Prosze o pomoc :(((
Mam kłopoty z wirusem W32.Spybot.Worm a takźe ładuje mi sie niechciana strona esearch zamiast google.To jet log .Prosze pomózcie mi w tych sprawach.
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesNavNTdefwatch.exe
C:Program FilesNavNT tvscan.exe
C:Program FilesATI TechnologiesPanel sterowania ATIatiptaxx.exe
C:Program FilesLavasoftAd–aware 6Ad–watch.exe
C:WINDOWSSystem32LXSUPMON.EXE
C:Program FilesNavNTvptray.exe
C:Program FilesRealtekRtl8180RtlWake.exe
C:WINDOWSwebshots.scr
C:Program FilesNorton UtilitiesNPROTECT.EXE
C:Program FilesSpeed Disk opdb.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32MsgSys.EXE
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
D:Programy uzytkoweHijackThisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.esearch.cc/s.php
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.esearch.cc/
O2 – BHO: (no name) – {0000CC75–ACF3–4cac–A0A9–DD3868E06852} – C:Program FilesDAPDAPBHO.dll
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – (no file)
O2 – BHO: (no name) – {0B90AA1B–F649–44C3–9FD3–736C332CBBCF} – (no file)
O2 – BHO: (no name) – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet3_88.dll
O2 – BHO: Shorty – {5C472352–90D0–4214–BF20–8E4A2B82F980} – C:WINDOWSwin32app.dll
O2 – BHO: (no name) – {82315A18–6CFB–44a7–BDFD–90E36537C252} – (no file)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: DAP Bar – {62999427–33FC–4baf–9C9C–BCE6BD127F08} – C:Program FilesDAPDAPIEBar.dll
O4 – HKLM..Run: [ATIPTA] atiptaxx.exe
O4 – HKLM..Run: [Ad–watch] "C:Program FilesLavasoftAd–aware 6Ad–watch.exe"
O4 – HKLM..Run: [LXSUPMON] C:WINDOWSSystem32LXSUPMON.EXE RUN
O4 – HKLM..Run: [vptray] C:Program FilesNavNTvptray.exe
O4 – Startup: Webshots.lnk = C:Program FilesWebshotsLauncher.exe
O4 – Global Startup: RtlWake.lnk = ?
O6 – HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 – Extra context menu item: &Download with &DAP – C:PROGRA~1DAPdapextie.htm
O8 – Extra context menu item: Download &all with DAP – C:PROGRA~1DAPdapextie2.htm
O8 – Extra context menu item: Download with GetRight – C:Program FilesGetRightGRdownload.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Open with GetRight Browser – C:Program FilesGetRightGRbrowse.htm
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Run DAP (HKLM)
O9 – Extra button: Badanie (HKLM)
O9 – Extra button: FlashGet (HKLM)
O9 – Extra 'Tools' menuitem: &FlashGet (HKLM)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 – HKLMSystemCCSServicesTcpip..{B28EB7DD–9C3E–446B–9F1E–874BEA8DCD15}: NameServer = 213.25.136.66,194.204.152.34,194.204.159.1
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesNavNTdefwatch.exe
C:Program FilesNavNT tvscan.exe
C:Program FilesATI TechnologiesPanel sterowania ATIatiptaxx.exe
C:Program FilesLavasoftAd–aware 6Ad–watch.exe
C:WINDOWSSystem32LXSUPMON.EXE
C:Program FilesNavNTvptray.exe
C:Program FilesRealtekRtl8180RtlWake.exe
C:WINDOWSwebshots.scr
C:Program FilesNorton UtilitiesNPROTECT.EXE
C:Program FilesSpeed Disk opdb.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32MsgSys.EXE
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
D:Programy uzytkoweHijackThisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.esearch.cc/s.php
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.esearch.cc/
O2 – BHO: (no name) – {0000CC75–ACF3–4cac–A0A9–DD3868E06852} – C:Program FilesDAPDAPBHO.dll
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – (no file)
O2 – BHO: (no name) – {0B90AA1B–F649–44C3–9FD3–736C332CBBCF} – (no file)
O2 – BHO: (no name) – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet3_88.dll
O2 – BHO: Shorty – {5C472352–90D0–4214–BF20–8E4A2B82F980} – C:WINDOWSwin32app.dll
O2 – BHO: (no name) – {82315A18–6CFB–44a7–BDFD–90E36537C252} – (no file)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: DAP Bar – {62999427–33FC–4baf–9C9C–BCE6BD127F08} – C:Program FilesDAPDAPIEBar.dll
O4 – HKLM..Run: [ATIPTA] atiptaxx.exe
O4 – HKLM..Run: [Ad–watch] "C:Program FilesLavasoftAd–aware 6Ad–watch.exe"
O4 – HKLM..Run: [LXSUPMON] C:WINDOWSSystem32LXSUPMON.EXE RUN
O4 – HKLM..Run: [vptray] C:Program FilesNavNTvptray.exe
O4 – Startup: Webshots.lnk = C:Program FilesWebshotsLauncher.exe
O4 – Global Startup: RtlWake.lnk = ?
