Użyj
AdwCleaner i kliknij w nim
Delete (uruchom z prawokliku "jako Administrator)
Pokaż raport z niego
Uruchom
BlitzBlank w karcie Script wklej :
DeleteFile:
"C:\Windows\System32\hyhhthoj.dll"
Klik w Execute Now. Zatwierdź restart komputera.
Pokaż nowy log z OTL i raport z pracy BlitzBlank
Uruchom OTL i w sekcji
własne opcje skanowania / skrypt wklej:
:OTL
O4 - HKU\S-1-5-21-725345543-484763869-854245398-1003..\Run: [Java] C:\Documents and Settings\Owner\Application Data\Microsoft\jusched.exe ()
O33 - MountPoints2\{0a004e60-5715-11e0-90f3-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a004e60-5715-11e0-90f3-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a004e60-5715-11e0-90f3-000e35b33663}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{0b9fabd0-7431-11e0-913c-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{0b9fabd0-7431-11e0-913c-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0b9fabd0-7431-11e0-913c-000e35b33663}\Shell\AutoRun\command - "" = F:\MicroLauncher.exe
O33 - MountPoints2\{1f04e380-dac2-11df-8f72-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{1f04e380-dac2-11df-8f72-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1f04e380-dac2-11df-8f72-000e35b33663}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{20c64780-5a0e-11e1-9410-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{20c64780-5a0e-11e1-9410-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{20c64780-5a0e-11e1-9410-000e35b33663}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{215214e0-1029-11e1-933a-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{215214e0-1029-11e1-933a-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{215214e0-1029-11e1-933a-000e35b33663}\Shell\AutoRun\command - "" = C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{2c8c89f3-fee5-11e0-92ef-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{2c8c89f3-fee5-11e0-92ef-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2c8c89f3-fee5-11e0-92ef-000e35b33663}\Shell\AutoRun\command - "" = C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{2c8c89f4-fee5-11e0-92ef-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{2c8c89f4-fee5-11e0-92ef-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2c8c89f4-fee5-11e0-92ef-000e35b33663}\Shell\AutoRun\command - "" = C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{34187480-7231-11e0-9137-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{34187480-7231-11e0-9137-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{34187480-7231-11e0-9137-000e35b33663}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{503f5f85-e3fc-11df-8f8d-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{503f5f85-e3fc-11df-8f8d-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{503f5f85-e3fc-11df-8f8d-000e35b33663}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{8e8e74c0-10ee-11e1-9344-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{8e8e74c0-10ee-11e1-9344-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8e8e74c0-10ee-11e1-9344-000e35b33663}\Shell\AutoRun\command - "" = C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{9322a2d0-209f-11e0-904b-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{9322a2d0-209f-11e0-904b-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9322a2d0-209f-11e0-904b-000e35b33663}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{cff8d7c0-3c45-11e0-90a3-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{cff8d7c0-3c45-11e0-90a3-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cff8d7c0-3c45-11e0-90a3-000e35b33663}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{cff8d7c1-3c45-11e0-90a3-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{cff8d7c1-3c45-11e0-90a3-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cff8d7c1-3c45-11e0-90a3-000e35b33663}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e23f3650-acb3-11e0-91e5-000e35b33663}\Shell\AutoRun\command - "" = RunDll32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e23f3650-acb3-11e0-91e5-000e35b33663}\Shell\Explore\command - "" = G:\
O33 - MountPoints2\{e23f3650-acb3-11e0-91e5-000e35b33663}\Shell\Open\command - "" = G:\
O33 - MountPoints2\{e8f26f20-35d8-11e1-93ad-000e35b33663}\Shell - "" = AutoRun
O33 - MountPoints2\{e8f26f20-35d8-11e1-93ad-000e35b33663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e8f26f20-35d8-11e1-93ad-000e35b33663}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{fac79a61-aa53-11e0-91e1-000e35b33663}\Shell\AutoRun\command - "" = F:\kolikoje/menito.exe
O33 - MountPoints2\{fac79a61-aa53-11e0-91e1-000e35b33663}\Shell\Explore\command - "" = F:\kolikoje/menito.exe
O33 - MountPoints2\{fac79a61-aa53-11e0-91e1-000e35b33663}\Shell\Open\command - "" = F:\kolikoje/menito.exe
[2012-03-11 20:59:10 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-03-11 02:00:00 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\AdobeAAMUpdater-1.0-PRIVE-BDXXP8P8F-Owner.job
[2012-02-28 17:58:10 | 044,040,192 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\update.exe
[2012-02-28 17:58:07 | 046,137,344 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\jusched.exe
[2012-02-28 17:58:07 | 000,001,917 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\localstore.rdf
[2012-02-28 17:58:07 | 000,000,226 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\Setup.dat
[2012-02-28 17:58:04 | 045,088,768 | ---- | M] ( ) -- C:\Documents and Settings\Owner\Local Settings\Application Data\DTlite.exe
[2012-02-28 17:58:07 | 000,000,226 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\Setup.dat
:Commands
[emptytemp]
[emptyflash]
Kliknij
wykonaj skrypt. I potwierdź reset komputera .
Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia (zawartość notatnika, która otworzy się po restarcie). + raport z ADW + raport z BlitzBlank (C:\blitzblank.log) . Forum akceptuje tylko rozszerzenie txt więc zmień z .log na txt
