ďťż
chomiki
CMOS BATTERY WRONG & CMOS MEMORY WRONG - POMOCY
błąd 41... pomocy... teraz blad 52
bialy dym, bierze duzo oleju, ubywa wody w chlodnicy POMOCY
zielony pzrekaznik przy kompie i dzikie obroty POMOCY
Za wysokie obroty, słabe chłodzenie silnika POMOCY 1,6 GL
zainfekowany komp, kto moze sobie z tym poradzic?pomocy
Pomocy - program do cięcia muzyki -cool edit
Problem z dyskiem według SpeedFana. POMOCY!!
brak pliku iertutil.dll. pomocy
Jeszcze raz - Bagnet do XU10J2 - POMOCY
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • russ.xlx.pl

  • chomiki

    Witam,

    bardzo prosze o pomoc, bo nie mam już sił. Mam wirusa o nazwie reklamiarz i nie umiem się go pozbyć. Adaware części krytycznych obiektów po prostu nie usuwa. kaspersky tez go nie moze usunac. Avast go wykrywa ale nic ponadto. Nie mam juz sił. Przesyłam loga z Hijackthis, może tu coś widać. Bardzo prosze o pomoc i o jasne wytłumaczenie co robić, bo nie znam się za bardzo na komputerach. Z góry dziękuję i pozdrawiam serdecznie. A oto log:

    Logfile of HijackThis v1.99.1
    Scan saved at 14:59:07, on 2006-02-21
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Gadu-Gadu\gg.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\user\Pulpit\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware....free/asinst.cab
    O20 - Winlogon Notify: MSSYCLM - C:\WINDOWS\system32\q0nu0a59ed.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


    Masz Look2Me - wpis O20.
    Ściągnij L2MFix - http://www.atribune.org/downloads/l2mfix.exe, rozpakuj go i uruchom l2mfix.bat. Użyj opcji 2 - Run fix. Jak sie nie poprawi to uzyj opcji 1-Run find log - po zrobieniu loga wrzuć go tutaj.
    Spróbuj Spybotem, ewentualnie jakimś innym antywirem (polecam pande).
    W trybie awaryjnym skanowałeś kompa?



    Masz Look2Me - wpis O20.
    Ściągnij L2MFix - http://www.atribune.org/downloads/l2mfix.exe, rozpakuj go i uruchom l2mfix.bat. Użyj opcji 2 - Run fix. Jak sie nie poprawi to uzyj opcji 1-Run find log - po zrobieniu loga wrzuć go tutaj.


    Zrobiłam jak pisałeś, użyłam tylko opcji 2 run fix, czy mam również użyć opcji 1? A oto log:
    L2mfix 010406
    Creating Account.
    Polecenie zostaˆo wykonane pomy˜lnie.

    Adding Administrative privleges.
    Checking for L2MFix account(0=no 1=yes):
    1
    Granting SeDebugPrivilege to L2MFIX ... successful

    Running From:
    C:\WINDOWS\SYSTEM32

    Killing Processes!

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 612 'smss.exe'

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 704 'winlogon.exe'
    Killing PID 704 'winlogon.exe'
    Killing PID 704 'winlogon.exe'
    Killing PID 704 'winlogon.exe'
    Killing PID 704 'winlogon.exe'
    Killing PID 704 'winlogon.exe'

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 464 'explorer.exe'
    Killing PID 464 'explorer.exe'
    Killing PID 464 'explorer.exe'
    Killing PID 464 'explorer.exe'

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 1672 'rundll32.exe'
    Killing PID 1672 'rundll32.exe'
    Killing PID 1672 'rundll32.exe'
    Killing PID 1672 'rundll32.exe'
    Killing PID 1672 'rundll32.exe'
    Killing PID 1672 'rundll32.exe'
    Restoring Sedebugprivilege:
    Granting SeDebugPrivilege to Administratorzy ... successful

    Scanning First Pass. Please Wait!

    First Pass Completed

    Second Pass Scanning

    Second pass Completed!
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Liczba skopiowanych plik¢w: 1.
    Deleting: C:\WINDOWS\system32\aytiveds.dll
    Successfully Deleted: C:\WINDOWS\system32\aytiveds.dll
    Deleting: C:\WINDOWS\system32\cUbinet.dll
    Successfully Deleted: C:\WINDOWS\system32\cUbinet.dll
    Deleting: C:\WINDOWS\system32\fp4003hme.dll
    Successfully Deleted: C:\WINDOWS\system32\fp4003hme.dll
    Deleting: C:\WINDOWS\system32\fp4m03h1e.dll
    Successfully Deleted: C:\WINDOWS\system32\fp4m03h1e.dll
    Deleting: C:\WINDOWS\system32\i024lafq1d2e.dll
    Successfully Deleted: C:\WINDOWS\system32\i024lafq1d2e.dll
    Deleting: C:\WINDOWS\system32\i4nm0e51eh.dll
    Successfully Deleted: C:\WINDOWS\system32\i4nm0e51eh.dll
    Deleting: C:\WINDOWS\system32\iKsrad.dll
    Successfully Deleted: C:\WINDOWS\system32\iKsrad.dll
    Deleting: C:\WINDOWS\system32\ir4ol5h31.dll
    Successfully Deleted: C:\WINDOWS\system32\ir4ol5h31.dll
    Deleting: C:\WINDOWS\system32\l4r0le9m1h.dll
    Successfully Deleted: C:\WINDOWS\system32\l4r0le9m1h.dll
    Deleting: C:\WINDOWS\system32\LBRTREND.dll
    Successfully Deleted: C:\WINDOWS\system32\LBRTREND.dll
    Deleting: C:\WINDOWS\system32\lv4q09h5e.dll
    Successfully Deleted: C:\WINDOWS\system32\lv4q09h5e.dll
    Deleting: C:\WINDOWS\system32\mexmlr.dll
    Successfully Deleted: C:\WINDOWS\system32\mexmlr.dll
    Deleting: C:\WINDOWS\system32\mmvideo.dll
    Successfully Deleted: C:\WINDOWS\system32\mmvideo.dll
    Deleting: C:\WINDOWS\system32\OygDS.dll
    Successfully Deleted: C:\WINDOWS\system32\OygDS.dll
    Deleting: C:\WINDOWS\system32\q0680ajuedo80.dll
    Successfully Deleted: C:\WINDOWS\system32\q0680ajuedo80.dll
    Deleting: C:\WINDOWS\system32\q0nu0a59ed.dll
    Successfully Deleted: C:\WINDOWS\system32\q0nu0a59ed.dll
    Deleting: C:\WINDOWS\system32\rfgapi.dll
    Successfully Deleted: C:\WINDOWS\system32\rfgapi.dll
    Deleting: C:\WINDOWS\system32\vypodbc.dll
    Successfully Deleted: C:\WINDOWS\system32\vypodbc.dll
    Deleting: C:\WINDOWS\system32\guard.tmp
    Successfully Deleted: C:\WINDOWS\system32\guard.tmp

    msg11?.dll
    Liczba skopiowanych plik¢w: 0.
    Desktop.ini sucessfully removed

    Restoring Windows Update Certificates.:

