• Ogłoszenie:

Samoczynnie wyskakujące reklamy

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Samoczynnie wyskakujące reklamy

Postprzez tonis38 27 Paź 2018, 21:15

reklama
Witam.

Na komputerze kuzyna po jakimś czasie pracy samoczynnie wyskakują okienka Google Chrome z reklamami. Gdy to się dzieje nie jest w stanie np. uruchomić skanowania w Malwarebytes (aplikacja po włączeniu skanu zawiesza się).
Ponadto w przeglądarce instaluja się samodzielnie rozszerzenia ScriptMonkey i Tampermonkey. Po ich usunięciu wszystko wraca do normy, po czym z powrotem jest to samo.

Z góry dziękuję za pomoc.
Załączniki
Shortcut.txt
(40.87 KiB) Ściągnięto 136 razy
Addition.txt
(62.62 KiB) Ściągnięto 131 razy
FRST.txt
(63.41 KiB) Ściągnięto 128 razy
tonis38
~user
 
Posty: 64
Dołączenie: 28 Kwi 2008, 16:51



Samoczynnie wyskakujące reklamy

Postprzez ordynat 27 Paź 2018, 22:52

Uruchom FRST. Na klawiaturze naciśnij jednocześnie CTRL+Y.Otworzy się Notatnik - wklej do niego:
Task: {5052B1C7-D7EC-4BAF-99A3-4D661B20812F} - System32\Tasks\{DCD092BE-2CC7-9C27-D63B-6C14B38D06DD} => C:\Program Files (x86)\Common Files\EloOrnIbqIOM.exe [2018-04-12] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\EloOrnIbqIOM.exe
Task: {8C270537-8532-4FF5-B9D8-319B58C383FB} - System32\Tasks\{0E02F32F-9F07-88FD-EF15-394BB1532155} => C:\Users\Kacper\AppData\Local\bPdHyxRy.exe [2018-04-12] (Microsoft Corporation) <==== ATTENTION
C:\Users\Kacper\AppData\Local\bPdHyxRy.exe
Task: {AC568CD5-F36E-483D-BE20-0F917C8A1DD0} - System32\Tasks\{FFB40A50-6AAE-1807-3835-74C7502C04E4} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://7runews.com/cl/?guid=aik594ckbkdeddph8qa3tz32zj83tgru&prid=1&pid=5_1301_38845
Task: {C0722744-341E-443E-97C7-43A017380FEF} - System32\Tasks\{38EF675E-362D-883A-6922-C3FFE12C11E7} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://bl0ging.com/cl/?guid=e37rcm2gxlnezf6623c2lxcaiasy6x3b&prid=1&pid=5_1301_163305
FirewallRules: [{ADB488FE-20F1-48BC-87B0-C6E661A4855E}] => (Allow) C:\WINDOWS\SysWOW64\msiexec.exe
FirewallRules: [{0A08072E-4ED1-45D0-8FA7-CB02F5501151}] => (Allow) C:\Users\Kacper\AppData\Local\bPdHyxRy.exe
FirewallRules: [{501B752E-4080-449A-B56B-C1CA4DC0B961}] => (Allow) C:\Program Files (x86)\Common Files\EloOrnIbqIOM.exe
FirewallRules: [{69BA441B-0B0C-4DC2-8A9D-1A0FACD3320B}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{27EE4B18-5971-4C84-A4F8-8B664C08C1DA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{A1DD425A-1AC7-446A-A13B-5CACF3C65DD7}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4299C6FA-6F63-4E71-ABB5-26AB415978FB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4924F362-297A-4E67-89C3-B6C85BAC9684}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{86F6E87A-0027-42D6-9263-A1610BD73D1D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{C0CE15B2-F02C-4648-BB2C-378D0FDB0BB1}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe
FirewallRules: [{B601FE72-5F79-4FF5-BA53-B72B5A5BAAEA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F913EEDA-A8E0-4A4C-A43B-DE525F28BCF0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F65A869B-BF5E-4CC0-A18F-C48D73A8E0D1}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{24CE6006-49D1-4313-9B51-C6242239FA59}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe
FirewallRules: [{FC85494F-7E66-485D-B95C-A0DEA1FD413F}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{707DCD39-0252-44EE-AA97-9BB8EAD3B1DA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{675B7800-21CC-4CE0-BD90-9A8863FFB063}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe
FirewallRules: [{552E4B7A-DF87-4FB2-B1AA-DABD035BF599}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D0EC5D1E-A9A7-43D5-BABA-BA11281CE5E9}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe
FirewallRules: [{777B633D-BC26-40F3-B5A4-99B03D78A1A4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{51E8A12D-6D1F-4F76-BBD7-50F7F689D7D3}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{832BA84C-B403-4BC1-8343-BFF2106E1F1B}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{33883BFE-09A0-481C-8A02-D76CB73035A4}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe
