Usuwanie wirusów

NoLop

Małe narzędzie do usuwania Adware Lop:

 

A tak wygląda log z tego programiku (znajdziecie go C:\NoLop.log

NoLop! Log by Skate_Punk_21

Fix running from: F:\Documents and Settings\Matt\Desktop
[1/5/2007]
[7:15:45 AM]

---Infection Files Found/Removed---
F:\WINDOWS\tasks\B9ADB0FE817A25FA.job

Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**

---Listing AppData sub directories---

F:\Documents and Settings\Matt\Application Data\Logitech
F:\Documents and Settings\Matt\Application Data\Macromedia
F:\Documents and Settings\Matt\Application Data\Mechsoft
F:\Documents and Settings\Matt\Application Data\Media Player Classic
F:\Documents and Settings\Matt\Application Data\Microsoft
F:\Documents and Settings\Matt\Application Data\Mozilla
F:\Documents and Settings\Matt\Application Data\Opera -- EMPTY Directory
F:\Documents and Settings\Matt\Application Data\Publish Providers -- EMPTY Directory
F:\Documents and Settings\Matt\Application Data\Rapidget
F:\Documents and Settings\Matt\Application Data\Real
F:\Documents and Settings\Matt\Application Data\Roxio
F:\Documents and Settings\Matt\Application Data\Smartftp
F:\Documents and Settings\Matt\Application Data\Sony
F:\Documents and Settings\Matt\Application Data\Ssh
F:\Documents and Settings\Matt\Application Data\Sun
F:\Documents and Settings\Matt\Application Data\Talkback
F:\Documents and Settings\Matt\Application Data\Thunderbird
F:\Documents and Settings\Matt\Application Data\Winamp
F:\Documents and Settings\Networkservice\Application Data\Microsoft

Uwaga: jesli otrzymujesz błąd  mscomctl.ocx albo podobna zależnosc -brakuje ci bilblioteki albo jest źle zainstalowana. Sciagnij ten pli :mscomctl.ocxdo folderu system32 i uruchom program.


Deljob.exe

Kolejny programik pomocny w walce z Lopem.Log wygląda tak:

BACKUPS CREATED in C:\DELJOB

B7FE6CA99F71E22D.job
--------------------------------------------------------
FILES IN TASKS FOLDER

AppleSoftwareUpdate.job
--------------------------------------------------------
EXPORT APP DATA FOLDERS
--------------------------------------------------------
Volume in drive C has no label.
Volume Serial Number is 9843-030B

Directory of C:\Documents and Settings\Owner\Application Data

30/11/2006 00:37 <DIR> Adobe
10/10/2006 19:13 869 AdobeDLM.log
10/10/2006 19:14 <DIR> AdobeUM
19/10/2006 14:28 <DIR> APPLEC~1 Apple Computer
21/09/2006 00:00 <DIR> ATI
02/02/2007 01:50 <DIR> AVG7
30/11/2006 15:41 <DIR> Azureus
18/09/2006 00:13 <DIR> DATARE~1 Datarescue
10/10/2006 19:13 0 dm.ini
16/01/2007 21:26 <DIR> Help
01/01/2003 17:47 <DIR> IDENTI~1 Identities
24/12/2006 14:35 <DIR> KNOBBO~1 Knob Bows Type
14/08/2006 14:26 <DIR> Lavasoft
21/09/2006 18:39 <DIR> LEADER~1 Leadertech
04/11/2006 19:30 <DIR> MACROM~1 Macromedia
14/08/2006 14:30 <DIR> Mozilla
21/01/2007 07:22 <DIR> MySpace
08/11/2006 16:41 <DIR> NOTEPA~1 Notepad++
27/01/2007 16:51 <DIR> PPLive
06/12/2006 19:49 <DIR> Real
03/11/2006 15:18 <DIR> SmartFTP
22/10/2006 22:34 <DIR> SPORTS~1 Sports Interactive
17/09/2006 19:35 <DIR> Sun
20/09/2006 16:30 <DIR> SYSTEM~1 System Requirements Lab
03/11/2006 03:41 <DIR> TEAMSP~1 teamspeak2
02/02/2007 03:46 <DIR> uTorrent
30/11/2006 20:01 <DIR> Webroot
19/12/2006 17:54 <DIR> WNR
26/01/2007 05:50 <DIR> Xfire
2 File(s) 869 bytes
27 Dir(s) 197,193,113,600 bytes free
Volume in drive C has no label.
Volume Serial Number is 9843-030B

Directory of C:\Documents and Settings\All Users\Application Data

10/10/2006 19:13 <DIR> Adobe
19/10/2006 14:28 <DIR> APPLEC~1 Apple Computer
16/01/2007 19:28 <DIR> avg7
05/11/2006 23:56 <DIR> Creative
16/01/2007 19:28 <DIR> Grisoft
22/12/2006 23:55 <DIR> Logitech
04/11/2006 19:29 <DIR> MACROM~1 Macromedia
29/01/2007 19:07 <DIR> MICROS~2 Microsoft Corporation
02/02/2007 06:48 <DIR> SPYBOT~1 Spybot - Search & Destroy
29/11/2006 19:49 <DIR> SURFON~1 surf once team gram
15/08/2006 13:54 <DIR> WINDOW~1 Windows Genuine Advantage
23/12/2006 01:16 <DIR> yahoo!
0 File(s) 0 bytes
12 Dir(s) 197,193,113,600 bytes free


FindLop

...i co tu pisać..ściągacie ,rozpakowujecie,klikacie na findlop.bat i ....otrzymacie loga na C:\findlop.txt ...

[TRACE] Enumerating jobs and queues
[TRACE] Activating job '1-Click Maintenance.job'
[TRACE] Printing all job properties

ApplicationName: 'C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe'
Parameters: '/schedulestart'
WorkingDirectory: ''
Comment: 'Runs 1-Click Maintenance at specified times'
Creator: 'TheEye'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 10/06/2006 17:15:00
NextRun: 10/27/2006 17:15:00
StartError: S_OK
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 0
TaskFlags: 0

[TRACE] Activating job 'A7161E4E91718F26.job'
[TRACE] Printing all job properties

ApplicationName: 'c:\docume~1\theeye\applic~1\adminv~1\Rulecomplink.exe'
Parameters: ''
WorkingDirectory: ''
Comment: ''
Creator: 'TheEye'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 10/26/2006 14:00:00
NextRun: 10/27/2006 0:00:00
StartError: S_OK
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 1
TaskFlags: 0


Usuwanie wirusów

Valid HTML 4.01 Transitional