    The following Is the Current Export of the Winlogon notify key:
    ****************************************************************************
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff"="ChainWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff"="CryptnetWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName"="cscdll.dll"
    "Logon"="WinlogonLogonEvent"
    "Logoff"="WinlogonLogoffEvent"
    "ScreenSaver"="WinlogonScreenSaverEvent"
    "Startup"="WinlogonStartupEvent"
    "Shutdown"="WinlogonShutdownEvent"
    "StartShell"="WinlogonStartShellEvent"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MSSYCLM]
    "Asynchronous"=dword:00000000
    "DllName"="C:\\WINDOWS\\system32\\q0nu0a59ed.dll"
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    "DLLName"="wlnotify.dll"
    "Logon"="SCardStartCertProp"
    "Logoff"="SCardStopCertProp"
    "Lock"="SCardSuspendCertProp"
    "Unlock"="SCardResumeCertProp"
    "Enabled"=dword:00000001
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "StartShell"="SchedStartShell"
    "Logoff"="SchedEventLogOff"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff"="WLEventLogoff"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001
    "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName"="WlNotify.dll"
    "Lock"="SensLockEvent"
    "Logon"="SensLogonEvent"
    "Logoff"="SensLogoffEvent"
    "Safe"=dword:00000001
    "MaxWait"=dword:00000258
    "StartScreenSaver"="SensStartScreenSaverEvent"
    "StopScreenSaver"="SensStopScreenSaverEvent"
    "Startup"="SensStartupEvent"
    "Shutdown"="SensShutdownEvent"
    "StartShell"="SensStartShellEvent"
    "PostShell"="SensPostShellEvent"
    "Disconnect"="SensDisconnectEvent"
    "Reconnect"="SensReconnectEvent"
    "Unlock"="SensUnlockEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "Logoff"="TSEventLogoff"
    "Logon"="TSEventLogon"
    "PostShell"="TSEventPostShell"
    "Shutdown"="TSEventShutdown"
    "StartShell"="TSEventStartShell"
    "Startup"="TSEventStartup"
    "MaxWait"=dword:00000258
    "Reconnect"="TSEventReconnect"
    "Disconnect"="TSEventDisconnect"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    "DLLName"="wlnotify.dll"
    "Logon"="RegisterTicketExpiredNotificationEvent"
    "Logoff"="UnregisterTicketExpiredNotificationEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    The following are the files found:
    ****************************************************************************
    C:\WINDOWS\system32\aytiveds.dll
    C:\WINDOWS\system32\cUbinet.dll
    C:\WINDOWS\system32\fp4003hme.dll
    C:\WINDOWS\system32\fp4m03h1e.dll
    C:\WINDOWS\system32\i024lafq1d2e.dll
    C:\WINDOWS\system32\i4nm0e51eh.dll
    C:\WINDOWS\system32\iKsrad.dll
    C:\WINDOWS\system32\ir4ol5h31.dll
    C:\WINDOWS\system32\l4r0le9m1h.dll
    C:\WINDOWS\system32\LBRTREND.dll
    C:\WINDOWS\system32\lv4q09h5e.dll
    C:\WINDOWS\system32\mexmlr.dll
    C:\WINDOWS\system32\mmvideo.dll
    C:\WINDOWS\system32\OygDS.dll
    C:\WINDOWS\system32\q0680ajuedo80.dll
    C:\WINDOWS\system32\q0nu0a59ed.dll
    C:\WINDOWS\system32\rfgapi.dll
    C:\WINDOWS\system32\vypodbc.dll
    C:\WINDOWS\system32\guard.tmp

    Registry Entries that were Deleted:
    Please verify that the listing looks ok.
    If there was something deleted wrongly there are backups in the backreg folder.
    ****************************************************************************
    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{01CD445D-747F-4E2D-8802-53CD2F3C16DA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{01CD445D-747F-4E2D-8802-53CD2F3C16DA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{01CD445D-747F-4E2D-8802-53CD2F3C16DA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{01CD445D-747F-4E2D-8802-53CD2F3C16DA}\InprocServer32]
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}\InprocServer32]
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DC9446F2-0568-4751-A910-995028BE4FC7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DC9446F2-0568-4751-A910-995028BE4FC7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DC9446F2-0568-4751-A910-995028BE4FC7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DC9446F2-0568-4751-A910-995028BE4FC7}\InprocServer32]
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{648AB860-EF86-4174-8EDF-5145D8C36410}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{648AB860-EF86-4174-8EDF-5145D8C36410}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{648AB860-EF86-4174-8EDF-5145D8C36410}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{648AB860-EF86-4174-8EDF-5145D8C36410}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mmvideo.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}\InprocServer32]
    @="C:\\WINDOWS\\system32\\aytiveds.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7D82BFAD-EDE1-4953-9465-B326C5884201}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D82BFAD-EDE1-4953-9465-B326C5884201}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D82BFAD-EDE1-4953-9465-B326C5884201}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D82BFAD-EDE1-4953-9465-B326C5884201}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mexmlr.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{1AE32824-F464-4910-9AF3-D6C4934D9B95}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1AE32824-F464-4910-9AF3-D6C4934D9B95}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1AE32824-F464-4910-9AF3-D6C4934D9B95}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1AE32824-F464-4910-9AF3-D6C4934D9B95}\InprocServer32]
    @="C:\\WINDOWS\\system32\\LBRTREND.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cUbinet.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{07720F84-8AC9-4012-8F72-5DB61D6D1E11}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{07720F84-8AC9-4012-8F72-5DB61D6D1E11}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{07720F84-8AC9-4012-8F72-5DB61D6D1E11}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{07720F84-8AC9-4012-8F72-5DB61D6D1E11}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CBE64E1D-FB06-43C0-8E40-492D3763D02E}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CBE64E1D-FB06-43C0-8E40-492D3763D02E}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CBE64E1D-FB06-43C0-8E40-492D3763D02E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CBE64E1D-FB06-43C0-8E40-492D3763D02E}\InprocServer32]
    @="C:\\WINDOWS\\system32\\vypodbc.dll"
    "ThreadingModel"="Apartment"

