Komputer został zablokowany z powodu naruszenia prawa polski
#1
Witam!
Na pulpicie laptopa kolezanki, wyświetliła się nakładka z godłem Polski i komunikatem w nagłówku: "Komputer został zablokowany z powodu naruszenia prawa polskiego".
Prosze o pomoc w usunieciu tego problemu.

[attachment=0] <!-- ia0 -->OTL.rar<!-- ia0 -->[/attachment]
Prosze o skrypt usuwajacy to malware.

Za pomoc z gory serdecznie dziekuje.
Pozdrawiam


Załączone pliki
.rar   OTL.rar (Rozmiar: 12,5 KB / Pobrań: 11)
Odpowiedz
#2
Witam w własne opcje skanowania skrypt wklej,po wykonaniu pokaż raport.
Brak raportu z Extras

Kod:
:OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=110824&tt=031012_ccp_4012_2&babsrc=HP_ss&mntrId=74db51370000000000003859f9385312
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=HJxdm007YYpl&ptb=381AF90F-A119-4213-B449-224E4BDF3D25&si=CIuu4MHj5bICFaTKtAodOXcA3g
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110824&tt=031012_ccp_4012_2&babsrc=SP_ss&mntrId=74db51370000000000003859f9385312
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=YYYYYYYYPL&apn_uid=6F411EA3-AE0D-4076-94CC-4CA2C4264AFD&apn_sauid=B244DF5A-B5E1-4D36-B99B-1A33810761E9
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKCU\..\SearchScopes\{FEE0DD82-0CF0-4100-A158-6F5A5ED34F71}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=YYYYYYYYPL&apn_uid=6F411EA3-AE0D-4076-94CC-4CA2C4264AFD&apn_sauid=B244DF5A-B5E1-4D36-B99B-1A33810761E9
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
[2012-10-03 22:12:20 | 000,002,360 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.0.7\BabylonToolbarTlbr.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h File not found
[2012-10-03 23:19:03 | 000,002,030 | ---- | M] () -- C:\Users\mediaexpert\Desktop\Continue SweetIM Installation.lnk
[2012-10-03 23:15:28 | 000,002,030 | ---- | C] () -- C:\Users\mediaexpert\Desktop\Continue SweetIM Installation.lnk
[2012-07-07 20:15:28 | 000,000,000 | ---D | M] -- C:\Users\mediaexpert\AppData\Roaming\Babylon
[2012-10-03 21:21:01 | 000,000,000 | ---D | C] -- C:\Users\mediaexpert\AppData\Roaming\hellomoto
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O4 - HKLM..\Run: []File not found
O4 - HKLM..\Run: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23762~1.17\{16cdf~1\browse~1.dll) -File not found

:Commands
[EMPTYTEMP]
Odpowiedz


Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości