Logi - Proces explorer.exe przestaje odpowiadać
#1
Napisano 23 02 2011 - 13:41
Proszę sprawdzić logi.
Dziękuję.
http://wklej.to/EF8Hq
http://wklej.to/r2yjr
#2
Napisano 23 02 2011 - 14:35
Znasz ten program?[2011-02-20 19:36:19 | 000,000,000 | ---D | C] -- C:\ProgramData\ResultTool
[2011-02-20 19:36:19 | 000,000,000 | ---D | C] -- C:\Program Files\ResultTool
Sprawdź go na --> JOTTI/ albo na VIRUSTOTAL albo na VIRSCANC:\Windows\System32\IGFXDEVLib.dll
Uruchom OTL i w oknie Własne opcje skanowania/Script wklej to:
Kliknij w Wykonaj Script. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.tangotoolbar.com/
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
[2010-02-13 11:53:55 | 000,002,426 | ---- | M] () -- C:\Users\strazak\AppData\Roaming\Mozilla\Firefox\Profiles\1nyn9rr0.default\searchplugins\askcom.xml
O2 - BHO: (Tango) - {ECD24449-6F9F-4506-BABC-9789C01D6383} - C:\Windows\System32\3678.dll ()
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Tango) - {ECD24448-6F9F-4506-BABC-9789C01D6383} - C:\Windows\System32\3678.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Tango) - {ECD24448-6F9F-4506-BABC-9789C01D6383} - C:\Windows\System32\3678.dll ()
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKCU..\Run: [GabPath] C:\Users\strazak\AppData\Roaming\GabPath\gabpath.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKCU..\Run: [WdT5FBN8[Xu:gMPHVbfONhiEMOC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPathC:\Users\strazak\AppData\Roaming\GabPath] C:\Users\strazak\AppData\Roaming\Microsoft\Windows\noawwtu.exe ()
O4 - HKLM..\RunOnce: [NoIE4StubProcessing] File not found
O33 - MountPoints2\{df83eaef-3113-11df-a0cb-002622183300}\Shell\AutoRun\command - "" = I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windows32.exe
O33 - MountPoints2\{df83eaef-3113-11df-a0cb-002622183300}\Shell\open\command - "" = I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windows32.exe
[2011-02-20 19:35:38 | 000,000,000 | ---D | C] -- C:\Users\strazak\AppData\Roaming\GabPath
[2011-02-20 19:35:40 | 000,909,312 | ---- | C] () -- C:\Windows\System32\3678.dll
:Files
C:\Users\strazak\AppData\Local\Temp*.html
RECYCLER /alldrives
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
Następnie uruchom OTL ponownie, tym razem klikn
.
Użytkownicy przeglądający ten temat: 0
0 użytkowników, 0 gości, 0 anonimowych



Temat jest zamknięty





