Skocz do zawartości

Wyskakujące czarne okienko cmd podczas korzystania z komputera


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Os razu rzucają się w oczy Zaplanowane Zadania infekcji...

 

 

Infekcję masz od 28 lipca.

 

Uruchom FRST. 
Skopiuj to poniższe: (ale nigdzie nie wklejaj tego!) - FRST sam znajdzie "fixlist" w schowku systemowym

Spoiler

START::
Task: {093747DF-12B6-421A-887E-08C6AEDA7404} - System32\Tasks\ZpEVDmIlefcqtj => rundll32 "C:\Program Files (x86)\ulQXJxdiHxSU2\iubiwSBgqMTtv.dll",#1
Task: {214DA309-B93A-4CA2-8B63-D1EBEA976A8B} - System32\Tasks\fNuIyawitAoDEGu2 => rundll32 "C:\Program Files (x86)\omepHXTcU\uiSgMt.dll",#1
ask: {7C16EB70-E5B3-41C6-9D90-15BCFCBBE3A7} - System32\Tasks\wgPoVvFawHYrCSXOC2 => rundll32 "C:\Program Files (x86)\PrRHHpsGxQEuyNXpirR\NhVVWjq.dll",#1
Task: {7DFB8387-310A-4B66-9B87-0FA4CE7D6C2D} - System32\Tasks\rNfsrCYQpNqfOcrfNNU2 => rundll32 "C:\Program Files (x86)\BayioKoEHcCpC\RJEmUKf.dll",#1
RemoveDirectory: C:\Program Files (x86)\ulQXJxdiHxSU2
RemoveDirectory: C:\Program Files (x86)\vsJnmafXoMUn
RemoveDirectory: C:\Program Files (x86)\PrRHHpsGxQEuyNXpirR
RemoveDirectory: C:\Program Files (x86)\omepHXTcU
RemoveDirectory: C:\Program Files (x86)\BayioKoEHcCpC
2022-05-13 13:50 - 2022-05-13 13:50 - 000248375 ___SH () C:\Users\Właściciel\AppData\Roaming\cvrberc
2022-05-13 13:50 - 2022-05-13 13:50 - 000042064 ___SH (Microsoft Corporation) C:\Users\Właściciel\AppData\Roaming\fietvws
EmptyEventLogs: 
HKU\S-1-5-18\...\Run: [] => [X]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Brak pliku)
HKLM-x32\...\Run: [Backup] => C:\Program Files (x86)\Wondershare\drfone\Addins\Backup\DrFoneBackup.exe /hide (Brak pliku)
HKLM\...\Run: [WSVCUUpdateHelper.exe] => C:\Program Files\Wondershare\UniConverter 13\WSVCUUpdateHelper.exe (Brak pliku)
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer1.log:F107EE40EF [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer1.log_backup1:2DD1EC5C91 [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer2.log:CCB2353F35 [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer2.log_backup1:0544EFE2DB [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer3.log:8A1F56CED6 [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer3.log_backup1:A473474DD2 [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer4.log:3B2EC2BDEF [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer4.log_backup1:DC5D04D24A [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer5.log:84BD5AAA09 [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer5.log_backup1:038079845B [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer6.log:4C1811BCCA [10]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer7.log:2C973AF0F1 [10]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [10]
FirewallRules: [TCP Query User{B1A6C29C-820D-46D7-8E4C-1E412E481957}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe => Brak pliku
FirewallRules: [UDP Query User{17646151-8747-4BA9-8E57-BB8B554C807A}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe => Brak pliku
FirewallRules: [TCP Query User{D3DE6175-A695-4FA0-9E4E-004E0797774D}C:\program files\epic games\gtav\gta5.exe] => (Block) C:\program files\epic games\gtav\gta5.exe => Brak pliku
FirewallRules: [UDP Query User{0B8661BC-1946-4002-A56C-563EDDE79F1A}C:\program files\epic games\gtav\gta5.exe] => (Block) C:\program files\epic games\gtav\gta5.exe => Brak pliku
FirewallRules: [TCP Query User{2FF5EF83-8968-4FA3-8DC5-516D224C6010}C:\program files\java\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\javaw.exe => Brak pliku
FirewallRules: [UDP Query User{92115BD4-1717-4598-832D-1B08004CA0C1}C:\program files\java\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_281\bin\javaw.exe => Brak pliku
FirewallRules: [{8DDA269F-8D60-454E-856C-ADF9FB336BC2}] => (Allow) C:\Program Files (x86)\HackShield\launcher.exe => Brak pliku
FirewallRules: [{0C4C7300-61E9-42D0-B52A-099980651FCB}] => (Allow) C:\Program Files (x86)\HackShield\launcher.exe => Brak pliku
FirewallRules: [{F6E7A53F-965B-406B-985D-7A66EA69E085}] => (Allow) C:\Program Files (x86)\HackShield\client\1.8\1.8.9\HackShield.exe => Brak pliku
Task: {A5061DD0-6BAD-4767-9156-44B8939F72B3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (Brak pliku)
Task: {B4370969-FEDE-4295-9452-027EF6CED26A} - System32\Tasks\AdLock Update Task-S-1-5-21-1154914137-4129568212-3990700504-1001 => "%WINDIR%\System32\msiexec.exe" /i "C:\Users\Właściciel\AppData\Local\Programs\AdLock\163f640756.msi" /quiet CHROME=1
Task: {BA776AB7-4BEC-4469-876B-153B4E4A96F8} - System32\Tasks\TaskbarX DESKTOP-M8N9LEJWłaściciel => explorer.exe taskbarx:"-tbs=3 -color=0;0;0;0 -tpop=0 -tsop=100 -as=elasticeaseinout -obas=cubiceaseinout -tbr=0 -asp=1000 -ptbo=0 -stbo=0 -lr=400 -oblr=400 -sr=0 -sr2=0 -sr3=0 -ftotc=1 -rzbt=1 -dtbsowm=1 "
AutoConfigURL: [{6FAD7336-3A26-4D51-BCD6-CF978C77D5BF}] => hxxp://35.236.159.79/win.pac <==== UWAGA
AutoConfigURL: [S-1-5-21-1154914137-4129568212-3990700504-1001] => hxxp://35.236.159.79/win.pac <==== UWAGA
S2 DFWSIDService; C:\Program Files (x86)\Wondershare\drfone\WsidService.exe [X]
S2 ElevationService; C:\Program Files (x86)\Wondershare\drfone\Addins\Recovery\ElevationService.exe [X]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 HPPrintScanDoctorService; "C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe" [X]
S2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [X]
S4 VBoxGuest; VBoxGuest [X]
S4 VBoxMouse; VBoxMouse [X]
S4 VBoxService; VBoxService [X]
S4 VBoxSF; VBoxSF [X]
S4 VBoxVideo; VBoxVideo [X]
S4 VBoxWddm; VBoxWddm [X]
EmptyTemp:
END::


