Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
Ukash! proszę o pomoc • programosy.pl

  • Ogłoszenie:

Ukash! proszę o pomoc

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Ukash! proszę o pomoc

Postprzez kamro 24 Wrz 2012, 18:09

reklama
POMOCY !! Jestem nowy i niezbyt biegły w komp. Również dopadł mnie UKASH :(( Mam liste błedów z OTL. Nie wiem co mam wkleic w skrypt. Pomóżcie/
Oto lista błedów

Kod: Zaznacz wszystko
OTL Extras logfile created on: 2012-09-24 17:54:42 - Run 1
OTL by OldTimer - Version 3.2.66.2     Folder = C:\Users\Kaczy\.swt\Downloads
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,41 Gb Available Physical Memory | 70,76% Memory free
4,21 Gb Paging File | 3,77 Gb Available in Paging File | 89,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 140,27 Gb Total Space | 15,97 Gb Free Space | 11,38% Space Free | Partition Type: NTFS
Drive D: | 8,78 Gb Total Space | 2,76 Gb Free Space | 31,46% Space Free | Partition Type: NTFS

Computer Name: K3 | User Name: Kaczy | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" ()
Directory [napiprojekt0] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" -pobierz_ang ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06C32D30-9C42-43BB-B158-861A0ECAD836}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E6711C37-E353-4B9A-9D5C-573CBC988B23}" = lport=2869 | protocol=6 | dir=in | app=system |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06BC5344-468C-4E71-9A66-A25D3F67872F}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{13A4D9EB-319A-4D06-90E6-E74A2CE06315}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{3ABBA822-6895-49E1-BF33-E97A7C0D5022}" = protocol=17 | dir=in | app=c:\program files\valve\steam\steam.exe |
"{5F745DD9-58E3-425A-A0F9-1E92F3B773B8}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{666AADAF-9D16-407F-9D6E-9E374569AB75}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{75FEC367-FF1D-4099-BB84-E1AEEE6992C1}" = protocol=6 | dir=in | app=c:\program files\valve\steam\steam.exe |
"{A0CB6E03-42FB-4CD8-9386-E676AF365DC4}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0C9221F6-1EA9-4D92-892D-A5FEB3084A75}" = Need for Speed Undeground 2
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{223818EB-2BB5-4AAD-9F38-BA9668A4E3F3}" = Windows Live Messenger
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26CE484D-2E8E-40D5-B251-158133114C69}" = TomTom HOME
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{306B39C9-3AB1-4161-8567-9C7E50B41AE3}" = Microsoft Works
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{7271AAA4-467B-4BD9-9D86-8965E563E788}" = Splinter Cell Chaos Theory
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{7F362F06-A9A3-440F-8B19-6A01A72723C4}" = AuthenTec Fingerprint Sensor Minimum Install
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BE7AED6-8EA2-4CEE-A5ED-97CDBD543896}" = MSCU for Microsoft Vista
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0020-0415-0000-0000000FF1CE}" = Pakiet zgodności dla systemu Office 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.3
"{95120000-00AF-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Polish)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{A0F40029-79E7-40B1-8841-C79199C9D0A2}" = ESU for Microsoft Vista
"{AC76BA86-7AD7-1045-7B44-A81000000003}" = Adobe Reader 8.1.0 - Polish
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C7AF7F33-9092-997E-2D29-DE8095863FE3}" = DigitalPersona Personal 3.0.0
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software  1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
"1ClickDownload" = 1ClickDownloader
"8461-7759-5462-8226" = Vuze
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"ALLPlayer_is1" = ALLPlayer V5.X
"Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v10.0.15
"Codec_is1" = Codec 8.3p
"conduitEngine" = Conduit Engine
"ffdshow_is1" = ffdshow v1.2.4453 [2012-05-21]
"Gadu-Gadu 10" = Gadu-Gadu 10
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HighGrow 4.2 Polish Version - http://www.highgrow.prv.pl" = HighGrow 4.2 Polish Version - http://www.highgrow.prv.pl
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0 (x86 pl)" = Mozilla Firefox 15.0 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151)
"Need for Speed Undeground 2" = Need for Speed Undeground 2
"NVIDIA Drivers" = NVIDIA Drivers
"RewardsArcade" = RewardsArcade
"SMSERIAL" = Motorola SM56 Data Fax Modem
"Softonic" = Softonic toolbar  on IE
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"Winamp" = Winamp
"WinRAR archiver" = WinRAR 4.01 (32-bitowy)

