Skocz do zawartości

Prośba o pomoc - otwieranie różnych stron w firefox


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Uruchom FRST. Na klawiaturze naciśnij jednocześnie CTRL+Y.
Otworzy się Notatnik - wklej do niego:

Spoiler

Task: {286AA064-375D-4EAB-910E-E9B7F10964ED} - System32\Tasks\{D70C3795-47EE-3AAA-EB89-8DF98E971913} => C:\Users\Tomek\AppData\Roaming\PaXOhZeFt.exe [2018-09-15] (Microsoft Corporation)
Task: {297ECAAD-6C0F-4CA6-A4B3-63B9BABBB894} - System32\Tasks\{7426A322-8F1E-5A0F-B6C2-6B36AD45452C} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://myxeneurt.net/cl/?guid=fvfmly8c8j73nppjgv1s8zcbnzllsrfy&prid=1&pid=4_1324_0
C:\Users\Tomek\AppData\Roaming\PaXOhZeFt.exe
Task: {33AFFC78-4A67-4DB3-B37F-602F43882062} - System32\Tasks\{77E079A7-596F-0F3D-B00F-BC9535175382} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://myxeneurt.net/cl/?guid=pviabuelzdhku7vx3kut1ak4b1n8pq84&prid=1&pid=4_1324_0
Task: {857686F6-5E73-46BF-B075-FA1E268C45A9} - System32\Tasks\{C162CCAA-08FA-D675-C7B9-18C6B7890788} => C:\Program Files (x86)\Common Files\aygetvej.exe [2018-09-15] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\aygetvej.exe
Task: {92E7727A-7D2D-4DF0-AA78-BFF4C0AE7F84} - System32\Tasks\{DE6692C9-982C-3EFF-87E9-3FAF4EAA7585} => C:\Users\Tomek\AppData\Roaming\PaXOhZeFt.exe [2018-09-15] (Microsoft Corporation)
Task: {A64B0701-C30E-4879-905C-B5720EE4959B} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
Task: {AEE72662-1B3F-41D8-842B-DF7002DBB476} - System32\Tasks\{40CD58BF-36BE-E594-BBA9-77717DC7CAB3} => "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://dhakil.com/cl/?guid=p5xbwzvve0gpcztuzs0i7kas84apdy8t&prid=1&pid=4_1324_0
Task: {D2C61568-2FA8-4714-ABEF-301CCBCD9379} - System32\Tasks\{F574134D-8C32-BBCA-89CC-09EA0A8FED68} => C:\Program Files (x86)\Common Files\aygetvej.exe [2018-09-15] (Microsoft Corporation)
RemoveDirectory: C:\Users\Tomek\AppData\Roaming\Microsoft\SoundMixer
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 [0 2018-11-29] ()
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 [0 2018-11-29] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-1177734181-163601610-57667068-1001\...\Run: [] => [X]
HKU\S-1-5-21-1177734181-163601610-57667068-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\Tomek\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\Tomek\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA
GroupPolicy: Ograniczenia ? <==== UWAGA
ProxyEnable: [S-1-5-21-1177734181-163601610-57667068-1001] => Proxy [funkcja włączona]
FF Session Restore: Mozilla\Firefox\Profiles\rm7tb51n.default-1489774386214-1523978532264 -> [funkcja włączona]
S3 SWDUMon; \SystemRoot\system32\DRIVERS\SWDUMon.sys [X]
2018-09-15 08:29 - 2018-09-15 08:29 - 000078336 ____N (Microsoft Corporation) C:\Users\Tomek\AlgEpkWIqiTbY.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000181760 ____N (Microsoft Corporation) C:\Users\Tomek\eHKOYFyUUADIQ.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000078336 ____N (Microsoft Corporation) C:\Program Files (x86)\euTniahQuNgEN.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000078336 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\aygetvej.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000078336 ____N (Microsoft Corporation) C:\Users\Tomek\AppData\Roaming\aaBFlOxYAny.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000181760 ____N (Microsoft Corporation) C:\Users\Tomek\AppData\Roaming\EYrXIyImFgOk.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000181760 ____N (Microsoft Corporation) C:\Users\Tomek\AppData\Roaming\lNwqgcqva.exe
2018-09-15 08:29 - 2018-09-15 08:29 - 000078336 ____N (Microsoft Corporation) C:\Users\Tomek\AppData\Roaming\PaXOhZeFt.exe
2018-11-18 13:38 - 2019-01-07 21:00 - 000000002 _____ () C:\Users\Tomek\AppData\Local\imw.ini
2018-05-25 23:23 - 2018-05-25 23:23 - 000140800 _____ () C:\Users\Tomek\AppData\Local\installer.dat
EmptyTemp:

