Infekcja z pendrive'a


(Arek Nawrocki) #1

Cześć!


(Atis) #2

W panelu sterowania odinstaluj:

AppCloudUpdater

Rock Turner

SpeedyPC Pro

sweet-page uninstaller

WPM17.8.0.3442

Pobierz i uruchom AdwCleaner Kliknij Szukaj i później Usuń.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.


(Arek Nawrocki) #3

Dzięki za bardzo szybką odpowiedź. Przez panel sterowania mogłem odinstalować jedynie Rock Turner (nie miałem wcześniej tego programu). Uruchomiłem komputer ponownie, ale mozilla działa jeszcze wolniej niż przed usunięciem. W pozostałej części system odzyskał normalną prędkość.

 

Poniżej log.

 

http://www.sendspace.pl/file/dfb52af2f9a3eb5673e7cfa


(Atis) #4

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No File
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No File
S2 Update Rock Turner; "C:\Program Files (x86)\Rock Turner\updateRockTurner.exe" [X]
R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys [61120 2014-06-02] (StdLib)
R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w64; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w64.sys [61120 2014-05-22] (StdLib)
C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
C:\Windows\system32\Drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys
C:\AdwCleaner
C:\Windows\system32\Drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w64.sys
C:\Program Files (x86)\Rock Turner
C:\Users\T420\AppData\Local\Temp\*.dll
C:\Users\T420\AppData\Local\Temp\*.exe
Task: {0A4A99B1-2B6E-4BC2-8377-B29BA24A2A81} - \Microsoft\Windows\Media Center\InstallPlayReady No Task File <==== ATTENTION
Task: {38280DB2-4B40-41FC-8634-381AFD13A05E} - \Microsoft\Windows\Media Center\OCURActivate No Task File <==== ATTENTION
Task: {3E9ECD48-7BC0-47EA-98A5-BA48CD4C3762} - System32\Tasks\SpeedyPC Pro => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2012-11-22] (SpeedyPC Software, Inc.)
Task: {412FACFE-7369-4A05-93C4-4B9F3448484E} - \Microsoft\Windows\Media Center\RecordingRestart No Task File <==== ATTENTION
Task: {4BFB40E8-19DE-4D0B-9A45-694C47D67BDC} - \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask No Task File <==== ATTENTION
Task: {6691AF13-1015-4E15-92EB-9111524839A8} - System32\Tasks\SpeedyPC Update Version3 => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-11-26] (SpeedyPC Software)
Task: {73D9101C-6802-41FB-8DD7-35143CAFB495} - \Microsoft\Windows\Media Center\SqlLiteRecoveryTask No Task File <==== ATTENTION
Task: {753C47AE-EC5E-44B3-95A9-2C8E553F0E39} - \Microsoft\Windows\Windows Media Sharing\UpdateLibrary No Task File <==== ATTENTION
Task: {7A0A96F2-4718-4CB7-A5E2-2D53F7B95D19} - \Microsoft\Windows\Media Center\ehDRMInit No Task File <==== ATTENTION
Task: {8F76E6C7-A228-43CD-86AD-59D8A63E862A} - System32\Tasks\AppCloudUpdater => C:\Users\T420\AppData\Roaming\AppCloudUpdater\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {9727B421-5E9B-49E9-A998-9EF5327E6507} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A7C0509F-25D4-4098-91B0-2A6F5C0232A3} - \Microsoft\Windows\Media Center\OCURDiscovery No Task File <==== ATTENTION
Task: {AA8311CA-D4F2-4C04-80F1-12E8B4992DE9} - \Microsoft\Windows\Media Center\PBDADiscoveryW1 No Task File <==== ATTENTION
Task: {A85E8B1E-2AF2-4BF2-A10A-7E198764946B} - System32\Tasks\SpeedyPC Update Version3 Startup Task => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-11-26] (SpeedyPC Software)
Task: {B0467886-E14E-42AF-B8CA-08D9EC5B48B5} - \Microsoft\Windows\Media Center\PvrScheduleTask No Task File <==== ATTENTION
Task: {B3A57C32-DB45-486A-A26E-B0E1617C2255} - System32\Tasks\SpeedyPC Registration3 => Rundll32.exe "C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll" RunUns
Task: {BAC3A0AE-1DAA-454B-AEA8-7EE266073548} - \Microsoft\Windows\Media Center\mcupdate No Task File <==== ATTENTION
Task: {BC7352CE-49DC-4021-86BC-B179D3C05374} - \Microsoft\Windows\Media Center\DispatchRecoveryTasks No Task File <==== ATTENTION
Task: {C02B85EE-CE0A-4279-9FB6-7F74F2C6F733} - \Microsoft\Windows\Media Center\PeriodicScanRetry No Task File <==== ATTENTION
Task: {C0505696-F27E-4607-8520-9CC788C44B12} - \Microsoft\Windows\Media Center\PvrRecoveryTask No Task File <==== ATTENTION
Task: {C4C8F65D-26C3-4B04-8C69-CB397D9E48AC} - \Microsoft\Windows\Media Center\PBDADiscoveryW2 No Task File <==== ATTENTION
Task: {CBBCAE81-FE6A-4C01-B945-DE70AEBB5BC4} - \Microsoft\Windows\Media Center\ReindexSearchRoot No Task File <==== ATTENTION
Task: {CDBE559A-F01E-4EAA-B2AE-C160D2C30DF4} - \Microsoft\Windows\Media Center\ConfigureInternetTimeService No Task File <==== ATTENTION
Task: {DD09C895-3707-4E7E-A6A1-DB1A2F29C313} - \Microsoft\Windows\Media Center\ActivateWindowsSearch No Task File <==== ATTENTION
Task: {DEA62B1B-E245-4C14-95BA-0D2CE96E1F5E} - \Microsoft\Windows\Media Center\PBDADiscovery No Task File <==== ATTENTION
Task: {E690E2CB-7A79-4518-A619-35115723F594} - \Microsoft\Windows\Media Center\UpdateRecordPath No Task File <==== ATTENTION
Task: {FB187016-21DE-4FBD-B52C-E4B93BD9CA59} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: {FCB8B685-F855-425B-9698-D9D0F701F92A} - \Microsoft\Windows\Media Center\RegisterSearch No Task File <==== ATTENTION
Task: {FE4F3216-1352-461B-85F8-F65DC3644E36} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask No Task File <==== ATTENTION
Task: {FF612B63-B548-4223-B513-CE9948975528} - \Microsoft\Windows\Media Center\MediaCenterRecoveryTask No Task File <==== ATTENTION
Task: {FF6492D1-397F-410A-88E0-530CF9464607} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline No Task File <==== ATTENTION
Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\T420\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: C:\Windows\Tasks\SpeedyPC Pro.job => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe
Task: C:\Windows\Tasks\SpeedyPC Registration3.job => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll
Task: C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe
Task: C:\Windows\Tasks\SpeedyPC Update Version3.job => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.


(Arek Nawrocki) #5

Dziękuję Atis!

 

Poniżej logi:

 

Fixlog: http://www.sendspace.pl/file/5dc3e612cdd6394b2102938

FRST: http://www.sendspace.pl/file/104157c1e68673040b31c1c


(Atis) #6

Skasuj folder C:\FRST

Pobierz TFC - Temp File Cleaner Uruchom TFC i kliknij Start.

Usuń stare punkty przywracania: Aby usunąć wszystkie punkty przywracania

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK


(Arek Nawrocki) #7

Atis, dziękuję za pomoc! Temat można zamknąć :slight_smile: