Skocz do zawartości

Złośliwe oprogramowanie


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Jest tu masowa inwazja szkodników. McAfee wygląda na uszkodzony - wiele wpisów wybrakowanych. Działania wstępne:

 

1. Otwórz Notatnik i wklej w nim:

 

CloseProcesses:
(Microsoft Corporation) C:\Windows\explorer.exe
CreateRestorePoint:
Task: {73684B5E-055F-47A2-9682-240E1AFEE85F} - System32\Tasks\Windows Update Check - 0x696D087B => C:\ProgramData\anjdfkhm.ru\bjrwzmzis.exe 
Task: {80B38D87-718E-4764-AC60-7B8AFE1CE745} - System32\Tasks\Windows Update Check - 0x5FF907D6 => C:\ProgramData\Winrar_Update\xegiwezhr.exe [] () 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [dXEFj.exe] => C:\Users\rwi\AppData\Local\Temp\dXEFj.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msqilyra.com] => C:\ProgramData\Local Settings\Temp\msqilyra.com [1469440 2009-07-14] () 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [000262c7.exe] => C:\Users\rwi\AppData\Local\Temp\000262c7.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [00014a0a.exe] => C:\Users\rwi\AppData\Local\Temp\00014a0a.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msvuti.cmd] => C:\ProgramData\Local Settings\Temp\msvuti.cmd [1469440 2009-07-14] () 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0111bf1f.exe] => C:\Users\rwi\AppData\Local\Temp\0111bf1f.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0009c6a8.exe] => C:\Users\rwi\AppData\Local\Temp\0009c6a8.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msvaawe.bat] => C:\ProgramData\Local Settings\Temp\msvaawe.bat [1468928 2009-07-14] () 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0011dcd7.exe] => C:\Users\rwi\AppData\Local\Temp\0011dcd7.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [Aktualizacja Przegladarki] => "C:\Users\rwi\AppData\Roaming\Microsoft\ICyq3HsaMLgxgfJrXq.exe"
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [000216da.exe] => C:\Users\rwi\AppData\Local\Temp\000216da.exe 
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [Winrar_Update] => C:\ProgramData\Winrar_Update\xegiwezhr.exe [0 ] ()
HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [eafpajiogfiowgqa.exe] => C:\Users\rwi\AppData\Roaming\eafpajiogfiowgqa.exe [1156608 2015-01-22] ()
HKLM\...\Run: [] => [X]
HKLM\...\Policies\Explorer\Run: [15388] => C:\ProgramData\Local Settings\Temp\msobywg.bat [360448 2009-07-14] ( (Microsoft Corporation))
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
IFEO\2.ini: [Debugger] wuauclt.exe
IFEO\20150122141436608779000000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436610494300000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436644745100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436659748100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436675069800000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436691848700000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436706132400000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436722844600000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436724077300000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436755545600000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436771818200000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