W sprawie Facebooka nic Ci nie pomogę, bo w ogóle się na tym nie znam, nigdy nie miałem nic wspólnego z Facebookiem.
Ale masz infekcję, więc:
1) Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
SRV - [2013/09/12 10:00:38 | 002,666,496 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe -- (Windows Internet Name Service)
O3 - HKU\S-1-5-21-2536541432-2282819063-181341213-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-2536541432-2282819063-181341213-1001..\Run: [Windows Time] rundll32.exe ",EntryPoint File not found
[2013/09/20 13:38:19 | 000,000,000 | ---D | C] -- C:\Users\Ola\AppData\Local\avgchrome
[2013/10/07 10:08:55 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
[2013/10/02 17:00:16 | 000,003,726 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013/06/26 11:56:11 | 000,197,120 | ---- | C] () -- C:\ProgramData\ueyeputontxcdqm
[2013/06/24 23:03:53 | 000,028,160 | ---- | C] () -- C:\ProgramData\mdptwebnbcfodph
[2013/06/24 18:38:12 | 000,000,355 | ---- | C] () -- C:\ProgramData\dbbaabdbfdaegfdgfdgdfg.cfg
[2013/06/24 18:38:12 | 000,000,000 | ---- | C] () -- C:\ProgramData\jcxrorvsxtqmqmx
:Files
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service
:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-2536541432-2282819063-181341213-1001\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.
2)
c:\windows\syswow64\dfrg\minerd.exe
C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe
Sprawdź je na -->
JOTTI/ albo na
VIRUSTOTAL.
[2012/04/05 18:28:20 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Avpo
[2012/04/05 20:51:26 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ciomp
[2013/05/26 10:19:05 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\DAEMON Tools Lite
[2012/04/06 12:23:54 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Duuf
[2012/04/06 12:23:56 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ecsuo
[2012/04/06 23:11:36 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Emlydy
[2012/04/07 19:04:07 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ethyk
[2012/04/09 00:02:08 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Exteze
[2012/01/17 00:54:47 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Gadu-Gadu 10
[2013/04/02 00:57:12 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\GanymedeNet
[2013/10/07 11:27:44 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\GG
[2012/04/05 08:21:43 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ibpye
[2012/04/05 18:28:20 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Imnowu
[2012/04/07 15:02:00 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Iqti
[2012/04/06 18:51:26 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Irnu
[2013/08/23 13:07:34 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Kode
[2012/04/07 19:04:07 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Kosofa
[2012/04/07 15:02:00 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Laur
[2012/04/08 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Mupa
[2012/04/03 20:24:36 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Oblie
[2012/04/05 16:51:21 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Okimke
[2012/04/06 23:11:36 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Omoba
[2012/04/05 08:21:43 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Oncy
[2012/04/05 08:21:15 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Owuznu
[2012/04/09 01:29:53 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Pyylno
[2013/08/23 13:07:34 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Raoch
[2012/04/07 15:01:37 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Roraru
[2012/04/07 19:01:33 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ryif
[2013/10/03 16:13:32 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\SimpleFiles
[2012/04/05 18:27:57 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Tula
[2012/04/06 12:23:56 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Unef
[2012/04/04 13:33:30 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Uxyk
[2012/04/04 22:48:26 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Vevyba
[2012/03/11 12:05:35 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Waiwib
[2012/04/08 01:23:00 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Wuyk
[2012/04/04 22:49:00 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ybnoe
[2012/02/29 15:09:35 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ymohme
[2012/04/08 20:20:53 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ypmyg
[2012/04/08 20:20:54 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ysuq
[2012/04/08 20:21:39 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Ywowz
[2012/04/06 16:23:30 | 000,000,000 | ---D | M] -- C:\Users\Ola\AppData\Roaming\Yzahw
Znasz te obiekty o dziwnych nazwach?
.