Jump to content

Проблем със затваряне на браузъра при сваляне на антивирусни програми


Препоръчан пост

Здравеите ПЦ-то ми е заразено с вируси но когато се опитам да сваля антивирусна програма или нещо от сорта браузера ми се затваря автоматично. Опитах се да пусна ПЦ-то под сафе моде но уви и това не работе ... моля ако някои има идеи да помага.
Link to comment
Сподели другаде

Ако имаш антивирусна на диск или дискета си я инсталирай ако не форматирай твърдия диск.

Хайде да не прибързваме с крайните и необмислени съвети.

Link to comment
Сподели другаде

Изтегли OTL и го запази на работния плот:

- стартирай инструмента;

- постави отметка в горната част на Scan All Users;

- в поле Standard Registry избери All;

- от падащо меню File Age избери 90 Days;

- постави отметки още на: Skip Microsoft Files, LOP Check и Purity Check;

- в поле Custom Scans/Fixes (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V):

netsvcs
netsvcs
msconfig
safebootminimal
safebootnetwork
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
/md5start
hlp.dat
winlogon.exe
wininit.exe
userinit.exe
explorer.exe
volsnap.sys
/md5stop

- кликни бутон Run Scan;

Изчакай сканирането да приключи. След края на сканирането автоматично ще се отворят двата новосъздадени на работния плот файла: OTL.txt и Extras.txt.

 

Моля, прикачи тези два файла (поотделно или в архив) към следващия си коментар.

Link to comment
Сподели другаде

Стартирай отново OTL. В празното поле "Custom Scans/Fixes" (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V):

 