    REGEDIT4

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{BF814DD1-5F6B-41B0-B7D0-2847DDA2DEB9}"=-
    "{01CD445D-747F-4E2D-8802-53CD2F3C16DA}"=-
    "{7EF93E79-DC9F-47F1-B71F-A2C7B999363E}"=-
    "{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}"=-
    "{A8BB1284-DBF9-4A46-8228-090AB4BDCADF}"=-
    "{0B733397-651C-463C-AD19-48ACBB88AF7B}"=-
    "{DC9446F2-0568-4751-A910-995028BE4FC7}"=-
    "{89D4B74E-8812-4451-82FA-9BAB353E9F3D}"=-
    "{1E382FE4-6C6F-46B1-B5FB-22F88D455032}"=-
    "{648AB860-EF86-4174-8EDF-5145D8C36410}"=-
    "{5FC666C1-066B-4306-A207-B92757D4C495}"=-
    "{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}"=-
    "{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}"=-
    "{7D82BFAD-EDE1-4953-9465-B326C5884201}"=-
    "{1AE32824-F464-4910-9AF3-D6C4934D9B95}"=-
    "{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}"=-
    "{07720F84-8AC9-4012-8F72-5DB61D6D1E11}"=-
    "{CBE64E1D-FB06-43C0-8E40-492D3763D02E}"=-
    [-HKEY_CLASSES_ROOT\CLSID\{BF814DD1-5F6B-41B0-B7D0-2847DDA2DEB9}]
    [-HKEY_CLASSES_ROOT\CLSID\{01CD445D-747F-4E2D-8802-53CD2F3C16DA}]
    [-HKEY_CLASSES_ROOT\CLSID\{7EF93E79-DC9F-47F1-B71F-A2C7B999363E}]
    [-HKEY_CLASSES_ROOT\CLSID\{3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425}]
    [-HKEY_CLASSES_ROOT\CLSID\{A8BB1284-DBF9-4A46-8228-090AB4BDCADF}]
    [-HKEY_CLASSES_ROOT\CLSID\{0B733397-651C-463C-AD19-48ACBB88AF7B}]
    [-HKEY_CLASSES_ROOT\CLSID\{DC9446F2-0568-4751-A910-995028BE4FC7}]
    [-HKEY_CLASSES_ROOT\CLSID\{89D4B74E-8812-4451-82FA-9BAB353E9F3D}]
    [-HKEY_CLASSES_ROOT\CLSID\{1E382FE4-6C6F-46B1-B5FB-22F88D455032}]
    [-HKEY_CLASSES_ROOT\CLSID\{648AB860-EF86-4174-8EDF-5145D8C36410}]
    [-HKEY_CLASSES_ROOT\CLSID\{5FC666C1-066B-4306-A207-B92757D4C495}]
    [-HKEY_CLASSES_ROOT\CLSID\{4CC041F0-0ABA-43DC-AE0F-00409DA9BC55}]
    [-HKEY_CLASSES_ROOT\CLSID\{C2D70FAA-7D6D-41D9-B27C-A2F517B283CD}]
    [-HKEY_CLASSES_ROOT\CLSID\{7D82BFAD-EDE1-4953-9465-B326C5884201}]
    [-HKEY_CLASSES_ROOT\CLSID\{1AE32824-F464-4910-9AF3-D6C4934D9B95}]
    [-HKEY_CLASSES_ROOT\CLSID\{B737DACC-E9B3-4EC0-A7CC-E40AB282BED4}]
    [-HKEY_CLASSES_ROOT\CLSID\{07720F84-8AC9-4012-8F72-5DB61D6D1E11}]
    [-HKEY_CLASSES_ROOT\CLSID\{CBE64E1D-FB06-43C0-8E40-492D3763D02E}]
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    ****************************************************************************
    Desktop.ini Contents:
    ****************************************************************************
    [.ShellClassInfo]
    CLSID={645FF040-5081-101B-9F08-00AA002F954E}
    ****************************************************************************
    Checking for L2MFix account(0=no 1=yes):
    0
    Zipping up files for submission:
    adding: dlls/aytiveds.dll (deflated 5%)
    adding: dlls/cUbinet.dll (deflated 5%)
    adding: dlls/fp4003hme.dll (deflated 5%)
    adding: dlls/fp4m03h1e.dll (deflated 5%)
    adding: dlls/i024lafq1d2e.dll (deflated 4%)
    adding: dlls/i4nm0e51eh.dll (deflated 5%)
    adding: dlls/iKsrad.dll (deflated 4%)
    adding: dlls/ir4ol5h31.dll (deflated 4%)
    adding: dlls/l4r0le9m1h.dll (deflated 5%)
    adding: dlls/LBRTREND.dll (deflated 5%)
    adding: dlls/lv4q09h5e.dll (deflated 5%)
    adding: dlls/mexmlr.dll (deflated 5%)
    adding: dlls/mmvideo.dll (deflated 5%)
    adding: dlls/OygDS.dll (deflated 4%)
    adding: dlls/q0680ajuedo80.dll (deflated 5%)
    adding: dlls/q0nu0a59ed.dll (deflated 5%)
    adding: dlls/rfgapi.dll (deflated 4%)
    adding: dlls/vypodbc.dll (deflated 5%)
    adding: dlls/guard.tmp (deflated 5%)
    adding: backregs/notibac.reg (deflated 87%)
    adding: backregs/shell.reg (deflated 72%)
    adding: backregs/01CD445D-747F-4E2D-8802-53CD2F3C16DA.reg (deflated 71%)
    adding: backregs/3F1994A8-B25E-4A69-A0EA-FDAC9C7BF425.reg (deflated 71%)
    adding: backregs/DC9446F2-0568-4751-A910-995028BE4FC7.reg (deflated 71%)
    adding: backregs/648AB860-EF86-4174-8EDF-5145D8C36410.reg (deflated 70%)
    adding: backregs/4CC041F0-0ABA-43DC-AE0F-00409DA9BC55.reg (deflated 70%)
    adding: backregs/C2D70FAA-7D6D-41D9-B27C-A2F517B283CD.reg (deflated 70%)
    adding: backregs/7D82BFAD-EDE1-4953-9465-B326C5884201.reg (deflated 70%)
    adding: backregs/1AE32824-F464-4910-9AF3-D6C4934D9B95.reg (deflated 70%)
    adding: backregs/B737DACC-E9B3-4EC0-A7CC-E40AB282BED4.reg (deflated 70%)
    adding: backregs/07720F84-8AC9-4012-8F72-5DB61D6D1E11.reg (deflated 70%)
    adding: backregs/CBE64E1D-FB06-43C0-8E40-492D3763D02E.reg (deflated 70%)

    W trybie awaryjnym skanowałeś kompa?

    Tak, nie pomogło. Ponadto Adaware nie wszystko usuwa. Za kazdym razem kiedy nim skanuje znajduje mi nowe krytyczne obiekty. Dlaczego? Przeciez cały czas chodzi mi Kaspersky?
    dopiero jak posprzątasz system włącz internet...

    dopiero jak posprzątasz system włącz internet...

    a niby jak mam go posprzątać? Chętnie to zrobię ale nie wiem od czego zacząć? Jak mam to zrobić? Uruchomiłam cc cleanera, co jeszcze moge zrobic?


    a niby jak mam go posprzątać? Chętnie to zrobię ale nie wiem od czego zacząć? Jak mam to zrobić? Uruchomiłam cc cleanera, co jeszcze moge zrobic?

    Zacznij od pozbycia się wszystkich wirusów/spyware. Jeżli widzisz że twój antywir nie sprawdza się, zainstaluj innego (ja taką metodą doszedłem do pandy, którą polecam wszystkim). Później posprzątaj rejestr (jv 16 tool), a później system jakims dobrym programem, cc cleaner może być.
    Oczywiście komp musi być odłączony od neta.
    Dobra - skoro użyłaś 2- fix to pokaż teraz loga (opcja 1) z tego L2MFix i Hijacka.
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • mandragora32.opx.pl
  • ďťż
    Wszelkie Prawa ZastrzeĹźone! chomiki Design by SZABLONY.maniak.pl.