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 15.0.1 (x86 pl)" = Mozilla Firefox 15.0.1 (x86 pl)

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2012-09-24 08:18:07 | Computer Name = K3 | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 2012-09-24 08:24:14 | Computer Name = K3 | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 2012-09-24 08:39:42 | Computer Name = K3 | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 2012-09-24 08:54:36 | Computer Name = K3 | Source = EventSystem | ID = 4609
Description =

Error - 2012-09-24 09:03:46 | Computer Name = K3 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd Explorer.EXE, wersja 6.0.6000.16771, sygnatura
czasowa 0x4907deda, moduł powodujący błąd unknown, wersja 0.0.0.0, sygnatura czasowa
0x00000000, kod wyjątku 0xc0000005, przesunięcie błędu 0x00000000,  identyfikator
procesu 0x6ac, godzina rozpoczęcia aplikacji 0x01cd9a53bb6a5b0a.

Error - 2012-09-24 09:04:16 | Computer Name = K3 | Source = EventSystem | ID = 4609
Description =

Error - 2012-09-24 09:15:35 | Computer Name = K3 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd explorer.exe, wersja 6.0.6000.16771, sygnatura
czasowa 0x4907deda, moduł powodujący błąd unknown, wersja 0.0.0.0, sygnatura czasowa
0x00000000, kod wyjątku 0xc0000005, przesunięcie błędu 0x00000000,  identyfikator
procesu 0x400, godzina rozpoczęcia aplikacji 0x01cd9a551281c2e2.

Error - 2012-09-24 09:16:14 | Computer Name = K3 | Source = EventSystem | ID = 4609
Description =

Error - 2012-09-24 11:05:29 | Computer Name = K3 | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 2012-09-24 11:09:04 | Computer Name = K3 | Source = EventSystem | ID = 4609
Description =

[ DigitalPersona Pro Events ]
Error - 2012-09-18 15:13:02 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-19 12:10:42 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-20 02:07:48 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-20 15:12:23 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-21 02:44:57 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-22 04:37:31 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-23 14:17:23 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-24 01:47:01 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-24 08:16:11 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

Error - 2012-09-24 08:23:27 | Computer Name = K3 | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start.    Description: Found other running Agent. 

[ System Events ]
Error - 2012-09-24 11:08:42 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:08:42 | Computer Name = K3 | Source = LSM | ID = 1048
Description =

Error - 2012-09-24 11:08:56 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:09:04 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:09:06 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:09:08 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:09:16 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =

Error - 2012-09-24 11:09:50 | Computer Name = K3 | Source = Service Control Manager | ID = 7001
Description =

Error - 2012-09-24 11:09:50 | Computer Name = K3 | Source = Service Control Manager | ID = 7026
Description =

Error - 2012-09-24 11:13:26 | Computer Name = K3 | Source = DCOM | ID = 10005
Description =


< End of report >
kamro
~user
 
Posty: 1
Dołączenie: 24 Wrz 2012, 17:50



Ukash! pomocy!

Postprzez ytaszey 24 Wrz 2012, 18:35

Odpowiedź dla kamro
To samo wysyłam na PW, bo nie wiem czy moderator nie usunie tego posta.

Poniżej przedstawiam instrukcję usuwania. Jeżeli chcesz zapisz ją albo wydrukuj, jeżeli nie jesteś biegły w komputerach.

W Panelu sterowania i w dodatkach do przeglądarek odinstaluj Vuze Remote Community Toolbar i Conduit Engine
Jeżeli którejś z wymionych pozycji nie ma, albo są problemy z usunięciem, to kontynuuj.


