ďťż
chomiki
Proszę o sprawdzenie log'a, trojanDownloader.Wigon.bs
witam.zamuliło mi kompa prosze o sprawdzenie logów
jak i gdzie sprawdzić ładowanie alternatora + pytanie o akku
moze ktos sprawdzic mi log?prosze
Dysk Twardy: nowy czy "z odzysku"_jak sprawdzić?
Proszę o sprawdzenie Loag z HiJack
Prosze o sprawdzenie. Kompletnie sie na tym niz znam :)
Proszę o sprawdzenie logów z HijackThis
sprawdzie moje logi plx
Bardzo prosze o sprawdzenie Logu :(
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • russ.xlx.pl

  • chomiki

    Witam,
    Podczas korzystania z internetu, co chwilę wyskakują mi reklamy w nowych oknach, np.Travian, Wojna Smoków, Get it on, Celldorado RADAR itp.
    Mam prośbę. Powiedzcie po kolei co mam zrobić bo nie mam pojęcia...

    Mój log:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:28:16, on 2010-01-02
    Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16945)
    Boot mode: Normal

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Common Files\Real\Update_OB\realsched.exe
    D:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
    D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    D:\Program Files\1st Security Agent\newlock.exe
    D:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvbapp.exe
    D:\WINDOWS\system32\CTsvcCDA.exe
    D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvbapp.exe
    D:\Program Files\Symantec AntiVirus\DefWatch.exe
    D:\Program Files\1st Security Agent\newlock.exe
    D:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice133.exe
    D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    D:\Program Files\QuestService\questservice.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Symantec AntiVirus\Rtvscan.exe
    D:\WINDOWS\system32\wuauclt.exe
    D:\Program Files\Mozilla Firefox\firefox.exe
    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - D:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - D:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
    O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - D:\Program Files\Automated Content Enhancer\4.1.0.5260\ACEIEAddOn.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (file missing)
    O2 - BHO: Customized Platform Advancer - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - D:\Program Files\Customized Platform Advancer\4.1.0.1850\CPAIEAddOn.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Content Management Wizard - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - D:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll
    O2 - BHO: Textual Content Provider - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - D:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll
    O2 - BHO: (no name) - {D032570A-5F63-4812-A094-87D007C23012} - D:\PROGRA~1\PRIVAC~1\tools\sp\sp.dll (file missing)
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O2 - BHO: Web Search Operator - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - D:\Program Files\Web Search Operator\4.1.0.1990\wso.dll
    O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\a\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
    O3 - Toolbar: Gameztar Toolbar - {D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} - D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] D:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [00saskda] "D:\Program Files\1st Security Agent\newlock.exe" saskda
    O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "D:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=2 /w /h
    O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] D:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
    O4 - HKCU\..\Run: [ALLUpdate] "D:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"
    O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray
    O4 - HKCU\..\Run: [VideoBarApp] D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvbapp.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
    O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204531940640
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - D:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: DeskSaverService - Unknown owner - D:\Program Files\1st Security Agent\newlock.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - D:\PROGRA~1\MYWEBS~1\bar\3.bin\mwssvc.exe
    O23 - Service: QuestService Service - Unknown owner - D:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice133.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - D:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - D:\Program Files\Symantec AntiVirus\Rtvscan.exe

    --
    End of file - 10452 bytes



    Jest syf, ale HijackThis tego w całości nie widzi, więc podaj log z OTL
    Na forum się nie zmieściło.

    OTL.txt :

    http://wklej.to/83YL

    Extras.txt :

    http://wklej.to/Ff3m
    Uruchom OTL w oknie Custom Scans/Fixes wklej:

