Ludzik Opublikowano 25 Czerwca 2014 Zgłoś Udostępnij Opublikowano 25 Czerwca 2014 Witam!Proszę o sprawdzenie poniższych logów, komputer nie działa tak jak powinien. Częste 'zamrażanie' systemu, spowolnione działanie etc. Addition.txt FRST.txt Shortcut.txt OTL.Txt Extras.Txt Odnośnik do komentarza
jessica Opublikowano 25 Czerwca 2014 Zgłoś Udostępnij Opublikowano 25 Czerwca 2014 @Picasso teraz pomaga tylko 2-3 razy w miesiącu, czyli średnio co 12 dni. https://www.fixitpc.pl/topic/23357-picasso/ Miała już być wczoraj wieczorem, ale ...? 1) Odinstaluj: BitGuard (HKLM\...\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - MediaTechSoft Inc.) <==== ATTENTION 2) Użyj >Adw-cleanernajpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.Pokaż raport z niego C:\AdwCleaner\AdwCleaner.txt 3) Otwórz Notatnik i wklej w nim: HKLM\...\Run: [] => [X]Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /fReg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /fReg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /fDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cabFF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\babylon.xmlFF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\BrowserDefender.xmlFF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\delta.xmlFF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\holasearch.xmlFF Extension: HolaSearch - C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\Extensions\ffxtlbr@holasearch.com [2013-06-11]R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}t; C:\WINDOWS\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}t.sys [55232 2014-06-16] (StdLib)C:\WINDOWS\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}t.sysC:\Documents and Settings\Właściciel\Application Data\BabylonC:\Documents and Settings\All Users\Application Data\IBUpdaterServiceC:\Documents and Settings\Właściciel\Local Settings\Temp\uninst1.exeC:\Documents and Settings\Właściciel\Application Data\BabSolutionC:\Documents and Settings\All Users\Application Data\BitGuardC:\Documents and Settings\All Users\Application Data\BabylonReboot: Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Powstanie plik fixlog.txt. Daj ten log. 4) Zrób nowe logi z FRST - już bez Shortcut. jessi Odnośnik do komentarza
Ludzik Opublikowano 25 Czerwca 2014 Autor Zgłoś Udostępnij Opublikowano 25 Czerwca 2014 Dziękuję za tak szybką odpowiedź! 1) Odinstaluj: BitGuard (HKLM\...\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - MediaTechSoft Inc.) <==== ATTENTION Może to głupie pytanie, ale jak? Przeszukałem regedit i nie znalazlem takiego wpisu w rejestrze, w Dodaj/Usuń nie ma Bitguard`a. Poniżej wkleiłem loga z AdwCleaner`a, w załącznikach nowe logi z FRST.AdwCleaner: # AdwCleaner v3.213 - Report created 25/06/2014 at 11:32:22# Updated 23/06/2014 by Xplode# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)# Username : Właściciel - YOUR-17A6EC0835# Running from : C:\Documents and Settings\Właściciel\Desktop\lukasz\adwcleaner_3.213.exe# Option : Clean***** [ Services ] *****Service Deleted : Update Greener Web***** [ Files / Folders ] *****Folder Deleted : C:\Documents and Settings\All Users\Application Data\BabylonFolder Deleted : C:\Documents and Settings\All Users\Application Data\BitGuardFolder Deleted : C:\Documents and Settings\All Users\Application Data\DriverCureFolder Deleted : C:\Documents and Settings\All Users\Application Data\IBUpdaterServiceFolder Deleted : C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\SafeBrowserFolder Deleted : C:\Documents and Settings\All Users\Application Data\ParetoLogicFolder Deleted : C:\Program Files\Greener WebFolder Deleted : C:\Documents and Settings\Właściciel\Local Settings\Application Data\OpenCandyFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\AD ON MultimediaFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\BabSolutionFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\BabylonFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\DriverCureFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\OpenCandyFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\PerformerSoftFolder Deleted : C:\Documents and Settings\Właściciel\Start Menu\Programs\BitGuardFolder Deleted : C:\Program Files\Mozilla Firefox\Extensions\ffxtlbr@babylon.comFolder Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\Extensions\ffxtlbr@holasearch.comFolder Deleted : C:\Program Files\Mozilla Firefox\Extensions\ffxtlbr@holasearch.comFile Deleted : C:\WINDOWS\system32\roboot.exeFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\bProtector_extensions.rdfFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\bprotector_extensions.sqliteFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\bprotector_prefs.jsFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\invalidprefs.jsFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\Babylon.xmlFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\BrowserDefender.xmlFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\delta.xmlFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\holasearch.xmlFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\user.jsFile Deleted : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\nts and Settings\user.js***** [ Shortcuts ] ********** [ Registry ] *****Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaaKey Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLLKey Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBndKey Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlprKey Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1Key Deleted : HKLM\SOFTWARE\Classes\esrv.holasearchesrvcKey Deleted : HKLM\SOFTWARE\Classes\esrv.holasearchesrvc.1Key Deleted : HKLM\SOFTWARE\Classes\Prod.capKey Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbhoKey Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1Key Deleted : HKLM\SOFTWARE\Classes\speedupmypcValue Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]Key Deleted : HKCU\Software\5d6dfdeb46eed17Key Deleted : HKLM\SOFTWARE\5d6dfdeb46eed17Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58B41DCD-55B2-48EB-A55A-E330070FFC00}Key Deleted : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}Key Deleted : HKCU\Software\BabSolutionKey Deleted : HKCU\Software\DataMngrKey Deleted : HKCU\Software\delta LTDKey Deleted : HKCU\Software\filescoutKey Deleted : HKCU\Software\holasearch LTDKey Deleted : HKCU\Software\InstallCoreKey Deleted : HKCU\Software\ParetoLogicKey Deleted : HKCU\Software\YahooPartnerToolbarKey Deleted : HKLM\Software\BabylonKey Deleted : HKLM\Software\BabylonToolbarKey Deleted : HKLM\Software\DataMngrKey Deleted : HKLM\Software\ParetoLogicKey Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}***** [ Browsers ] *****-\\ Internet Explorer v7.0.6000.21376Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]-\\ Mozilla Firefox v30.0 (pl)[ File : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\prefs.js ]Line Deleted : user_pref("extensions.delta.admin", false);Line Deleted : user_pref("extensions.delta.aflt", "babsst");Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");Line Deleted : user_pref("extensions.delta.autoRvrt", "false");Line Deleted : user_pref("extensions.delta.bbDpng", "2");Line Deleted : user_pref("extensions.delta.cntry", "PL");Line Deleted : user_pref("extensions.delta.dfltLng", "en");Line Deleted : user_pref("extensions.delta.excTlbr", false);Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);Line Deleted : user_pref("extensions.delta.hdrMd5", "E947B26DA55ECACB4A90279D20C88708");Line Deleted : user_pref("extensions.delta.id", "60170b1f0000000000000013d3689942");Line Deleted : user_pref("extensions.delta.instlDay", "15894");Line Deleted : user_pref("extensions.delta.instlRef", "sst");Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.21.510:52:19");Line Deleted : user_pref("extensions.delta.newTab", false);Line Deleted : user_pref("extensions.delta.prdct", "delta");Line Deleted : user_pref("extensions.delta.prtnrId", "delta");Line Deleted : user_pref("extensions.delta.rvrt", "false");Line Deleted : user_pref("extensions.delta.sg", "azb");Line Deleted : user_pref("extensions.delta.smplGrp", "none");Line Deleted : user_pref("extensions.delta.tlbrId", "base");Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5");Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.510:52:19");Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5");Line Deleted : user_pref("extensions.delta_i.babExt", "");Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=070713_9124&tsp=4937");Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");Line Deleted : user_pref("extensions.holasearch.admin", false);Line Deleted : user_pref("extensions.holasearch.aflt", "babsst");Line Deleted : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}");Line Deleted : user_pref("extensions.holasearch.autoRvrt", "false");Line Deleted : user_pref("extensions.holasearch.bbDpng", "9");Line Deleted : user_pref("extensions.holasearch.cntry", "PL");Line Deleted : user_pref("extensions.holasearch.dfltLng", "en");Line Deleted : user_pref("extensions.holasearch.excTlbr", false);Line Deleted : user_pref("extensions.holasearch.ffxUnstlRst", false);Line Deleted : user_pref("extensions.holasearch.hdrMd5", "D7C8554CF9D40C78AFF592E5EB17E9F1");Line Deleted : user_pref("extensions.holasearch.id", "60170b1f0000000000000013d3689942");Line Deleted : user_pref("extensions.holasearch.instlDay", "15889");Line Deleted : user_pref("extensions.holasearch.instlRef", "sst");Line Deleted : user_pref("extensions.holasearch.lastVrsnTs", "1.8.16.1610:18:59");Line Deleted : user_pref("extensions.holasearch.newTab", false);Line Deleted : user_pref("extensions.holasearch.prdct", "holasearch");Line Deleted : user_pref("extensions.holasearch.prtnrId", "holasearch");Line Deleted : user_pref("extensions.holasearch.rvrt", "false");Line Deleted : user_pref("extensions.holasearch.sg", "azb");Line Deleted : user_pref("extensions.holasearch.smplGrp", "none");Line Deleted : user_pref("extensions.holasearch.tlbrId", "base");Line Deleted : user_pref("extensions.holasearch.tlbrSrchUrl", "");Line Deleted : user_pref("extensions.holasearch.vrsn", "1.8.16.16");Line Deleted : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1610:18:59");Line Deleted : user_pref("extensions.holasearch.vrsni", "1.8.16.16");[ File : C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\nts and Settings\prefs.js ]*************************AdwCleaner[R0].txt - [10479 octets] - [25/06/2014 11:29:27]AdwCleaner[s0].txt - [10469 octets] - [25/06/2014 11:32:22]########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [10530 octets] ########## Fixlog.txt Addition.txt FRST.txt Odnośnik do komentarza
jessica Opublikowano 25 Czerwca 2014 Zgłoś Udostępnij Opublikowano 25 Czerwca 2014 Może to głupie pytanie, ale jak? Przeszukałem regedit i nie znalazlem takiego wpisu w rejestrze, w Dodaj/Usuń nie ma Bitguard`a. Było (to BitGuard): Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Adw-Cleaner już to usunął z listy programów. W nowych logach nie widzę już niczego podejrzanego. Jeśli @Picasso nie poda jeszcze jakichś zaleceń, to będziemy kończyć: Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. przez SHIFT+DEL usuń pozostały folder C:\FRST W Adw-Cleaner kliknij na przycisk Odinstaluj (UNINSTALL) Mam nadzieję, że to choć trochę poprawiło sytuację. jesso Odnośnik do komentarza
Ludzik Opublikowano 25 Czerwca 2014 Autor Zgłoś Udostępnij Opublikowano 25 Czerwca 2014 Bardzo dziękuję za pomoc! Odnośnik do komentarza
Rekomendowane odpowiedzi
Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto
Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.
Zarejestruj nowe konto
Załóż nowe konto. To bardzo proste!
Zarejestruj sięZaloguj się
Posiadasz już konto? Zaloguj się poniżej.
Zaloguj się