Deal Keeper


(Mani 78) #1

Nie jestem pewny czy wszystko zostalo wyczyszczone. Prosze o sprawdzenie logow.

 

 

AdvCleaner

http://www.wklej.org/id/1433750/

 

FRST

http://www.wklej.org/id/1433760/

 

Addition

http://www.wklej.org/id/1433762/


(Acorus) #2

Odinstaluj ASUS WebStorage,Foxtab.Otwórz Notatnik i wklej:

Task: {139834AC-9A05-4165-917C-3348C1115C28} - System32\Tasks\WOT W1 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {1F4C65A4-7945-48F4-969C-91521FF686DF} - System32\Tasks\WOT WTHUR1 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {352938E1-990E-4CC1-B6E4-482ACBDD0204} - System32\Tasks\WOT WFRI1 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {7F84E4F7-F7B5-4807-9B04-EB9BD39CF4D9} - System32\Tasks\WOT WWED1 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {C6864561-7BCB-4CEE-B563-28028982F7CE} - System32\Tasks\WOT WW2 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {FA37C5F3-C384-4280-BF2F-8F2764D1D479} - System32\Tasks\WOT WW1 = Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
HKLM-x32\...\Run: [ASUSWebStorage] = C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
S2 Update Deal Keeper; "C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe" [X]
S2 Util Deal Keeper; "C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe" [X]
S3 atillk64; \\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 catchme; \\C:\ComboFix\catchme.sys [X]
2014-08-06 11:54 - 2014-08-06 12:01 - 00000000 ____ D () C:\AdwCleaner
2014-08-02 21:45 - 2014-08-02 23:39 - 00000000 ____ D () C:\Program Files (x86)\Deal Keeper
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT WWED1
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT WW2
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT WW1
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT WTHUR1
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT WFRI1
2014-08-02 21:45 - 2014-08-02 21:45 - 00003462 _____ () C:\Windows\System32\Tasks\WOT W1
2014-08-02 21:45 - 2014-08-02 21:45 - 00000000 ____ D () C:\Users\Maniek\AppData\Roaming\SimilarAddon
2014-08-02 21:45 - 2014-08-02 21:45 - 00000000 ____ D () C:\Program Files (x86)\SiteLookup
CMD: del /f /s /q %TEMP%\*.*

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Mani 78) #3

Dzieki za pomoc, ale to badziewie dalej  mi buszuje po kompie :confused:

dorzucam nowe skany

 

Malwarebytes Anti-Malware

PUP.Optional.DealKeeper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1ec8187a-6435-44e3-bbe4-6ce6d3c69254}, , [2672358dde9da6908ff55b0a4fb3ca36],
PUP.Optional.DealKeeper.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{ba0ab49b-34a1-4c36-bb3b-e6f458974507}, , [2672358dde9da6908ff55b0a4fb3ca36],
PUP.Optional.DealKeeper.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3D62014A-A3A3-45C4-AAD8-754A3B854048}, , [2672358dde9da6908ff55b0a4fb3ca36],
PUP.Optional.DealKeeper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3D62014A-A3A3-45C4-AAD8-754A3B854048}, , [2672358dde9da6908ff55b0a4fb3ca36],
PUP.Optional.DealKeeper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{ba0ab49b-34a1-4c36-bb3b-e6f458974507}, , [2672358dde9da6908ff55b0a4fb3ca36],

AdwCleaner

Klucz Znaleziono : HKCU\Software\Conduit
Klucz Znaleziono : [x64] HKCU\Software\Conduit
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASAPI32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\DealKeeper_RASMANCS
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASAPI32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\updateDealKeeper_RASMANCS

-\ Mozilla Firefox v31.0 (x86 pl)

[Plik : C:\Users\Maniek\AppData\Roaming\Mozilla\Firefox\Profiles\z650q86z.default\prefs.js]

-\ Google Chrome v36.0.1985.125

[Plik : C:\Users\Maniek\AppData\Local\Google\Chrome\User Data\Default\preferences]

FRST

 

Addition

http://www.wklej.org/id/1436639/


(Acorus) #4

W logach nie widać .Usuń to co znalazł Malwarebytes i AdwCleaner.