:Processes
killallprocesses
:OTL
MOD - [2011.12.30 18:41:44 | 000,630,784 | RHS- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Temp\jivphurhxqazsbfpih.exe
MOD - [2011.12.08 18:24:53 | 000,720,896 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Temp\uiktaco.exe
O4 - HKLM..\Run: [aykdugcrgyhfxfirj] C:\Documents and Settings\Administrator\Local Settings\Temp\tqbtjupdriqnelnv.exe ()
O4 - HKLM..\Run: [ogmzkqgpykn] C:\WINDOWS\System32\tqbtjupdriqnelnv.exe ()
O4 - HKU\S-1-5-21-1177238915-1078145449-839522115-500..\Run: [lgpftcvhtiojyd] C:\WINDOWS\System32\hixtncbtlgstozfrmnna.exe ()
O4 - HKU\S-1-5-21-1177238915-1078145449-839522115-500..\Run: [ogmzkqgpykn] C:\Documents and Settings\Administrator\Local Settings\Temp\hixtncbtlgstozfrmnna.exe ()
O4 - HKLM..\RunOnce: [lelzlsjtdqun] C:\WINDOWS\System32\hixtncbtlgstozfrmnna.exe ()
O4 - HKLM..\RunOnce: [tqbtjupdriqnelnv] C:\Documents and Settings\Administrator\Local Settings\Temp\tqbtjupdriqnelnv.exe ()
O4 - HKU\S-1-5-21-1177238915-1078145449-839522115-500..\RunOnce: [lelzlsjtdqun] C:\Documents and Settings\Administrator\Local Settings\Temp\jivphurhxqazsbfpih.exe ()
O4 - HKU\S-1-5-21-1177238915-1078145449-839522115-500..\RunOnce: [okulakereubxntu] C:\WINDOWS\System32\tqbtjupdriqnelnv.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: kembowozkydxl = uuidwkizqkvvpzepjji.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tkpblqfnvg = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wyolgwwpiertpbivrtuif.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1177238915-1078145449-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1
O7 - HKU\S-1-5-21-1177238915-1078145449-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1177238915-1078145449-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
1O32 - AutoRun File - [2011.12.31 11:50:24 | 000,000,822 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011.12.31 11:50:24 | 000,000,827 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011.12.31 11:50:25 | 000,000,831 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
[2011.12.31 14:28:26 | 000,000,316 | -H-- | M] () -- C:\Program Files\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\wyolgwwpiertpbivrtuif.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\uuidwkizqkvvpzepjji.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\tqbtjupdriqnelnv.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\nqhfbstnhesvsfnbybdsql.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\jivphurhxqazsbfpih.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\hixtncbtlgstozfrmnna.exe
[2011.12.31 14:28:18 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\aykdugcrgyhfxfirj.exe
[2011.12.31 14:28:01 | 000,002,384 | -H-- | M] () -- C:\WINDOWS\System32\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.31 14:28:01 | 000,002,384 | -H-- | M] () -- C:\WINDOWS\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.31 14:28:01 | 000,002,384 | -H-- | M] () -- C:\Program Files\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.31 14:28:01 | 000,002,384 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.31 14:28:01 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\ygcfgcihgibjldqjltauxxu.wea
[2011.12.31 14:28:01 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\System32\ygcfgcihgibjldqjltauxxu.wea
[2011.12.31 14:28:01 | 000,000,280 | -H-- | M] () -- C:\Program Files\ygcfgcihgibjldqjltauxxu.wea
[2011.12.31 14:28:01 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ygcfgcihgibjldqjltauxxu.wea
[2011.12.31 14:27:26 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\System32\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 14:27:26 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 14:27:26 | 000,000,316 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 11:50:24 | 000,000,822 | RHS- | M] () -- C:\autorun.inf
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\wyolgwwpiertpbivrtuif.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\uuidwkizqkvvpzepjji.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\tqbtjupdriqnelnv.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\nqhfbstnhesvsfnbybdsql.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\jivphurhxqazsbfpih.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\hixtncbtlgstozfrmnna.exe
[2011.12.31 11:49:42 | 000,630,784 | RHS- | M] () -- C:\WINDOWS\System32\aykdugcrgyhfxfirj.exe
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\WINDOWS\System32\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\WINDOWS\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\Program Files\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\System32\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\WINDOWS\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\Program Files\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.09 00:05:43 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2011.12.08 18:40:20 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\System32\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.08 18:40:20 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.08 18:40:20 | 000,000,316 | -H-- | C] () -- C:\Program Files\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.08 18:40:20 | 000,000,316 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.08 18:40:20 | 000,000,073 | -H-- | C] () -- C:\WINDOWS\System32\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | C] () -- C:\WINDOWS\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | C] () -- C:\Program Files\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:40:20 | 000,000,073 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.08 18:32:21 | 000,000,822 | RHS- | C] () -- C:\autorun.inf
[2011.12.08 18:32:11 | 000,002,372 | -H-- | C] () -- C:\WINDOWS\System32\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:32:11 | 000,002,372 | -H-- | C] () -- C:\WINDOWS\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:32:11 | 000,002,372 | -H-- | C] () -- C:\Program Files\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:32:11 | 000,002,372 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:25:01 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\System32\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | C] () -- C:\WINDOWS\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | C] () -- C:\Program Files\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,004,248 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.08 18:25:01 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\ygcfgcihgibjldqjltauxxu.wea
[2011.12.08 18:25:01 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\System32\ygcfgcihgibjldqjltauxxu.wea
[2011.12.08 18:25:01 | 000,000,280 | -H-- | C] () -- C:\Program Files\ygcfgcihgibjldqjltauxxu.wea
[2011.12.08 18:25:01 | 000,000,280 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ygcfgcihgibjldqjltauxxu.wea
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\wyolgwwpiertpbivrtuif.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\wyolgwwpiertpbivrtuif.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\uuidwkizqkvvpzepjji.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\uuidwkizqkvvpzepjji.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\tqbtjupdriqnelnv.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\tqbtjupdriqnelnv.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\nqhfbstnhesvsfnbybdsql.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\nqhfbstnhesvsfnbybdsql.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\jivphurhxqazsbfpih.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\jivphurhxqazsbfpih.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\hixtncbtlgstozfrmnna.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\hixtncbtlgstozfrmnna.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\System32\aykdugcrgyhfxfirj.exe
[2011.12.08 18:24:44 | 000,630,784 | RHS- | C] () -- C:\WINDOWS\aykdugcrgyhfxfirj.exe
[2009.04.09 10:04:14 | 000,630,784 | RHS- | M] () -- C:\aqufosgnu.bat
[2011.12.31 11:50:24 | 000,000,822 | RHS- | M] () -- C:\autorun.inf
[2009.07.15 11:17:36 | 000,630,784 | RHS- | M] () -- C:\kembowozkydxl.bat
[2009.04.20 08:18:44 | 000,630,784 | RHS- | M] () -- C:\ogmzkqgpykn.bat
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.31 14:28:26 | 000,000,316 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 14:28:28 | 000,002,384 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.31 14:28:28 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ygcfgcihgibjldqjltauxxu.wea
[2011.12.08 18:25:01 | 000,004,248 | -H-- | M] () -- C:\Program Files\lelzlsjtdqunadbfsldiwhptngnbnulvfs.pcf
[2011.12.31 14:28:26 | 000,000,316 | -H-- | M] () -- C:\Program Files\lgpftcvhtiojyddjytnukxhnjendratfrgmh.bbh
[2011.12.31 14:28:28 | 000,002,384 | -H-- | M] () -- C:\Program Files\ogmzkqgpyknfrtqtfxosfpwzskqdouktc.rjv
[2011.12.08 18:40:20 | 000,000,073 | -H-- | M] () -- C:\Program Files\okulakereubxntubrniqhvgnkgqhwganaqxtj.qxn
[2011.12.31 14:28:28 | 000,000,280 | -H-- | M] () -- C:\Program Files\ygcfgcihgibjldqjltauxxu.wea
:Files
C:\Documents and Settings\Administrator\Local Settings\Temp\uiktaco.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\jivphurhxqazsbfpih.exe
:Commands
[emptytemp]
[reboot]

Копирай текста точно както е в полето. Внимавай да не изтървеш началното двуеточие и всяка команда да е на отделен ред, както е в полето.

 

Кликни бутон Run Fix. Потвърди с OK на съобщението, че е нужен рестарт на системата.

 

След рестарта ще се появи текстов дневник/лог. Същият файл се намира в C:\_OTL\MovedFiles. Моля, прикачи го към следващия си коментар.

 

След това стартирай отново OTL, създай пресни дневници (както бях описал по-рано) и ги прикачи отново. Можеш да архивираш всичките файлове в един архив, а можеш и да ги прикачиш поотделно.

Link to comment
Сподели другаде

Правих всичко по стъпките ти обаче само накрая не разбрах за какви пресни дневници става въпрос?Как да ги направя ?

По същия начин по който поставях и тези текстове ли?

Link to comment
Сподели другаде

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Гост
Отговори на тази тема

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   Не можете да качите директно снимка. Качете или добавете изображението от линк (URL)

Loading...
×
×
  • Създай ново...