FirewallRules: [{9D165198-C21D-4D64-8D54-8018D5C38EC8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D6EBC063-95EC-4EF2-9047-3DD49AC114F7}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F529F38B-2893-4EDE-84A3-F6EC5EF2E51A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{986A2B1B-A6D3-4972-AEA5-1F715C596CFC}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D257832C-C5BC-47F9-9317-F8D1FD7E0260}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{1D647995-56C2-4E42-AB24-595776E7EB56}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{EDE9C614-5FB3-4407-B509-CB330011E220}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{2263F3C8-C57E-4212-8A0B-FB8EADB20153}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{95F23769-2C1B-4FD9-B0F8-463F2C2C30BF}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{3905D3D3-3767-4E57-90C6-0B863CF1A8D1}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{305866CE-CFC4-43AE-8B9D-FD097191F2EB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FC5AF2E1-3E12-4F2D-9C4C-1A798CAE6E1E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{93D05E1A-004F-449A-A3AC-81D380866909}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F78F3DCF-D1AC-4C00-B8DA-2D4F223227B3}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{A2515ED8-807B-4EA4-A864-13045F12943A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F08EBA83-CC89-4699-A534-17AA7A704541}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{8215414C-92FC-4C02-90BC-D608016FA822}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D331168C-ABF1-4A80-9ECB-ABEE649B75BC}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{7830FDDD-D1E9-4FDF-9928-906B1AD3C019}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{ADE1B5BF-41E5-4456-9626-6EDCE30575B0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{0FA3BFBC-3B21-47B3-AAFC-41D2539F94D4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4810D5AA-7872-40BF-8349-136BE52E7AD3}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F1EB78F8-DFAA-4DA0-B65A-B31ED28DF75C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{B5FB3162-F349-4942-9FF4-630FD09C0566}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F741385A-22ED-4363-AECA-AA56D55D8300}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{271A0E8B-1966-463E-A96B-91A0B57E838E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D10E4755-BF1C-4E74-9530-9757DE09EE6E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9844CB19-8EA9-4FE0-933A-04A5BC1E7240}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{2080A8A2-9A56-4D1C-9076-6F527D886FEC}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{AD022327-2F17-408F-990A-226CB7E1681E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{6DAEFFD2-D735-40A2-8D0B-D1C130DABBF5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E4466092-5F28-4843-B2A1-F64A059CC6E4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{27B6FE49-6D02-4851-BF45-9C1B987EFA4D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{1C164C5B-145B-413B-AE76-D1277295842C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F07E7718-5190-4530-81A0-F4D18B840E01}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{351B7B87-5404-415A-828B-429232D2AD89}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E502D896-F68A-4AA4-9E01-4F5516AFBE51}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{29871F5B-CEA9-4B61-9A29-CA17D7699312}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{2ED07D5A-0C77-40AB-A3DD-B1FA3F60F44C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4B1C6F36-69BD-4AE5-B9A8-E924CC99D4D3}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{C4660777-9928-471D-B1BC-DECEBC030501}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{002F3144-C29C-4D75-8310-ED1179CE14A4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{AF1A3A78-1A8A-4A43-AD14-6F05C17DFA9E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{8974CB7A-B463-49DA-9391-C09C994C5AFD}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{DA2ECC2B-677F-4A78-959D-7808A7017FF8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{2B1CC946-7B33-44CD-8F89-116D08E95B47}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{7D457802-E3CD-4E8E-86C6-7FA9FD539005}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{0D68C428-D16F-414F-92AC-95A216509F16}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{19734D46-E164-474C-87C7-D6C15393BAC0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{33A855B7-24B2-4A87-B4E8-8CE84DF84ED9}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4359E186-8DF9-4D31-A169-8C8A799DA79E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{89141989-5DB2-4FE3-A9D0-3FA1D2F05B98}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FA0DAC17-7922-43AB-B7BB-3166ECDC940E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{86FC6E21-D057-4441-A8E2-965ABAB64EA9}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{9A643FBA-E357-460C-A3AF-7A652A21E03C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{A97078A0-B00D-4044-8C52-B94B7778B78F}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E3D18534-33AF-4B4B-878C-B448E87F4191}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{34EE6A87-4258-48F7-BCF3-B1FCCB611DC5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FDCB6DE0-35B9-4A1D-92ED-DE9B91F8CF73}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{CBEE268B-40CB-44E3-983E-709E58B8B360}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{3C7B155D-9F78-421D-AA54-0DD521F07EB0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{EA09C5F7-8BA0-432F-8C8D-7D2CB3C01929}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{522A09BE-86A7-4305-AFC6-E370D0D7F582}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{3EDB9170-C244-40FE-AC47-E46142205CE2}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FF9036A7-6B3B-4D8A-A9A4-0A72374FAA13}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{5FAFBFC1-3DA2-4C9A-B72B-BBD9B1B7AB7D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{A90429FB-5092-41C7-8DF9-B238DD21E907}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E0072067-04CE-4BFF-8486-B6ACAB4F66A4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{0F875298-4F9A-45B5-BA78-D6E5733D6C0D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
FF ProfilePath: C:\Users\Kacper\AppData\Roaming\Mozilla\Firefox\Profiles\5430uSi7.default [not found] <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
OPR Extension: (Tampermonkey) - C:\Users\Kacper\AppData\Roaming\Opera Software\Opera Stable\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-10-13]
OPR Extension: (ScriptMonkey) - C:\Users\Kacper\AppData\Roaming\Opera Software\Opera Stable\Extensions\lblbnlfhhblmfconjalikamamlgoobbe [2018-10-13]
S2 PaceLicenseDServices; "C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe" -u https://activation.paceap.com/InitiateActivation [X] <==== ATTENTION
C:\Users\Kacper\AppData\Local\imw.ini
Task: {0D69B9B4-BA50-449E-8AC9-309925626AE6} - System32\Tasks\{38442B6D-4E9F-4555-8F23-825F314E6051} => C:\Windows\system32\pcalua.exe -a "D:\Program files\NFS MW\Need For Speed Most Wanted\TEXTURES\Texmod.exe" -d "D:\Program files\NFS MW\Need For Speed Most Wanted\TEXTURES"
Task: {194BB826-BA5C-401A-AFBF-BBAC806AA6AE} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {3E3AD881-9E5A-46A5-84A1-76B3B36E6EBB} - System32\Tasks\{F437D1E6-CF86-49F2-87BC-2C7495B879D6} => C:\Windows\system32\pcalua.exe -a "D:\Program files\Need For Speed The Run\Mr DJ\Need For Speed The Run\Need For Speed The Run.exe" -d "D:\Program files\Need For Speed The Run\Mr DJ\Need For Speed The Run"
C:\Program Files (x86)\eoYUx.exe
C:\Users\Kacper\AppData\Roaming\FC29FA0894FE.ini
C:\Users\Kacper\AppData\Local\bPdHyxRy.exe
C:\Windows\System32\.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLok License Manager.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks\lightworks x64 (14.0.0.0).lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks\Uninstall Lightworks.lnk
Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
EmptyTemp:

Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).

2) Zainstaluj nowszą wersję Javy, wg https://www.fixitpc.pl/topic/5-dezynfekcja-kroki-finalizuj%C4%85ce-temat/?tab=comments#comment-179769
Pozwól nowej wrsji usunąć wszystkie stare wersje.

3) Zrób nowe logi FRST - już bez Shortcut.
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Samoczynnie wyskakujące reklamy

Postprzez tonis38 28 Paź 2018, 15:29

Przesyłam fixlog i nowe logi.
Załączniki
FRST.txt
(62.01 KiB) Ściągnięto 141 razy
Addition.txt
(51.14 KiB) Ściągnięto 130 razy
Fixlog.txt
(32.53 KiB) Ściągnięto 133 razy
tonis38
~user
 
Posty: 64
Dołączenie: 28 Kwi 2008, 16:51



Samoczynnie wyskakujące reklamy

Postprzez ordynat 28 Paź 2018, 16:59

Uruchom FRST. Na klawiaturze naciśnij jednocześnie CTRL+Y.Otworzy się Notatnik - wklej do niego:
FirewallRules: [{FB52443D-9952-4EA5-B018-1056DB4C9AE5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{94A091B2-E5B8-49F3-858A-79497108968E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{DD39EF67-F367-43D8-9C33-0FCE230578CB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F529A2FA-820A-42CA-AF93-82AAE0942F34}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E5795F0D-4A87-421A-82C0-FB99893D958B}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{14FA3638-5280-419E-8F07-924EACBCE76F}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{676DCC75-D8D4-44B5-89F2-4927524A8D11}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{49CF7023-FBAE-431A-9184-FD403A253DB6}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{0538E5DD-A206-4743-B80F-796D00000B8C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{099BDF0B-5A92-4FB9-9B2A-AAF2086D00E4}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4D0AA554-DCDE-47EA-AFC7-CB35ACBF2DBE}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{0B503C16-578F-4177-B69F-4967E2D35923}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{103900B1-F41C-403C-A618-B9AA03D52BAD}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{E546BE75-E66A-4231-9A7E-E6D22E5EEDED}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{8F190397-6FD4-4906-8312-991C0145CB63}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{756E5C88-0D29-4E3C-9D4B-BB4DB888EA46}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D31EE053-739F-46F3-AB41-216030D4FCE5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{3E0210A5-EAED-4C8B-A009-DED5CF6D89C8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{F4989AE6-EA2E-4B0B-AAC2-F48CC24B289A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{12256868-9C67-4E27-A090-E79218C10C12}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{07E93164-1463-4E7F-870F-DEB2B1B458EF}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{22AC9D19-23BC-44DB-976E-9CD2AD74D4D5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FB4F933B-92EE-4FEB-87D5-3CF637BDB9D0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{16C0F6A1-6307-467B-A228-786C47FE4081}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{69D1D05C-08B7-4E9B-B8AC-D1BB293165B1}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{4D44A7B5-0437-422A-A8AF-B0BB00282CB2}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{6C92B69B-822E-4D53-84F8-60F67BA4D22C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{411807AA-3697-4D2F-97D0-C4002989FB6C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{276E27EE-93E4-4A49-977F-28F1B3551296}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{D121174B-AF77-4ED3-B29D-5BFF1C4107B2}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FB0AD897-BC6A-458A-9D1F-11A31AE0C696}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{B13B93F2-10DF-4FFD-8255-B2C9A6708677}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
FirewallRules: [{FC060BB1-3F71-44DF-972C-D38AC81C2D62}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
CHR DefaultSearchURL: Default -> hxxps://defaultsearch.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Default Search
EmptyTemp:

Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).

Powinno już być OK.
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 20 gości