Witam, od jakiegoś czasu strona główna zmieniała się na “qooqlle.com” Gdy ustawiłem znowu na Google, ale po restarcie znowu w oknie przeglądarki widzę “qooqlle”. Po włożeniu pen-drive wirus go automatycznie infekuje
========== OTL ==========
Service cpuz132 stopped successfully!
Service cpuz132 deleted successfully!
File C:\DOCUME~1\Viki\USTAWI~1\Temp\cpuz132\cpuz132_x32.sys not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "qooqlle" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "http://www.qooqlle.com/" removed from browser.startup.homepage
Prefs.js: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198 removed from extensions.enabledItems
Prefs.js: toolbar@ask.com:3.9.1.14019 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 removed from extensions.enabledItems
Prefs.js: jqs@sun.com:1.0 removed from extensions.enabledItems
Prefs.js: expressivo@expressivo.com:1.0 removed from extensions.enabledItems
Prefs.js: DTToolbar@toolbarnet.com:1.1.2.0185 removed from extensions.enabledItems
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dc37da6-df4d-11df-950c-001a4d961a57}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7dc37da6-df4d-11df-950c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dc37da6-df4d-11df-950c-001a4d961a57}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7dc37da6-df4d-11df-950c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7dc37da6-df4d-11df-950c-001a4d961a57}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7dc37da6-df4d-11df-950c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93562c14-b1ca-11df-948c-001a4d961a57}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93562c14-b1ca-11df-948c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93562c14-b1ca-11df-948c-001a4d961a57}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93562c14-b1ca-11df-948c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93562c14-b1ca-11df-948c-001a4d961a57}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93562c14-b1ca-11df-948c-001a4d961a57}\ not found.
File G:\ln9.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c845964c-a7bf-11df-945f-000ee8ef4e75}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c845964c-a7bf-11df-945f-000ee8ef4e75}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c845964c-a7bf-11df-945f-000ee8ef4e75}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c845964c-a7bf-11df-945f-000ee8ef4e75}\ not found.
File move failed. H:\LaunchU3.exe scheduled to be moved on reboot.
========== FILES ==========
C:\WINDOWS\system32\kav320.dll moved successfully.
C:\Documents and Settings\All Users\GProton.exe moved successfully.
C:\WINDOWS\system32\amvo.exe moved successfully.
OTL by OldTimer - Version 3.2.20.1 log created on 01052011_162311
Files\Folders moved on Reboot...
File move failed. H:\LaunchU3.exe scheduled to be moved on reboot.
Registry entries deleted on Reboot...