Prosze o sprawdzenie logów.

Wszelkie problemy komputerowe, których nie można jednoznacznie sklasyfikować do wybranego działu

Awatar użytkownika
djarta

Globalny Moderator
Posty: 5854
Rejestracja: 26 gru 2008, 17:15
Lokalizacja: Białystok
Kontaktowanie:

Prosze o sprawdzenie logów.

Post03 lut 2015, 14:45

1. Otwórz notatnik i wklej:
CloseProcesses:
S3 btwampfl; system32\drivers\btwampfl.sys [X]
S3 btwaudio; system32\drivers\btwaudio.sys [X]
S3 btwavdt; system32\drivers\btwavdt.sys [X]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X]
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
S3 cpuz130; No ImagePath
S2 DgiVecp; No ImagePath
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] ()
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14944 2014-11-18] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] ()
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] ()
C:\Windows\system32\EuGdiDrv.sys
C:\Windows\SysWOW64\EuGdiDrv.sys
C:\Windows\SysWOW64\epmntdrv.sys
C:\Windows\system32\epmntdrv.sys
R2 SyncThru Admin 5 Database; C:/Program Files (x86)/Samsung Network Printer Utilities/SyncThru Admin 5/postgresql/engine/bin/pg_ctl.exe runservice -N "SyncThru Admin 5 Database" -D "C:/Program Files (x86)/Samsung Network Printer Utilities/SyncThru Admin 5/postgresql/database" [X]
CHR HKU\S-1-5-21-2706788398-920284960-3489454249-1001\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Aga\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-07-28]
CHR HKU\S-1-5-21-2706788398-920284960-3489454249-1001\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
FF Extension: No Name - C:\Users\Aga\AppData\Roaming\Mozilla\Firefox\Profiles\a4egat7t.default\extensions\faststartff@gmail.com [Not Found]
HKU\S-1-5-21-2706788398-920284960-3489454249-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2706788398-920284960-3489454249-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll No File
ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll No File
ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll No File
ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll No File
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
2015-02-02 22:16 - 2015-02-02 23:41 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task cf2d915c-9926-449c-8334-7e7b2c96f8a5.job
2015-02-02 22:16 - 2015-02-02 23:41 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 5fd67b57-d841-485a-8a21-8ec0508cf5b6.job
2015-02-02 22:16 - 2015-02-02 22:16 - 00003576 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 5fd67b57-d841-485a-8a21-8ec0508cf5b6
2015-02-02 22:16 - 2015-02-02 22:16 - 00003502 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task cf2d915c-9926-449c-8334-7e7b2c96f8a5
Task: {0E16EADD-E9B2-41C0-8734-C36C099A9388} - System32\Tasks\{59C4F0B2-D0E0-4C55-9BB3-2D2330FA8771} => C:\Program Files (x86)\Diablo\Diablo.exe
Task: {167DD38A-4C32-423F-AFBF-3006AE0FDEDE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {33FE534C-AF2D-429F-A099-8A8B7A4A4DD4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {3B317F31-9DDD-47F1-80D3-C8ADEE2B4EC7} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {3C4F3A9C-817E-4D85-9886-C093CD75DF81} - System32\Tasks\{942CAA80-0209-4283-A9AE-4B7008BB9C19} => C:\Program Files (x86)\Diablo\Diablo.exe
Task: {3F64566F-1DA9-4078-8B75-7C5176100AC3} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {472B1821-E4D6-47F5-82E3-229247FC4B1F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {590730A7-49D1-4187-BE46-3E42093B049A} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe
Task: {59418CD6-A361-4448-B3B7-F70DCCF191AE} - System32\Tasks\{D092C974-3407-4E9D-BFC8-F6381E9D7366} => C:\Program Files (x86)\Halo Spartan Assault\Data\HaloSpartanAssault.exe
Task: {5A4ADC3B-3FB8-4440-BECA-BE89B55872F6} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {6B6E0992-872D-4EE2-B754-704429CEFBC4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {73CAADE0-6D73-47A4-B03D-CC76A19900F7} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {836249C0-6D1F-4F54-8087-DC4D2848B743} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2706788398-920284960-3489454249-1001
Task: {8FF11F61-5A3F-4AF1-BF9C-D0C137E12BBC} - System32\Tasks\SUPERAntiSpyware Scheduled Task cf2d915c-9926-449c-8334-7e7b2c96f8a5 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {948613EC-ADAB-41D3-B326-98117E2D8F85} - System32\Tasks\{97E9314F-32E0-42CE-8853-08C9749745F6} => C:\Program Files (x86)\Diablo\Diablo.exe
Task: {96FA5ED8-7BDD-44C5-98C5-D9C5A6693F17} - System32\Tasks\{D7CEADD6-3718-4A89-B026-A7DF54117CBE} => C:\Program Files (x86)\Diablo\Diablo.exe
Task: {C0ABF9AB-8DA9-4F63-BAEF-968015DB4BF1} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {C4A21135-B9D5-4113-9705-9C177F86247F} - System32\Tasks\Opera scheduled Autoupdate 1415905830 => C:\Program Files (x86)\Opera\launcher.exe [2015-01-23] (Opera Software)
Task: {CC6A0185-5178-4530-BE4C-C8C3B0D3ADA4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-28] (Adobe Systems Incorporated)
Task: {DB4842B2-2D0E-471E-AECD-3D6F77E06462} - System32\Tasks\{3F5C4FA5-5102-4EDB-95C3-3852F8109D96} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {E01C161F-AF68-4C2F-B3CA-B59CDA051FF7} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-05-31] (Sony Corporation)
Task: {F2B6A88E-11F3-4CA3-82F9-F11CC9B9E6FA} - System32\Tasks\SUPERAntiSpyware Scheduled Task 5fd67b57-d841-485a-8a21-8ec0508cf5b6 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {F514BE2C-CA05-48AC-B7F8-8E809E562F57} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-05-31] (Sony Corporation)
Task: {F9326B77-481B-4214-ADDD-47E38CF8F98A} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {FE2BAA29-C5BE-48FA-A275-844C62A6543F} - System32\Tasks\{3326CB6F-D804-4EF8-874E-A4F7C3297CE3} => C:\Fakturka\Fakturka.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 5fd67b57-d841-485a-8a21-8ec0508cf5b6.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task cf2d915c-9926-449c-8334-7e7b2c96f8a5.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
AlternateDataStreams: C:\Users\Aga\AppData\Local\0pZ3oASz2W:VHY66M2CLMOjyjKn7zRK
AlternateDataStreams: C:\Users\Aga\AppData\Local\WclP4fdqfa:9vb3XedYrCugWoup9DP
AlternateDataStreams: C:\ProgramData\TEMP:27A6A257
AlternateDataStreams: C:\ProgramData\TEMP:430C6D84
AlternateDataStreams: C:\ProgramData\TEMP:55B41E6A
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2
AlternateDataStreams: C:\ProgramData\TEMP:ECF54A0E
Hosts:
Emptytemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix.

