
Wirus ukash zablokował mi komputer. Z góry dziękuję za pomoc w usunięciu paskudztwa. Przeskanowałem programem OTL komputer, poniżej w załącznikach pliki po skanowaniu.
:OTL
IE - HKLM\..\SearchScopes\{3A616AD2-A6DE-4EF7-A026-811CA163AAE0}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=c05d459a-2411-11e1-8045-002215332234&q={searchTerms}
IE - HKCU\..\SearchScopes\{3A616AD2-A6DE-4EF7-A026-811CA163AAE0}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=c05d459a-2411-11e1-8045-002215332234&q={searchTerms}
IE - HKCU\..\SearchScopes\{C1767BFC-2256-4E60-8E56-CE10C086F725}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AWR&o=1955&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^A17&apn_dtid=^YYYYYY^YY^PL&apn_uid=19e57595-82be-4931-b1e0-0816abcd9bf8&apn_sauid=F82E82F2-67F4-45C6-95FD-B795412B3834
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.732
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=c05d459a-2411-11e1-8045-002215332234&q="
[2012-05-09 15:55:42 | 000,000,000 | ---D | M] (Alawar Ask Toolbar) -- C:\Users\Monika i Czarek\AppData\Roaming\mozilla\Firefox\Profiles\y401p0ie.default\extensions\toolbar@ask.com
[2012-05-09 15:55:42 | 000,002,334 | ---- | M] () -- C:\Users\Monika i Czarek\AppData\Roaming\Mozilla\Firefox\Profiles\y401p0ie.default\searchplugins\askcom.xml
[2011-07-11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\Monika i Czarek\AppData\Roaming\Mozilla\Firefox\Profiles\y401p0ie.default\searchplugins\startsear.xml
O4 - HKLM..\Run: [xircwbrdiokijsk] C:\ProgramData\xircwbrd.exe ()
O4 - HKCU..\Run: [xircwbrdiokijsk] C:\ProgramData\xircwbrd.exe ()
O4 - HKCU..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O33 - MountPoints2\{4386070c-1e9b-11e0-89c4-002215332234}\Shell - "" = AutoRun
O33 - MountPoints2\{4386070c-1e9b-11e0-89c4-002215332234}\Shell\AutoRun\command - "" = G:\Setup.exe
O33 - MountPoints2\{9ad496c9-1a78-11e0-9c10-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9ad496c9-1a78-11e0-9c10-806e6f6e6963}\Shell\AutoRun\command - "" = F:\win\CDSplash.exe -- [2006-05-05 23:27:06 | 001,159,168 | R--- | M] (Beenox)
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:9FD757A9
:Files
C:\ProgramData\wvlkeodlindhuoj
C:\ProgramData\znhbttbqaammppn
C:\ProgramData\xircwbrd.exe
C:\Users\Monika i Czarek\0.052056455825074566.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-795372177-2463488241-2741379307-1001UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-795372177-2463488241-2741379307-1001Core.job
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości