Reklamy w oknach Google Chrome

Wszystko co dotyczy bezpieczeństwa systemów oraz walki z malware, w szczególności analiza logów
mietus13

Użytkownik
Posty: 1
Rejestracja: 16 gru 2014, 11:18

Reklamy w oknach Google Chrome

Post16 gru 2014, 11:33

OTL Extras logfile created on: 2014-12-17 11:02:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\przemek\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,94 Gb Total Physical Memory | 1,68 Gb Available Physical Memory | 42,70% Memory free
7,89 Gb Paging File | 4,67 Gb Available in Paging File | 59,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116,34 Gb Total Space | 71,81 Gb Free Space | 61,73% Space Free | Partition Type: NTFS
Drive D: | 349,32 Gb Total Space | 48,91 Gb Free Space | 14,00% Space Free | Partition Type: NTFS

Computer Name: MIETUS | User Name: przemek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2050BD09-D752-449A-9A1A-A62C1522739E}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{51B4BA95-24DA-4A48-9B11-C994811C9373}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{21327CEB-34CC-4A77-ADCB-EB17E29DC428}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{43554B51-AD6B-422E-82A6-B70A8F396610}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{4B21E2D5-8434-4B0D-B419-0661AC6D0CD0}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{5057A2A6-A950-4189-83A2-6A0507BD4831}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{61135DEB-0A84-47DD-9F0F-3B36E5EA682E}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{6CB8D75E-DA8D-418A-9B96-A9365F503112}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{6EE142FC-5F90-4674-8D7C-3227716258DE}" = protocol=6 | dir=in | app=d:\wowww\starcraft ii\starcraft ii\starcraft ii.exe |
"{AB915DCA-EE24-48C4-A4D0-ABA1411BBE8B}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{D3E3F577-5AB1-434E-AEC4-A91AB99872AD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{E55083D2-8823-4D34-9BBB-4A7E2D5EEAD5}" = protocol=17 | dir=in | app=d:\wowww\starcraft ii\starcraft ii\starcraft ii.exe |
"TCP Query User{0A9B5E16-A3BC-4675-843D-06AC89EC6BA9}D:\wowww\starcraft ii\starcraft ii\versions\base32283\sc2.exe" = protocol=6 | dir=in | app=d:\wowww\starcraft ii\starcraft ii\versions\base32283\sc2.exe |
"TCP Query User{55D67623-D2BE-4682-8195-1D92F951E393}C:\torent2\starcraft no install\starcraft.exe" = protocol=6 | dir=in | app=c:\torent2\starcraft no install\starcraft.exe |
"TCP Query User{E73A515C-F90F-4D34-9911-C43968E8DF7E}C:\program files (x86)\dvdvideosoft\free torrent download\freetorrentdownload.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dvdvideosoft\free torrent download\freetorrentdownload.exe |
"UDP Query User{275D0AC8-0D90-4931-9110-364A7D268EE1}C:\torent2\starcraft no install\starcraft.exe" = protocol=17 | dir=in | app=c:\torent2\starcraft no install\starcraft.exe |
"UDP Query User{3C61A25E-8FAA-4872-AA18-57CC0042AC98}D:\wowww\starcraft ii\starcraft ii\versions\base32283\sc2.exe" = protocol=17 | dir=in | app=d:\wowww\starcraft ii\starcraft ii\versions\base32283\sc2.exe |
"UDP Query User{7A224A4A-7A9B-46B4-9438-67956A5F2984}C:\program files (x86)\dvdvideosoft\free torrent download\freetorrentdownload.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dvdvideosoft\free torrent download\freetorrentdownload.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B9D5D50-1530-496F-81FF-CB1B4A298FCA}" = Intel(R) Chipset Device Software
"{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components
"{203BCA8D-BC00-4DD5-85DF-2F84DB803B57}" = Sonic Radar II
"{3DE97849-544D-4D68-9255-11DF6F9F10D8}" = Intel® Trusted Connect Service Client
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Sterownik dźwięku HD 1.3.16.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B9C27F57-AB84-425F-9D00-E18C5D65C18D}" = Intel(R) Rapid Storage Technology
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D4FC649C-0247-4873-930D-D9E6904DCAF5}" = Intel(R) Management Engine Components
"{E1CBE9A2-1323-488E-9F3B-736DF6399F38}" = Intel(R) Management Engine Components
"{FD42EE05-18F9-459F-935D-770E75B3BEE5}" = Intel(R) Network Connections 19.1.51.0
"McAfee Security Scan" = McAfee Security Scan Plus
"PodoWeb" = PodoWeb
"PROSetDX" = Intel(R) Network Connections 19.1.51.0
"TeamSpeak 3 Client" = TeamSpeak 3 Client

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Polish
"{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}" = ASUS Product Register Program
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f3e3c5dd-edd0-406b-8aa2-ce5acb93660e}" = Oprogramowanie mikroukładu Intel®
"Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI
"Adobe Flash Player PPAPI" = Adobe Flash Player 16 PPAPI
"Avast" = Avast Free Antivirus
"Battle.net" = Battle.net
"DAEMON Tools Lite" = DAEMON Tools Lite
"Elite Unzip" = Elite Unzip
"Free Torrent Download_is1" = Free Torrent Download version 1.0.27.1111
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"StarCraft II" = StarCraft II
"WinRAR archiver" = WinRAR 5.11 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"MyFreeCodec" = MyFreeCodec
"OpenFM" = OpenFM

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2014-12-17 05:06:54 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:06:54 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:06:54 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:36:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:36:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:36:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 05:36:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 06:06:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 06:06:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

Error - 2014-12-17 06:06:55 | Computer Name = mietus | Source = ESENT | ID = 412
Description = wuaueng.dll (568) SUS20ClientDataStore: Nie można odczytać nagłówka
pliku dziennika C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Błąd -546.

[ System Events ]
Error - 2014-12-17 05:54:28 | Computer Name = mietus | Source = DCOM | ID = 10010
Description =

Error - 2014-12-17 06:01:08 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:02:18 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:04:09 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:05:01 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:05:30 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:05:30 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:07:52 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:08:24 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =

Error - 2014-12-17 06:08:43 | Computer Name = mietus | Source = DCOM | ID = 10016
Description =


< End of report >

Awatar użytkownika
XMan

Globalny Moderator
Posty: 13385
Rejestracja: 30 lis 2008, 00:40

Reklamy w oknach Google Chrome

Post16 gru 2014, 12:01

Użyj opcji EDYTUJ.

Wrzuć obowiązkowe logi
OTL.txt i Extras.txt --> http://www.hotfix.pl/obsluga-programu-otl-a143.htm
FRST --> bezpieczenstwo/korzystanie-z-frst-t28530.html

Logi/raporty wklejasz na:
Dostępne tylko dla zarejestrowanych użytkowników
lub: Dostępne tylko dla zarejestrowanych użytkowników
a na forum podajesz tylko linki do nich.

Przenoszę z Zagrożenia i leczenie :arrow: Bezpieczeństwo,
XMan.
Kto pyta - nie błądzi, kto szuka - znajduje.
Obrazek
Dostępne tylko dla zarejestrowanych użytkowników



  • Reklama

Wróć do „Bezpieczeństwo”



Kto jest online

Użytkownicy przeglądający to forum: Obecnie na forum nie ma żadnego zarejestrowanego użytkownika i 3 gości