O6 – HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 – Extra context menu item: &Download with &DAP – C:PROGRA~1DAPdapextie.htm
O8 – Extra context menu item: Download &all with DAP – C:PROGRA~1DAPdapextie2.htm
O8 – Extra context menu item: Download with GetRight – C:Program FilesGetRightGRdownload.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Open with GetRight Browser – C:Program FilesGetRightGRbrowse.htm
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Run DAP (HKLM)
O9 – Extra button: Badanie (HKLM)
O9 – Extra button: FlashGet (HKLM)
O9 – Extra 'Tools' menuitem: &FlashGet (HKLM)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 – HKLMSystemCCSServicesTcpip..{B28EB7DD–9C3E–446B–9F1E–874BEA8DCD15}: NameServer = 213.25.136.66,194.204.152.34,194.204.159.1
Odpowiedzi: 4
Wyłącz przywracanie,
Zakończ proces :
setup1.exe
Wyszukaj i usuń :
setup1.exe
newdotnet3_88.dll
win32app.dll – ta biblioteka jest odpowiedzialna u Ciebie za zmiane strony startowej na esearch .cc .
Napraw :
Gdybyś miał problemy uźyj CWShredder ( klasyfikuje i usuwa owy moduł .dll na podstawie swojej bazy ).
Włącz przywracanie systemu.
Update :
Dobrze Bobi_robert, źe teź pomalutku zabierasz się za weryfikacje :wink:
Zakończ proces :
setup1.exe
Wyszukaj i usuń :
setup1.exe
newdotnet3_88.dll
win32app.dll – ta biblioteka jest odpowiedzialna u Ciebie za zmiane strony startowej na esearch .cc .
Napraw :
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – (no file)
O2 – BHO: (no name) – {0B90AA1B–F649–44C3–9FD3–736C332CBBCF} – (no file)
O2 – BHO: (no name) – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet3_88.dll
O2 – BHO: Shorty – {5C472352–90D0–4214–BF20–8E4A2B82F980} – C:WINDOWSwin32app.dll
O2 – BHO: (no name) – {82315A18–6CFB–44a7–BDFD–90E36537C252} – (no file)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
Gdybyś miał problemy uźyj CWShredder ( klasyfikuje i usuwa owy moduł .dll na podstawie swojej bazy ).
Włącz przywracanie systemu.
Update :
Dobrze Bobi_robert, źe teź pomalutku zabierasz się za weryfikacje :wink:
Jeypi:Zrobiłem tak jak mi radziłeś.Przez moment myslałem źe juź się zmieniło na startowa google ale póxniej znowu wyskoczył AdWarei ta stronka
http://www.centrumxp.pl/forum/viewtopic.php?t=14198
Zrobiłem tak jak mi radziłeś.Przez moment myslałem źe juź się zmieniło na startowa google ale póxniej znowu wyskoczył AdWarei ta stronka.Teraz log wyglada tak:
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32Ati2evxx.exe
C:Program FilesNavNTdefwatch.exe
C:Program FilesNavNT tvscan.exe
C:Program FilesNorton UtilitiesNPROTECT.EXE
C:Program FilesSpeed Disk opdb.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32MsgSys.EXE
C:WINDOWSExplorer.EXE
C:Program FilesATI TechnologiesPanel sterowania ATIatiptaxx.exe
C:Program FilesLavasoftAd–aware 6Ad–watch.exe
C:WINDOWSSystem32LXSUPMON.EXE
C:Program FilesNavNTvptray.exe
C:WINDOWSSystem32lexpps.exe
C:Program FilesRealtekRtl8180RtlWake.exe
C:WINDOWSwebshots.scr
D:Programy uzytkoweHijackThisHijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
O2 – BHO: (no name) – {0000CC75–ACF3–4cac–A0A9–DD3868E06852} – C:Program FilesDAPDAPBHO.dll
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – (no file)
O2 – BHO: (no name) – {0B90AA1B–F649–44C3–9FD3–736C332CBBCF} – (no file)
O2 – BHO: (no name) – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet3_88.dll
O2 – BHO: Shorty – {5C472352–90D0–4214–BF20–8E4A2B82F980} – C:WINDOWSwin32app.dll
O2 – BHO: (no name) – {82315A18–6CFB–44a7–BDFD–90E36537C252} – (no file)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: DAP Bar – {62999427–33FC–4baf–9C9C–BCE6BD127F08} – C:Program FilesDAPDAPIEBar.dll
O4 – HKLM..Run: [ATIPTA] atiptaxx.exe
O4 – HKLM..Run: [Ad–watch] "C:Program FilesLavasoftAd–aware 6Ad–watch.exe"
O4 – HKLM..Run: [LXSUPMON] C:WINDOWSSystem32LXSUPMON.EXE RUN
O4 – HKLM..Run: [vptray] C:Program FilesNavNTvptray.exe
O4 – Startup: Webshots.lnk = C:Program FilesWebshotsLauncher.exe
O4 – Global Startup: RtlWake.lnk = ?
