Stránka 3 z 3
Re: Facebook vir - s RSIT logem
Napsal: 25 srp 2011 09:20
od vyosek

Spustte znovu
OTL
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
:otl
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-4185333999-712101943-672219948-1006\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\FUri\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\FUri\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O9 - Extra Button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not found
O15 - HKU\S-1-5-21-4185333999-712101943-672219948-1006\..Trusted Domains: localhost ([]http in Místní intranet)
O15 - HKU\S-1-5-21-4185333999-712101943-672219948-1006\..Trusted Ranges: GD ([http] in Místní intranet)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O33 - MountPoints2\{1eef95d6-bc1a-11df-9a95-0024d24a88cc}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk /r \??\F:) - File not found
[21 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[3 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[28 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\*.tmp files -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\*.tmp -> ]
[3 C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp files -> C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\aa6a9ee01709b9c392afb705bba73f9d\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\aa6a9ee01709b9c392afb705bba73f9d\*.tmp -> ]
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[33 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDWMon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
:files
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4185333999-712101943-672219948-1006.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4185333999-712101943-672219948-1006.job
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
- Nasledne kliknete na Opravit
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Facebook vir - s RSIT logem
Napsal: 25 srp 2011 10:15
od furij
All processes killed
========== OTL ==========
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-4185333999-712101943-672219948-1006\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-4185333999-712101943-672219948-1006\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
C:\Documents and Settings\FUri\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ not found.
File C:\Documents and Settings\FUri\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{76577871-04EC-495E-A12B-91F7C3600AFA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found.
Registry key HKEY_USERS\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-4185333999-712101943-672219948-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1eef95d6-bc1a-11df-9a95-0024d24a88cc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1eef95d6-bc1a-11df-9a95-0024d24a88cc}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk /r \??\F: deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1265.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP135.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP23.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP27D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DC.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP418.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP515F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5DE.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7C.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP87F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP959.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPB1.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCE.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD28.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD6B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFE.tmp folder deleted successfully.
C:\WINDOWS\Installer\MSI117.tmp deleted successfully.
C:\WINDOWS\Installer\MSI12E.tmp deleted successfully.
C:\WINDOWS\Installer\MSI4FD.tmp deleted successfully.
C:\WINDOWS\Installer\MSIBF.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF10.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF11.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF12.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF14.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF15.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF16.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF17.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF18.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF19.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF21.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF22.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF24.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF25.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF4C.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF4D.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF4F.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF50.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF5F.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF60.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF62.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF63.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF8C.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF8D.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF92.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSF93.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSFD.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSFE.tmp deleted successfully.
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\WSFF.tmp deleted successfully.
C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\wlt1E5.tmp deleted successfully.
C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\wlt3C.tmp deleted successfully.
C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\wlt44.tmp deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
C:\WINDOWS\system32\SET557.tmp deleted successfully.
C:\WINDOWS\system32\SET55C.tmp deleted successfully.
C:\WINDOWS\Temp\HxC1.tmp deleted successfully.
C:\WINDOWS\twain_32\hpqgnds2.tmp deleted successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray\ deleted successfully.
========== FILES ==========
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4185333999-712101943-672219948-1006.job moved successfully.
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4185333999-712101943-672219948-1006.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 32292 bytes
->Temporary Internet Files folder emptied: 49286 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes
User: FUri
->Temp folder emptied: 7342423 bytes
->Temporary Internet Files folder emptied: 1626696 bytes
->Java cache emptied: 308460 bytes
->FireFox cache emptied: 52560353 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 530 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 214403 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 126645 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 65728130 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 122,00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: FUri
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.26.5 log created on 08252011_111050
Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!
Registry entries deleted on Reboot...
Re: Facebook vir - s RSIT logem
Napsal: 25 srp 2011 10:22
od vyosek
Re: Facebook vir - s RSIT logem
Napsal: 25 srp 2011 11:28
od furij
Děkuji za ochotu a podporu, vypadá to vše v pořádku a funkční

Vaše práce má opravdu moje uznání.
Re: Facebook vir - s RSIT logem
Napsal: 25 srp 2011 11:35
od vyosek
Dekuji za uznani
Jinak nemate zac, rado se stalo
