Częsty reser kompa, dziwne procesy? nie wykrywa urządzeń


(Junak) #1

LOG

http://www.wklej.org/id/5091/

p.s. starałem się napisać posta według zasad. pomożecie? i sprawdzicie? :slight_smile:


(huber2t) #2

fix w hiajckthis

Podaj log z Combofix


(Junak) #3

LOG z Comofix

http://wklej.org/id/5571/


(huber2t) #4

Pobierz ComboFix, ale nie uruchamiaj

Otwórz notatnik i wklej do niego:

File::

C:\Documents and Settings\Wcatchme.zip

C:\WINDOWS\system32\upuuojei.dll

C:\WINDOWS\system32\upuuojei.nls

C:\WINDOWS\system32\glypodlb.dll

C:\WINDOWS\system32\disysrwb.dll

C:\WINDOWS\system32\dphqyacg.dll

C:\WINDOWS\system32\glypodlb.nls

C:\WINDOWS\system32\dphqyacg.nls

C:\WINDOWS\system32\disysrwb.nls

C:\WINDOWS\system32\jydhjaco.dll

C:\WINDOWS\system32\jrabhcsy.dll

C:\WINDOWS\system32\jydhjaco.nls

C:\WINDOWS\system32\jrabhcsy.nls

C:\WINDOWS\system32\tdvbvbyo.nls

C:\WINDOWS\system32\jrqqcduk.nls

C:\WINDOWS\system32\dtisoykm.nls

C:\WINDOWS\system32\aughvqcp.nls

C:\WINDOWS\system32\pequqian.nls

C:\WINDOWS\system32\mtvpyhic.nls


Registry::

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-

"{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"mtvpyhic.dll"=-

"jrabhcsy.dll"=-

"nwapi32dj.dll"=-

Plik -> zapisz jako -> CFScript.txt.

Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu->

cfscript10uc2.gif

Rozpocznie się usuwanie i powstanie log, który dasz na forum.

Logi dajesz na http://wklej.eu lub na http://wklej.org a w poście dajesz tylko link


(Junak) #5

Kolejny LOG

http://wklej.org/id/5746/


(Leon$) #6

pobierz i zastosuj ATF Cleaner http://cybertrash.pl/images/tata/ATF/ATF.html

Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl

pobierz i przeskanuj Kaspersky Virus Removal Tool http://www.searchengines.pl/index.php?s ... ntry354381

potem nowy log Combifixa

Pobierz System Repair Engineer

http://www.cybertrash.pl/images/tata/System%20Repair/System%20Repair%20Engineer.html

przeskanuj daj log

:slight_smile:


(Junak) #7

ATF Cleaner zastosowałem

Wyłącz przywracanie systemu na wszystkich dyskach - zrobione

Kaspersky Virus Removal Tool - skanował ale nie do końca zacinał się :frowning: ponowna próba również nie udana. :evil: :?: :!:

LOG z Combofixa http://wklej.org/id/5949/

LOG z System Repair Engineer http://wklej.org/id/5951/


(huber2t) #8

Pobierz ComboFix, ale nie uruchamiaj

Otwórz notatnik i wklej do niego:

File::

C:\WINDOWS\system32\eqheccev.dll

C:\WINDOWS\system32\xlwathli.dll

C:\WINDOWS\system32\qbdutjzp.dll

C:\WINDOWS\system32\xlwathli.nls

C:\WINDOWS\system32\qbdutjzp.nls

C:\WINDOWS\system32\eqheccev.nls

C:\WINDOWS\system32\ghjvdwys.dll

C:\WINDOWS\system32\pikfkvat.dll

C:\WINDOWS\system32\pikfkvat.nls

C:\WINDOWS\system32\ghjvdwys.nls

C:\WINDOWS\system32\fhmoohuz.dll

C:\WINDOWS\system32\ssqwfgos.dll

C:\WINDOWS\system32\lutscltj.dll

C:\WINDOWS\system32\fhmoohuz.nls

C:\WINDOWS\system32\ssqwfgos.nls

C:\WINDOWS\system32\lutscltj.nls

C:\WINDOWS\system32\yqanwxux.dll

C:\WINDOWS\system32\rlpjottr.dll

C:\WINDOWS\system32\ohzkyrsp.dll

C:\WINDOWS\system32\xumazbtz.dll

C:\WINDOWS\system32\rlpjottr.nls

C:\WINDOWS\system32\ohzkyrsp.nls

C:\WINDOWS\system32\xumazbtz.nls

C:\WINDOWS\system32\yqanwxux.nls

C:\WINDOWS\system32\qydzlyge.dll

C:\WINDOWS\system32\qydzlyge.nls

C:\WINDOWS\system32\nwjmsxnu.nls

C:\WINDOWS\system32\cvhztxrw.dll

C:\WINDOWS\system32\jagsqqwv.dll

C:\WINDOWS\system32\mvxrgtxq.dll

C:\WINDOWS\system32\jagsqqwv.nls

C:\WINDOWS\system32\cvhztxrw.nls

C:\WINDOWS\system32\mvxrgtxq.nls

C:\WINDOWS\system32\vklnende.nls

C:\WINDOWS\system32\psfmhiat.nls

C:\WINDOWS\system32\pofshpxg.nls

C:\Program Files\YSFLIGHT.COM

C:\WINDOWS\system32\odtknxcd.nls

C:\WINDOWS\system32\ktkqfhgh.nls

C:\WINDOWS\system32\wwgmftfr.dll

C:\WINDOWS\system32\aolfsshs.nls

C:\WINDOWS\system32\wwgmftfr.nls


Registry::

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"3PMmUpdate"=-

"HBService"=-

"WinSysM"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}”=-

"{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}”=-

"{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}”=-

"{71A78CD4-E470-4a18-8457-E0E0283DD507}”=-

"{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}”=-

"{F0930A2F-D971-4828-8209-B7DFD266ED44}”=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"sysocmgr”=-

"omruqtuh.dll”=-

"oifhnovm.dll”=-

"pxjjzzsd.dll”=-

"vzrifyno.dll”=-

"zvwnsrac.dll”=-

"dmchfpcv.dll”=-

Plik -> zapisz jako -> CFScript.txt.

Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu->

cfscript10uc2.gif

Rozpocznie się usuwanie i powstanie log, który dasz na forum.

Logi dajesz na http://wklej.eu lub na http://wklej.org a w poście dajesz tylko link

uruchom System Repair Engineer zakładka System Repair Browser Add-ons odszukaj i usuń


(Junak) #9

LOG z Combofix http://wklej.org/id/6153/

Usunięte:

  • {c95fe080-8f5d-11d2-a20b-00aa003c157a}

(Spandau) #10

Wyłącz przywracanie systemu na wszystkich dyskach. Instrukcja

Pobierz Combofix ale nie uruchamiaj wklej do notatnika:

File::

C:\WINDOWS\system32\drivers\nvmini.sys

C:\WINDOWS\linkinfo.dll

C:\Documents and Settings\Wcatchme.zip

C:\WINDOWS\system32\ylmkblgo.dll

C:\WINDOWS\system32\ryqsqkds.dll

C:\WINDOWS\system32\zosdofk.exe

C:\WINDOWS\system32\ylmkblgo.nls

C:\WINDOWS\system32\ryqsqkds.nls

C:\WINDOWS\system32\axzbwcqh.dll

C:\WINDOWS\system32\axzbwcqh.nls

C:\WINDOWS\system32\qsiqinrs.dll

C:\WINDOWS\system32\qpxdgjsx.dll

C:\WINDOWS\system32\qsiqinrs.nls

C:\WINDOWS\system32\qpxdgjsx.nls

C:\WINDOWS\system32\scnhmzfr.dll

C:\WINDOWS\system32\sjzwhxpz.dll

C:\WINDOWS\system32\bzpzlmff.dll

C:\WINDOWS\system32\vxpzfmkt.dll

C:\WINDOWS\system32\sjzwhxpz.nls

C:\WINDOWS\system32\scnhmzfr.nls

C:\WINDOWS\system32\bzpzlmff.nls

C:\WINDOWS\system32\vxpzfmkt.nls

C:\WINDOWS\system32\kacvuvdc.dll

C:\WINDOWS\system32\utpgntzg.dll

C:\WINDOWS\system32\xlgdluxv.nls

C:\WINDOWS\system32\utpgntzg.nls

C:\WINDOWS\system32\bzakwotu.nls

C:\WINDOWS\system32\kacvuvdc.nls

C:\WINDOWS\system32\arapebft.nls

C:\WINDOWS\system32\zvwnsrac.nls

C:\WINDOWS\system32\vzrifyno.nls

C:\WINDOWS\system32\dmchfpcv.nls

C:\WINDOWS\system32\pxjjzzsd.nls

C:\WINDOWS\system32\oifhnovm.nls

C:\WINDOWS\855731MM.DLL

C:\WINDOWS\855731M.exe

C:\WINDOWS\system32\zosdof.dll

C:\WINDOWS\system32\omruqtuh.nls

C:\WINDOWS\system32\nwapi32dj.dll

C:\WINDOWS\system32\nwapi32dj.nls

C:\WINDOWS\system32\twainyy.nls


Registry::

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}"=-

"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=-

[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nvmini]

Zapisz plik jako CFScript.txt najlepiej aby ikonka tego pliku znajdowała się obok ikonki ComboFix.exe

Przeciągnij i upuść plik CFScript.txt na ikonkę ComboFix.exe powinno rozpocząć się usuwanie po tym daj log na forum.

Loga wklej na http://www.wklejto.pl lub http://www.wklej.org/ a w poście daj linka


(Junak) #11

przywracanie wyłączone.

LOG z Combofixa http://www.wklej.org/id/6346/


(Leon$) #12

Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

potem nowy log System Repair przed skanem odznacz Hosts File

:slight_smile:


(Junak) #13

Log z Combofixa http://wklej.org/id/6979/

Log z System Repair http://wklej.org/id/6982/


(Leon$) #14

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

Pobierz program SDFix

-


(Junak) #15

Log z Combofix http://wklej.org/id/7413/

Report z SDFix http://wklej.org/id/7418/


(Junak) #16

kolejny loghttp://wklej.org/id/8055/\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\r\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\np.s. często komp się resetuje podczas uruchamiania Mozilla Firefox... doszło do tego ze cały czas tak się działo, przeskanowanie Combofixem pomogło, ale na jak długo??


(Leon$) #17

Wyłącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

:slight_smile:


(Junak) #18

log http://wklej.org/id/8240/


(Leon$) #19

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

Pobierz program SDFix

-


(Junak) #20

Log z combofix http://wklej.org/id/8502/

w miedzy czasie combofixa używałem kilka razy gdyż przy każdej próbie uruchomienia przeglądarki następował reset, dopiera combofix pomagał.

Report z SDFixhttp://wklej.org/id/8506/

Log z System Repair Engineer http://wklej.org/id/8511/

:slight_smile: