Cholerna strona: http://homepage.com/
Witajcie! Juź krew mnie zalewa, bo dpoiero zainstalowałem Windoza a tu wpakował mi się syf pod nazwą http://homepage.com/ w IE i za diabła nie mogę się pozbyć tej strony. Poczytałem posty na forum, próbowałem róźnych programów i kicha. Moźe ktoś pomóc?
Odpowiedzi: 4
Przesyłam ukłony i podziękowania w Twoją stronę. Zadziałało!!!!
P.S. Tak, bo zaglądam na chińskie i japońskie strony.
Pozdrawiam.
P.S. Tak, bo zaglądam na chińskie i japońskie strony.
Pozdrawiam.
Wyłącz przywracanie systemu :
Wyłącz proces w Menadzerze zadań :
MSMSGSVC.exe
Wyszukaj zaznaczając ukryte i usuń z lokalizacji :
C:WINDOWSSystemMSMSGSVC.exe
C:WINDOWSwebrelated.htm
C:WINDOWSdpe.dll, gdyby się nie udało odrazu usunąć to wyrejestruj tą bibliotekę poleceniem w Uruchom :
regsvr32 /u C:WINDOWSdpe.dll .
Fix :
O4 – HKLM..Run:[IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
Uźywasz Windows East Asian language ?
Włącz przywracanie systemu.
Spróbuj takźe uźyć CWShredder, poniewaź eliminuje on wariant Trojan CWS, który obecnie masz.
Wyłącz proces w Menadzerze zadań :
MSMSGSVC.exe
Wyszukaj zaznaczając ukryte i usuń z lokalizacji :
C:WINDOWSSystemMSMSGSVC.exe
C:WINDOWSwebrelated.htm
C:WINDOWSdpe.dll, gdyby się nie udało odrazu usunąć to wyrejestruj tą bibliotekę poleceniem w Uruchom :
regsvr32 /u C:WINDOWSdpe.dll .
Fix :
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Not Available
O2 – BHO: DOMPeek Class – {834261E1–DD97–4177–853B–C907E5D5BD6E} – C:WINDOWSdpe.dll
O4 – HKCU..Run: [MSMsgSvc] C:WINDOWSSystemMSMSGSVC.exe
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O13 – DefaultPrefix: http://%65%68%74%74%70%2E%63%63/?
O13 – WWW Prefix: http://%65%68%74%74%70%2E%63%63/?
O4 – HKLM..Run:[IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
Uźywasz Windows East Asian language ?
Włącz przywracanie systemu.
Spróbuj takźe uźyć CWShredder, poniewaź eliminuje on wariant Trojan CWS, który obecnie masz.
Proszę bardzo, oto log:
Logfile of HijackThis v1.98.2
Scan saved at 09:21:02, on 2004–10–08
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAnalog DevicesSoundMAXSMTray.exe
C:WINDOWSSystem32RUNDLL32.EXE
C:Program FilesRivaTunerRivaTuner.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:Program FilesSlySoftAnyDVDAnyDVD.exe
C:WINDOWSSystemMSMSGSVC.exe
C:WINDOWSSystem32devldr32.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program Files otalcmdTOTALCMD.EXE
C:Program FilesDVD2SVCDDVD2SVCD.exe
C:Program FilesDVD2SVCDBeSweetBeSweet.exe
C:Program FilesInternet Exploreriexplore.exe
C:DownloadsHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Not Available
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: DOMPeek Class – {834261E1–DD97–4177–853B–C907E5D5BD6E} – C:WINDOWSdpe.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETfgiebar.dll
O4 – HKLM..Run: [IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 – HKLM..Run: [Smapp] C:Program FilesAnalog DevicesSoundMAXSMTray.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [RivaTuner] "C:Program FilesRivaTunerRivaTuner.exe" /T
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [AnyDVD] C:Program FilesSlySoftAnyDVDAnyDVD.exe
O4 – HKLM..Run: [PinnacleDriverCheck] C:WINDOWSSystem32PSDrvCheck.exe
O4 – HKCU..Run: [MSMsgSvc] C:WINDOWSSystemMSMSGSVC.exe
O4 – Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O13 – DefaultPrefix: http://%65%68%74%74%70%2E%63%63/?
O13 – WWW Prefix: http://%65%68%74%74%70%2E%63%63/?
Logfile of HijackThis v1.98.2
Scan saved at 09:21:02, on 2004–10–08
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAnalog DevicesSoundMAXSMTray.exe
C:WINDOWSSystem32RUNDLL32.EXE
C:Program FilesRivaTunerRivaTuner.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:Program FilesSlySoftAnyDVDAnyDVD.exe
C:WINDOWSSystemMSMSGSVC.exe
C:WINDOWSSystem32devldr32.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program Files otalcmdTOTALCMD.EXE
C:Program FilesDVD2SVCDDVD2SVCD.exe
C:Program FilesDVD2SVCDBeSweetBeSweet.exe
C:Program FilesInternet Exploreriexplore.exe
C:DownloadsHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://homepage.com%00@www.e–finder.cc/hp/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearch,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKLMSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://homepage.com%00@www.e–finder.cc/search/ (obfuscated)
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Not Available
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: DOMPeek Class – {834261E1–DD97–4177–853B–C907E5D5BD6E} – C:WINDOWSdpe.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETfgiebar.dll
O4 – HKLM..Run: [IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 – HKLM..Run: [Smapp] C:Program FilesAnalog DevicesSoundMAXSMTray.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [RivaTuner] "C:Program FilesRivaTunerRivaTuner.exe" /T
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [AnyDVD] C:Program FilesSlySoftAnyDVDAnyDVD.exe
O4 – HKLM..Run: [PinnacleDriverCheck] C:WINDOWSSystem32PSDrvCheck.exe
O4 – HKCU..Run: [MSMsgSvc] C:WINDOWSSystemMSMSGSVC.exe
O4 – Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O13 – DefaultPrefix: http://%65%68%74%74%70%2E%63%63/?
O13 – WWW Prefix: http://%65%68%74%74%70%2E%63%63/?
Zapodaj log z HJ to pomoźemy Tobie usunąć
stronę domową.com :wink:
stronę domową.com :wink:
Strona 1 / 1