poweeK
(Bakus352)
24 Sierpień 2015 13:45
#1
Tak jak w temacie, od pewnego czasu nie uruchamiają mi się programy regedit oraz ccleaner, wcześniej nie były mi one zbyt potrzebne więc nie interesowałem się zbytnio tym, że po prostu nie działają.
Teraz jestem troszkę zaniepokojony tym że nadal nie chcą się uruchamiać.
Proszę o szybką pomoc i pozdrawiam
Atis
(Atis)
24 Sierpień 2015 14:17
#2
poweeK
(Bakus352)
24 Sierpień 2015 15:02
#3
Atis
(Atis)
24 Sierpień 2015 17:24
#4
W takim przypadku wystarczy zmienić nazwę FRST na losową.
W panelu sterowania odinstaluj:
Akamai NetSession Interface
Foxtab
GoHD
PC Speed Maximizer v3.2
webssearches uninstall
WindowsMangerProtect20.0.0.722
Pobierz i uruchom AdwCleaner Kliknij Scan i później Cleaning.
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
HKU\S-1-5-21-2675070612-3490617206-619097661-1000\...\Run: [Akamai NetSession Interface] => C:\Users\User\AppData\Local\Akamai\netsession_win.exe [4691384 2015-07-23] (Akamai Technologies, Inc.)
IFEO\adwcleaner_4.204.exe: [Debugger] svchost.exe
IFEO\AnVir.exe: [Debugger] svchost.exe
IFEO\AutoLogger.exe: [Debugger] svchost.exe
IFEO\avz.exe: [Debugger] svchost.exe
IFEO\CCleaner.exe: [Debugger] svchost.exe
IFEO\CCleaner64.exe: [Debugger] svchost.exe
IFEO\FRST.exe: [Debugger] svchost.exe
IFEO\FRST64.exe: [Debugger] svchost.exe
IFEO\HiJackThis.exe: [Debugger] svchost.exe
IFEO\regedit.exe: [Debugger] svchost.exe
IFEO\RegWorks.exe: [Debugger] svchost.exe
IFEO\RSIT.exe: [Debugger] svchost.exe
IFEO\RSITx64.exe: [Debugger] svchost.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
OPR Extension: (GoHD) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\bokijhalndhhhikpnaniimagniglonke [2014-11-12]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [157824 2015-05-20] (XTab system)
Task: {08E30F29-1CE0-4DFA-B788-2F74839D968E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {1D07B4C0-BC65-4937-9B98-73691C264C01} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {37867BE2-8F5F-40FD-9993-BE2ECF1D5C7E} - System32\Tasks\rG3FavrHUfeqvAxdTj6 => C:\Program Files (x86)\globalUpdate\Update\Install\{7930369F-E11A-463B-AA35-4AA3D190C9E5}\setup.exe <==== ATTENTION
Task: {38BB6485-F772-44F6-83AE-7F7224140B8A} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-1 => C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe <==== ATTENTION
Task: {3CD38CFA-2A8F-4404-8766-EDAD5156609B} - System32\Tasks\{7D7E31DE-CCEE-4BDC-8596-47560698E964} => D:\Magicka\Magicka.exe
Task: {4357E931-76DE-42EF-A191-7F564598AA2F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {43CEAEE7-2F7E-4EA9-93A7-37DDBAC49FB8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {546A50E5-F0A1-477D-BEF1-7C3E863A6CF5} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5 => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5.exe <==== ATTENTION
Task: {5B617777-4002-4B44-ACD9-F44B80C8A233} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-11 => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-11.exe <==== ATTENTION
Task: {6052B5CF-6FA1-4FF2-96AE-DF782C8274C5} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {64AF3E85-06D3-4263-8E4A-0797CC457238} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {72873AD0-BA92-45F7-BC5D-B0543A3B0444} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-2 => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-2.exe <==== ATTENTION
Task: {93318DBB-8AE0-48C5-9925-C72E06F1F392} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {99DC0D06-C7C5-430A-8FF7-998AAA68316C} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5_user => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5.exe <==== ATTENTION
Task: {A4E92E5F-F142-4E5F-BFE0-6A6DBFE903EF} - System32\Tasks\{EF8CF74A-9833-4A47-87DE-EE16C981E6F5} => pcalua.exe -a C:\Users\User\Downloads\dxwebsetup(pobierz.pl).exe -d C:\Users\User\Downloads
Task: {A780164A-58E0-4A92-82DA-FFB80CF24BE0} - System32\Tasks\{AD826C50-46B4-4F64-9BFF-4C3AA6349ED5} => D:\Magicka\Magicka.exe
Task: {ABAE352B-53C4-47CB-9D0B-A720A3AC16F7} - System32\Tasks\LndXzcEnGs1OAlY => C:\Program Files (x86)\globalUpdate\Update\Install\{77E6C6AD-639A-4D3C-A4E0-FAAC6FFA16A7}\setup.exe <==== ATTENTION
