przeskanowalem skanerem online eset wyszly jakies pliki win 32 odrazu mi je usunelo problem nadal jest
To nie są programy do wyboru. Pokaż OTL oraz RSIT
Pokaż plik OTL.txt z programu OTL
Pliki:
Kod:
C: \Windows\System32\srvany.exe
Przeskanuj na
http://www.virustotal.com
Do OTL w własne pole skanowania skrypt wklej :
Kod:
: Processes
Killallprocesses
: Files
C: \Windows\tsnp325.exe
C: \Windows\tsnp2std.exe
C: \Windows\tsnp325.exe
C: \Windows\vsnp325.exe
C: \Windows\hpdj3840.ini
C: \Windows\snp2std.ini
C: \Windows\System32\drivers\snp2sxp.sys
C: \Windows\System32\drivers\sncamd.sys
: OTL
O2 - BHO: (ALOT Toolbar Helper) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C: \Program Files\alot\bin\BHO\alotBHO.dll (Vertro)
O2 - BHO: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C: \Program Files\Softonic-Eng7\prxtbSof0.dll File not found
O2 - BHO: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C: \Program Files\Mario_Forever\tbMari.dll File not found
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C: \Program Files\BitTorrentBar\prxtbBit2.dll File not found
O2 - BHO: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - C: \Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C: \Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (mobilewitch Toolbar) - {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C: \Program Files\mobilewitch\prxtbmobi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C: \Program Files\Softonic-Eng7\prxtbSof0.dll File not found
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C: \Program Files\alot\bin\alot.dll (Vertro)
O3 - HKLM\..\Toolbar: (Mario Forever Toolbar) - {707db484-2428-402d-afb5-d85b387544c7} - C: \Program Files\Mario_Forever\tbMari.dll File not found
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C: \Program Files\BitTorrentBar\prxtbBit2.dll File not found
O3 - HKLM\..\Toolbar: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - C: \Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (mobilewitch Toolbar) - {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C: \Program Files\mobilewitch\prxtbmobi.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Softonic-Eng7 Toolbar) - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C: \Program Files\Softonic-Eng7\prxtbSof0.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C: \Program Files\BitTorrentBar\prxtbBit2.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (PageRage Toolbar) - {9565115D-C7D6-46D3-BD63-B67B481A4368} - C: \Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (mobilewitch Toolbar) - {FCBF663E-8530-46F8-A880-AC5ABE9D2B23} - C: \Program Files\mobilewitch\prxtbmobi.dll (Conduit Ltd.)
O4 - HKLM..\Run: [snp2std] C: \Windows\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [tsnp2std] C: \Windows\tsnp2std.exe ()
O4 - HKLM..\Run: [tsnp325] C: \Windows\tsnp325.exe ()
@Alternate Data Stream - 139 bytes -> C: \ProgramData\TEMP: 0B4227B4
@Alternate Data Stream - 104 bytes -> C: \ProgramData\TEMP: D1B5B4F1
: Commands
[EMPTYTEMP]
[EMPTYFLASH]
Wykonaj skrypt.
Przeskanuj obszar wszystkich partycji programem
http://www.dobreprogramy.pl/Malwarebytes...13117.html - Aktualizacja , pełny skan.
tu masz ten otl jak wklejilem skrypt
http://wklej.org/id/654332/
w ViruTotal - TheHacker 6.7.0.1.365 2011.12.25 Trojan/FlyStudio.bo
malwarebytes nic nie wykryło
Jakaś poprawa? Pokaż nowy log z OTL oraz RSIT
C:\Windows\system32\Dwm.exe czysto
Windows\system32\drivers\DrvAgent32.sys czysto
Windows\system32\drivers\nvlddmkm.sys czysto
W OTL naciśnij sprzątanie. Wszystko. To nie jest wina złośliwego oprogramowania.
Nacisnąłem i ponownie uruchomiłem kompa, żadnej poprawy nie widze, nie da sie włączyć dalej zapory