Ветеран
Консультант
Сообщения: 1544
Благодарности: 489
|
Профиль
|
Отправить PM
| Цитировать
- Запустите повторно OTL by OldTimer или OTL.com или OTL.scr.
Обратите внимание, что утилиты необходимо запускать от имени Администратора. По умолчанию в Windows XP так и есть. В Windows Vista и Windows 7 администратор понижен в правах по умолчанию, поэтому, не забудьте нажать правой кнопкой на программу, выбрать Запуск от имени Администратора, при необходимости укажите пароль администратора и нажмите "Да".
- В окно Custom Scans/Fixes скопируйте следующую информацию:
Код:
:processes
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B6 B6 52 01 B8 13 CC 01 [binary data]
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=a0366cfe000000000000000000000000&tlver=1.4.19.19&affID=17160
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B6 B6 52 01 B8 13 CC 01 [binary data]
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=a0366cfe000000000000000000000000&tlver=1.4.19.19&affID=17160
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B6 B6 52 01 B8 13 CC 01 [binary data]
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=gear&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=a0366cfe000000000000000000000000&tlver=1.4.19.19&affID=17160
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.http: "62.122.102.170"
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.http_port: 8080
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.no_proxies_on: "localhost, 127.0.0.1"
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.share_proxy_settings: false
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.socks: ""
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.socks_port: 0
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.ssl: ""
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.ssl_port: 0
FF - prefs.js..extensions.charles.settings.disabled.network.proxy.type: 0
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.http: "127.0.0.1"
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.http_port: 8888
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.no_proxies_on: ""
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.share_proxy_settings: false
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.socks: ""
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.socks_port: 0
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.ssl: "127.0.0.1"
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.ssl_port: 8888
FF - prefs.js..extensions.charles.settings.enabled.network.proxy.type: 1
FF - prefs.js..keyword.URL: "http://yandex.ru/yandsearch?stype=first&clid=188001&text="
FF - prefs.js..network.proxy.http: "62.122.102.170"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.type: 0
[2011.06.14 17:11:01 | 000,002,423 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.03.01 18:17:14 | 000,002,047 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.10\facemoodsTlbr.dll (facemoods.com)
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {00000004-002A-0000-3104-410443043404} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0346A430-3960-02BE-3800-00000CA44603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0346C978-3960-02BE-3800-000054C94603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0346CB6C-3960-02BE-3800-000048CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0346CB74-3960-02BE-1C00-000050CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0346CFAC-D034-0346-D0CE-4603E2080600} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0349A368-3960-038A-3800-000044A34903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0349C8B0-3960-038A-3800-00008CC84903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0349CA9C-3960-038A-3800-000078CA4903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\..\Toolbar\WebBrowser: (no name) - {0349CB64-CBEC-0349-88CA-490304CB4903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {00000004-002A-0000-3104-410443043404} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0346A430-3960-02BE-3800-00000CA44603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0346C978-3960-02BE-3800-000054C94603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0346CB6C-3960-02BE-3800-000048CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0346CB74-3960-02BE-1C00-000050CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0346CFAC-D034-0346-D0CE-4603E2080600} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0349A368-3960-038A-3800-000044A34903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0349C8B0-3960-038A-3800-00008CC84903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0349CA9C-3960-038A-3800-000078CA4903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1003\..\Toolbar\WebBrowser: (no name) - {0349CB64-CBEC-0349-88CA-490304CB4903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {00000004-002A-0000-3104-410443043404} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0346A430-3960-02BE-3800-00000CA44603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0346C978-3960-02BE-3800-000054C94603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0346CB6C-3960-02BE-3800-000048CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0346CB74-3960-02BE-1C00-000050CB4603} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0346CFAC-D034-0346-D0CE-4603E2080600} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0349A368-3960-038A-3800-000044A34903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0349C8B0-3960-038A-3800-00008CC84903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0349CA9C-3960-038A-3800-000078CA4903} - No CLSID value found.
O3 - HKU\S-1-5-21-1973410950-3332720337-4240644562-500\..\Toolbar\WebBrowser: (no name) - {0349CB64-CBEC-0349-88CA-490304CB4903} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4EDAE4A5-0194-4919-B46A-A62AE9BCB1F0}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{905C92D3-310C-4E82-8390-E9A2980F9240}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E065AA5C-59D1-4D17-A308-563B58D1EEAB}: NameServer = 127.0.0.1
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\...com [@ = comfile] -- Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-1973410950-3332720337-4240644562-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found
[2011.05.18 19:28:49 | 000,000,138 | ---- | C] () -- C:\Windows\SysWow64\operaprefs_fixed.ini
[2011.10.25 16:36:16 | 000,002,256 | ---- | M] () -- C:\ProgramData\cf
[2011.05.18 13:55:30 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2012.02.10 23:37:16 | 000,004,998 | ---- | M] () -- C:\ProgramData\mtbjfghn.xbe
@Alternate Data Stream - 242 bytes -> C:\ProgramData\TEMP:10D14739
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:41ADDB8A
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:A064CECC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:1C422577
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A914DABB
:Services
:Files
autorun.inf /alldrives
recycler /alldrives
ipconfig /flushdns /c
:Reg
[-HKEY_CLASSES_ROOT\.exe]
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"
[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"FriendlyTypeName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,\
00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,\
32,00,5c,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
00,2c,00,2d,00,31,00,30,00,31,00,35,00,36,00,00,00
[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"
[HKEY_CLASSES_ROOT\exefile\shell]
[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile\shell\runas]
"HasLUAShield"=""
[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile\shell\runasuser]
@="@shell32.dll,-50944"
"Extended"=""
"SuppressionPolicyEx"="{F211AA05-D4DF-4370-A2A0-9F19C09756A7}"
[HKEY_CLASSES_ROOT\exefile\shell\runasuser\command]
"DelegateExecute"="{ea72d00e-4960-42fa-ba92-7792a7944c1d}"
[HKEY_CLASSES_ROOT\exefile\shellex]
[HKEY_CLASSES_ROOT\exefile\shellex\ContextMenuHandlers]
@="Compatibility"
[HKEY_CLASSES_ROOT\exefile\shellex\ContextMenuHandlers\Compatibility]
@="{1d27f844-3a1f-4410-85ac-14651078412d}"
[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"
[-HKEY_CLASSES_ROOT\SystemFileAssociations\.exe]
[HKEY_CLASSES_ROOT\SystemFileAssociations\.exe]
"FullDetails"="prop:System.PropGroup.Description;System.FileDescription;System.ItemTypeText;System.FileVersion;System.Software.ProductName;System.Software.ProductVersion;System.Copyright;*System.Category;*System.Comment;System.Size;System.DateModified;System.Language;*System.Trademarks;*System.OriginalFileName"
"InfoTip"="prop:System.FileDescription;System.Company;System.FileVersion;System.DateCreated;System.Size"
"TileInfo"="prop:System.FileDescription;System.Company;System.FileVersion;System.DateCreated;System.Size"
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithList]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids]
"exefile"=hex(0):
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
@="exefile"
"Content Type"="application/x-msdownload"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
[-HKEY_CLASSES_ROOT\.com]
[HKEY_CLASSES_ROOT\.com]
@="comfile"
[HKEY_CLASSES_ROOT\.com\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
[-HKEY_CLASSES_ROOT\comfile]
[HKEY_CLASSES_ROOT\comfile]
@="MS-DOS Application"
"EditFlags"=hex:30,00,00,00
"FriendlyTypeName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,\
00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,\
32,00,5c,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
00,2c,00,2d,00,38,00,34,00,36,00,34,00,00,00
[HKEY_CLASSES_ROOT\comfile\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,68,00,\
65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,00,32,00,00,00
[HKEY_CLASSES_ROOT\comfile\shell]
[HKEY_CLASSES_ROOT\comfile\shell\open]
"EditFlags"=dword:00000000
[HKEY_CLASSES_ROOT\comfile\shell\open\command]
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\comfile\shellex]
[HKEY_CLASSES_ROOT\comfile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"
[-HKEY_CLASSES_ROOT\SystemFileAssociations\.com]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com]
[-HKEY_CLASSES_ROOT\.scr]
[HKEY_CLASSES_ROOT\.scr]
@="scrfile"
[-HKEY_CLASSES_ROOT\scrfile]
[HKEY_CLASSES_ROOT\scrfile]
@="Screen saver"
"FriendlyTypeName"="@shell32,-10162"
[HKEY_CLASSES_ROOT\scrfile\shell]
[HKEY_CLASSES_ROOT\scrfile\shell\config]
@="C&onfigure"
"MUIVerb"="@shell32.dll,-10209"
[HKEY_CLASSES_ROOT\scrfile\shell\config\command]
@="\"%1\""
[HKEY_CLASSES_ROOT\scrfile\shell\install]
@="&Install"
"MUIVerb"="@shell32.dll,-10210"
[HKEY_CLASSES_ROOT\scrfile\shell\install\command]
@="rundll32.exe desk.cpl,InstallScreenSaver %l"
[HKEY_CLASSES_ROOT\scrfile\shell\open]
@="T&est"
[HKEY_CLASSES_ROOT\scrfile\shell\open\command]
@="\"%1\" /S"
[HKEY_CLASSES_ROOT\scrfile\shellex]
[HKEY_CLASSES_ROOT\scrfile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"
[-HKEY_CLASSES_ROOT\SystemFileAssociations\.scr]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scr]
:Commands
[EMPTYJAVA]
[EMPTYFLASH]
[EMPTYTEMP]
[RESETHOSTS]
[purity]
[start explorer]
[Reboot]
- Проверьте, что весь текст скрипта был скопирован / вставлен верно и нажмите кнопку "Run Fix"
- Компьютер перезагрузится.
- После перезагрузки откройте папку "C:\_OTL\MovedFiles", найдите последний .log файл (лог в формате mmddyyyy_hhmmss.log), откройте и скопируйте текст из него в следующее сообщение.
|