14 Paź 2015, 13:27
16 Paź 2015, 11:50
Task: C:\Windows\Tasks\QuickSend.job => c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}\7292064150217130620b.exe <==== UWAGA
c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
CHR dev: Chrome dev build wykryto! <======= UWAGA
ShellIconOverlayIdentifiers: [00avast] {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku
CHR HKU\S-1-5-21-614731021-3141606484-428700027-1000\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM-x32\...\Run: [Smart File Advisor] => C:\Program Files (x86)\Smart File Advisor\sfa.exe [283248 2015-02-04] (Filefacts.net)
C:\Program Files (x86)\Smart File Advisor
EmptyTemp:
18 Paź 2015, 11:58
18 Paź 2015, 12:51
Następnie podaj nowe logi z FRST.
10 Lis 2015, 13:36
12 Lis 2015, 17:18
21 Lis 2015, 17:11
22 Lis 2015, 18:59
02 Gru 2015, 14:20
02 Gru 2015, 16:56
Odinstaluj SecurityUtility, WinZipper.
02 Gru 2015, 22:45
mateo8898 napisał(a):Odinstaluj SecurityUtility, WinZipper.
Wykonałeś to? Bo te elementy nadal widnieją w zainstalowanych programach.
03 Gru 2015, 17:10
Task: {00920B07-3796-431E-8557-E77612F10D7D} - System32\Tasks\XPRICZF1 => C:\ProgramData\SecurityUtility\SecurityUtility.exe [2015-09-26] (SecurityUtility) <==== UWAGA
C:\ProgramData\SecurityUtility
Task: C:\Windows\Tasks\XPRICZF1.job => C:\ProgramData\SecurityUtility\SecurityUtility.exe <==== UWAGA
Task: {74199555-72AA-485A-B43A-4E783D691DCA} - System32\Tasks\QuickSend => c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}\7292064150217130620b.exe <==== UWAGA
c:\programdata\{237fffb7-aa50-e38d-237f-fffb7aa5fede}
AppInit_DLLs: C:\ProgramData\SecurityUtility\SecurityUtility64.dll => Brak pliku
AppInit_DLLs-x32: C:\ProgramData\SecurityUtility\SecurityUtility32.dll => Brak pliku
SearchScopes: HKLM DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM-x32 DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKLM-x32 {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-614731021-3141606484-428700027-1000 DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-614731021-3141606484-428700027-1000 {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447139520&z=1ded44833991871bba88f6bg1zdz7m5g1cbt6w0o5o&from=wpm07163&uid=ST1000DL002-9TT153_W1V166P8XXXXW1V166P8&q={searchTerms}
FF Extension: Brak nazwy - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\0wbuyme5.default\extensions\[email protected] [nie znaleziono]
FF Extension: Brak nazwy - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\0wbuyme5.default\extensions\[email protected] [nie znaleziono]
2015-12-02 13:15 - 2015-07-26 11:52 - 00000000 ____D C:\AdwCleaner
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:
03 Gru 2015, 19:30
04 Gru 2015, 20:40
05 Gru 2015, 00:34