Illidan
Ekspert
Liczba postów: 1.024
|
RE: System uruchamia się baaardzo wolno (około 15 minut)
Uruchom "OTL" jako administrator w opcji "Własne opcje skanowania/skrypt" wklej:
Kod:
: OTL
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}: "URL" = http: //dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerm s}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http: //search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http: //fr.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http: //feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid= 44fb5bdd-7fbd-4fb9-9eb4-99e81a4f494a&affid=110774&searchtype=ds&babsrc=lnkry&q={ searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}: "URL" = http: //dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerm s}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http: //fr.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http: //feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid= 44fb5bdd-7fbd-4fb9-9eb4-99e81a4f494a&affid=110774&searchtype=ds&babsrc=lnkry&q={ searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http: //feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid= 44fb5bdd-7fbd-4fb9-9eb4-99e81a4f494a&affid=110774&searchtype=ds&babsrc=lnkry&q={ searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}
IE - HKCU\..\SearchScopes\${searchCLSID}: "URL" = http: //search.live.com/results.aspx?q={searchTerms}&src={referrer: source?}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http: //feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid= 44fb5bdd-7fbd-4fb9-9eb4-99e81a4f494a&affid=110774&searchtype=ds&babsrc=lnkry&q={ searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}: "URL" = http: //dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerm s}
FF - prefs.js..browser.startup.homepage: "http: //www.searchnu.com/417"
FF - prefs.js..keyword.URL: "http: //dts.search-results.com/sr?src=ffb&appid=0&systemid=417&sr=0&q="
FF - user.js - File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-06-16 11: 45: 08 | 000,000,000 | ---D | M] (DataMngr) -- C: \PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION
O3: [b]64bit: [/b] - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3: [b]64bit: [/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C: \Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O18: [b]64bit: [/b] - Protocol\Handler\ms-help - No CLSID value found
O20: [b]64bit: [/b] - AppInit_DLLs: (C: \PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll) - C: \Program Files (x86)\Searchqu Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20: [b]64bit: [/b] - AppInit_DLLs: (C: \PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll) - C: \Program Files (x86)\Searchqu Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C: \PROGRA~2\SEARCH~1\Datamngr\datamngr.dll) - C: \Program Files (x86)\Searchqu Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C: \PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll) - C: \Program Files (x86)\Searchqu Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20: [b]64bit: [/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-07-12 21: 36: 44 | 000,000,000 | RHSD | M] - C: \Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012-07-12 21: 36: 44 | 000,000,000 | RHSD | M] - E: \Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-07-14 11: 29: 38 | 000,000,122 | R--- | M] () - F: \autorun.inf -- [ UDF ]
: Files
C: \Windows\pss
C: \Windows\symbols
C: \Autorun.inf
C: \Users\Rafal\j_quetry
C: \Users\Rafal\Desktop\zma
: Commands
[emptytemp]
[emptyflash]
[resethosts]
"Wykonaj skrypt".
Potem podaj raport z usuwania do wglądu.Pokaż też log "Extrass" który nie zmieściłeś.Przeskanuj jeszcze system programem " Malwaresbytes Anti-Malware" i jak coś znajdzie to usuń.Posprzątaj jeszcze system "SlimCleaner" lub "CCleaner".
(Ten post był ostatnio modyfikowany: 24.07.2012 03:18 przez Illidan.)
24.07.2012 03:16
|