trabant11
(Trabant11)
29 Sierpień 2011 18:50
#1
Witam
Kilka dni temu złapałem wirusa z portalu facebook, i od tego czasu komputer przestał się uruchamiać. Kolega poradził sobie z tym problemem i komputer działa ale nie mogę uruchomić strony Facebook. Proszę o pomoc, lub nakierowanie w tym temacie.
4lpha
(4lpha)
29 Sierpień 2011 19:12
#2
trabant11
(Trabant11)
29 Sierpień 2011 19:25
#3
Leon1
(Leon$)
29 Sierpień 2011 19:52
#4
OTL w oknie Custom Scans-Fixes (własne opcje skanowania/skrypt)wklej następujący skrypt:
:OTL SRV - File not found [Auto | Stopped] – -- (wxpdrivers) SRV - File not found [Auto | Stopped] – -- (srvsysdriver32) SRV - File not found [Auto | Stopped] – -- (srviecheck) SRV - File not found [Auto | Stopped] – -- (srvbtcclient) SRV - File not found [Auto | Stopped] – -- (ddservice) SRV - File not found [Auto | Stopped] – -- (avg9wd) IE - HKU.DEFAULT…\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found IE - HKU\S-1-5-18…\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found IE - HKU\S-1-5-21-1708537768-1659004503-1177238915-1003…\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found IE - HKU\S-1-5-21-1708537768-1659004503-1177238915-1003…\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net \prxtbfre0.dll (Conduit Ltd.) FF - prefs.js…browser.search.defaultthis.engineName: “free-downloads.net Customized Web Search” FF - prefs.js…browser.search.defaulturl: “http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms} ” FF - HKLM\Software\MozillaPlugins@real.com/nsJSRealPlayerPlugin;version=: File not found [2011-06-20 14:08:26 | 000,000,939 | ---- | M] () – C:\Documents and Settings\Iv\Dane aplikacji\Mozilla\Firefox\Profiles\kus7nnb6.default\searchplugins\conduit.xml [2011-08-01 14:56:22 | 000,000,000 | —D | M] (free-downloads.net Community Toolbar) – C:\Documents and Settings\Iv\Dane aplikacji\Mozilla\Firefox\Profiles\kus7nnb6.default\extensions{ecdee021-0d17-467f-a1ff-c7a115230949} O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net \prxtbfre0.dll (Conduit Ltd.) O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found. O3 - HKLM…\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found O3 - HKLM…\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net \prxtbfre0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-1708537768-1659004503-1177238915-1003…\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found O4 - HKU\S-1-5-21-1708537768-1659004503-1177238915-1003…\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10s_Plugin.exe (Adobe Systems, Inc.) O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found O31 - SafeBoot: AlternateShell - services32.exe O33 - MountPoints2{82d4ca16-22f0-11e0-ba14-001dd9fc8bdd}\Shell\AutoRun\command - “” = G:\kyme.exe O33 - MountPoints2{82d4ca16-22f0-11e0-ba14-001dd9fc8bdd}\Shell\open\Command - “” = G:\kyme.exe O33 - MountPoints2{da64510b-189d-11df-b8e3-001b380d7516}\Shell\AutoRun\command - “” = G:\RECYCLER32\dmgr.exe O33 - MountPoints2{da64510b-189d-11df-b8e3-001b380d7516}\Shell\open\command - “” = G:\RECYCLER32\dmgr.exe MsConfig - StartUpReg: AVG9_TRAY - hkey= - key= - File not found MsConfig - StartUpReg: Broadcom Wireless Manager UI - hkey= - key= - File not found MsConfig - StartUpReg: ctfmon.exe - hkey= - key= - File not found MsConfig - StartUpReg: HotKeysCmds - hkey= - key= - File not found MsConfig - StartUpReg: IgfxTray - hkey= - key= - File not found MsConfig - StartUpReg: Persistence - hkey= - key= - File not found MsConfig - StartUpReg: uTorrent - hkey= - key= - File not found SafeBootMin: wxpdrivers - File not found SafeBootNet: wxpdrivers - File not found [2011-08-22 17:21:21 | 000,000,000 | —D | C] – C:\WINDOWS\av_ico [2011-08-23 19:15:50 | 000,000,202 | ---- | M] () – C:\WINDOWS\info1 [2011-08-22 22:35:26 | 000,000,000 | ---- | M] () – C:\WINDOWS\loader2.exe_ok [2011-08-22 22:35:10 | 000,904,792 | ---- | M] () – C:\WINDOWS\geoiplist.rar [2011-08-22 22:35:10 | 000,246,272 | ---- | M] () – C:\WINDOWS\unrar.exe [2011-08-22 22:35:11 | 004,636,907 | ---- | C] () – C:\WINDOWS\geoiplist [2011-08-29 21:20:00 | 000,000,456 | -H-- | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{18DF5627-44EF-4E0A-9B1E-1CCEEFC9ADC4}.job :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] “AlternateShell”=“cmd.exe” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] “D:\Flash-Player.exe”=- “C:\WINDOWS\update.1\svchost.exe”=- “C:\WINDOWS\services32.exe”=- “C:\WINDOWS\update.2\svchost.exe”=- :Commands [CLEARALLRESTOREPOINTS] [RESETHOSTS] [emptytemp]
Kliknij w Run Fix (Wykonaj scrypt). Zatwierdź restart komputera.
Pokaż log z usuwania.
potem nowy log OTL robiony opcją Run Scan (Skanuj)
trabant11
(Trabant11)
29 Sierpień 2011 20:20
#5
nie mogę wykonać scryptu, zacina się w momencie kiedy dojdzie do pliku wxpdrivers i pisze że nie może go odnaleźć
trabant11
(Trabant11)
30 Sierpień 2011 17:44
#7
Leon1
(Leon$)
30 Sierpień 2011 18:46
#8
Log wygląda na czysty
Pobierz CCleaner http://www.filehippo.com/download_ccleaner/
przeskanuj nim i wyczyść rejestr.
W OTL kilknij CleanUp (Sprzątanie)
przeskanuj
Dr.WEB CureIt! http://www.dobreprogramy.pl/DrWEB-CureI … 12976.html
trabant11
(Trabant11)
4 Wrzesień 2011 19:52
#9
ok dziękuje wszystko gra i działa w porządku