Na klawiaturze naciśnij jednocześnie CTRL+S.

W FRST kliknij na Fix (NAPRAW).

 

Zrób nowe logi FRST.

 

jessi

Odnośnik do komentarza

Uruchom FRST. Na klawiaturze naciśnij jednocześnie CTRL+Y.
Otworzy się Notatnik - wklej do niego:

Spoiler

C:\Users\Tomek\AppData\Local\installer.dat
C:\Users\Tomek\Desktop\qubmgiwyvkffyile.txt
SearchScopes: HKLM-x32 -> DefaultScope - brak wartości

Na klawiaturze naciśnij jednocześnie CTRL+S.

W FRST kliknij na Fix (NAPRAW).

 

Wg mnie - powinno już być OK.

 

jessi

Odnośnik do komentarza

Uruchom FRST. Na klawiaturze naciśnij jednocześnie CTRL+Y.
Otworzy się Notatnik - wklej do niego:

Spoiler

Task: {4779355F-8C94-40E3-8B57-57856A5D0BE9} - System32\Tasks\{FE52F2F9-12AC-3454-AF4E-2C122F35952F} => "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://hedlen.net/cl/?guid=xhiw7jocq66w74zwzfl5ycnpa8y5itk6&prid=1&pid=4_1324_0
Task: {77F744B7-B7F0-4E7A-8B15-4BFFB6116400} - System32\Tasks\{4DB7DA8D-EEED-6B24-382A-BBF12E6D996B} => C:\WINDOWS\SysWOW64\aeXmiqAi.exe [2018-09-15] (Microsoft Corporation) <==== UWAGA
C:\WINDOWS\SysWOW64\aeXmiqAi.exe
Task: {FDC8CBE1-E406-4359-A2B8-1B6D36942C4F} - System32\Tasks\{8480DF37-A4E9-5C75-827C-E253CA7CDED3} => "msiexec" /q -package hxxps://overseiths.com/mnzteeseqydr.fsy
FirewallRules: [{987E4DA6-D730-4375-85D1-E7D356CFD159}] => (Allow) C:\Program Files (x86)\AvkGiUhpiFt.exe Brak pliku
FirewallRules: [{6970AC5E-0FED-466D-9B0C-CCBAF5A0C31F}] => (Allow) C:\WINDOWS\SysWOW64\aeXmiqAi.exe (Microsoft Corporation)
FirewallRules: [{5D8D3D5B-D58C-410D-963F-59E91A9F8398}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{BE3A4778-0451-4B9C-8E9D-23F581891739}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{662D8CF0-4A2E-459C-BFCD-5547070260D6}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{6811A185-4CD5-4F24-87A6-7F33DA77AA53}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{602D578E-C5E3-44DB-A9BD-25FBDB1713C0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{972D3FDA-4444-4BBA-A127-26D5ADDC8257}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{919B612B-8679-4E52-AECC-1BC163AC8AA6}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{90497E23-0407-4123-A600-25E7D97037F0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{7913E47A-B3F4-4E6D-8A3F-522B3BEB1F75}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{BD1E098E-6E4F-4D2B-BB60-3E3D21B95964}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{2244029C-E2ED-4217-8CCB-AA8D1DF3F333}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{6487ADFF-C554-4F8B-9E02-6D028C204188}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{19DD18F5-7897-40CA-93EA-74DAD1504B17}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{087DBD78-7767-4773-AF46-158C8B76E057}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{EFD1B949-A80C-465D-9EC8-5FA37A87A5C7}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{51C56EFA-4139-4BC7-BC8A-75ACA96C3D72}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{12EE84A5-E2AD-4A90-952B-77DBE71DB06D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{306198E9-1675-46E6-8730-FE0A7DC63D4E}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{953C50F0-F9F2-4B26-91FB-EA94B4850067}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{101DBAB5-6812-4C1F-8825-DE65C4AE8A12}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{34B6B995-FAC3-42C0-92E0-57AC430186C6}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{36AF6FB6-34A0-4010-B89C-7D713B0B5C51}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