Logi - prośba o napisanie sktyptu
#1
Napisano 09 07 2010 - 18:19
#2
Napisano 09 07 2010 - 18:50
Widać tylko zarażony pendrive (lub inna pamięć przenośna), który w chwili robienia logu nie był podpięty do komputera.
Uruchom OTL i w oknie Custom Scans/Fixes (Własne opcje skanowania/Script)wklej to:
Kliknij w Run Fix (Wykonaj Script). Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.:OTL
O33 - MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\Shell\AutoRun\command - "" = G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe -- File not found
O33 - MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\Shell\eXpLorE\CoMmAnD - "" = G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe -- File not found
O33 - MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\Shell\oPeN\cOmMaNd - "" = G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe -- File not found
O33 - MountPoints2\{9cd32f5f-c2e3-11de-a5f6-9610f43bc634}\Shell\AutoRun\command - "" = Z1I1WFANENPQ9CBKN0O8TBAZX\Z1I1WFANENPQ9CBKN0O8TBAZX.exe
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll File not found
SRV - [2009-04-02 13:47:04 | 000,234,888 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
SRV - [2009-04-02 13:47:02 | 000,464,264 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe -- (ASKService)
:Files
C:\Program Files (x86)\AskBarDis
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
[Reboot]
Pokaż raport z usuwania.
.
#3
Napisano 10 07 2010 - 01:04
All processes killed
========== OTL ==========
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ not found.
File G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ not found.
File G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1eb95796-1bc8-11df-9199-002556d8ca4c}\ not found.
File G:\PQ98A5LDFR12GB8NDX7FZST1R\PQ98A5LDFR12GB8NDX7FZST1R.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9cd32f5f-c2e3-11de-a5f6-9610f43bc634}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cd32f5f-c2e3-11de-a5f6-9610f43bc634}\ not found.
File Z1I1WFANENPQ9CBKN0O8TBAZX\Z1I1WFANENPQ9CBKN0O8TBAZX.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}\ deleted successfully.
Service ASKUpgrade stopped successfully!
Service ASKUpgrade deleted successfully!
C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe moved successfully.
Service ASKService stopped successfully!
Service ASKService deleted successfully!
C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe moved successfully.
========== FILES ==========
C:\Program Files (x86)\AskBarDis\bar\Settings folder moved successfully.
C:\Program Files (x86)\AskBarDis\bar\bin folder moved successfully.
C:\Program Files (x86)\AskBarDis\bar folder moved successfully.
C:\Program Files (x86)\AskBarDis folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: maciek
->Temp folder emptied: 641864964 bytes
->Temporary Internet Files folder emptied: 133932058 bytes
->Java cache emptied: 55509027 bytes
->FireFox cache emptied: 38687697 bytes
->Flash cache emptied: 3600438 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 1561088 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 93314816 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 52847 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 187824911 bytes
Total Files Cleaned = 1 103,00 mb
OTL by OldTimer - Version 3.2.8.1 log created on 07092010_211739
Files\Folders moved on Reboot...
C:\Users\maciek\AppData\Local\Mozilla\Firefox\Profiles\j304nv06.default\Cache\_CACHE_001_ moved successfully.
C:\Users\maciek\AppData\Local\Mozilla\Firefox\Profiles\j304nv06.default\Cache\_CACHE_002_ moved successfully.
C:\Users\maciek\AppData\Local\Mozilla\Firefox\Profiles\j304nv06.default\Cache\_CACHE_003_ moved successfully.
C:\Users\maciek\AppData\Local\Mozilla\Firefox\Profiles\j304nv06.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\maciek\AppData\Local\Mozilla\Firefox\Profiles\j304nv06.default\urlclassifier3.sqlite moved successfully.
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VYSG8B5C\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UT95I1CB\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LD2MD94F\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JCLOYXCU\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Użytkownik Katarina edytował ten post 19 07 2010 - 22:16
#4
Napisano 10 07 2010 - 09:13
Użyj USBFix (http://www.fixitpc.pl/index.php?/topic/8-kolekcja-narzedzi-usuwajacych/page__p__74&#entry74), z opcji VACCINATE.
.
#5
Napisano 10 07 2010 - 14:53
#6
Napisano 10 07 2010 - 15:51
>prawoklik na ikonkę Avasta w prawym dolnym rogu pulpitu>>Sterowanie osłonami Avast >wybierz: na 1 godzinę
.
Użytkownicy przeglądający ten temat: 0
0 użytkowników, 0 gości, 0 anonimowych



Temat jest zamknięty