2. Użyj >Dostępne tylko dla zarejestrowanych użytkowników
najpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.
Pokaż raport z niego C:\AdwCleaner\AdwCleaner[S].txt

3. Uruchom Dostępne tylko dla zarejestrowanych użytkowników. Wciśnij dowolny klawisz i czekaj, aż skończy się operacja. (UWAGA: podczas pobierania, programy mogą wskazywać, że to jest zagrożenie, proszę to zignorować). Pokaż raport.

4. Wykonaj i wklej nowe logi z FRST.

Cretino

Użytkownik
Posty: 3
Rejestracja: 03 lut 2015, 14:23

Prosze o sprawdzenie logów.

Post03 lut 2015, 20:43

pkt. 1. zrobiony

pkt. 2. zrobiony, raport (pozwalam se tutaj bo krotki jest):

# AdwCleaner v4.109 - Log utworzony 03/02/2015 o 20:23:38
# Aktualizacja 24/01/2015 przez Xplode
# Database : 2015-02-03.1 [Live]
# System operacyjny : Windows 7 Home Premium Service Pack 1 (64 bits)
# Użytkownik : Aga - AGA-VAIO
# Ścieżka : C:\Users\Aga\Downloads\adwcleaner_4.109.exe
# Opcja : Usuń

***** [ Usługi ] *****


***** [ Pliki / Foldery ] *****


***** [ Zadania ] *****


***** [ Skróty ] *****


***** [ Rejestr ] *****


***** [ Przeglądarki internetowe ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v33.0 (x86 pl)


-\\ Google Chrome v39.0.2171.95


-\\ Opera v27.0.1689.66


*************************

AdwCleaner[R4].txt - [3917 octets] - [02/02/2015 22:09:29]
AdwCleaner[R5].txt - [977 octets] - [03/02/2015 14:15:12]
AdwCleaner[R6].txt - [1035 octets] - [03/02/2015 14:38:12]
AdwCleaner[R7].txt - [1124 octets] - [03/02/2015 20:18:30]
AdwCleaner[S2].txt - [2129 octets] - [02/02/2015 23:36:36]
AdwCleaner[S3].txt - [1096 octets] - [03/02/2015 15:18:12]
AdwCleaner[S4].txt - [1043 octets] - [03/02/2015 20:23:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [1103 octets] ##########

pkt. 3 - JRT (tez tu bo krotki):

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Aga on 2015-02-03 at 20:32:05,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Aga\appdata\local\{E4CA8849-32BA-4F76-B158-5BB9C080F0DA}

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015-02-03 at 20:36:29,60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

pkt. 4. zaraz bedzie :P

-- 03 lut 2015, 20:43 --

FRST: Dostępne tylko dla zarejestrowanych użytkowników

Addition: Dostępne tylko dla zarejestrowanych użytkowników

Awatar użytkownika
djarta

Globalny Moderator
Posty: 5854
Rejestracja: 26 gru 2008, 17:15
Lokalizacja: Białystok
Kontaktowanie:

Prosze o sprawdzenie logów.

Post03 lut 2015, 20:46

Wykonaj wszystko z tego tematu: Kroki kończące temat.
Końcowo pokazujesz: raport z DelFix oraz raport z pełnego skanowania Malwarebytes

Cretino

Użytkownik
Posty: 3
Rejestracja: 03 lut 2015, 14:23

Prosze o sprawdzenie logów.

Post04 lut 2015, 13:09

# DelFix v10.8 - Logfile created 03/02/2015 at 21:03:39
# Updated 29/07/2014 by Xplode
# Username : Aga - AGA-VAIO
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\log.txt
Deleted : C:\TDSSKiller.3.0.0.44_02.02.2015_22.07.50_log.txt
Deleted : C:\Users\Aga\Desktop\Addition.txt
Deleted : C:\Users\Aga\Desktop\FRST.txt
Deleted : C:\Users\Aga\Desktop\FRST64 (2).exe
Deleted : C:\Users\Aga\Desktop\JRT.txt
Deleted : C:\Users\Aga\Downloads\Addition.txt
Deleted : C:\Users\Aga\Downloads\AdwCleaner (1).exe
Deleted : C:\Users\Aga\Downloads\AdwCleaner.exe
Deleted : C:\Users\Aga\Downloads\adwcleaner_4.109.exe
Deleted : C:\Users\Aga\Downloads\Extras.Txt
Deleted : C:\Users\Aga\Downloads\FRST.txt
Deleted : C:\Users\Aga\Downloads\FRST64 (1).exe
Deleted : C:\Users\Aga\Downloads\FRST64 (2).exe
Deleted : C:\Users\Aga\Downloads\FRST64.exe
Deleted : C:\Users\Aga\Downloads\JRT.exe
Deleted : C:\Users\Aga\Downloads\HiJackThis.msi
Deleted : C:\Users\Aga\Downloads\OTL.Txt
Deleted : C:\Users\Aga\Downloads\OTL.exe
Deleted : C:\Users\Aga\Downloads\Shortcut.txt
Deleted : C:\Users\Aga\Downloads\tdsskiller (1).exe
Deleted : C:\Users\Aga\Downloads\tdsskiller (2).exe
Deleted : C:\Users\Aga\Downloads\tdsskiller.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner

########## - EOF - ##########

-- 03 lut 2015, 21:11 --

2. wykonany ze wskazanego tematu ...

3. wykonany ze wskazanego tematu ....

-- 04 lut 2015, 13:09 --

Malwarebytes Anti Malware - niestety nie generuje logu zadnego :(



  • Reklama

Wróć do „Problemy”



Kto jest online

Użytkownicy przeglądający to forum: Obecnie na forum nie ma żadnego zarejestrowanego użytkownika i 4 gości