LOG
p.s. starałem się napisać posta według zasad. pomożecie? i sprawdzicie?
LOG
p.s. starałem się napisać posta według zasad. pomożecie? i sprawdzicie?
Pobierz ComboFix, ale nie uruchamiaj
Otwórz notatnik i wklej do niego:
File::
C:\Documents and Settings\Wcatchme.zip
C:\WINDOWS\system32\upuuojei.dll
C:\WINDOWS\system32\upuuojei.nls
C:\WINDOWS\system32\glypodlb.dll
C:\WINDOWS\system32\disysrwb.dll
C:\WINDOWS\system32\dphqyacg.dll
C:\WINDOWS\system32\glypodlb.nls
C:\WINDOWS\system32\dphqyacg.nls
C:\WINDOWS\system32\disysrwb.nls
C:\WINDOWS\system32\jydhjaco.dll
C:\WINDOWS\system32\jrabhcsy.dll
C:\WINDOWS\system32\jydhjaco.nls
C:\WINDOWS\system32\jrabhcsy.nls
C:\WINDOWS\system32\tdvbvbyo.nls
C:\WINDOWS\system32\jrqqcduk.nls
C:\WINDOWS\system32\dtisoykm.nls
C:\WINDOWS\system32\aughvqcp.nls
C:\WINDOWS\system32\pequqian.nls
C:\WINDOWS\system32\mtvpyhic.nls
Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-
"{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"mtvpyhic.dll"=-
"jrabhcsy.dll"=-
"nwapi32dj.dll"=-
Plik -> zapisz jako -> CFScript.txt.
Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu->
Rozpocznie się usuwanie i powstanie log, który dasz na forum.
Logi dajesz na http://wklej.eu lub na http://wklej.org a w poście dajesz tylko link
pobierz i zastosuj ATF Cleaner http://cybertrash.pl/images/tata/ATF/ATF.html
Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl
pobierz i przeskanuj Kaspersky Virus Removal Tool http://www.searchengines.pl/index.php?s … ntry354381
potem nowy log Combifixa
Pobierz System Repair Engineer
http://www.cybertrash.pl/images/tata/System%20Repair/System%20Repair%20Engineer.html
przeskanuj daj log
ATF Cleaner zastosowałem
Wyłącz przywracanie systemu na wszystkich dyskach - zrobione
Kaspersky Virus Removal Tool - skanował ale nie do końca zacinał się ponowna próba również nie udana. :evil: :?: :!:
LOG z Combofixa http://wklej.org/id/5949/
LOG z System Repair Engineer http://wklej.org/id/5951/
Pobierz ComboFix, ale nie uruchamiaj
Otwórz notatnik i wklej do niego:
File::
C:\WINDOWS\system32\eqheccev.dll
C:\WINDOWS\system32\xlwathli.dll
C:\WINDOWS\system32\qbdutjzp.dll
C:\WINDOWS\system32\xlwathli.nls
C:\WINDOWS\system32\qbdutjzp.nls
C:\WINDOWS\system32\eqheccev.nls
C:\WINDOWS\system32\ghjvdwys.dll
C:\WINDOWS\system32\pikfkvat.dll
C:\WINDOWS\system32\pikfkvat.nls
C:\WINDOWS\system32\ghjvdwys.nls
C:\WINDOWS\system32\fhmoohuz.dll
C:\WINDOWS\system32\ssqwfgos.dll
C:\WINDOWS\system32\lutscltj.dll
C:\WINDOWS\system32\fhmoohuz.nls
C:\WINDOWS\system32\ssqwfgos.nls
C:\WINDOWS\system32\lutscltj.nls
C:\WINDOWS\system32\yqanwxux.dll
C:\WINDOWS\system32\rlpjottr.dll
C:\WINDOWS\system32\ohzkyrsp.dll
C:\WINDOWS\system32\xumazbtz.dll
C:\WINDOWS\system32\rlpjottr.nls
C:\WINDOWS\system32\ohzkyrsp.nls
C:\WINDOWS\system32\xumazbtz.nls
C:\WINDOWS\system32\yqanwxux.nls
C:\WINDOWS\system32\qydzlyge.dll
C:\WINDOWS\system32\qydzlyge.nls
C:\WINDOWS\system32\nwjmsxnu.nls
C:\WINDOWS\system32\cvhztxrw.dll
C:\WINDOWS\system32\jagsqqwv.dll
C:\WINDOWS\system32\mvxrgtxq.dll
C:\WINDOWS\system32\jagsqqwv.nls
C:\WINDOWS\system32\cvhztxrw.nls
C:\WINDOWS\system32\mvxrgtxq.nls
C:\WINDOWS\system32\vklnende.nls
C:\WINDOWS\system32\psfmhiat.nls
C:\WINDOWS\system32\pofshpxg.nls
C:\Program Files\YSFLIGHT.COM
C:\WINDOWS\system32\odtknxcd.nls
C:\WINDOWS\system32\ktkqfhgh.nls
C:\WINDOWS\system32\wwgmftfr.dll
C:\WINDOWS\system32\aolfsshs.nls
C:\WINDOWS\system32\wwgmftfr.nls
Registry::
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"3PMmUpdate"=-
"HBService"=-
"WinSysM"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}”=-
"{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}”=-
"{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}”=-
"{71A78CD4-E470-4a18-8457-E0E0283DD507}”=-
"{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}”=-
"{F0930A2F-D971-4828-8209-B7DFD266ED44}”=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"sysocmgr”=-
"omruqtuh.dll”=-
"oifhnovm.dll”=-
"pxjjzzsd.dll”=-
"vzrifyno.dll”=-
"zvwnsrac.dll”=-
"dmchfpcv.dll”=-
Plik -> zapisz jako -> CFScript.txt.
Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu->
Rozpocznie się usuwanie i powstanie log, który dasz na forum.
Logi dajesz na http://wklej.eu lub na http://wklej.org a w poście dajesz tylko link
uruchom System Repair Engineer zakładka System Repair Browser Add-ons odszukaj i usuń
Wyłącz przywracanie systemu na wszystkich dyskach. Instrukcja
Pobierz Combofix ale nie uruchamiaj wklej do notatnika:
File::
C:\WINDOWS\system32\drivers\nvmini.sys
C:\WINDOWS\linkinfo.dll
C:\Documents and Settings\Wcatchme.zip
C:\WINDOWS\system32\ylmkblgo.dll
C:\WINDOWS\system32\ryqsqkds.dll
C:\WINDOWS\system32\zosdofk.exe
C:\WINDOWS\system32\ylmkblgo.nls
C:\WINDOWS\system32\ryqsqkds.nls
C:\WINDOWS\system32\axzbwcqh.dll
C:\WINDOWS\system32\axzbwcqh.nls
C:\WINDOWS\system32\qsiqinrs.dll
C:\WINDOWS\system32\qpxdgjsx.dll
C:\WINDOWS\system32\qsiqinrs.nls
C:\WINDOWS\system32\qpxdgjsx.nls
C:\WINDOWS\system32\scnhmzfr.dll
C:\WINDOWS\system32\sjzwhxpz.dll
C:\WINDOWS\system32\bzpzlmff.dll
C:\WINDOWS\system32\vxpzfmkt.dll
C:\WINDOWS\system32\sjzwhxpz.nls
C:\WINDOWS\system32\scnhmzfr.nls
C:\WINDOWS\system32\bzpzlmff.nls
C:\WINDOWS\system32\vxpzfmkt.nls
C:\WINDOWS\system32\kacvuvdc.dll
C:\WINDOWS\system32\utpgntzg.dll
C:\WINDOWS\system32\xlgdluxv.nls
C:\WINDOWS\system32\utpgntzg.nls
C:\WINDOWS\system32\bzakwotu.nls
C:\WINDOWS\system32\kacvuvdc.nls
C:\WINDOWS\system32\arapebft.nls
C:\WINDOWS\system32\zvwnsrac.nls
C:\WINDOWS\system32\vzrifyno.nls
C:\WINDOWS\system32\dmchfpcv.nls
C:\WINDOWS\system32\pxjjzzsd.nls
C:\WINDOWS\system32\oifhnovm.nls
C:\WINDOWS\855731MM.DLL
C:\WINDOWS\855731M.exe
C:\WINDOWS\system32\zosdof.dll
C:\WINDOWS\system32\omruqtuh.nls
C:\WINDOWS\system32\nwapi32dj.dll
C:\WINDOWS\system32\nwapi32dj.nls
C:\WINDOWS\system32\twainyy.nls
Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}"=-
"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nvmini]
Zapisz plik jako CFScript.txt najlepiej aby ikonka tego pliku znajdowała się obok ikonki ComboFix.exe
Przeciągnij i upuść plik CFScript.txt na ikonkę ComboFix.exe powinno rozpocząć się usuwanie po tym daj log na forum.
Loga wklej na http://www.wklejto.pl lub http://www.wklej.org/ a w poście daj linka
Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl
Otwórz notatnik i wklej
zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe
http://img.wklej.org/images/88953CFScri … iemoes.gif
Powinno rozpocząć się usuwanie
Potem log z usuwania Combofix
potem nowy log System Repair przed skanem odznacz Hosts File
Otwórz notatnik i wklej
zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe
http://img.wklej.org/images/88953CFScri … iemoes.gif
Powinno rozpocząć się usuwanie
Potem log z usuwania Combofix
Pobierz program SDFix
kolejny loghttp://wklej.org/id/8055/\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\r\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\np.s. często komp się resetuje podczas uruchamiania Mozilla Firefox… doszło do tego ze cały czas tak się działo, przeskanowanie Combofixem pomogło, ale na jak długo??
Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl
Otwórz notatnik i wklej
zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe
http://img.wklej.org/images/88953CFScri … iemoes.gif
Powinno rozpocząć się usuwanie
Potem log z usuwania Combofix
Otwórz notatnik i wklej
zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe
http://img.wklej.org/images/88953CFScri … iemoes.gif
Powinno rozpocząć się usuwanie
Potem log z usuwania Combofix
Pobierz program SDFix
Log z combofix http://wklej.org/id/8502/
w miedzy czasie combofixa używałem kilka razy gdyż przy każdej próbie uruchomienia przeglądarki następował reset, dopiera combofix pomagał.
Report z SDFixhttp://wklej.org/id/8506/
Log z System Repair Engineer http://wklej.org/id/8511/