436787883900000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436802925100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436818884900000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436820082200000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436852371300000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436867827900000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436883057100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436898937200000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436914025100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436930620500000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436945453300000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436948464300000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436979595400000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141436994272000000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437010619800000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437041487100000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437044776900000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437075983900000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437091065700000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437106696600000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437122941400000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437124017800000D14.xml: [Debugger] wuauclt.exe
IFEO\20150122141437155460700000D14.xml: [Debugger] wuauclt.exe
IFEO\3.ini: [Debugger] wuauclt.exe
IFEO\4.ini: [Debugger] wuauclt.exe
IFEO\advisory_dlg.ini: [Debugger] wuauclt.exe
IFEO\advisory_dlg.png: [Debugger] wuauclt.exe
IFEO\Agent.dll: [Debugger] wuauclt.exe
IFEO\Agent.ini: [Debugger] wuauclt.exe
IFEO\agentDefault.ini: [Debugger] wuauclt.exe
IFEO\AgentEvents: [Debugger] wuauclt.exe
IFEO\AgentPlugin.dll: [Debugger] wuauclt.exe
IFEO\agentprvkey.bin: [Debugger] wuauclt.exe
IFEO\agentpubkey.bin: [Debugger] wuauclt.exe
IFEO\AgentRes.Dll: [Debugger] wuauclt.exe
IFEO\Agent_F-M-F-R.log: [Debugger] wuauclt.exe
IFEO\Agent_F-M-F-R.xml: [Debugger] wuauclt.exe
IFEO\Agent_F-M-F-R_backup.log: [Debugger] wuauclt.exe
IFEO\Agent_F-M-F-R_error.log: [Debugger] wuauclt.exe
IFEO\Agent_W530-THINK.log: [Debugger] wuauclt.exe
IFEO\Agent_W530-THINK.xml: [Debugger] wuauclt.exe
IFEO\Agent_W530-THINK_error.log: [Debugger] wuauclt.exe
IFEO\allow.png: [Debugger] wuauclt.exe
IFEO\AppLib.dll: [Debugger] wuauclt.exe
IFEO\aslicense.bin: [Debugger] wuauclt.exe
IFEO\avvclean.dat: [Debugger] wuauclt.exe
IFEO\avvnames.dat: [Debugger] wuauclt.exe
IFEO\avvscan.dat: [Debugger] wuauclt.exe
IFEO\BBCpl.dll: [Debugger] wuauclt.exe
IFEO\bidirectional.png: [Debugger] wuauclt.exe
IFEO\BocDet_VSE.McS: [Debugger] wuauclt.exe
IFEO\boost_thread-vc100-mt-1_39.dll: [Debugger] wuauclt.exe
IFEO\button_disabled.png: [Debugger] wuauclt.exe
IFEO\button_down.png: [Debugger] wuauclt.exe
IFEO\button_hover.png: [Debugger] wuauclt.exe
IFEO\button_up.png: [Debugger] wuauclt.exe
IFEO\cabundle.cer: [Debugger] wuauclt.exe
IFEO\catalog.z: [Debugger] wuauclt.exe
IFEO\ccme_base.dll: [Debugger] wuauclt.exe
IFEO\checked.png: [Debugger] wuauclt.exe
IFEO\checkmark.png: [Debugger] wuauclt.exe