  • Uruchom OTL Image
  • Jeżeli używasz Windows Vista/7 może zostać wyświetlony alert Kontroli Konta Użytkownika. Kliknij Tak.
    Image
  • W okno Image wklej (zaczynając od dwukropka)
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=806e12d1- ... 1e37a43bda
    IE - HKLM\..\SearchScopes\{96C7A291-0A63-4C65-AACD-C2C542B8DD10}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=109217 ... 1e37a43bda
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2481033
    IE - HKCU\..\URLSearchHook: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No CLSID value found
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=109217&tt=120912_cpc_3712_1&babsrc=SP_ss&mntrId=ac8748cd000000000000001e37a43bda
    IE - HKCU\..\SearchScopes\{96C7A291-0A63-4C65-AACD-C2C542B8DD10}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033
    FF - prefs.js..browser.search.defaultengine: "Web Search"
    FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
    FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
    [2012-08-23 08:03:40 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Users\Kaczy\AppData\Roaming\mozilla\Firefox\Profiles\4x78tmvy.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
    [2012-09-23 20:22:25 | 000,000,000 | ---D | M] ("RewardsArcade") -- C:\Users\Kaczy\AppData\Roaming\mozilla\Firefox\Profiles\4x78tmvy.default\extensions\crossriderapp498@crossrider.com
    [2012-09-16 00:41:21 | 000,002,223 | ---- | M] () -- C:\Users\Kaczy\AppData\Roaming\mozilla\firefox\profiles\4x78tmvy.default\searchplugins\BabylonMngr.xml
    [2011-09-27 22:23:52 | 000,000,879 | ---- | M] () -- C:\Users\Kaczy\AppData\Roaming\mozilla\firefox\profiles\4x78tmvy.default\searchplugins\conduit.xml
    [2012-06-01 22:55:14 | 000,002,060 | ---- | M] () -- C:\Users\Kaczy\AppData\Roaming\mozilla\firefox\profiles\4x78tmvy.default\searchplugins\softonic.xml
    [2012-09-15 23:08:51 | 000,000,792 | ---- | M] () -- C:\Users\Kaczy\AppData\Roaming\mozilla\firefox\profiles\4x78tmvy.default\searchplugins\startsear.xml
    [2012-09-16 00:40:38 | 000,002,360 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
    O2 - BHO: (RewardsArcade) - {11111111-1111-1111-1111-110011041198} - C:\Program Files\RewardsArcade\RewardsArcade.dll (215 Apps)
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O2 - BHO: (Softonic Helper Object) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\Softonic\1.5.24.3\bh\Softonic.dll (Softonic.com)
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\Softonic\1.5.24.3\SoftonicTlbr.dll (Softonic.com)
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [TimeDateMUICallback] C:\Users\Kaczy\AppData\Local\Microsoft\Windows\3455\TimeDateMUICallback.exe ()

    :Files
    C:\Users\Kaczy\AppData\Local\Microsoft\Windows\3455
    C:\Users\Kaczy\AppData\Roaming\hellomoto
    C:\Program Files\BabylonToolbar

    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]

    :Commands
    [emptytemp]
  • Kliknij Image
  • Zgódź się na ponowne uruchomienie (restart). Naciśnij OK.
    Image
  • Jeżeli używasz Windows Vista/7, po restarcie, może zostać wyświetlony alert zabezpieczeń. Naciśnij Uruchom.
    Image

Użyj AdwCleaner
  • Pobierz AdwCleaner
  • Uruchom AdwCleaner Image
  • Jeżeli używasz Windows Vista/7 może zostać wyświetlony alert Kontroli Konta Użytkownika. Kliknij Tak.
    Image
  • W głównym oknie programu naciśnij Delete
    Image
  • Zamknij wszystkie przeglądarki internetowe i naciśnij OK.
    Image
  • Poczekaj
    Image
  • Naciśnij OK na komunikatach, które zostaną wyświetlone
    Image
    Image
  • System zostanie uruchomiony ponownie (restart)

Po wszystkim przedstaw
  • Nowy log OTL z opcji Image
  • Raport z usuwania OTL
  • Raport z usuwania AdwCleaner (C:\AdwCleaner[S1].txt)

Użyj SecurityCheck i zaktualizuj programy oznaczone jako "Out of date!". To jedna z metod zapobiegania podobnym infekcjom w przyszłości. Szkodliwe oprogramowanie może dostać się do komputera przez luki w starych wersjach programów podczas gdy nowsze wersje programów posiadają załatane luki, które są obecne w starszych wersjach tychże. W razie problemów z samodzielnym przejrzeniem raportu z SecurityCheck, przedstaw go proszę na forum, to pomyślimy razem.
  • Pobierz Security Check
  • Uruchom Security Check Image
  • Jeżeli używasz Windows Vista/7, może zostać wyświetlony alert Kontroli Konta Użytkownika. Kliknij Tak.
    Image
  • W oknie Security Check naciśnij dowolny klawisz, np. Enter
    Image
  • Poczekaj
    Image
  • Gdy program zakończy pracę wyświetli informację na ten temat oraz otworzy raport w Notatniku.
    Image Image
  • Zamknij okno Security Check a raport wklej do posta
ytaszey
~user
 
Posty: 72
Dołączenie: 22 Sie 2012, 13:42
Pochwały: 9




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 11 gości