harryadr Opublikowano 1 Lipca 2015 Zgłoś Udostępnij Opublikowano 1 Lipca 2015 zauważyłem problemy systemowe komputera rodziców ,był bym wdzieęczny jak ktos by rzucił okiem na logi.z góry dziekuje i pozdrawiam Addition.txt FRST.txt Shortcut.txt Odnośnik do komentarza
picasso Opublikowano 2 Lipca 2015 Zgłoś Udostępnij Opublikowano 2 Lipca 2015 Akcje do przeprowadzenia: 1. Otwórz Notatnik i wklej w nim: CloseProcesses: CreateRestorePoint: ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 ShortcutWithArgument: C:\Users\zibi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150509 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150509 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=hp&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=hp&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 HKU\S-1-5-21-2030126852-3812474721-3917447742-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150509 HKU\S-1-5-21-2030126852-3812474721-3917447742-1000\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://isearch.avg.com/?cid={30D4757C-1A9F-4E81-B89E-052C3F0A8F5F}&mid=624e592709e747d084d18965c6f77b90-a3bcec884083189fbe2319d437a293f55a3f7b04&lang=pl&ds=st011&pr=sa&d=2012-10-17 00:02:48&v=11.1.0.7&sap=hp HKU\S-1-5-21-2030126852-3812474721-3917447742-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=hp&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268352 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000 -> {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20121018&user_guid=C57FCB49214244CAB53E415CC3AE68C5&machine_id=c70db57d294546fd1b71def832dc4216&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source} SearchScopes: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=2031001FC63C34D6&affID=119357&tsp=4991 SearchScopes: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=HitachiXHDS721010CLA332_JP9911HZ0R9TZU0R9TZUX&ts=1380268353&type=default&q={searchTerms} BHO-x32: Crazy Score -> {f439aa7e-a2a0-4635-99a2-164180e848ca} -> C:\Program Files (x86)\Crazy Score\Extensions\f439aa7e-a2a0-4635-99a2-164180e848ca.dll No File Toolbar: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File HKU\S-1-5-21-2030126852-3812474721-3917447742-1000\...\Run: [iLivid] => "C:\Users\zibi\AppData\Local\iLivid\iLivid.exe" -autorun HKU\S-1-5-21-2030126852-3812474721-3917447742-1000\...\Run: [PeenyBee] => C:\Users\zibi\AppData\Local\PennyBee\PennyBeeW.exe CustomCLSID: HKU\S-1-5-21-2030126852-3812474721-3917447742-1000_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\zibi\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll No File Task: {2F0D7694-3F42-40D3-B578-4E43265F5917} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe Task: {65A7C468-A85B-413C-B5DE-D76DD5DEF030} - System32\Tasks\{56D9BDA3-E5E9-48DA-AAB3-3EE57AFBC965} => pcalua.exe -a G:\Support\DotNetRedist\dotnetfx.exe -d G:\Support\DotNetRedist Task: {6C41A5F4-308E-4651-8224-A6AA4FECDABC} - System32\Tasks\{15E4C85E-516A-42C7-91F4-CC316496E2B6} => pcalua.exe -a "C:\Program Files (x86)\DVD PixPlay\unins000.exe" Task: {99E79350-8C66-4BE7-92DF-22CDAA7CA85F} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{1B0C630F-0C07-496B-AD4B-BBD7839C18DB}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{1B0C630F-0C07-496B-AD4B-BBD7839C18DB}.exe S3 ALSysIO; \??\C:\Users\zibi\AppData\Local\Temp\ALSysIO64.sys [X] C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD PixPlay C:\Users\zibi\Favorites\GG dysk.lnk Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKLM\SOFTWARE\Clients\StartMenuInternet\Opera /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f CMD: netsh advfirewall reset EmptyTemp: Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach. Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Czekaj cierpliwie, nie przerywaj działania. Gdy Fix ukończy pracę, system zostanie zresetowany. W tym samym katalogu skąd uruchamiano FRST powstanie plik fixlog.txt. 2. Wyczyść Firefox z adware: menu Pomoc > Informacje dla pomocy technicznej > Odśwież program Firefox. Zakładki i hasła nie zostaną naruszone. menu Historia > Wyczyść historię przeglądania 3. Zrób nowy log FRST z opcji Scan (bez Addition i Shortcut). Dołącz też plik fixlog.txt. Podsumuj na czym stoimy. Odnośnik do komentarza
harryadr Opublikowano 3 Lipca 2015 Autor Zgłoś Udostępnij Opublikowano 3 Lipca 2015 Dzięki wielkie .. wydaje się że wszystko jest już Ok Jeszcze raz dziekuje FRST.txt Odnośnik do komentarza
Rekomendowane odpowiedzi