W FRST kliknij na Fix (NAPRAW).

Daj raport z tego.

 

Zrób nowe logi FRST.

 

Zrób log z Farbar Service Scanner > http://download.bleepingcomputer.com/farbar/FSS.exe (do skanowania zaznacz wszystko). 

 

jessi
 

Odnośnik do komentarza

Uruchom FRST. 
Skopiuj to poniższe: (ale nigdzie nie wklejaj tego!) - FRST sam znajdzie "fixlist" w schowku systemowym

Spoiler

START::
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Brak pliku)
HKLM\...\Run: [WSVCUUpdateHelper.exe] => C:\Program Files\Wondershare\UniConverter 13\WSVCUUpdateHelper.exe (Brak pliku)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Brak pliku)
HKLM-x32\...\Run: [Backup] => C:\Program Files (x86)\Wondershare\drfone\Addins\Backup\DrFoneBackup.exe /hide (Brak pliku)
Task: {093747DF-12B6-421A-887E-08C6AEDA7404} - System32\Tasks\ZpEVDmIlefcqtj => rundll32 "C:\Program Files (x86)\ulQXJxdiHxSU2\iubiwSBgqMTtv.dll",#1
Task: {0DBC642A-B424-4DC9-9CEA-007802D6CC78} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c (Brak pliku)
Task: {214DA309-B93A-4CA2-8B63-D1EBEA976A8B} - System32\Tasks\fNuIyawitAoDEGu2 => rundll32 "C:\Program Files (x86)\omepHXTcU\uiSgMt.dll",#1
Task: {7C16EB70-E5B3-41C6-9D90-15BCFCBBE3A7} - System32\Tasks\wgPoVvFawHYrCSXOC2 => rundll32 "C:\Program Files (x86)\PrRHHpsGxQEuyNXpirR\NhVVWjq.dll",#1
Task: {7DFB8387-310A-4B66-9B87-0FA4CE7D6C2D} - System32\Tasks\rNfsrCYQpNqfOcrfNNU2 => rundll32 "C:\Program Files (x86)\BayioKoEHcCpC\RJEmUKf.dll",#1
RemoveDirectory: C:\Program Files (x86)\PrRHHpsGxQEuyNXpirR
RemoveDirectory: C:\Program Files (x86)\ulQXJxdiHxSU2
RemoveDirectory: C:\Program Files (x86)\omepHXTcU
RemoveDirectory: C:\Program Files (x86)\BayioKoEHcCpC
Task: {B4370969-FEDE-4295-9452-027EF6CED26A} - System32\Tasks\AdLock Update Task-S-1-5-21-1154914137-4129568212-3990700504-1001 => "%WINDIR%\System32\msiexec.exe" /i "C:\Users\Właściciel\AppData\Local\Programs\AdLock\163f640756.msi" /quiet CHROME=1
AutoConfigURL: [{6FAD7336-3A26-4D51-BCD6-CF978C77D5BF}] => hxxp://35.236.159.79/win.pac <==== UWAGA
AutoConfigURL: [S-1-5-21-1154914137-4129568212-3990700504-1001] => hxxp://35.236.159.79/win.pac <==== UWAGA
S2 DFWSIDService; C:\Program Files (x86)\Wondershare\drfone\WsidService.exe [X]
S2 ElevationService; C:\Program Files (x86)\Wondershare\drfone\Addins\Recovery\ElevationService.exe [X]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 HPPrintScanDoctorService; "C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe" [X]
S2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [X]
S4 VBoxGuest; VBoxGuest [X]
S4 VBoxMouse; VBoxMouse [X]
S4 VBoxService; VBoxService [X]
S4 VBoxSF; VBoxSF [X]
S4 VBoxVideo; VBoxVideo [X]
S4 VBoxWddm; VBoxWddm [X]
StartRegedit:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv]
"PreshutdownTimeout"=dword:036ee800
"DisplayName"="@%systemroot%\\system32\\wuaueng.dll,-105"
"ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
  74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Description"="@%systemroot%\\system32\\wuaueng.dll,-106"
"ObjectName"="LocalSystem"
"ErrorControl"=dword:00000001
"Start"=dword:00000002
"DelayedAutoStart"=dword:00000001
"Type"=dword:00000020
"DependOnService"=hex(7):72,00,70,00,63,00,73,00,73,00,00,00,00,00
"ServiceSidType"=dword:00000001
"RequiredPrivileges"=hex(7):53,00,65,00,41,00,75,00,64,00,69,00,74,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
  65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
  00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
  61,00,74,00,65,00,50,00,61,00,67,00,65,00,46,00,69,00,6c,00,65,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,54,00,63,00,\
  62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,\
  00,41,00,73,00,73,00,69,00,67,00,6e,00,50,00,72,00,69,00,6d,00,61,00,72,00,\
  79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,\
  00,67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,\
  6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
  00,00,00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,\
  75,00,6f,00,74,00,61,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
  00,00,00,53,00,65,00,53,00,68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,\
  72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
  00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\Parameters]
"ServiceDll"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
  00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  77,00,75,00,61,00,75,00,65,00,6e,00,67,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="WUServiceMain"
"ServiceDllUnloadOnStop"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wuauserv\Security]
"Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,00,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,48,00,03,00,00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,ff,01,0f,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\
  01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
EndRegedit:
EmptyEventLogs: 
EmptyTemp:
END::


