arturosz
(Szkurlat)
16 Marzec 2011 18:27
#1
Witam, ja również potrzebuje pomocy przy usunięciu “qooqli”
log:
http://www.wklej.org/hash/376232a881f/
Wklej w OTL i naciśnij wykonaj skrypt:
:OTL IE - HKU\S-1-5-21-1085031214-790525478-842925246-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBR IE - HKU\S-1-5-21-1085031214-790525478-842925246-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ FF - prefs.js…browser.search.selectedEngine: “qooqlle” FF - prefs.js…browser.startup.homepage: “http://www.qooqlle.com/ ” O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O3 - HKLM…\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O3 - HKU\S-1-5-21-1085031214-790525478-842925246-1003…\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O4 - HKLM…\Run: [] File not found O4 - HKU.DEFAULT…\RunOnce: [KeyScrambler] File not found O4 - HKU.DEFAULT…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-18…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-19…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-19…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-20…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-20…\RunOnce: [nltide_2] File not found O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} https://merlin.merlinx.pl/iris_plus/jin … s-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Reg Error: Key error.) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found O32 - AutoRun File - [2006-11-09 09:00:19 | 000,000,047 | R— | M] () - H:\Autorun.inf – [CDFS] O33 - MountPoints2{16033283-81f2-11df-b80b-001a92ba5618}\Shell - “” = AutoRun O33 - MountPoints2{16033283-81f2-11df-b80b-001a92ba5618}\Shell\AutoRun\command - “” = I:\LaunchU3.exe -a O33 - MountPoints2{3b33cbe6-2a24-11df-b685-001a92ba5618}\Shell\AutoRun\command - “” = I:\SamsungSoftware\APPInst.exe O33 - MountPoints2\H\Shell - “” = AutoRun O33 - MountPoints2\H\Shell\AutoRun\command - “” = H:\instaluj.exe – [2006-11-13 15:52:52 | 000,699,904 | R— | M] () [2011-03-16 19:13:00 | 000,000,462 | -H-- | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{089B7558-98AF-4DE0-919B-46A7566ADA27}.job [2011-03-16 19:00:01 | 000,000,540 | ---- | M] () – C:\WINDOWS\tasks\Konserwacja jednym kliknięciem.job [2010-04-14 09:42:30 | 000,000,472 | ---- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job @Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DE039443 @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E74F5F70 :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]
dajesz log z usuwania i nowy log z OTL
Acorus
(Acorus)
16 Marzec 2011 18:42
#3
Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL IE - HKU\S-1-5-21-1085031214-790525478-842925246-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ FF - prefs.js…browser.search.selectedEngine: “qooqlle” FF - prefs.js…browser.startup.homepage: “http://www.qooqlle.com/ ” [2009-02-14 19:44:37 | 000,000,000 | —D | M] (“Ask Toolbar for Firefox”) – C:\Documents and Settings\Artur\Dane aplikacji\Mozilla\Firefox\Profiles\rhvqgzn9.default\extensions{E9A1DEE0-C623-4439-8932-001E7D17607D} [2010-12-09 15:16:24 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Artur\Dane aplikacji\Mozilla\Firefox\Profiles\rhvqgzn9.default\extensions\engine@conduit.com O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O3 - HKLM…\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O3 - HKU\S-1-5-21-1085031214-790525478-842925246-1003…\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com ) O4 - HKLM…\Run: [] File not found O4 - HKU.DEFAULT…\RunOnce: [KeyScrambler] File not found O4 - HKU.DEFAULT…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-18…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-19…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-19…\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-20…\RunOnce: [KeyScrambler] File not found O4 - HKU\S-1-5-20…\RunOnce: [nltide_2] File not found O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} https://merlin.merlinx.pl/iris_plus/jin … s-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Reg Error: Key error.) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found [2010-04-14 09:42:30 | 000,000,472 | ---- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]
Kliknij Wykonaj skrypt…Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.
arturosz
(Szkurlat)
16 Marzec 2011 19:31
#4
Acorus
(Acorus)
17 Marzec 2011 08:39
#5
W porządku.W OTL użyj opcji Sprzątanie.Przeskanuj progr.Dr.WEB CureIt.
Witam, ja również w żaden sposób nie potrafie sobie poradzić z qooqle i dlatego własnie proszę o pomoc.
Oto log:
http://www.wklej.org/id/511227/
Acorus
(Acorus)
12 Kwiecień 2011 12:49
#8
Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.htm … sb&sysid=2 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.htm … sb&sysid=2 FF - prefs.js…browser.search.selectedEngine: “qooqlle” FF - prefs.js…browser.startup.homepage: “http://www.qooqlle.com/ ” [2010-12-11 20:27:39 | 000,000,000 | —D | M] (MediaBar) – C:\Documents and Settings\chillout\Dane aplikacji\Mozilla\Firefox\Profiles\xo6xugsz.default\extensions{E84D42CA-64EB-11DE-A65F-8C3656D89593} [2010-09-14 14:41:12 | 000,002,506 | ---- | M] () – C:\Documents and Settings\chillout\Dane aplikacji\Mozilla\Firefox\Profiles\xo6xugsz.default\searchplugins\BearShareWebSearch.xml [2010-12-07 12:26:48 | 000,000,863 | ---- | M] () – C:\Documents and Settings\chillout\Dane aplikacji\Mozilla\Firefox\Profiles\xo6xugsz.default\searchplugins\conduit.xml [2011-04-12 14:19:13 | 000,001,860 | ---- | M] () – C:\Documents and Settings\chillout\Dane aplikacji\Mozilla\Firefox\Profiles\xo6xugsz.default\searchplugins\search.xml [2010-12-11 20:27:28 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\BEARSHARE APPLICATIONS\MEDIABAR\DATAMNGR\FIREFOXEXTENSION [2010-09-14 14:41:12 | 000,002,506 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC) O3 - HKLM…\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () O3 - HKCU…\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found. O3 - HKCU…\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found. O4 - HKLM…\Run: [CFSServ.exe] File not found O4 - HKLM…\Run: [DATAMNGR] C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe (MusicLab, LLC) O4 - HKLM…\Run: [NDSTray.exe] File not found O4 - HKLM…\Run: [Readar_sl] C:\Documents and Settings\chillout\Dane aplikacji\Readar_sl.exe (Created with WinAutomation (http://www.WinAutomation.com )) O4 - HKLM…\Run: [TFncKy] File not found O4 - HKLM…\Run: [TunesHelper] C:\Documents and Settings\All Users\TunesHelper.exe () O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\datamngr.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngr.dll (MusicLab, LLC) O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC) [2011-04-04 23:58:41 | 000,311,296 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\Documents and Settings\chillout\Dane aplikacji\Readar_sl.exe [2011-04-04 23:58:29 | 008,180,224 | RHS- | M] () – C:\Documents and Settings\All Users\TunesHelper.exe :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]
Kliknij Wykonaj skrypt…Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.
Acorus
(Acorus)
12 Kwiecień 2011 13:33
#10
W porządku.W OTL użyj opcji Sprzątanie.Przeskanuj progr.Malwarebytes Anti-Malware.
Przeskanuj programem Dr.WEB CureIt http://ftp.drweb.com/pub/drweb/cureit/launch.exe
Już wszytsko pięknie działa! CCleaner’em przeczyściłem i zrobilem zrobiłem to sprzątanie.
WIELKIE dzięki i pozdrawiam.
Cześć, szkoda zakładać nowe tematy… nie chcę posypać sobie rejestru więc miałbym prośbę o dokonanie u mnie podobnej analizy.
http://www.wklej.org/id/512741/
Z góry dzięki
Acorus
(Acorus)
14 Kwiecień 2011 16:19
#13
Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ O3 - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM…\Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - No CLSID value found. O3 - HKLM…\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKCU…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM…\Run: [Readar_sl] D:\Documents and Settings\Monisia\Dane aplikacji\Readar_sl.exe (Created with WinAutomation (http://www.WinAutomation.com )) O4 - HKLM…\Run: [TunesHelper] D:\Documents and Settings\All Users\TunesHelper.exe () [2011-03-20 01:25:32 | 000,311,296 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – D:\Documents and Settings\Monisia\Dane aplikacji\Readar_sl.exe [2011-03-20 01:25:20 | 008,180,224 | RHS- | M] () – D:\Documents and Settings\All Users\TunesHelper.exe :Commands [emptytemp]
Kliknij Wykonaj skrypt…Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.
Odinstaluj DAEMON Tools Toolbar,BearShare MediaBar.
Acorus
(Acorus)
14 Kwiecień 2011 16:54
#15
W porządku.W OTL użyj opcji Sprzątanie.Przeskanuj progr.Malwarebytes Anti-Malware.
