Antivirus Protection 2012 problem

Witam. Zauwazyłem ze nie tylko ja mam problem z tym dziadostwem… Nie wiem jak to usunąc… widziałem poprzednie wątki dotyczące tego problemu ale nie wiem czy rozwiazania które tam byly mozna zastosowac do kazdego kompa. Wiec prosze o pomoc w odinstalowaniu tego programu

Dodane 03.03.2012 (So) 15:51

http://wklej.org/id/700841/

Dodane 03.03.2012 (So) 20:04

http://wklej.org/id/701054/

Dodane 03.03.2012 (So) 20:14

E tam sam to ja ch… zrobie:D pół dnia i nic ehehe niby robiłem tak jak było w innych postach ale juz nic nie wiem… chyba wywale to przez okno przynajmniej bd wolny od nałogu: /

Dodane 03.03.2012 (So) 20:16

moze ktos pomoze??: )

Odinstaluj MediaBar, ASK Toolbar, SearchYa Toolbar, DAEMON Tools Toolbar, compliance 54328 Toolbar, Babylon Toolbar, VShareToolBar, DealPly, System Search Dispatcher, My Global Search Bar.

Do okna Własne opcje skanowania / skrypt wklej:

:OTL

DRV - File not found [Kernel | On_Demand | Unknown] -- -- (azqckw3k)

DRV - [2012-02-27 15:28:15 | 000,143,360 | ---- | M] () [Kernel | Auto | Running] -- C:\Documents and Settings\MARIUSZ\Ustawienia lokalne\Temp\5689.sys -- (5689)

SRV - [2009-11-26 15:27:50 | 000,058,744 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\QueryService\queryservice129.exe -- (QueryService Service)

SRV - [2009-04-02 11:47:04 | 000,234,888 | ---- | M] () [Auto | Stopped] -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/

IE - HKU\S-1-5-21-2000478354-1972579041-725345543-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=ace03152-28c0-11e1-9b4e-0019213cba57

IE - HKU\S-1-5-21-2000478354-1972579041-725345543-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.theprizeday.com/today.php

IE - HKU\S-1-5-21-2000478354-1972579041-725345543-1001\..\URLSearchHook: {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - C:\Program Files\MyPlayCity\prxtbMyP0.dll (Conduit Ltd.)

IE - HKU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

IE - HKU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp

IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/ie.aspx?q={searchTerms}

IE - HKU\..\SearchScopes\{0B278C6F-EC6B-3477-311E-6342928C69FF}: "URL" = http://flv.asksearch.com/s/?q={searchTerms}&iesrc={referrer:source?}&cfg=2-113-11-yXRH

IE - HKU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=ace03152-28c0-11e1-9b4e-0019213cba57&q={searchTerms}

IE - HKU\..\SearchScopes\{436F784C-2503-423d-9111-0F4B0D49585B}: "URL" = http://home.speedbit.com/search.aspx?aff=206&q={searchTerms}

IE - HKU\..\SearchScopes\{62DB0434-847A-4836-BF16-07153B2CE9C5}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1392740

IE - HKU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/webResults.html?src=ieb&q={searchTerms}

IE - HKU\..\SearchScopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D}: "URL" = 

IE - HKU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q={searchTerms}&crm=1

IE - HKU\..\SearchScopes\{FC822380-5D46-4D33-8280-2674879B41D7}: "URL" = http://search.babylon.com/?q={searchTerms}&babsrc=SP_def&AF=15627

IE - HKU\S-1-5-21-2000478354-1972579041-725345543-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKU\S-1-5-21-2000478354-1972579041-725345543-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63414

FF - prefs.js..network.proxy.http: "127.0.0.1"

FF - prefs.js..network.proxy.http_port: 63414

FF - prefs.js..network.proxy.type: 1

O4 - HKLM..\Run: [921.exe] C:\Program Files\LP\A57F\921.exe ()

O4 - HKLM..\Run: [AVPDWIN] "C:\Program Files\Panda Software\Panda Demo\pandasft.exe" File not found

O4 - HKLM..\Run: [BearShare] "e:\Program Files\BearShare\BearShare.exe" /pause File not found

O4 - HKLM..\Run: [crrss] C:\WINDOWS\system32\crrss.exe ()

O4 - HKLM..\Run: [wcmdmgr] C:\WINDOWS\wt\wcmdmgrl.exe (WildTangent, Inc.)

O4 - HKLM..\Run: [WinDefender] C:\WINDOWS\Wincft.exe ()

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [9uhlt1uwvd87] C:\Documents and Settings\Właściciel\Dane aplikacji\Antivirus Protection 2012\securityhelper.exe (KlureIn)

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [AdVantage] C:\Documents and Settings\Właściciel\Dane aplikacji\advantage\AdVantage.exe (Vomba Network)

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [Antivirus Protection 2012] C:\Documents and Settings\Właściciel\Dane aplikacji\Antivirus Protection 2012\AntivirusProtection2012.exe (KlureIn)

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [Antivirus Protection 2012 SH] C:\Documents and Settings\Właściciel\Dane aplikacji\Antivirus Protection 2012\securityhelper.exe (KlureIn)

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [Antivirus Protection 2012 SM] C:\Documents and Settings\Właściciel\Dane aplikacji\Antivirus Protection 2012\securitymanager.exe (KlureIn)

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [Badoo Desktop] C:\Documents and Settings\All Users\Dane aplikacji\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe File not found

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [DAEMON Tools Pro Agent] "E:\Program Files\DAEMON Tools Pro\DTProAgent.exe" File not found

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [Gadu-Gadu] "E:\Program Files\Gadu-Gadu\gg.exe" /tray File not found

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [odk_mcd] File not found

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [PowerBar] File not found

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [RegistryWm] C:\Documents and Settings\Właściciel\Dane aplikacji\qtwm.exe ()

O4 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001..\Run: [winlogon] C:\Documents and Settings\Właściciel\winlogon.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\WebChoice.lnk = File not found

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\crrss.exe) - C:\WINDOWS\system32\crrss.exe ()

O20 - HKU\S-1-5-21-2000478354-1972579041-725345543-1001 Winlogon: Shell - ("C:\Documents and Settings\Właściciel\winlogon.exe") - C:\Documents and Settings\Właściciel\winlogon.exe ()

O32 - AutoRun File - [2008-09-09 15:21:47 | 000,000,056 | ---- | M] () - E:\autorun.inf -- [NTFS]

O33 - MountPoints2\{9948a6c9-314f-11dc-b196-0019213cba57}\Shell\AutoRun\command - "" = N:\RECYCLER\S-1-6-21-6129016431-0312943124-490191164-4243\fileview.exe

O33 - MountPoints2\{9948a6c9-314f-11dc-b196-0019213cba57}\Shell\open\command - "" = N:\RECYCLER\S-1-6-21-6129016431-0312943124-490191164-4243\fileview.exe

O33 - MountPoints2\{dffd851e-504a-11dd-b4fe-0019213cba57}\Shell\AutoRun\command - "" = D:\RECYCLER\S-1-6-21-6129016431-0312943124-490191164-4243\fileview.exe

O33 - MountPoints2\{dffd851e-504a-11dd-b4fe-0019213cba57}\Shell\open\command - "" = D:\RECYCLER\S-1-6-21-6129016431-0312943124-490191164-4243\fileview.exe


:Files

C:\Documents and Settings\Właściciel\Menu Start\Programy\Antivirus Protection 2012

C:\Documents and Settings\Właściciel\Dane aplikacji\Antivirus Protection 2012

C:\Program Files\87490

C:\Documents and Settings\Właściciel\Dane aplikacji\F8F87

C:\Program Files\LP

C:\Documents and Settings\Właściciel\Dane aplikacji\*.exe

C:\Documents and Settings\Właściciel\Pulpit\Antivirus Protection 2012.lnk


:Reg

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

[HKEY_USERS\S-1-5-21-2000478354-1972579041-725345543-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"Shell"=- 


:Commands

[emptytemp]

Kliknij Wykonaj skrypt i zatwierdź restart.

Pokaż raport z usuwania i nowy log Skanuj.