Task: {B9EC8228-828A-401E-A310-A9EB1B77FD8B} - System32\Tasks\YL56SGPuz0zgwtuSQFT => C:\Program Files (x86)\globalUpdate\Update\Install\{0B96C1F3-7090-46B1-8405-5274DC13ADC0}\setup.exe <==== ATTENTION
Task: {C0ADFFBF-820F-493D-96D4-1709A50E43ED} - System32\Tasks\qqnOZoZK58X8iz2m1TR => C:\Program Files (x86)\globalUpdate\Update\Install\{441D9FC7-D83E-4CC5-919B-96877AC48621}\setup.exe <==== ATTENTION
Task: {C37176AF-D085-4066-9317-CE362F2D5A06} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {CA8F32F9-94E1-42AD-A157-B7574867F29C} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D2E50970-DAC8-4E64-A5DD-8F38F233CF4D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {E0E25EB7-C32E-4FF5-BD27-AEBA6EE02285} - System32\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-4 => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-4.exe <==== ATTENTION
Task: {F64B42FA-983C-426D-AECF-1B554FD9799F} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-12] (globalUpdate) <==== ATTENTION
Task: {FC3C7C86-A4FC-4780-AC8B-2C302B1A8E2B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-1.job => C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-11.job => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-11.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-2.job => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-4.job => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-4.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5.job => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5_user.job => C:\Program Files (x86)\GoHD\5b8c1867-eda0-4be1-a8c7-f3fc27cc6e49-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
EmptyTemp:
Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.
Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.
poweeK
(Bakus352)
24 Sierpień 2015 17:48
#5
Zrobiłem jak chciałeś, oto rezultat skanowania FRST: http://wklej.to/NjMry
Co ciekawe po restarcie systemu bezpośrednio po odpaleniu się systemu wyskoczyło mi coś takiego: http://scr.hu/0bji/u6f92 a także w przeglądarce której domyślnie używam nie chce mi się włączyć forum http://scr.hu/0bji/r3iqa
Bo ogólnie regedit oraz ccleaner już działa, co było powodem że nie działało? Trojan jakiś?
Atis
(Atis)
24 Sierpień 2015 18:14
#6
Tak jakiś trojan.
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
HKU\S-1-5-21-2675070612-3490617206-619097661-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\User\AppData\Local\Akamai\netsession_win.exe"
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
SearchScopes: HKU\S-1-5-21-2675070612-3490617206-619097661-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422988338&from=smt&uid=WDCXWD10EZEX-08M2NA0_WD-WCC3FFN5ZUV55ZUV5&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2675070612-3490617206-619097661-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422988338&from=smt&uid=WDCXWD10EZEX-08M2NA0_WD-WCC3FFN5ZUV55ZUV5&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2675070612-3490617206-619097661-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=WDCXWD10EZEX-08M2NA0_WD-WCC3FFN5ZUV55ZUV5&ts=1422988348&type=default&q={searchTerms}
BHO: GoHD -> {11111111-1111-1111-1111-110611211180} -> C:\Program Files (x86)\GoHD\GoHD-bho64.dll Brak pliku
BHO-x32: GoHD -> {11111111-1111-1111-1111-110611211180} -> C:\Program Files (x86)\GoHD\GoHD-bho.dll Brak pliku
2015-08-24 19:29 - 2015-08-24 19:30 - 00000000 ____ D C:\AdwCleaner
2015-08-23 23:02 - 2015-08-24 19:39 - 00000442 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2015-08-06 11:23 - 2014-08-22 17:54 - 00000000 ____ D C:\Temp
Task: {7B278461-1972-468B-9254-9DA086874B33} - System32\Tasks\Web Car => Rundll32.exe "C:\Users\User\AppData\Local\Web Car\Bin\WebCar.dll",#3
DeleteQuarantine:
Uruchom FRST i kliknij Fix. Później skasuj folder C:\FRST
Dysk przeskanuj Malwarebytes Anti-Malware
Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.
http://wstaw.org/m/2014/03/25/2014-03-25_123039.png
Język PL > Settings > General Settings > Language > Polish
Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK
Odinstaluj Java 7 Update 67 i Java 8 Update 25.
Zainstaluj Java 8 Update 60