Re: přepsani souboru na připonu ENCODED
Napsal: 27 říj 2010 15:26
spust OTL-do okna zkopiruj zeleny text a klik RunFix
log po restarte vloz sem.
Potom otestuj na www.virustotal.com subory
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\dllcache\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
link z testov vloz sem, ak vypise ze uz boli testovane, daj reanalyse.
log po restarte vloz sem.
Potom otestuj na www.virustotal.com subory
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\dllcache\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
link z testov vloz sem, ak vypise ze uz boli testovane, daj reanalyse.
Kód: Vybrat vše
:OTL
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
[2010.10.21 23:09:53 | 000,026,684 | ---- | M] () -- C:\WINDOWS\Řeka Sumida.bmp.ENCODED
[2010.10.21 23:09:53 | 000,026,586 | ---- | M] () -- C:\WINDOWS\Zelený kámen.bmp.ENCODED
[2010.10.21 23:09:53 | 000,017,066 | ---- | M] () -- C:\WINDOWS\Zrnko kávy.bmp.ENCODED
[2010.10.21 23:09:53 | 000,009,526 | ---- | M] () -- C:\WINDOWS\Zapotec.bmp.ENCODED
[2010.10.21 23:09:52 | 002,359,354 | ---- | M] () -- C:\WINDOWS\Windows XP XII.BMP.ENCODED
[2010.10.21 23:09:52 | 000,048,684 | -HS- | M] () -- C:\WINDOWS\winnt256.bmp.ENCODED
[2010.10.21 23:09:52 | 000,048,684 | -HS- | M] () -- C:\WINDOWS\winnt.bmp.ENCODED
[2010.10.21 23:09:27 | 000,016,734 | ---- | M] () -- C:\WINDOWS\Textura peří.bmp.ENCODED
[2010.10.21 23:09:19 | 000,240,124 | ---- | M] () -- C:\WINDOWS\System32\setup.bmp.ENCODED
[2010.10.21 23:04:53 | 000,017,366 | ---- | M] () -- C:\WINDOWS\Rododendron.bmp.ENCODED
[2010.10.21 23:04:52 | 000,065,958 | ---- | M] () -- C:\WINDOWS\Prérijní vítr.bmp.ENCODED
[2010.10.21 23:04:29 | 000,065,982 | ---- | M] () -- C:\WINDOWS\Mýdlové bubliny.bmp.ENCODED
[2010.10.21 23:04:29 | 000,065,836 | ---- | M] () -- C:\WINDOWS\Omítka Santa Fe.bmp.ENCODED
[2010.10.21 23:04:29 | 000,017,340 | ---- | M] () -- C:\WINDOWS\Na rybách.bmp.ENCODED
[2010.10.21 23:04:29 | 000,001,276 | ---- | M] () -- C:\WINDOWS\Modrá krajka 16.bmp.ENCODED
[2010.10.21 23:04:21 | 000,082,948 | ---- | M] () -- C:\WINDOWS\clock.avi.ENCODED
:Commands
[resethosts]
[emptytemp]
[clearallrestorepoints]
[start explorer]
[EMPTYFLASH]
[Reboot]