    :OTL
    PRC - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () -- D:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice133.exe
    PRC - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () -- D:\Program Files\QuestService\questservice.exe
    PRC - [2009-12-23 16:02:15 | 00,032,838 | ---- | M] (MyWebSearch.com) -- D:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
    PRC - [2009-12-23 16:02:15 | 00,024,688 | ---- | M] (MyWebSearch.com) -- D:\Program Files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE
    PRC - [2009-12-10 08:06:54 | 00,659,456 | ---- | M] () -- D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvbapp.exe
    PRC - [2007-06-13 14:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
    MOD - [2009-12-31 21:09:50 | 00,598,016 | ---- | M] () -- D:\Program Files\QuestService\questservice.dll
    MOD - [2009-12-23 16:02:15 | 00,045,134 | ---- | M] (MyWebSearch.com) -- D:\Program Files\MyWebSearch\bar\3.bin\MWSOESTB.DLL
    MOD - [2009-12-23 16:02:14 | 00,024,685 | ---- | M] (MyWebSearch.com) -- D:\Program Files\MyWebSearch\bar\3.bin\F3HKSTUB.DLL
    SRV - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () [Auto | Running] -- D:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice133.exe -- (QuestService Service)
    SRV - [2009-12-23 16:02:15 | 00,028,762 | ---- | M] (MyWebSearch.com) [Auto | Stopped] -- D:\Program Files\MyWebSearch\bar\3.bin\MWSSVC.EXE -- (MyWebSearchService)
    IE - HKU\S-1-5-21-220523388-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default
    IE - HKU\S-1-5-21-220523388-2139871995-725345543-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - D:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL (MyWebSearch.com)
    FF - prefs.js..extensions.enabledItems: m3ffxtbr@mywebsearch.com:1.1
    FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKfox000&fl=0&ptb=JU85uUxBzxeCe3qBFVsW1A&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor="
    FF - HKLM\software\mozilla\Firefox\Extensions\\{40f1eb95-4de4-4f36-a826-054ee36bb905}: D:\Program Files\Gameztar Toolbar\2.1.3.6670\FFToolbar [2009-12-13 15:41:29 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: D:\Program Files\Web Search Operator\4.1.0.1990\FF [2009-12-13 15:41:43 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: D:\Program Files\Automated Content Enhancer\4.1.0.5260\FF [2009-12-13 15:41:48 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: D:\Program Files\Customized Platform Advancer\4.1.0.1850\FF [2009-12-13 15:41:54 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: D:\Program Files\MyWebSearch\bar\firefox\ [2009-12-23 16:02:18 | 00,000,000 | ---D | M]
    [2009-05-18 17:42:35 | 00,009,895 | ---- | M] () -- D:\Documents and Settings\a\Dane aplikacji\Mozilla\Firefox\Profiles\92ji4ix8.default\searchplugins\mywebsearch.xml
    [2010-01-01 16:31:09 | 00,000,000 | ---D | M] (QuestService) -- D:\Program Files\Mozilla Firefox\extensions\{F2DDDB92-1605-4260-9B25-45A4DAE87B50}
    [2009-12-13 17:17:49 | 00,002,405 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\questservice129.xml
    [2009-12-28 15:35:54 | 00,002,405 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\questservice131.xml
    [2010-01-01 16:31:09 | 00,002,405 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\questservice133.xml
    O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - D:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL (MyWebSearch.com)
    O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
    O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - D:\Program Files\Automated Content Enhancer\4.1.0.5260\ACEIEAddOn.dll ()
    O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - D:\Program Files\Customized Platform Advancer\4.1.0.1850\CPAIEAddOn.dll ()
    O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - D:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll ()
    O2 - BHO: (Textual Content Provider) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - D:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll ()
    O2 - BHO: () - {D032570A-5F63-4812-A094-87D007C23012} - D:\PROGRA~1\PRIVAC~1\tools\sp\sp.dll File not found
    O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - D:\Program Files\Web Search Operator\4.1.0.1990\WSO.dll ()
    O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
    O3 - HKLM\..\Toolbar: (Gameztar Toolbar) - {D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} - D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll ()
    O3 - HKU\S-1-5-21-220523388-2139871995-725345543-1003\..\Toolbar\ShellBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
    O3 - HKU\S-1-5-21-220523388-2139871995-725345543-1003\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - D:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
    O3 - HKU\S-1-5-21-220523388-2139871995-725345543-1003\..\Toolbar\WebBrowser: (Gameztar Toolbar) - {D45817B8-3EAD-4D1D-8FCA-EC63A8E35DE2} - D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll ()
    O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] D:\Program Files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE (MyWebSearch.com)
    O4 - HKLM..\Run: [MyWebSearch Email Plugin] D:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE (MyWebSearch.com)
    O4 - HKU\S-1-5-21-220523388-2139871995-725345543-1003..\Run: [MyWebSearch Email Plugin] D:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE (MyWebSearch.com)
    O4 - HKU\S-1-5-21-220523388-2139871995-725345543-1003..\Run: [VideoBarApp] D:\Program Files\Gameztar Toolbar\2.1.3.6670\mvbapp.exe ()
    O4 - HKU\S-1-5-21-220523388-2139871995-725345543-1003..\Run: [ALLUpdate] D:\Program Files\ALLPlayer\ALLUpdate.exe File not found

    :Files
    D:\Documents and Settings\All Users\Dane aplikacji\QuestService
    D:\Program Files\QuestService
    D:\Program Files\MyWebSearch
    D:\Program Files\Gameztar Toolbar
    D:\Program Files\Web Search Operator
    D:\Program Files\Automated Content Enhancer
    D:\Program Files\Customized Platform Advancer
    D:\Program Files\Content Management Wizard
    D:\Program Files\Textual Content Provider
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Textual Content Provider
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Internet Today
    D:\Program Files\Internet Today
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Customized Platform Advancer
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Automated Content Enhancer
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Web Search Operator
    D:\Documents and Settings\All Users\Dane aplikacji\{FE09428E-9E54-4117-AC27-50C2DA4B2EC3}
    D:\Documents and Settings\a\Ustawienia lokalne\Dane aplikacji\Gameztar Toolbar

    :Commands
    [emptytemp]
    [reboot]

    Klikasz Run Fix. Dajesz log z usuwania + nowy log z OTL.


    Log z usuwania :

    http://wklej.to/ANfx

    Nowy log :

    http://wklej.to/qEkA
    Uruchom OTL w oknie Custom Scans/Fixes wklej:

    :OTL
    IE - HKU\S-1-5-21-220523388-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default
    O3 - HKU\S-1-5-21-220523388-2139871995-725345543-1003\..\Toolbar\ShellBrowser: (no name) - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No CLSID value found.

    :Files
    D:\Documents and Settings\a\Dane aplikacji\FunWebProducts

    Klikasz Run Fix. Następnie:

    W OTL kliknij CleanUp

    Przeczyść dysk oraz rejestr CCleaner

    Wyłącz i włącz przywracanie systemu na wszystkich dyskach Instrukcja

    Wykonaj pełne skanowanie Malwarebytes' Anti-Malware - jeśli coś znajdzie usuń i daj raport
    Znalazł...

    Raport :

    http://wklej.to/D9mE
    W porządku, opróżnij jeszcze kwarantannę Malwarebytes
    Ok.
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • mandragora32.opx.pl
  • ďťż
    Wszelkie Prawa ZastrzeĹźone! chomiki Design by SZABLONY.maniak.pl.