Niebieski ekran podejrzenie wirusa


(pawel75) #1

Witam
Proszę o sprawdzenie logów
http://www.wklej.org/id/3326713/
http://www.wklej.org/id/3326714/
http://www.wklej.org/id/3326715/
niebieski ekran z błędem BSOD System_Service_Exception win32kbase.sys

http://www.wklej.org/id/3326719/


(Atis) #2

Nie widać infekcji.
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist:

ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Brak pliku
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Brak pliku
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> Brak pliku
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> Brak pliku
Task: {0197F4E9-36FD-43E0-A7E4-0EBF3C1D76BC} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {09CC35E1-8EA6-452C-A21E-B3AFE77B121B} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {1268155D-889D-43C3-A32B-E925D3C811D7} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {1304F2E4-AFCA-47D5-AD98-62C01FCB8C94} - \{A8E2D75C-FE5D-4B39-8B5E-E4DD412BC6B5} -> Brak pliku <==== UWAGA
Task: {13D996BB-CB79-4A81-82C8-BCC3DB5E45AE} - \{FB0C95A3-5DED-4B16-ABED-A6103E72FEED} -> Brak pliku <==== UWAGA
Task: {15E38AA4-7BB1-4573-8103-BD0ECFB5F781} - System32\Tasks\{39DED369-FC6B-4827-9E88-1EF57CE2DADF} => D:\ALFA_EM_NOWA\em.exe [2015-06-30] () <==== UWAGA
Task: {1CDB2D9C-7098-4107-8125-EDCC2F42215D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3A4F0AFE-1470-4E5D-8404-F15AC0196ABC} - \{7E8CC9EF-1D18-4FD0-8490-461FBEA4B9A2} -> Brak pliku <==== UWAGA
Task: {3FDA28E9-2467-47B2-ACDE-A6147344BC29} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {4784273B-85E5-443C-A026-61803CBCDC85} - System32\Tasks\{0AC73D58-0B36-4BAC-920B-EA4F60F8F5B2} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Nox\bin\Nox_unload.exe"
Task: {5B53F410-8B31-44A5-A332-6B355508126E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {64973AD7-ECD4-4554-833B-9213C1B6BC40} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6F0D190C-18B0-4FA0-A20A-E8E1E471B527} - \{7E38B726-C20C-4541-989F-0F50FE779960} -> Brak pliku <==== UWAGA
Task: {776C48D1-DE21-4BDC-8CEA-96C15C67289C} - \{301E8F37-3038-4CF4-9D50-E544162AF2B1} -> Brak pliku <==== UWAGA
Task: {8043ABCE-A4B7-4C4B-B882-346E1BEDC955} - \{A28C10CF-4966-4BDF-9503-61A717861678} -> Brak pliku <==== UWAGA
Task: {8701F0BC-4200-46A8-B1E2-DCF68AF1BC9B} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {87ADCAF9-4B23-42D7-B0B9-661A0E5B5A16} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {89F24EA7-9208-4583-B393-CBDC0E0DB338} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {9F3CC00B-842B-4A4A-9AB0-EF98C5210177} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B9D58CF6-5727-401E-A9D5-D45CE12B12A1} - \{D836DA11-7422-45F1-B74C-8A130EC1989C} -> Brak pliku <==== UWAGA
Task: {BD3791F8-F103-4A0E-9A00-39B50BBC27DD} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C42C3390-D1C0-42CD-8B74-8C9D8524EF0E} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {C513C835-FE05-4A27-B29C-78D4E189439F} - System32\Tasks\{B04804ED-A959-4797-8F5F-CEE3A38FA017} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Longer\PROGRA~1\UNINST~1.EXE" -c C:\Program Files (x86)\Longer\PROGRA~1\INSTALL.LOG
Task: {CE414C4C-67CB-4679-8DC0-E785ECA1700D} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CE84369F-EE93-4321-8A4D-ABA49899858E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DA083259-4798-4E6D-99B1-66ED5FC29389} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DA61CB18-64BA-49F7-B618-B6BE9282B107} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DDABE66B-5791-4C02-899C-39A82EA15E2A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E23028CB-B465-429D-A61B-D8F3552921A6} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {E2E57B61-A1F2-44F6-92F1-5D6778BF16BD} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EFF768DC-73DC-4015-B246-A3ACE70567CC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-08-15] ()
Task: {F045483A-8F3D-4482-A2A8-59523ABE7AF2} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {F23EE6F4-11BE-4E67-9A1F-38B63D5E7F0C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F6EC88F4-E453-431C-83D9-BFD56C0EF076} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {FCF82F9D-1F11-4493-9ECE-7E505290ADC1} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
U3 idsvc; Brak ImagePath
2017-12-20 13:14 - 2016-02-26 09:10 - 000000000 ____D C:\AdwCleaner

Uruchom FRST i kliknij Napraw (Fix). Później skasuj folder C:\FRST


(pawel75) #3

zrobione