
[2012-11-26 00:18:01 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\27F1.exe
[2012-11-25 21:05:41 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\FCA.exe
[2012-11-25 21:05:20 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BF79.exe
[2012-11-25 21:05:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B0C8.exe
[2012-11-25 17:51:37 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6533.exe
[2012-11-25 17:51:11 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\FDE8.exe
[2012-11-25 17:51:06 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\EA67.exe
[2012-11-25 11:57:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\50CF.exe
[2012-11-25 11:57:35 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4431.exe
[2012-11-25 11:57:30 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2F88.exe
[2012-11-25 01:36:39 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\8ADF.exe
[2012-11-25 01:36:36 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7D57.exe
[2012-11-25 01:36:32 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7099.exe
[2012-11-24 16:58:44 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6134.exe
[2012-11-24 16:58:41 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\532F.exe
[2012-11-24 16:58:31 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2E5F.exe
[2012-11-24 10:48:48 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\44CE.exe
[2012-11-24 10:48:45 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\37C3.exe
[2012-11-24 10:48:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1CA4.exe
[2012-11-23 17:46:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BEA4.exe
[2012-11-23 17:46:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B1F6.exe
[2012-11-23 17:46:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\A307.exe
[2012-11-23 15:55:33 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5504.exe
[2012-11-23 15:55:30 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4894.exe
[2012-11-23 15:55:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\337E.exe
[2012-11-22 21:30:20 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\AD8E.exe
[2012-11-22 21:30:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\A0F0.exe
[2012-11-22 21:30:13 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\92EA.exe
[2012-11-22 17:51:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\359A.exe
[2012-11-22 17:51:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\29E6.exe
[2012-11-22 17:51:15 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1A2C.exe
[2012-11-22 13:35:51 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4664.exe
[2012-11-22 13:35:47 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\391A.exe
[2012-11-22 13:35:42 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\255A.exe
[2012-11-21 22:04:54 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9674.exe
[2012-11-21 22:04:50 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\88CD.exe
[2012-11-21 22:04:47 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7A2C.exe
[2012-11-21 21:25:45 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\C03E.exe
[2012-11-21 21:25:42 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B3BF.exe
[2012-11-21 21:25:39 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\A55C.exe
[2012-11-21 15:20:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3A72.exe
[2012-11-21 15:20:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2D95.exe
[2012-11-21 15:20:16 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\21E1.exe
[2012-11-20 21:38:46 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\CDC5.exe
[2012-11-20 21:38:42 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BF62.exe
[2012-11-20 21:38:38 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B1E9.exe
[2012-11-20 16:09:20 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\342B.exe
[2012-11-20 16:09:17 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2867.exe
[2012-11-20 16:09:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1498.exe
[2012-11-19 18:23:30 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3A53.exe
[2012-11-19 18:23:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\2DD4.exe
[2012-11-19 18:23:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\207A.exe
[2012-11-18 20:20:26 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\D53A.exe
[2012-11-18 20:20:23 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\C810.exe
[2012-11-18 20:20:19 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BAE5.exe
[2012-11-18 19:07:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\396.exe
[2012-11-18 19:07:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\F63C.exe
[2012-11-18 19:07:20 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\E921.exe
[2012-11-18 11:35:30 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3E58.exe
[2012-11-18 11:35:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\317C.exe
[2012-11-18 11:35:21 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\1C56.exe
[2012-11-18 00:20:52 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B7BE.exe
[2012-11-18 00:20:49 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\AAF1.exe
[2012-11-18 00:20:45 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\9D3A.exe
[2012-11-17 16:48:28 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\8760.exe
[2012-11-17 16:48:24 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7A35.exe
[2012-11-17 16:48:20 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6A5C.exe
[2012-11-17 13:27:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6D35.exe
[2012-11-17 13:27:19 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6087.exe
[2012-11-17 13:27:14 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4D92.exe
[2012-11-16 17:54:13 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\BDD4.exe
[2012-11-16 17:54:10 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\B348.exe
[2012-11-16 17:54:01 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\8FC0.exe
[2012-11-15 23:03:29 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4FCF.exe
[2012-11-15 23:03:26 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4218.exe
[2012-11-15 23:03:00 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\DC15.exe
[2012-11-15 17:21:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\67C8.exe
[2012-11-15 17:21:39 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5B2A.exe
[2012-11-15 17:21:33 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4105.exe
[2012-11-15 15:11:56 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\65C6.exe
[2012-11-15 15:11:53 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\58BA.exe
[2012-11-15 15:11:47 | 000,000,070 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\424C.exe
[2012-11-14 17:16:27 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6ECB.exe
[2012-11-14 17:16:22 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5D7B.exe
[2012-11-14 17:16:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\36A9.exe
[2012-11-13 21:41:52 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\D765.exe
[2012-11-13 21:41:48 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\C931.exe
[2012-11-13 19:11:11 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\E42C.exe
[2012-11-13 19:11:08 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\D6D3.exe
[2012-11-13 19:11:04 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\C97A.exe
[2012-11-13 19:00:54 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\77C0.exe
[2012-11-13 19:00:50 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6AE3.exe
[2012-11-13 19:00:43 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4F09.exe
[2012-11-13 18:48:48 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4E1C.exe
[2012-11-13 18:48:45 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\4084.exe
[2012-11-13 18:48:41 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\3250.exe
[2012-11-13 11:57:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\79D2.exe
[2012-11-13 11:57:09 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6D53.exe
[2012-11-13 11:57:06 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6009.exe
[2012-11-12 19:45:21 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\86EC.exe
[2012-11-12 19:45:18 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\7974.exe
[2012-11-12 19:45:12 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\645D.exe
[2012-11-08 21:03:07 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\79A3.exe
[2012-11-08 21:03:04 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\6C69.exe
[2012-11-08 21:03:00 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\5DD8.exe
[2012-11-08 19:21:29 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\8D87.exe
[2012-11-08 19:21:26 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\809A.exe
[2012-11-08 19:21:23 | 000,255,776 | ---- | C] () -- C:\Users\Maciek\AppData\Roaming\72A5.exe
[2012-11-29 21:12:17 | 000,000,000 | -HSD | C] -- C:\Config.Msi

