Stránka 2 z 2
Re: vir z facebooku ověření, že se podařilo odstranit
Napsal: 31 led 2013 14:58
od vyosek

Stahnete
OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=-
:files
c:\users\Andrejka a Tomáš\AppData\Roaming\nMNtfaARw2l97e30p5ev.exe
c:\users\Andrejka a Tomáš\AppData\Roaming\winsvcns.sys
c:\users\Andrejka a Tomáš\6438640620394286720310355
c:\users\Andrejka a Tomáš\AppData\Roaming\*.exe
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[EMPTYJAVA]
- Nasledne kliknete na Opravit
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: vir z facebooku ověření, že se podařilo odstranit
Napsal: 31 led 2013 17:18
od Wajda77
All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
========== FILES ==========
c:\users\Andrejka a Tomáš\AppData\Roaming\nMNtfaARw2l97e30p5ev.exe moved successfully.
c:\users\Andrejka a Tomáš\AppData\Roaming\winsvcns.sys moved successfully.
c:\users\Andrejka a Tomáš\6438640620394286720310355 folder moved successfully.
File\Folder c:\users\Andrejka a Tomáš\AppData\Roaming\*.exe not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
[EMPTYTEMP]
User: All Users
User: Andrejka
->Temp folder emptied: 0 bytes
User: Andrejka a Tomáš
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 516725 bytes
->Java cache emptied: 1040230 bytes
->FireFox cache emptied: 5826941 bytes
->Google Chrome cache emptied: 342936676 bytes
->Flash cache emptied: 850 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 120056 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 334,00 mb
[EMPTYFLASH]
User: All Users
User: Andrejka
User: Andrejka a Tomáš
->Flash cache emptied: 0 bytes
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0,00 mb
[EMPTYJAVA]
User: All Users
User: Andrejka
User: Andrejka a Tomáš
->Java cache emptied: 0 bytes
User: Default
User: Default User
User: Public
Total Java Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 01312013_171319
Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Andrejka a Tomáš\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Re: vir z facebooku ověření, že se podařilo odstranit
Napsal: 31 led 2013 20:41
od vyosek
Re: vir z facebooku ověření, že se podařilo odstranit
Napsal: 31 led 2013 21:06
od Wajda77
Tak mockrát děkuju. Ccleaner používám pravidelně. Dám sem ještě log ženina stroje jako preventivku. Založím nové vlákno. Tady můžeme zamykat. ještě jednou díky.
Re: vir z facebooku ověření, že se podařilo odstranit
Napsal: 31 led 2013 21:08
od vyosek
Nemate zac, rad jsem pomohl

Zase nekdy
A na zaklade Pravidla o zamykani temat