Re: Facebook vir, prosím o pomoc. Jde o zmíněný nový vir
Napsal: 25 črc 2011 22:50
Jste se do toho nejak zamotala, vlozte ten novy skript, dam vam ho sem znovu a kliknete na Opravit
Kód: Vybrat vše
:otl
SRV - [2011.07.25 16:16:37 | 000,256,000 | ---- | M] () [Auto | Running] -- C:\Windows\sysdriver32.exe -- (srvsysdriver32)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ppcb&s={searchTerms}&f=4
IE - HKU\S-1-5-21-134749277-38998122-1694357166-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=TSEH
IE - HKU\S-1-5-21-134749277-38998122-1694357166-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-134749277-38998122-1694357166-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ppcb
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.3.0244
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.2.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..keyword.URL: "http://start.facemoods.com/results.php?f=5&a=ppcb&q="
[2011.05.09 08:07:07 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Terez\AppData\Roaming\Mozilla\Firefox\Profiles\o11wdm2r.default\extensions\DTToolbar@toolbarnet.com
[2010.11.30 15:54:45 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\Terez\AppData\Roaming\Mozilla\Firefox\Profiles\o11wdm2r.default\extensions\ffxtlbr@Facemoods.com
[2010.07.13 16:02:02 | 000,002,059 | ---- | M] () -- C:\Users\Terez\AppData\Roaming\Mozilla\Firefox\Profiles\o11wdm2r.default\searchplugins\daemon-search.xml
[2010.10.26 17:57:38 | 000,002,036 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchppcb.xml
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [18057473-loader2.exe] File not found
O4 - HKLM..\Run: [4759496.exe] C:\Windows\Temp\4759496.exe ()
O4 - HKLM..\Run: [63009422-loader2.exe] C:\Users\Terez\AppData\Local\Temp\63009422-loader2.exe ()
O4 - HKLM..\Run: [836238.exe] C:\Users\Terez\AppData\Local\Temp\836238.exe ()
O4 - HKLM..\Run: [8559526.exe] C:\Users\Terez\AppData\Local\Temp\8559526.exe ()
O4 - HKLM..\Run: [8747021.exe] File not found
O4 - HKLM..\Run: [89562825-loader2.exe] File not found
O4 - HKLM..\Run: [9144587.exe] C:\Users\Terez\AppData\Local\Temp\9144587.exe ()
O4 - HKLM..\Run: [9546946.exe] C:\Windows\TEMP\9546946.exe ()
O4 - HKLM..\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe ()
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico1] C:\Windows\update.tray-15-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKLM..\Run: [WinampAgent] File not found
O4 - HKLM..\Run: [wxpdrv] C:\Windows\services32.exe ()
O4 - HKU\S-1-5-21-134749277-38998122-1694357166-1000..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O31 - SafeBoot: AlternateShell - services32.exe
[2011.07.20 16:22:39 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0-lnk
[2011.07.20 16:22:39 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0
[2011.07.20 16:20:39 | 000,000,000 | ---D | C] -- C:\Windows\ufa
[2011.07.20 16:20:39 | 000,000,000 | ---D | C] -- C:\Windows\rpcminer
[2011.07.20 16:20:39 | 000,000,000 | ---D | C] -- C:\Windows\phoenix
[2011.07.20 16:20:24 | 000,000,000 | -H-D | C] -- C:\Windows\update.2
[2011.07.20 16:19:53 | 000,000,000 | -H-D | C] -- C:\Windows\update.5.0
[2011.07.20 16:11:12 | 000,000,000 | ---D | C] -- C:\Windows\av_ico
[2011.07.20 16:09:04 | 000,000,000 | -H-D | C] -- C:\Windows\update.1
[2011.07.20 16:09:01 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-7-0-lnk
[2011.07.20 16:09:01 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-7-0
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Terez\Desktop\*.tmp files -> C:\Users\Terez\Desktop\*.tmp -> ]
[2011.07.25 16:16:37 | 000,256,000 | ---- | M] () -- C:\Windows\sysdriver32_.exe
[2011.07.25 16:16:37 | 000,256,000 | ---- | M] () -- C:\Windows\sysdriver32.exe
[2011.07.24 18:56:58 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
[2011.07.20 16:25:03 | 000,000,000 | ---- | M] () -- C:\Windows\loader2.exe_ok
[2011.07.20 16:21:08 | 000,114,176 | ---- | M] () -- C:\Windows\systemup.exe
[2011.07.20 16:20:38 | 005,589,370 | ---- | M] () -- C:\Windows\phoenix.rar
[2011.07.20 16:20:38 | 001,075,284 | ---- | M] () -- C:\Windows\rpcminer.rar
[2011.07.20 16:20:38 | 000,246,272 | ---- | M] () -- C:\Windows\unrar.exe
[2011.07.20 16:20:38 | 000,182,617 | ---- | M] () -- C:\Windows\ufa.rar
[2011.07.20 16:20:21 | 000,904,792 | ---- | M] () -- C:\Windows\geoiplist.rar
[2011.07.20 15:57:03 | 001,147,392 | ---- | M] () -- C:\Windows\services32.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[9 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[5 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\f1eb035a88c96e55f04cb025e02ae297\*.tmp files -> C:\Windows\SoftwareDistribution\Download\f1eb035a88c96e55f04cb025e02ae297\*.tmp -> ]
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=-
"NokiaMServer"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"QuickTime Task"=-
"iTunesHelper"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
"DAEMON Tools Lite"=-
""=-
"NokiaOviSuite2"=-
:files
C:\Windows\update.tray-7-0
C:\Windows\update.tray-15-0
C:\Windows\update.2
C:\Program Files (x86)\DAEMON Tools Toolbar
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]