toms07
(Toms07)
12 Marzec 2011 14:08
#1
Witam wszystkich. Mam następujacy problem, mianowicie zamiast domyslnie wp.pl (jak mialem zawsze), wyskakuje mi ‘przegladarka’ qooqlle. Zauwazylem takze coraz wiecej problemow w systemie( po qooqllu ), min. dosc duze zamulanie systemu oraz opcja ‘pokazuj ukryte pliki i foldery’ nagle sama sie wlacza. Zobaczylem program OTL, wiec zrobilem skan (wedlug tej stronki - otl-gmer-rsit-dss-inne-instrukcje-t370405.html .
http://wklej.org/id/491460/
http://wklej.org/id/491462/
Jesli cos zauwazycie to prosze o pomoc, gdyz Avast oczywiscie nie widzi zadnych problemow
Wklej w OTL i naciśnij wykonaj skrypt:
:OTL SRV - File not found [Auto | Stopped] – -- (StarWindService) DRV - [2004-02-15 23:06:34 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Stopped] – C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\dbustrcm.sys – (dbustrcm) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ FF - prefs.js…browser.search.selectedEngine: “qooqlle” FF - prefs.js…browser.startup.homepage: “http://www.qooqlle.com/ ” O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found. O3 - HKCU…\Toolbar\WebBrowser: (no name) - {1CE4EE89-2D5C-4361-AF3B-D902AB545381} - No CLSID value found. O3 - HKCU…\Toolbar\WebBrowser: (no name) - {3B5BA1A9-F973-465F-B12B-7B648ADF8391} - No CLSID value found. O4 - HKLM…\Run: [TunesHelper] C:\Documents and Settings\All Users\TunesHelper.exe () O33 - MountPoints2{2a4520ae-160f-11de-a314-028037130300}\Shell\AutoRun\command - “” = K:\bd3q0qix.exe O33 - MountPoints2{2a4520ae-160f-11de-a314-028037130300}\Shell\open\Command - “” = K:\bd3q0qix.exe O33 - MountPoints2{93d5d255-1e0c-11dd-a0ca-0080c6e9e0b8}\Shell\Open(&0)\command - “” = Recycled\ctfmon.exe O33 - MountPoints2{9904d329-eb80-11dc-b57c-0080c6e9e0b8}\Shell\Auto\command - “” = sal.xls.exe O33 - MountPoints2{9904d329-eb80-11dc-b57c-0080c6e9e0b8}\Shell\AutoRun\command - “” = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe O33 - MountPoints2{9979f116-d711-11dc-a0f9-0080c6e9e0b8}\Shell - “” = AutoRun O33 - MountPoints2{9979f116-d711-11dc-a0f9-0080c6e9e0b8}\Shell\AutoRun\command - “” = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs O33 - MountPoints2{f18217cc-d4c7-11dc-a0f3-0080c6e9e0b8}\Shell - “” = AutoRun O33 - MountPoints2{f18217cc-d4c7-11dc-a0f3-0080c6e9e0b8}\Shell\AutoRun\command - “” = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - File not found [2011-02-14 00:38:16 | 000,331,776 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\Documents and Settings\Administrator\Dane aplikacji\Readar_sl.exe [2011-02-14 00:38:14 | 000,335,872 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\Documents and Settings\Administrator\Dane aplikacji\VolPanel.exe [2011-03-12 14:35:22 | 000,000,260 | ---- | M] () – C:\windows\tasks\WGASetup.job [2011-02-14 00:37:55 | 000,335,872 | RHS- | M] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\Documents and Settings\Administrator\Dane aplikacji\VolPanel.exe [2011-02-14 00:37:53 | 008,179,200 | RHS- | M] () – C:\Documents and Settings\All Users\TunesHelper.exe [2011-02-14 00:37:52 | 000,331,776 | RHS- | M] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\Documents and Settings\Administrator\Dane aplikacji\Readar_sl.exe @Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:CE2C623F :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]
dajesz log z usuwania i nowy log z OTL
toms07
(Toms07)
12 Marzec 2011 14:44
#3
Podałeś stare logi z OTL, wykonaj teraz nowe i wstaw aby mieć pewność ze wszystko się usunęło.
toms07
(Toms07)
12 Marzec 2011 14:55
#5
Wklej jeszcze w OTL i naciśnij wykonaj skrypt
Po restarcie komputera naciśnij w OTL sprzątanie i to na tyle