O6 – HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 – Extra context menu item: &Download with &DAP – C:PROGRA~1DAPdapextie.htm
O8 – Extra context menu item: Download &all with DAP – C:PROGRA~1DAPdapextie2.htm
O8 – Extra context menu item: Download with GetRight – C:Program FilesGetRightGRdownload.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Open with GetRight Browser – C:Program FilesGetRightGRbrowse.htm
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Badanie (HKLM)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 – HKLMSystemCCSServicesTcpip..{B28EB7DD–9C3E–446B–9F1E–874BEA8DCD15}: NameServer = 213.25.136.66,194.204.152.34,194.204.159.1
Coś chyba trza jeszcze usunąc. Tylko co? Prosze poradźcie co.Z góry dzieki:))
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32Ati2evxx.exe
C:Program FilesNavNTdefwatch.exe
C:Program FilesNavNT tvscan.exe
C:Program FilesNorton UtilitiesNPROTECT.EXE
C:Program FilesSpeed Disk opdb.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32MsgSys.EXE
C:WINDOWSExplorer.EXE
C:Program FilesATI TechnologiesPanel sterowania ATIatiptaxx.exe
C:Program FilesLavasoftAd–aware 6Ad–watch.exe
C:WINDOWSSystem32LXSUPMON.EXE
C:Program FilesNavNTvptray.exe
C:WINDOWSSystem32lexpps.exe
C:Program FilesRealtekRtl8180RtlWake.exe
C:WINDOWSwebshots.scr
D:Programy uzytkoweHijackThisHijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
O2 – BHO: (no name) – {0000CC75–ACF3–4cac–A0A9–DD3868E06852} – C:Program FilesDAPDAPBHO.dll
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – (no file)
O2 – BHO: (no name) – {0B90AA1B–F649–44C3–9FD3–736C332CBBCF} – (no file)
O2 – BHO: (no name) – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet3_88.dll
O2 – BHO: Shorty – {5C472352–90D0–4214–BF20–8E4A2B82F980} – C:WINDOWSwin32app.dll
O2 – BHO: (no name) – {82315A18–6CFB–44a7–BDFD–90E36537C252} – (no file)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: DAP Bar – {62999427–33FC–4baf–9C9C–BCE6BD127F08} – C:Program FilesDAPDAPIEBar.dll
O4 – HKLM..Run: [ATIPTA] atiptaxx.exe
O4 – HKLM..Run: [Ad–watch] "C:Program FilesLavasoftAd–aware 6Ad–watch.exe"
O4 – HKLM..Run: [LXSUPMON] C:WINDOWSSystem32LXSUPMON.EXE RUN
O4 – HKLM..Run: [vptray] C:Program FilesNavNTvptray.exe
O4 – Startup: Webshots.lnk = C:Program FilesWebshotsLauncher.exe
O4 – Global Startup: RtlWake.lnk = ?
O6 – HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 – Extra context menu item: &Download with &DAP – C:PROGRA~1DAPdapextie.htm
O8 – Extra context menu item: Download &all with DAP – C:PROGRA~1DAPdapextie2.htm
O8 – Extra context menu item: Download with GetRight – C:Program FilesGetRightGRdownload.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Open with GetRight Browser – C:Program FilesGetRightGRbrowse.htm
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: Badanie (HKLM)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 – HKLMSystemCCSServicesTcpip..{B28EB7DD–9C3E–446B–9F1E–874BEA8DCD15}: NameServer = 213.25.136.66,194.204.152.34,194.204.159.1
Coś chyba trza jeszcze usunąc. Tylko co? Prosze poradźcie co.Z góry dzieki:))
fix
Zakoncz jesli jest w tasku proces setup1.exe
Wyszukaj go na HDD zaznaczajac rowiez ukryte pliki i usun
PS. Pewnie cos jeszcze pominalem
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.esearch.cc/s.php
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.esearch.cc/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.esearch.cc/s.php
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://www.esearch.cc/
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.esearch.cc/
O16 – DPF: {13112111–1224–1141–1451–111111113533} – file://c:windowssystem32setup1.exe
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
Zakoncz jesli jest w tasku proces setup1.exe
Wyszukaj go na HDD zaznaczajac rowiez ukryte pliki i usun
PS. Pewnie cos jeszcze pominalem
Strona 1 / 1