Ok takže postupně udělej toto:
Stáhni si Avengera spusť ho pod účtem administrátora.
Zvol možnost - Input script manually a klikni na ikonku lupy vyskočí prázdné okno kam zkopíruj celý tento tučný text:
Files to delete:
C:\WINDOWS\System32\wmpuurlm.exe
C:\WINDOWS\svcsr.exe
C:\WINDOWS\system32\wmpuurlm.dll
Registry keys to delete:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmpuurlm
Registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | svcsr.exe
Poté klikni na Done.
Pak klikni na ikonku semafory.
Vyskočí ti hláška kde odklikni Yes. PC se restartuje po restartu by ti měl "vyskočit" výpis z Avengeru tak ho sem zkopíruj.
Pak odinstaluj jeden antivir jak už bylo zmíněno a nechej si tam jen jeden z nich buď Nod nebo Avast.
Vypni v nastavení Spyware Terminátora ClamAntivirus.
Pak sem dej nový log z HJT.
prosim o kontrolu logu dekuji
a
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\kmuyvaky
*******************
Script file located at: \??\C:\byounowm.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\System32\wmpuurlm.exe deleted successfully.
File C:\WINDOWS\svcsr.exe deleted successfully.
File C:\WINDOWS\system32\wmpuurlm.dll deleted successfully.
Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmpuurlm deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|svcsr.exe deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\kmuyvaky
*******************
Script file located at: \??\C:\byounowm.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\System32\wmpuurlm.exe deleted successfully.
File C:\WINDOWS\svcsr.exe deleted successfully.
File C:\WINDOWS\system32\wmpuurlm.dll deleted successfully.
Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmpuurlm deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|svcsr.exe deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
hezky
Zpět na “Viry, antiviry, firewally…”
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 7 hostů