Cześć.
Podejrzewam, że w moim komputerze jest jakiś syf. Sądzę tak ponieważ jakiś czas temu było kilka nieudanych logowań na moje konto bankowe. Proszę o sprawdzenie logów.
OTL: http://wklej.org/hash/7bd3707abd4/
Extras: http://wklej.org/hash/5ae4a84e5f2/
Leon1
(Leon$)
27 Luty 2011 13:09
#2
OTL w oknie Custom Scans-Fixes (własne opcje skanowania/skrypt)wklej następujący skrypt:
:OTL PRC - [2010-12-14 16:21:05 | 000,161,361 | RHS- | M] () – C:\Windows\SysWOW64\service148.exe [2011-01-20 19:56:26 | 000,000,000 | —D | M] (vShare) – C:\Users\Mateusz\AppData\Roaming\mozilla\Firefox\Profiles\oea8b0t9.default\extensions\vshare@toolbar O2:64bit: - BHO: (no name) - {8664889D-ED18-4713-918F-E2BB69D8452B} - No CLSID value found. O2 - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll () O3:64bit: - HKLM…\Toolbar: (no name) - {8664889D-ED18-4713-918F-E2BB69D8452B} - No CLSID value found. O3 - HKLM…\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll () O3 - HKU\S-1-5-21-3048241399-3072757814-650109448-1000…\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll () O4 - HKLM…\Run: [Adobe Reader Speed Launcher] C:\Windows\SysWOW64\service148.exe () O4 - HKU\S-1-5-21-3048241399-3072757814-650109448-1000…\Run: [] File not found O4 - HKU\S-1-5-21-3048241399-3072757814-650109448-1000…\Run: [Adobe Reader Speed Launcher] C:\Windows\SysWOW64\service148.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Adobe Reader Speed Launcher = C:\Windows\SysWOW64\service148.exe () O7 - HKU\S-1-5-21-3048241399-3072757814-650109448-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Adobe Reader Speed Launcher = C:\Windows\SysWOW64\service148.exe () O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll () O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Windows\SysWOW64\service148.exe () MsConfig:64bit - StartUpReg: AOL Fast Start - hkey= - key= - File not found MsConfig:64bit - StartUpReg: Surfbar - hkey= - key= - File not found MsConfig:64bit - StartUpReg: SYSTEM - hkey= - key= - File not found MsConfig:64bit - StartUpReg: {A578008C-D130-B08E-D74A-76C29C9D2C1E} - hkey= - key= - File not found MsConfig:64bit - State: “startup” - Reg Error: Key error. [2010-12-14 16:21:08 | 000,161,361 | RHS- | C] () – C:\Windows\SysWow64\service148.exe :Files C:\Users\Mateusz\AppData\Local\Temp*.html :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp] [start explorer] [Reboot]
Kliknij w Run Fix (Wykonaj scrypt). Zatwierdź restart komputera.
potem nowy log OTL robiony opcją Run Scan (Skanuj)
Leon1
(Leon$)
27 Luty 2011 13:37
#4
Log wygląda na czysty
Pobierz CCleaner http://www.filehippo.com/download_ccleaner/
przeskanuj nim i wyczyść rejestr.
W OTL kilknij CleanUp (Sprzątanie)
Wyłącz i włącz przywracanie systemu na wszystkich dyskach.
przeskanuj
Dr.WEB CureIt! http://www.dobreprogramy.pl/DrWEB-CureI … 12976.html