Utils.cdneurope.com/js/mo.js. Problem


(rastafariii) #1

Witam.

 

Mam problem z tym plikiem/wirusem gdy włączam przeglądarkę nie ważne na jaką stronę wejdę kaspersky wyszukuje cały czas "utils.cdneurope.com/js/mo.js."

 

Czytałem na forum że można użyć programu "Farbar Recovery Scan Tool" i to zrobiłem

 

Załączam Logi

 

Z góry dziękuję i pozdrawiam :slight_smile:

FRST.txt

Addition.txt


(Acorus) #2

Odinstaluj GoiSave,coupon monkey,Adblocker.Otwórz notatnik systemowy i wklej:

Task: {D3711602-08DC-48C9-B66E-F81825D04DF6} - System32\Tasks\pricemeterdownloader = C:\Users\USER\AppData\Local\PriceMeter\pricemeterd.exe ==== ATTENTION
Task: {FBE2F253-479E-4C2A-B9FD-B8E2BDDA7BD1} - System32\Tasks\pricemetertask = C:\Users\USER\AppData\Local\PriceMeter\pricemeter.exe ==== ATTENTION
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] = [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-1493254825-4290588197-3515477493-1000\...\Run: [PriceMeterW] = "C:\Users\USER\AppData\Local\PriceMeter\pricemeterw.exe"
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL = C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL = "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1399737488from=coruid=WDCXWD10EARS-00Y5B1_WD-WCAV5S40464404644q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1399737488from=coruid=WDCXWD10EARS-00Y5B1_WD-WCAV5S40464404644q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1399737488from=coruid=WDCXWD10EARS-00Y5B1_WD-WCAV5S40464404644q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1399737488from=coruid=WDCXWD10EARS-00Y5B1_WD-WCAV5S40464404644q={searchTerms}
FF SearchPlugin: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\3ewiwemp.default\searchplugins\ask-search.xml
FF Extension: Adblocker - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\3ewiwemp.default\Extensions\io-mlpc@uiffsf.org [2014-10-07]
FF Extension: GoSaVVE - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\3ewiwemp.default\Extensions\uaozbx@hazkji.edu [2014-10-07]
FF Extension: FT DeepDark - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\3ewiwemp.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2014-09-21]
FF Extension: Better-Fox - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\3ewiwemp.default\Extensions\{9ee1c043-893a-4b68-a804-54db7cc4de3b} [2014-12-20]
CHR Extension: (GoSaVVE) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\opaabilnkchanljmdngeiekoenicbgmo [2014-10-07]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh [Not Found]
S3 EagleX64; \\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2014-12-20 21:37 - 2014-12-20 21:38 - 00000000 ____ D () C:\Program Files (x86)\PennyBee
2014-12-20 21:33 - 2014-12-20 21:33 - 00000000 ____ D () C:\Program Files\D51D0083-1C6B-4CB4-8FA1-7CF891242EBD
2014-12-20 21:33 - 2014-12-20 21:33 - 00000000 ____ D () C:\Program Files\007
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(rastafariii) #3

Już nic nie wyskakuje. Pozdrawiam i jeszcze raz dziękuję i przy okazji życzę Wesołych Świąt :slight_smile:


(Acorus) #4

Skasuj folder C:\FRST