klema80
(klema80)
25 Sierpień 2011 17:34
#1
Złapałem jakieś świństwo. Zamiast domyślnego google w firefoxie mam searchcompletion. Proszę o pomoc
http://wklej.org/id/584544/
http://wklej.org/id/584545/
Przeskanuj cały dysk programem malwarebytes.
Acorus
(Acorus)
26 Sierpień 2011 08:57
#3
Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKU\S-1-5-21-380733987-2623084136-2634799506-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1 FF - prefs.js…browser.search.defaultengine: “Web Search” FF - prefs.js…browser.search.defaultenginename: “Web Search” FF - prefs.js…browser.search.order.1: “Web Search” FF - prefs.js…browser.search.selectedEngine: “Web Search” FF - prefs.js…keyword.URL: “http://startsear.ch/?aff=1&q= ” [2011-07-11 20:04:02 | 000,000,633 | ---- | M] () – C:\Users\Klema\AppData\Roaming\Mozilla\Firefox\Profiles\xseqvaee.default\searchplugins\startsear.xml [2010-12-13 14:36:54 | 000,002,035 | ---- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchddr.xml O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com \facemoods\1.4.17.3\bh\facemoods.dll (facemoods.com BHO) O3:64bit: - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM…\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com \facemoods\1.4.17.3\facemoodsTlbr.dll (facemoods.com ) O3:64bit: - HKU\S-1-5-21-380733987-2623084136-2634799506-1001…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKU\S-1-5-21-380733987-2623084136-2634799506-1001…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM…\Run: [CafeNews] File not found O4 - HKLM…\Run: [facemoods] C:\Program Files (x86)\facemoods.com \facemoods\1.4.17.3\facemoodssrv.exe (facemoods.com ) O4 - HKU\S-1-5-21-380733987-2623084136-2634799506-1001…\Run: [AdobeBridge] File not found [2011-08-20 09:32:17 | 000,000,000 | —D | C] – C:\Users\Klema\AppData\Local\OpenCandy [2011-08-20 09:32:09 | 000,000,000 | —D | C] – C:\Users\Klema\AppData\Roaming\OpenCandy [2011-08-25 19:11:39 | 000,000,408 | ---- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job :Commands [emptytemp]
Kliknij Wykonaj skrypt .Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.
Odinstaluj Przyspiesz Komputer,Ad-Aware,DAEMON Tools Toolbar.