• Ogłoszenie:

Ukash

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Ukash

Postprzez Djoeke 18 Sie 2012, 16:20

reklama
Tak jak inni użytkownicy, mam Ukasha.
Proszę o pomoc. Jestem zielona, wiem tyle ile wyczytam w necie.
Załączniki
Extras.Txt
(223.74 KiB) Ściągnięto 54 razy
OTL.Txt
(62.25 KiB) Ściągnięto 57 razy
Djoeke
~user
 
Posty: 5
Dołączenie: 18 Sie 2012, 15:55



Ukash

Postprzez defacto19 19 Sie 2012, 11:44

Uruchom OTL i w sekcji (Własne opcje skanowania/Skrypt) wklej:

:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=40aafbdb0000000000000016d4d2149c&tlver=1.4.23.10&affID=19637
IE - HKLM\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://startsear.ch/?aff=1&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {539F76FD-084E-4858-86D5-62F02F54AE86} - SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}\InprocServer32 File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://startsear.ch/?aff=1&q={searchTerms}
IE - HKCU\..\SearchScopes\{C510BE39-4045-47C9-8657-461774829B82}: "URL" = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=40aafbdb0000000000000016d4d2149c&tlver=1.4.23.10&affID=19637
IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKCU\..\SearchScopes\{FA4FF68E-24B4-4222-BBD6-030176441441}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1"
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.1.1
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=40aafbdb0000000000000016d4d2149c&tlver=1.4.23.10&affID=19637"
FF - prefs.js..network.proxy.type: 1
[2011-06-15 23:19:35 | 000,000,000 | ---D | M] (FaceSmooch) -- C:\Users\ghalib\AppData\Roaming\mozilla\Firefox\Profiles\xysc543g.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}
[2011-07-08 18:23:11 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\ghalib\AppData\Roaming\mozilla\Firefox\Profiles\xysc543g.default\extensions\DTToolbar@toolbarnet.com
[2011-07-11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\ghalib\AppData\Roaming\Mozilla\Firefox\Profiles\xysc543g.default\searchplugins\startsear.xml
[2009-05-20 19:08:25 | 000,001,196 | ---- | M] () -- C:\Users\ghalib\AppData\Roaming\Mozilla\Firefox\Profiles\xysc543g.default\searchplugins\winamp-search.xml
[2011-06-09 13:41:48 | 000,081,920 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-06-15 23:19:43 | 000,002,423 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll File not found
O4 - HKLM..\Run: [Acer Tour] File not found
O4 - HKLM..\Run: [auospfewpdfuofv] C:\ProgramData\auospfew.exe ()
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [Windows Terminal Services] C:\Windows\system32\wmpdtk32.exe File not found
O4 - HKCU..\Run: [auospfewpdfuofv] C:\ProgramData\auospfew.exe ()
O4 - HKCU..\Run: [Disk Cleaner] "C:\Program Files\Disk Cleaner\DiskCleaner.Exe" /boot File not found
O4 - HKCU..\Run: [MSConfig] C:\Users\ghalib\ootxql.exe ()
O4 - HKCU..\Run: [捁牥吠畯r] File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O33 - MountPoints2\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\Shell - "" = AutoRun
O33 - MountPoints2\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1
@Alternate Data Stream - 938314 bytes -> C:\Windows\Temp:temp

:Files
C:\Users\ghalib\cn.exe
C:\Users\ghalib\bm2.exe
C:\Users\ghalib\bm.exe
C:\ProgramData\delcbmaw.exe
C:\ProgramData\auospfew.exe
C:\ProgramData\czerqbkjhpduqcc
C:\Users\ghalib\ms.exe
C:\Users\ghalib\ootxql.exe
C:\ProgramData\HitmanPro
C:\Windows\bthservsdp.dat

:Commands
[emptytemp]


Kliknij wykonaj skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, i kliknij skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania.

Autor postu otrzymał pochwałę
defacto19
~user
 
Posty: 205
Dołączenie: 23 Cze 2012, 11:51
Pochwały: 42



Ukash

Postprzez Djoeke 19 Sie 2012, 15:48

W załączniku nowy log i raport.
Robione w trybie awaryjnym, w zwykłym podczas skanowania komp restartuje.

Edit:
Nie mogę załączyć raportu, wyskakuje komunikat
Rozszerzenie log jest zabronione.