:Files
C:\Windows\tasks\*.*
C:\Users\Maciek\AppData\Local\Temp
C:\Program Files (x86)\Google\Update
C:\Program Files (x86)\Przyspiesz Komputer
C:\Users\Maciek\AppData\Local\Facebook\Update

:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

:Commands
[clearallrestorepoints]
[emptytemp]


Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podaj log z ADWCleaner (z opcji Delete) -> Dostępne tylko dla zarejestrowanych użytkowników + log z Combofix -> http://www.hotfix.pl/articles.php?article_id=41 + log z TDSSKiller -> http://www.hotfix.pl/instrukcja-obslugi ... r-a341.htm + nowe logi z OTL.
Kiedy komputery staną się twoim jedynym życiem, jedynym totemem odstraszającym klątwę nudy, wtedy prędzej czy później granica między tymi dwoma wymiarami zniknie i postacie z Błękitnej Pustki zaczną pojawiać się w Realu. Czasem są twoimi przyjaciółmi. A czasem nie.

maczoszym12

Użytkownik
Posty: 2
Rejestracja: 19 gru 2012, 17:20

CoinMincer - Pomocy.

Post21 gru 2012, 01:09


Awatar użytkownika
kominekl

Ekspert
Posty: 5855
Rejestracja: 27 lis 2011, 14:25
Kontaktowanie:

CoinMincer - Pomocy.

Post21 gru 2012, 20:32

Oto log z po wykonaniu skryptu:


Powtórz wykonywanie skryptu, ale tym razem w trybie awaryjnym, a ponadto zapomniałeś o ADWCleaner.
Kiedy komputery staną się twoim jedynym życiem, jedynym totemem odstraszającym klątwę nudy, wtedy prędzej czy później granica między tymi dwoma wymiarami zniknie i postacie z Błękitnej Pustki zaczną pojawiać się w Realu. Czasem są twoimi przyjaciółmi. A czasem nie.



  • Reklama

Wróć do „Bezpieczeństwo”



Kto jest online

Użytkownicy przeglądający to forum: Obecnie na forum nie ma żadnego zarejestrowanego użytkownika i 5 gości