W FRST kliknij na Fix (NAPRAW).

 

Daj z tego usuwania raport.

 

Zrób nowe log z FRST oraz z FSS.

 

Znasz te programy:

Cytat

AdLock Privacy Ad Blocker 1.0.0.0 (HKU\S-1-5-21-1154914137-4129568212-3990700504-1001\...\{2e143188-cc4f-4e9a-a9df-63015b904811}) (Version: 1.0.0.0 - AdLock) Hidden
aqSearcher 1.34 (HKLM-x32\...\{B612D48E-91B4-4910-9006-9BC6A208E137}_is1) (Version: 1.3.0.33 - AQSearcher)

 

jessi

 

Odnośnik do komentarza

1) Uruchom FRST.
Skopiuj to poniższe: (ale nigdzie nie wklejaj tego!) - FRST sam znajdzie "fixlist" w schowku systemowym

Spoiler

START::
Tcpip\..\Interfaces\{9ef110dc-0abd-4fdf-a1d0-d4d2df741bac}: [NameServer] 178.175.133.61,45.95.11.175
AdLock Privacy Ad Blocker 1.0.0.0 (HKU\S-1-5-21-1154914137-4129568212-3990700504-1001\...\{2e143188-cc4f-4e9a-a9df-63015b904811}) (Version: 1.0.0.0 - AdLock) Hidden
Task: {65FC26C0-12A5-4315-8E31-6633FD6DC141} - System32\Tasks\Firefox Default Browser Agent 2EA14A206E338D7D => C:\Users\Właściciel\AppData\Roaming\fietvws.exe (Brak pliku) <==== UWAGA
C:\Users\Właściciel\AppData\Roaming\fietvws.exe
Task: {8B61079A-7A5C-473B-8AFE-CE821A435F94} - System32\Tasks\Intelligent StandbyList Cleaner => C:\Users\Właściciel\Desktop\ISLC v1.0.2.5\Intelligent standby list cleaner ISLC.exe (Brak pliku)
S3 BraveElevationService; "C:\Program Files\BraveSoftware\Brave-Browser\Application\104.1.42.97\elevation_service.exe" [X]
C:\Users\Właściciel\Downloads\fixlist.txt
EmptyTemp:
END::


W FRST kliknij na Fix (NAPRAW).

 

2) Teraz program AdLock Privacy Ad Blocker 1.0.0.0 (HKU\S-1-5-21-1154914137-4129568212-3990700504-1001\...\{2e143188-cc4f-4e9a-a9df-63015b904811})

powinien się już pokazać, więc spróbuj go odinstalować.

 

3) >START > URUCHOM > wybierz lub wpisz: services.msc

w okienku po prawej znajdź usługę "Centrum Zabezpieczeń"

po lewej kliknij na "Uruchom usługę"

 

4) Napisz, jak oceniasz sytuację po tych zabiegach?

 

jessi

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...