Wklejam go tutaj:
All processes killed
========== OTL ==========
Error: No service named UIUSys was found to stop!
Service\Driver key UIUSys not found.
File system32\DRIVERS\UIUSYS.SYS not found.
Error: No service named blbdrive was found to stop!
Service\Driver key blbdrive not found.
File C:\Windows\system32\drivers\blbdrive.sys not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SEARCH PAGE| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SearchMigratedDefaultName| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SearchMigratedDefaultURL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{539F76FD-084E-4858-86D5-62F02F54AE86} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C510BE39-4045-47C9-8657-461774829B82}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C510BE39-4045-47C9-8657-461774829B82}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FA4FF68E-24B4-4222-BBD6-030176441441}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FA4FF68E-24B4-4222-BBD6-030176441441}\ not found.
Prefs.js: "Web Search" removed from browser.search.defaultengine
Prefs.js: "Web Search" removed from browser.search.defaultenginename
Prefs.js: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" removed from browser.search.defaulturl
Prefs.js: "Web Search" removed from browser.search.order.1
Prefs.js: "Google" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "http://startsear.ch/?aff=1" removed from browser.startup.homepage
Prefs.js: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.1.1 removed from extensions.enabledItems
Prefs.js: "http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=40aafbdb0000000000000016d4d2149c&tlver=1.4.23.10&affID=19637" removed from keyword.URL
Prefs.js: 1 removed from network.proxy.type
Folder C:\Users\ghalib\AppData\Roaming\mozilla\Firefox\Profiles\xysc543g.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}\ not found.
Folder C:\Users\ghalib\AppData\Roaming\mozilla\Firefox\Profiles\xysc543g.default\extensions\DTToolbar@toolbarnet.com\ not found.
File C:\Users\ghalib\AppData\Roaming\Mozilla\Firefox\Profiles\xysc543g.default\searchplugins\startsear.xml not found.
File C:\Users\ghalib\AppData\Roaming\Mozilla\Firefox\Profiles\xysc543g.default\searchplugins\winamp-search.xml not found.
File C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll not found.
File C:\Program Files\mozilla firefox\searchplugins\babylon.xml not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Acer Tour not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\auospfewpdfuofv not found.
File C:\ProgramData\auospfew.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\eRecoveryService not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Terminal Services not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\auospfewpdfuofv not found.
File C:\ProgramData\auospfew.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Disk Cleaner not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSConfig not found.
File C:\Users\ghalib\ootxql.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\捁牥吠畯r not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{858f1a84-1366-11dc-b5c0-0016d4d2149c}\ not found.
File F:\setup.exe AUTORUN=1 not found.
Unable to delete ADS C:\Windows\Temp:temp .
========== FILES ==========
File\Folder C:\Users\ghalib\cn.exe not found.
File\Folder C:\Users\ghalib\bm2.exe not found.
File\Folder C:\Users\ghalib\bm.exe not found.
File\Folder C:\ProgramData\delcbmaw.exe not found.
File\Folder C:\ProgramData\auospfew.exe not found.
File\Folder C:\ProgramData\czerqbkjhpduqcc not found.
File\Folder C:\Users\ghalib\ms.exe not found.
File\Folder C:\Users\ghalib\ootxql.exe not found.
File\Folder C:\ProgramData\HitmanPro not found.
File\Folder C:\Windows\bthservsdp.dat not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: ghalib
->Temp folder emptied: 2325196002 bytes
->Temporary Internet Files folder emptied: 11955994 bytes
->Java cache emptied: 35598813 bytes
->FireFox cache emptied: 413386023 bytes
->Flash cache emptied: 2055178 bytes

User: Olok

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 126103931 bytes
RecycleBin emptied: 1430054453 bytes

Total Files Cleaned = 4 143,00 mb


OTL by OldTimer - Version 3.2.57.0 log created on 08192012_144744

Files\Folders moved on Reboot...
File\Folder C:\Users\ghalib\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YJ6PXMX8\cm.daphnecm.com\cm.php\int12id6\s \flash.swf\int12id6.sol not found!

PendingFileRenameOperations files...
File C:\Users\ghalib\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YJ6PXMX8\cm.daphnecm.com\cm.php\int12id6\s \flash.swf\int12id6.sol not found!

Registry entries deleted on Reboot...
Załączniki
OTL1.Txt
(58.23 KiB) Ściągnięto 53 razy
Djoeke
~user
 
Posty: 5
Dołączenie: 18 Sie 2012, 15:55



Ukash

Postprzez defacto19 19 Sie 2012, 17:11

Uruchom OTL i użyj opcji sprzątanie.

Zastosuj Adwcleaner z opcji Delete.
(Po ponownym uruchomieniu komputera uruchom Adwcleaner`a raz jeszcze i kliknij na przycisk Uninstall)

Wykonaj pełne skanowanie programem Malwarebytes Anti-Malware
(Przed skanowaniem wykonaj ręczną aktualizację bazy sygnatur wirusów)

Zainstaluj aktualizacje do programow wskazanych przez Security Check jako out of date.

Autor postu otrzymał pochwałę
defacto19
~user
 
Posty: 205
Dołączenie: 23 Cze 2012, 11:51
Pochwały: 42



Ukash

Postprzez Djoeke 19 Sie 2012, 17:46

Bardzo Ci dziękuję.
:ok:
Djoeke
~user
 
Posty: 5
Dołączenie: 18 Sie 2012, 15:55




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości