wiktor137
(Wiktor137)
2 Kwiecień 2012 17:07
#1
Po wgraniu wtyczki (vshare) do firefoxa, moja strona startowa samoistnie zmienia się na searchcompletion.com .
Oto logi z OTL:
http://wklej.to/PRon9
http://wklej.to/frII7
Acorus
(Acorus)
2 Kwiecień 2012 17:46
#2
Odinstaluj Browsers Protector,LiveVDO plugin 1.3.Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL SRV - File not found [Auto | Stopped] – C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe – (MyWebSearchService) IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=f8f877ff- … 13339e2536 IE - HKLM…\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://startsear.ch/?aff=1&src=sp&cf=f8 … 39e2536&q={searchTerms} IE - HKLM…\SearchScopes{56256A51-B582-467e-B8D4-7786EDA79AE0}: “URL” = http://search.mywebsearch.com/mywebsear … searchfor={searchTerms} IE - HKLM…\SearchScopes{F3957D4C-D502-498B-86EA-6694074D493A}: “URL” = http://startsear.ch/?aff=2&src=sp&cf=f8 … 39e2536&q={searchTerms} IE - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=f8f877ff- … 13339e2536 IE - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found FF - prefs.js…browser.search.defaultenginename: “Web Search” FF - prefs.js…browser.search.order.1: “Web Search” FF - prefs.js…keyword.URL: “http://startsear.ch/?aff=1&src=sp&cf=f8f877ff-e79e-11e0-9c00-0013339e2536&q= ” [2011-12-26 18:15:31 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\przemek\AppData\Roaming\mozilla\Firefox\extensions{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} O3 - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000…\Toolbar\WebBrowser: (no name) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No CLSID value found. O3 - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000…\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found. O4 - HKLM…\Run: [browsers Protector] C:\Program Files\Browsers Protector\regmon32.exe () O4 - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000…\Run: [EA Core] “C:\Program Files\Electronic Arts\EADM\Core.exe” -silent File not found O4 - HKU\S-1-5-21-4144661595-1384159049-2455311969-1000…\Run: [EADM] “C:\Program Files\Origin\Origin.exe” -AutoStart File not found [2012-04-01 20:52:42 | 000,000,000 | —D | C] – C:\Program Files\v9Soft [2011-11-20 22:20:50 | 000,000,000 | —D | M] – C:\Users\przemek\AppData\Roaming\OpenCandy :Commands [emptytemp]
Kliknij Wykonaj skrypt.Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.