{A456CB16-43EF-4DB0-93E7-055F3FF47F8B}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{B4DC967C-3549-4C01-A344-F67F58DAF6F7}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{A3B965CF-10F3-4C76-91B3-F23F06DB48F2}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{8B6213D1-2BE7-42EF-9CC0-E2FE0983DD5F}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{D3DA55D1-FCD7-44EF-A7CA-F8A786DAF652}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{B677BFA6-4781-415E-8011-F06D7DDD6B65}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{09EE8648-9AE1-43DD-9C24-F816927C21D8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{F17F6E9E-8ADB-48FA-8B59-C55DC6AD94E5}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{F62B14D8-0E40-420D-BDB7-38ED992B6025}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{4EDD8182-3616-4BC2-910B-C6893185124A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{8D972820-B07E-4588-A1D6-528AD9182EF1}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{8E55CD85-929F-42CD-AF35-6AEB1FCABD0A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{A5E31A9A-4EE5-4739-BD44-E611648ACAE0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{E8D0A1E4-1570-4E0A-9996-610632ABB2D0}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{60350B1E-B3E9-484F-A6BC-353A7F2E7524}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{1A452EA2-D14A-4B0E-B10F-779E6A42AD06}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{CBDFCC17-D1B6-4482-931F-EF9737878C48}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{0764F6B6-AB35-4210-9EB0-BCA88DEBE2BC}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{4898A1D8-1ADB-46B0-A746-F66F4610E875}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{9D745CA2-DFEA-464E-85AA-111020D440D2}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{D70740E8-48EC-4B43-B7BC-8C29800305A7}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{73A34EEA-560B-454C-914A-86761336D19F}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{8ED44B19-B0BD-448B-A716-FE8FF04C7657}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FirewallRules: [{ECFA9B9D-2A2C-4118-AB21-278399CA6272}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{AC826C84-96C2-4B0D-ADF9-F38188C42D80}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe (Microsoft Corporation)
FirewallRules: [{8C1EAC7D-30C8-4F63-B47A-159D299F0B10}] => (Allow) C:\WINDOWS\SysWOW64\InstallShield\setup.exe (InstallShield Software Corporation)
FF Session Restore: Mozilla\Firefox\Profiles\ysa19prf.default-1489774386214-1547404058691 -> [funkcja włączona]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asystent uaktualnienia do systemu Windows 10.lnk
Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  -> Brak pliku
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  -> Brak pliku
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} =>  -> Brak pliku
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} =>  -> Brak pliku
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} =>  -> Brak pliku
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} =>  -> Brak pliku
EmptyTemp:

Na klawiaturze naciśnij jednocześnie CTRL+S.
W FRST kliknij na Fix (NAPRAW).

 

Napisz, jak oceniasz sytuację po tych usuwaniach?

 

Cytat

Jak zabezpieczyć kompa żeby uniknąć sytuacji ?

Masz komputer zabezpieczony - ale niestety infekcje zawsze będą potrafiły przeniknąć do komputera.

 

jessi

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...