Przeskanuj programem Dr.WEB CureIt http://ftp.drweb.com/pub/drweb/cureit/launch.exe
Zainstaluj aktualizacje do programow wskazanych przez: http://screen317.spywareinfoforum.org/SecurityCheck.exe
Wszystko gra, wielkie dzięki
kolejna ofiara qooqlle.com . prosze o pomoc. z góry dziekuje.
LOg z OT:
http://wklej.org/id/513269/
jacus135
(Jacus135)
15 Kwiecień 2011 17:00
#18
Niestety również mam problem z qooqle…
LOg z OTL:
http://wklej.org/id/513276/
Proszę o pomoc i z góry dziękuję.
wklej w OTL i naciśnij wykonaj skrypt:
:OTL SRV - File not found [Auto | Stopped] – -- (cmdAgent) IE - HKLM…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ IE - HKCU…\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - Reg Error: Key error. File not found IE - HKCU…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found O2 - BHO: (mignet) - {840eee8a-6536-30e3-b03b-df9e1d80b894} - C:\Windows\System32\c8klEhTRqk.dll () O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found O3 - HKCU…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - File not found O4 - HKLM…\Run: [csrs] C:\ProgramData\csrs.exe (Created with WinAutomation (http://www.WinAutomation.com )) O4 - HKLM…\Run: [svhost] C:\Program Files\Common Files\svhost.exe () O4 - HKLM…\Run: [winloqon] C:\ProgramData\winloqon.exe (Created with WinAutomation (http://www.WinAutomation.com )) O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar … PIDPDE.cab (Reg Error: Key error.) [2011-04-12 00:07:28 | 000,331,776 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\ProgramData\winloqon.exe [2011-04-12 00:07:26 | 000,339,968 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\ProgramData\csrs.exe [2011-04-12 00:07:25 | 006,855,168 | RHS- | M] () – C:\Program Files\Common Files\svhost.exe @Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0B4227B4 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:63238B95 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:DF462FF6 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:1CE11B51 :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]
dajesz log z usuwania i nowe logi z OTL
Leon1
(Leon$)
15 Kwiecień 2011 17:08
#20
OTL w oknie Custom Scans-Fixes (własne opcje skanowania/skrypt)wklej następujący skrypt:
:OTL PRC - [2011-04-13 14:34:45 | 000,580,608 | ---- | M] (OldTimer Tools) – C:\Users\Alicja\Desktop\nhgcjmh.exe MOD - [2011-04-13 14:34:45 | 000,580,608 | ---- | M] (OldTimer Tools) – C:\Users\Alicja\Desktop\nhgcjmh.exe IE - HKLM…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/ IE - HKCU…\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - Reg Error: Key error. File not found IE - HKCU…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found O2 - BHO: (mignet) - {840eee8a-6536-30e3-b03b-df9e1d80b894} - C:\Windows\System32\c8klEhTRqk.dll () O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - File not found O3 - HKCU…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - File not found O4 - HKLM…\Run: [csrs] C:\ProgramData\csrs.exe (Created with WinAutomation (http://www.WinAutomation.com )) O4 - HKLM…\Run: [svhost] C:\Program Files\Common Files\svhost.exe () O4 - HKLM…\Run: [winloqon] C:\ProgramData\winloqon.exe (Created with WinAutomation (http://www.WinAutomation.com )) O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar … PIDPDE.cab (Reg Error: Key error.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. [2011-04-15 17:31:47 | 000,580,608 | ---- | C] (OldTimer Tools) – C:\Users\Alicja\Desktop\nhgcjmh.exe [2011-04-12 00:07:28 | 000,331,776 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\ProgramData\winloqon.exe [2011-04-12 00:07:26 | 000,339,968 | RHS- | C] (Created with WinAutomation (http://www.WinAutomation.com )) – C:\ProgramData\csrs.exe [2011-04-12 00:07:25 | 006,855,168 | RHS- | M] () – C:\Program Files\Common Files\svhost.exe [2011-02-24 20:20:40 | 002,119,168 | ---- | C] () – C:\Windows\System32\c8klEhTRqk.dll :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [CLEARALLRESTOREPOINTS] [emptytemp]
Kliknij w Run Fix (Wykonaj scrypt). Zatwierdź restart komputera.
potem nowy log OTL robiony opcją Run Scan (Skanuj)