UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.107 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Task: C:\Windows\Tasks\QuickSend.job => c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}\7292064150217130620b.exe <==== UWAGA
c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
CHR dev: Chrome dev build wykryto! <======= UWAGA
ShellIconOverlayIdentifiers: [00avast] {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku
CHR HKU\S-1-5-21-614731021-3141606484-428700027-1000\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM-x32\...\Run: [Smart File Advisor] => C:\Program Files (x86)\Smart File Advisor\sfa.exe [283248 2015-02-04] (Filefacts.net)
C:\Program Files (x86)\Smart File Advisor
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.107 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Następnie podaj nowe logi z FRST.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.86 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
Odinstaluj SecurityUtility, WinZipper.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36
mateo8898 napisał(a):Odinstaluj SecurityUtility, WinZipper.
Wykonałeś to? Bo te elementy nadal widnieją w zainstalowanych programach.
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
Task: {00920B07-3796-431E-8557-E77612F10D7D} - System32\Tasks\XPRICZF1 => C:\ProgramData\SecurityUtility\SecurityUtility.exe [2015-09-26] (SecurityUtility) <==== UWAGA
C:\ProgramData\SecurityUtility
Task: C:\Windows\Tasks\XPRICZF1.job => C:\ProgramData\SecurityUtility\SecurityUtility.exe <==== UWAGA
Task: {74199555-72AA-485A-B43A-4E783D691DCA} - System32\Tasks\QuickSend => c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}\7292064150217130620b.exe <==== UWAGA
c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}
AppInit_DLLs: C:\ProgramData\SecurityUtility\SecurityUtility64.dll => Brak pliku
AppInit_DLLs-x32: C:\ProgramData\SecurityUtility\SecurityUtility32.dll => Brak pliku
SearchScopes: HKLM DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM-x32 DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM-x32 {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-614731021-3141606484-428700027-1000 DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-614731021-3141606484-428700027-1000 {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
FF Extension: Brak nazwy - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\0wbuyme5.default\extensions\[email protected] [nie znaleziono]
FF Extension: Brak nazwy - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\0wbuyme5.default\extensions\[email protected] [nie znaleziono]
2015-12-02 13:15 - 2015-07-26 11:52 - 00000000 ____D C:\AdwCleaner
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot]