chewingum
(Lipskibartek)
22 Sierpień 2011 12:46
#1
prosze o pomoc w sprawie tego nieszczesnego wirusa z facebooka, z gory dzieki i ponizej przesylam logi…
otl : http://wklej.to/lTHzC
extras : http://wklej.to/FPAln
Acorus
(Acorus)
22 Sierpień 2011 14:01
#2
Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:
:OTL MOD - [2011/08/20 10:33:48 | 001,182,208 | -H-- | M] () – C:\Windows\update.tray-7-0-lnk\svchost.exe O3 - HKLM…\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - File not found O3 - HKLM…\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM…\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com \GenericAskToolbar.dll (Ask) O3 - HKLM…\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU.DEFAULT…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKU.DEFAULT…\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com \GenericAskToolbar.dll (Ask) O3 - HKU\S-1-5-18…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKU\S-1-5-18…\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com \GenericAskToolbar.dll (Ask) O3 - HKU\S-1-5-21-2071869296-2185399040-3217962726-1000…\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2071869296-2185399040-3217962726-1000…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2071869296-2185399040-3217962726-1000…\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com \GenericAskToolbar.dll (Ask) O4 - HKLM…\Run: [avast] File not found O4 - HKLM…\Run: [babylonToolbar] C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.) O4 - HKLM…\Run: [COMODO] File not found O4 - HKLM…\Run: [CPA] File not found O4 - HKLM…\Run: [tray_ico] File not found O4 - HKLM…\Run: [tray_ico3] File not found O4 - HKLM…\Run: [tray_ico4] File not found O4 - HKU\S-1-5-21-2071869296-2185399040-3217962726-1000…\Run: [iSUSPM] File not found [2011/08/20 14:04:07 | 000,000,000 | -H-D | C] – C:\windows\update.tray-7-0-lnk [2011/08/20 14:04:07 | 000,000,000 | -H-D | C] – C:\windows\update.tray-7-0 [2011/08/20 11:01:36 | 000,000,000 | —D | C] – C:\windows\ufa [2011/08/20 11:01:36 | 000,000,000 | —D | C] – C:\windows\phoenix [2011/08/20 10:59:03 | 000,000,000 | -H-D | C] – C:\windows\update.5.0 [2011/08/20 10:57:42 | 000,000,000 | -H-D | C] – C:\windows\update.2 [2011/08/20 10:52:46 | 000,000,000 | —D | C] – C:\windows\av_ico [2011/08/20 10:52:21 | 000,000,000 | -H-D | C] – C:\windows\update.7.1 [2011/08/20 10:49:56 | 000,000,000 | -H-D | C] – C:\windows\update.1 [2011/08/20 10:49:51 | 000,000,000 | -H-D | C] – C:\windows\update.tray-5-0-lnk [2011/08/20 10:49:51 | 000,000,000 | -H-D | C] – C:\windows\update.tray-5-0 [2011/08/20 10:49:51 | 000,000,000 | -H-D | C] – C:\windows\update.tray-2-0-lnk [2011/08/20 10:49:51 | 000,000,000 | -H-D | C] – C:\windows\update.tray-2-0 [2011/08/20 11:02:23 | 000,000,178 | ---- | M] () – C:\windows\info1 [2011/08/20 11:01:35 | 005,589,370 | ---- | M] () – C:\windows\phoenix.rar [2011/08/20 11:01:35 | 001,075,284 | ---- | M] () – C:\windows\rpcminer.rar [2011/08/20 11:01:35 | 000,246,272 | ---- | M] () – C:\windows\unrar.exe [2011/08/20 11:01:35 | 000,182,617 | ---- | M] () – C:\windows\ufa.rar [2011/08/20 10:57:36 | 000,904,792 | ---- | M] () – C:\windows\geoiplist.rar [2011/08/20 10:52:03 | 000,000,000 | ---- | M] () – C:\windows\loader2.exe_ok [2011/04/17 01:11:41 | 000,010,112 | -HS- | C] () – C:\Users\Kasia\AppData\Local\fnai4q15sdnfexykmam5q2dl86l [2011/04/17 01:11:41 | 000,009,516 | -HS- | C] () – C:\ProgramData\fnai4q15sdnfexykmam5q2dl86l @Alternate Data Stream - 816 bytes -> C:\windows\2003149107:3428752008.exe :Services OberonGameConsoleService CLPSLS ddservice :Reg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] “AlternateShell”=“cmd.exe” :Commands [emptytemp] [resethosts]
Kliknij Wykonaj skrypt…Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).
Pokaż nowy log OTL.txt oraz raport z usuwania.