macios94
(Maciek Raczkowski94)
30 Styczeń 2015 12:27
#1
Siema
Mam na komputerze mnóstwo syfu typu podoweb i enterdigital przez co korzystanie z przegladarki stało sie strasznie uciązliwe przesledziłem juz kilka wątków na temat tego jak to usunąć i skorzystałem z programu FRST. Stworzyłem pliki FRST i Addition (dodaje w załącznikach), ale nie potrafie stworzyć fixlist.txt
Pomoże ktoś?
Atis
(Atis)
30 Styczeń 2015 12:43
#2
W panelu sterowania odinstaluj:
PodoWeb
Remote Desktop Access
Softonic Assistant
Softonic for Windows
SpyHunter 4
Yahoo! Search
Pobierz i uruchom AdwCleaner Kliknij Szukaj i później Usuń.
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
CloseProcesses:
Task: {2A994FD0-4D85-48EB-835A-AC548F744E85} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-01-30] (Enigma Software Group USA, LLC.)
HKU\S-1-5-21-2646645825-2344415619-2575484176-1001\...\Run: [SoftonicAssistant] => C:\Users\Marta\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe [1829832 2014-11-11] ()
HKU\S-1-5-21-2646645825-2344415619-2575484176-1001\...\Run: [Softonic for Windows] => C:\Users\Marta\AppData\Local\Softonic\Softonic.exe [4170224 2014-05-26] (Softonic)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2646645825-2344415619-2575484176-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com
SearchScopes: HKU\S-1-5-21-2646645825-2344415619-2575484176-1001 -> {F9625471-7596-421B-96CC-01DA09066C8E} URL = http://rts.dsrlte.com/?q={searchTerms}&r=734
CHR RestoreOnStartup: Default -> "hxxp://rts.dsrlte.com?affID=pr_4ae218a8-86a7-40da-ae26-37cfacc34642"
CHR StartupUrls: Default -> "hxxp://rts.dsrlte.com?affID=pr_4ae218a8-86a7-40da-ae26-37cfacc34642"
CHR DefaultSearchKeyword: Default -> dsrlte.com
CHR DefaultNewTabURL: Default -> http://rts.dsrlte.com?affID=pr_4ae218a8-86a7-40da-ae26-37cfacc34642
CHR Extension: (EnterDigital) - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\loaijddfgbgdmididoklildabncemoog [2014-12-03]
CHR Extension: (PodoWeb) - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofbadnfgflalgnlglgchfonmpoiiclig [2014-12-11]
R2 MaintainerSvc6.37.565328; C:\ProgramData\7bb6df21-8ca8-4eec-965d-8cd2261544c7\maintainer.exe [123632 2015-01-28] ()
R2 MaintainerSvc6.89.573444; C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe [123632 2015-01-28] ()
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-01-30] (Enigma Software Group USA, LLC.)
