Jak usunąć wirusa Surfvox?!

Witam, od pewnego czasu mam tego wirusa w swoim komputerze, męczyłem sie kilka godzin, aby go usunąć, ale sam nie dam rady! :c Nie moge otworzyć folderu .Roaming bo odrazu sie wyłącza. Przeglądarki też maja problem… Gdy próbuję włączyć Google to odpala sie ten Surfvox :confused:

 

Czytałem, że będą potrzebne dwa logi Addition i FRST więc link daje niżej.

Addition: http://www.wklej.org/hash/c5ff7394e4c/

FRST: http://www.wklej.org/hash/7a4a4179fa1/

 

Pomocy :c

Odinstaluj BrowseToSave,YAC(Yet Another Cleaner!)Pobierz i uruchom AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Szukaj i później Usuń.

Pokaż nowe logi z FRST.

Zrobiłem co kazałeś i o to wyniki:

Additional: http://www.wklej.org/id/1619169/

FRST: http://www.wklej.org/hash/3bc3e1906d6/

Otwórz notatnik systemowy i wklej:

Task: {19705508-2874-4184-86BF-0DCB23E368AA} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-2 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-2.exe ==== ATTENTION
Task: {295F12F3-2950-4D45-ACA8-E8967BF77E75} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-1 = C:\Program Files (x86)\Radio Canyon\Radio Canyon-codedownloader.exe ==== ATTENTION
Task: {428325E0-F2A6-4A55-9E16-D2233B285795} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-5_user = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-5.exe ==== ATTENTION
Task: {AFEEAF8F-20E9-439D-8D88-DB9A06983762} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-5 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-5.exe ==== ATTENTION
Task: {B3AD9752-D5DE-47A3-B3B7-702E3442E6ED} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-4 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-4.exe ==== ATTENTION
Task: {B65D4DAF-7044-4D01-BC7C-68A282217148} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-11 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-11.exe ==== ATTENTION
Task: {CEC68AF4-654C-4767-8E5C-C2C6AC0A6F9B} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-7 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-7.exe ==== ATTENTION
Task: {E76E35F4-72DB-4831-B774-C45EC5E6EF85} - System32\Tasks\c533c256-3b92-4f9b-a7de-db5566f6fdba-6 = C:\Program Files (x86)\Radio Canyon\c533c256-3b92-4f9b-a7de-db5566f6fdba-6.exe ==== ATTENTION
HKU\S-1-5-21-2013917218-1627672027-1686527233-1000\...\Run: [nvxasync] = C:\Users\Ja\AppData\Roaming\nvxasync\nvxasync.exe [76678656 2015-01-28] ()
HKU\S-1-5-21-2013917218-1627672027-1686527233-1000\...\Winlogon: [Shell] C:\ProgramData\nvxasync\cvxasync.exe [76678656 2015-01-28] () ==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891
HKU\S-1-5-21-2013917218-1627672027-1686527233-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.surfvox.com/
SearchScopes: HKU\.DEFAULT - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891ts=1422793213
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891ts=1422793213
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891ts=1422793213
BHO: No Name - {D15C208E-636C-572A-A0AA-C895435843AD} - No File
BHO-x32: No Name - {D15C208E-636C-572A-A0AA-C895435843AD} - No File
FF Homepage: hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF SearchPlugin: C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\bj6u10cu.default\searchplugins\starter.xml
FF Extension: webget - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\bj6u10cu.default\Extensions\firefox@webwebget.com.xpi [2014-05-23]
CHR StartupUrls: Default - "hxxp://search.yac.mx/?utm_source=butm_medium=iSafefrom=iSafeuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891"
CHR DefaultSearchKeyword: Default - YAC Safe Search
CHR DefaultSearchURL: Default - http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891ts=1422474322
CHR HKU\S-1-5-21-2013917218-1627672027-1686527233-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Ja\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-04-17]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S1 HssDRV6; system32\DRIVERS\hssdrv6.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
2015-01-28 21:14 - 2015-01-28 21:14 - 00000000 _RSHD () C:\ProgramData\nvxasync
2015-01-28 19:55 - 2015-01-28 20:08 - 00000000 _RSHD () C:\Users\Ja\AppData\Roaming\nvxasync
2015-01-28 19:55 - 2015-01-28 19:55 - 40068694 _____ () C:\Users\Ja\AppData\Roaming\fpacked.exe
2015-01-28 19:55 - 2014-09-22 04:39 - 00000000 ____ D () C:\Users\Ja\AppData\Roaming\fportable
2015-02-01 13:27 - 2013-09-26 21:09 - 00000000 ____ D () C:\AdwCleaner
C:\Users\Ja\AppData\Roaming\Origin\update.vbe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Baaardzo Ci dziękuje, wirus prawdopodobnie został usunięty, ale pojawił sie nowy problem… Mianowicie z internetem, a dokładniej mówiąc nie działa… Na połączeniu WiFi mam napisane _ Ograniczony dostęp _ a gdy daje rozwiązywanie problemów mam napisane Podczas rozwiązywania problemów wystąpił błąd ;c

To nie ma z tym związku.Pokaż nowy log z FRST bez Addition.

Proszę: http://www.wklej.org/hash/96337849185/

Otwórz notatnik systemowy i wklej:

FF Homepage: www.wp.pl/?src01=dp220140915
FF Homepage: hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
FF Homepage: user_pref("extensions.lastPlatformVersion");hxxp://www.surfvox.com
FF DefaultSearchEngine: SurfVox
FF SelectedSearchEngine: SurfVox
CHR DefaultSearchKeyword: Default - YAC Safe Search
CHR DefaultSearchURL: Default - http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=wdcxwd5000lpvt-00g33t0_wd-wx21ac2t1891t1891ts=1422474322
2015-01-09 15:10 - 2015-01-13 16:15 - 00061068 _____ () C:\Windows\temp023423.vbe

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Przeskanuj programem Malwarebytes Anti-Malware http://data-cdn.mbamupdates.com/v2/mbam/consumer/data/mbam-setup-2.0.4.1028.exe

Zrobiłem wszystko co kazałeś. I chyba wirusa już nie ma… Teraz tylko muszę naprawić neta. :F