R2 Update EnterDigital; C:\Program Files (x86)\EnterDigital\updateEnterDigital.exe [668912 2015-01-30] ()
R2 Update PodoWeb; C:\Program Files (x86)\PodoWeb\updatePodoWeb.exe [681200 2015-01-30] ()
R2 Util EnterDigital; C:\Program Files (x86)\EnterDigital\bin\utilEnterDigital.exe [668912 2015-01-30] ()
R2 Util PodoWeb; C:\Program Files (x86)\PodoWeb\bin\utilPodoWeb.exe [681200 2015-01-30] ()
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-01-30] ()
R1 {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64; C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys [48720 2014-10-07] (StdLib)
R1 {16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}Gw64; C:\Windows\System32\drivers\{16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}Gw64.sys [48784 2014-11-11] (StdLib)
R1 {19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64; C:\Windows\System32\drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64.sys [48776 2014-10-25] (StdLib)
R1 {37853ded-5f26-4b06-88d4-a4f00ea1c972}Gw64; C:\Windows\System32\drivers\{37853ded-5f26-4b06-88d4-a4f00ea1c972}Gw64.sys [48776 2014-11-29] (StdLib)
R1 {51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64; C:\Windows\System32\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64.sys [48776 2014-11-01] (StdLib)
R1 {60fb1691-e7e8-4d48-b26c-c3f85822f710}Gw64; C:\Windows\System32\drivers\{60fb1691-e7e8-4d48-b26c-c3f85822f710}Gw64.sys [48784 2014-11-02] (StdLib)
R1 {6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64; C:\Windows\System32\drivers\{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64.sys [48776 2014-11-06] (StdLib)
R1 {70ed362e-6c2f-4f13-9f05-a5b35ff4be55}Gw64; C:\Windows\System32\drivers\{70ed362e-6c2f-4f13-9f05-a5b35ff4be55}Gw64.sys [48784 2014-12-01] (StdLib)
R1 {8ca7f150-5454-4b4c-9537-1b831c71d329}Gw64; C:\Windows\System32\drivers\{8ca7f150-5454-4b4c-9537-1b831c71d329}Gw64.sys [48784 2014-11-17] (StdLib)
R1 {9015bae7-cdbb-4473-a5d0-ecfa559b2ca5}Gw64; C:\Windows\System32\drivers\{9015bae7-cdbb-4473-a5d0-ecfa559b2ca5}Gw64.sys [48784 2014-11-05] (StdLib)
R1 {93feeb25-9f23-4de1-b697-6a2c12816bac}Gw64; C:\Windows\System32\drivers\{93feeb25-9f23-4de1-b697-6a2c12816bac}Gw64.sys [48784 2014-11-23] (StdLib)
R1 {9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64; C:\Windows\System32\drivers\{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64.sys [48776 2014-11-12] (StdLib)
R1 {972b8ad0-9d6f-4688-9227-759df6914df4}Gw64; C:\Windows\System32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw64.sys [48776 2014-10-23] (StdLib)
R1 {98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64; C:\Windows\System32\drivers\{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64.sys [48776 2014-11-10] (StdLib)
R1 {a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64; C:\Windows\System32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64.sys [48776 2014-11-04] (StdLib)
R1 {ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64; C:\Windows\System32\drivers\{ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64.sys [48776 2014-11-27] (StdLib)
R1 {adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64; C:\Windows\System32\drivers\{adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64.sys [48776 2014-11-18] (StdLib)
R1 {b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64; C:\Windows\System32\drivers\{b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64.sys [48776 2014-11-22] (StdLib)
R1 {b28b16f8-524c-4f96-b046-1c8f12a5fe03}Gw64; C:\Windows\System32\drivers\{b28b16f8-524c-4f96-b046-1c8f12a5fe03}Gw64.sys [48784 2014-11-15] (StdLib)
R1 {b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64; C:\Windows\System32\drivers\{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64.sys [48776 2014-12-01] (StdLib)
R1 {b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64; C:\Windows\System32\drivers\{b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64.sys [48776 2014-11-28] (StdLib)
R1 {bf07813e-aac8-4cea-bf69-7178c16076ac}Gw64; C:\Windows\System32\drivers\{bf07813e-aac8-4cea-bf69-7178c16076ac}Gw64.sys [48784 2014-11-21] (StdLib)
R1 {c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64; C:\Windows\System32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys [48776 2014-11-16] (StdLib)
R1 {cb0b6f3d-aa8b-4a68-acf6-6ff30e1d0243}Gw64; C:\Windows\System32\drivers\{cb0b6f3d-aa8b-4a68-acf6-6ff30e1d0243}Gw64.sys [48784 2014-11-27] (StdLib)
R1 {d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64; C:\Windows\System32\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64.sys [48776 2014-10-29] (StdLib)
R1 {dbe9acb7-ca74-4c18-ad13-f0270d74c42d}Gw64; C:\Windows\System32\drivers\{dbe9acb7-ca74-4c18-ad13-f0270d74c42d}Gw64.sys [48784 2014-11-09] (StdLib)
R1 {e761f54c-32c6-465c-ba31-504773457b77}Gw64; C:\Windows\System32\drivers\{e761f54c-32c6-465c-ba31-504773457b77}Gw64.sys [48784 2014-11-26] (StdLib)
R1 {ea73a685-645b-47a8-a8f5-2538cc24ab81}Gw64; C:\Windows\System32\drivers\{ea73a685-645b-47a8-a8f5-2538cc24ab81}Gw64.sys [48784 2014-11-29] (StdLib)
R1 {f0aab91b-f97e-4d3d-b745-53663865729c}Gw64; C:\Windows\System32\drivers\{f0aab91b-f97e-4d3d-b745-53663865729c}Gw64.sys [48784 2014-11-28] (StdLib)
R1 {f1d7e225-e39d-4bcb-8a90-eaa4181b222b}Gw64; C:\Windows\System32\drivers\{f1d7e225-e39d-4bcb-8a90-eaa4181b222b}Gw64.sys [48784 2014-11-02] (StdLib)
2015-01-30 12:00 - 2015-01-30 12:00 - 00003338 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2015-01-30 12:00 - 2015-01-30 12:00 - 00001089 _____ () C:\Users\Marta\Desktop\SpyHunter.lnk
2015-01-30 12:00 - 2015-01-30 12:00 - 00000000 ____ D () C:\Users\Marta\AppData\Roaming\Enigma Software Group
2015-01-30 12:00 - 2015-01-30 12:00 - 00000000 ____ D () C:\sh4ldr
2015-01-30 11:57 - 2015-01-30 11:57 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
2015-01-30 11:56 - 2015-01-30 11:56 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-01-30 11:54 - 2015-01-30 11:54 - 02998656 _____ (Enigma Software Group USA, LLC.) C:\Users\Marta\Downloads\SpyHunter-Installer.exe
2015-01-30 12:11 - 2014-11-02 21:53 - 00000000 ____ D () C:\Program Files (x86)\EnterDigital
2015-01-30 12:11 - 2014-10-07 19:15 - 00000000 ____ D () C:\Program Files (x86)\PodoWeb
2015-01-28 22:33 - 2014-11-03 16:14 - 00000000 ____ D () C:\ProgramData\7bb6df21-8ca8-4eec-965d-8cd2261544c7
2015-01-28 22:33 - 2014-10-28 20:05 - 00000000 ____ D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2015-01-03 19:44 - 2014-12-15 19:57 - 00000000 ____ D () C:\Users\Marta\AppData\Local\SoftonicAssistant
C:\Windows\System32\drivers\{ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64.sys
C:\Windows\System32\drivers\{adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64.sys
C:\Windows\System32\drivers\{b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64.sys
C:\Windows\System32\drivers\{b28b16f8-524c-4f96-b046-1c8f12a5fe03}Gw64.sys
C:\Windows\System32\drivers\{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64.sys
C:\Windows\System32\drivers\{b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64.sys
C:\Windows\System32\drivers\{bf07813e-aac8-4cea-bf69-7178c16076ac}Gw64.sys
C:\Windows\System32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys
C:\Windows\System32\drivers\{cb0b6f3d-aa8b-4a68-acf6-6ff30e1d0243}Gw64.sys
C:\Windows\System32\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64.sys
C:\Windows\System32\drivers\{dbe9acb7-ca74-4c18-ad13-f0270d74c42d}Gw64.sys
C:\Windows\System32\drivers\{e761f54c-32c6-465c-ba31-504773457b77}Gw64.sys
C:\Windows\System32\drivers\{ea73a685-645b-47a8-a8f5-2538cc24ab81}Gw64.sys
C:\Windows\System32\drivers\{f0aab91b-f97e-4d3d-b745-53663865729c}Gw64.sys
C:\Windows\System32\drivers\{f1d7e225-e39d-4bcb-8a90-eaa4181b222b}Gw64.sys
EmptyTemp:
Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.
Kliknij Scan i pokaż nowy raport z FRST bez Addition.