IFEO\ClientUI.dll: [Debugger] wuauclt.exe
IFEO\CMALib.dll: [Debugger] wuauclt.exe
IFEO\CMAUIRes.dll: [Debugger] wuauclt.exe
IFEO\CmdAgent.exe: [Debugger] wuauclt.exe
IFEO\cmdagent.sig: [Debugger] wuauclt.exe
IFEO\Common Framework: [Debugger] wuauclt.exe
IFEO\ComponentSubsystem.dll: [Debugger] wuauclt.exe
IFEO\ComponentUserInterface.dll: [Debugger] wuauclt.exe
IFEO\condl.dll: [Debugger] wuauclt.exe
IFEO\config.dat: [Debugger] wuauclt.exe
IFEO\consl.dll: [Debugger] wuauclt.exe
IFEO\coptcpl.dll: [Debugger] wuauclt.exe
IFEO\cryptocme2.dll: [Debugger] wuauclt.exe
IFEO\cryptocme2.sig: [Debugger] wuauclt.exe
IFEO\cryptshim.dll: [Debugger] wuauclt.exe
IFEO\csscan.exe: [Debugger] wuauclt.exe
IFEO\dainstall.exe: [Debugger] wuauclt.exe
IFEO\DataStore.bin: [Debugger] wuauclt.exe
IFEO\DesktopProtection: [Debugger] wuauclt.exe
IFEO\details_close_normal.png: [Debugger] wuauclt.exe
IFEO\details_close_pressed.png: [Debugger] wuauclt.exe
IFEO\details_open_normal.png: [Debugger] wuauclt.exe
IFEO\details_open_pressed.png: [Debugger] wuauclt.exe
IFEO\disallow.png: [Debugger] wuauclt.exe
IFEO\Dispatcher.dll: [Debugger] wuauclt.exe
IFEO\document.png: [Debugger] wuauclt.exe
IFEO\Emabout.dll: [Debugger] wuauclt.exe
IFEO\EmailOnDeliveryLog.txt: [Debugger] wuauclt.exe
IFEO\EmCfgCpl.dll: [Debugger] wuauclt.exe
IFEO\EmHelp.dll: [Debugger] wuauclt.exe
IFEO\Engine: [Debugger] wuauclt.exe
IFEO\engmin.zip: [Debugger] wuauclt.exe
IFEO\engmin64.zip: [Debugger] wuauclt.exe
IFEO\EvtFiltr.ini: [Debugger] wuauclt.exe
IFEO\folder_closed.png: [Debugger] wuauclt.exe
IFEO\folder_open.png: [Debugger] wuauclt.exe
IFEO\FrameworkLog.html: [Debugger] wuauclt.exe
IFEO\FrameworkLog.js: [Debugger] wuauclt.exe
IFEO\FrameworkLog.xsl: [Debugger] wuauclt.exe
IFEO\FrameworkLogFirefox.xsl: [Debugger] wuauclt.exe
IFEO\FrameworkManifest.xml: [Debugger] wuauclt.exe
IFEO\FrameworkService.exe: [Debugger] wuauclt.exe
IFEO\FrameworkService.sig: [Debugger] wuauclt.exe
IFEO\FrmInst.exe: [Debugger] wuauclt.exe
IFEO\ftcfg.dll: [Debugger] wuauclt.exe
IFEO\ftl.dll: [Debugger] wuauclt.exe
IFEO\Genevtinf3.dll: [Debugger] wuauclt.exe
IFEO\GenEvtInf3_64.dll: [Debugger] wuauclt.exe
IFEO\gradated_background.png: [Debugger] wuauclt.exe
IFEO\gradated_background_with_mcafee_logo.png: [Debugger] wuauclt.exe
IFEO\graphics.dll: [Debugger] wuauclt.exe
IFEO\gray_checked.png: [Debugger] wuauclt.exe
IFEO\grip.png: [Debugger] wuauclt.exe
IFEO\group_folder_closed.png: [Debugger] wuauclt.exe
IFEO\gui_redirect.ini: [Debugger] wuauclt.exe
IFEO\Images: [Debugger] wuauclt.exe
IFEO\inbound.png: [Debugger] wuauclt.exe
IFEO\inetmgr.dll: [Debugger] wuauclt.exe
IFEO\InstallMain.McS: [Debugger] wuauclt.exe
IFEO\ipcchannel.dll: [Debugger] wuauclt.exe
IFEO\LastProp.xml: [Debugger] wuauclt.exe
IFEO\LastPropsSentToServer.xml: [Debugger] wuauclt.exe
IFEO\LazyCache.dll: [Debugger] wuauclt.exe
IFEO\license.bin: [Debugger] wuauclt.exe
IFEO\license.dat: [Debugger] wuauclt.exe
IFEO\license.txt: [Debugger] wuauclt.exe
IFEO\ListenServer.dll: [Debugger] wuauclt.exe
IFEO\lockdown.dll: [Debugger] wuauclt.exe
IFEO\Logging.dll: [Debugger] wuauclt.exe
IFEO\logparser.exe: [Debugger] wuauclt.exe
IFEO\main_window.ini: [Debugger] wuauclt.exe
IFEO\Management.dll: [Debugger] wuauclt.exe
IFEO\mcadmin.exe: [Debugger] wuauclt.exe
IFEO\McAfee: [Debugger] wuauclt.exe
IFEO\McAfeeCommonUpdaterPlugin.dll: [Debugger] wuauclt.exe
IFEO\McAfeeWin32GUISupportDLL.dll: [Debugger] wuauclt.exe
IFEO\mcafee_m_small.png: [Debugger] wuauclt.exe
IFEO\McAVDetect.DLL: [Debugger] wuauclt.exe
IFEO\McAVSCV.DLL: [Debugger] wuauclt.exe
IFEO\mcconsol.exe: [Debugger] wuauclt.exe
IFEO\McScan32.dll: [Debugger] wuauclt.exe
IFEO\McScanCheck.exe: [Debugger] wuauclt.exe
IFEO\McScript.log: [Debugger] wuauclt.exe
IFEO\McScript_backup.log: [Debugger] wuauclt.exe
IFEO\McScript_error.log: [Debugger] wuauclt.exe
IFEO\McScript_error_backup.log: [Debugger] wuauclt.exe
IFEO\McScript_InUse.exe: [Debugger] wuauclt.exe
IFEO\McShield.dll: [Debugger] wuauclt.exe
IFEO\McTray: [Debugger] wuauclt.exe
IFEO\McTray.exe: [Debugger] wuauclt.exe
IFEO\McTrayErrorLoggingPlugin.dll: [Debugger] wuauclt.exe
IFEO\McTrayEventLog.dll: [Debugger] wuauclt.exe
IFEO\McTrayInstSupp.dll: [Debugger] wuauclt.exe
IFEO\McTrayInterfaceLib.dll: [Debugger] wuauclt.exe
IFEO\McTrayLegacySupportPlugin32.dll: [Debugger] wuauclt.exe
IFEO\McTrayRes.dll: [Debugger] wuauclt.exe
IFEO\mcupdate.exe: [Debugger] wuauclt.exe
IFEO\Mcurial.Dll: [Debugger] wuauclt.exe
IFEO\mcvssnmp.dll: [Debugger] wuauclt.exe
IFEO\MERTool.url: [Debugger] wuauclt.exe
IFEO\Messages.dat: [Debugger] wuauclt.exe
IFEO\mfeagent.cat: [Debugger] wuauclt.exe
IFEO\MFEagent.msi: [Debugger] wuauclt.exe
IFEO\mfeann.exe: [Debugger] wuauclt.exe
IFEO\mfeapconfig.dll: [Debugger] wuauclt.exe
IFEO\mfeavfa.dll: [Debugger] wuauclt.exe
IFEO\mfeCmnLib71.dll: [Debugger] wuauclt.exe
IFEO\mfecryptc.dll: [Debugger] wuauclt.exe
IFEO\mfecryptc.sig: [Debugger] wuauclt.exe
IFEO\mfecurl.dll: [Debugger] wuauclt.exe
IFEO\mfediscovery.dll: [Debugger] wuauclt.exe
IFEO\mfehida.dll: [Debugger] wuauclt.exe
IFEO\mfehidin.exe: [Debugger] wuauclt.exe
IFEO\mfelpc.dll: [Debugger] wuauclt.exe
IFEO\mferuntime20150119092906965.dat: [Debugger] wuauclt.exe
IFEO\MfeServiceMgr.exe: [Debugger] wuauclt.exe
IFEO\MfeServiceMgr.sig: [Debugger] wuauclt.exe
IFEO\mfevtpa.dll: [Debugger] wuauclt.exe
IFEO\mfezlib.dll: [Debugger] wuauclt.exe
IFEO\Microsoft.VC100.CRT.manifest: [Debugger] wuauclt.exe
IFEO\Microsoft.VC80.CRT.manifest: [Debugger] wuauclt.exe
IFEO\midutil.dll: [Debugger] wuauclt.exe
IFEO\minus_sign.png: [Debugger] wuauclt.exe
IFEO\msaconfig.exe: [Debugger] wuauclt.exe
IFEO\msaconfig.sig: [Debugger] wuauclt.exe
IFEO\Mscan64a.dll: [Debugger] wuauclt.exe
IFEO\msvcm80.dll: [Debugger] wuauclt.exe
IFEO\msvcp100.dll: [Debugger] wuauclt.exe
IFEO\msvcp71.dll: [Debugger] wuauclt.exe
IFEO\msvcp80.dll: [Debugger] wuauclt.exe
IFEO\msvcr100.dll: [Debugger] wuauclt.exe
IFEO\msvcr71.dll: [Debugger] wuauclt.exe
IFEO\msvcr80.dll: [Debugger] wuauclt.exe
IFEO\Mue.exe: [Debugger] wuauclt.exe
IFEO\Mue.sig: [Debugger] wuauclt.exe
IFEO\MueRes.dll: [Debugger] wuauclt.exe
IFEO\MueRes_InUse.dll: [Debugger] wuauclt.exe
IFEO\mytilus3.dll: [Debugger] wuauclt.exe
IFEO\mytilus3_worker.dll: [Debugger] wuauclt.exe
IFEO\naCmnLib3_71.dll: [Debugger] wuauclt.exe
IFEO\naevent.dll: [Debugger] wuauclt.exe
IFEO\nagshr32.dll: [Debugger] wuauclt.exe
IFEO\naiann.dll: [Debugger] wuauclt.exe
IFEO\nailite.dll: [Debugger] wuauclt.exe
IFEO\nailog3.dll: [Debugger] wuauclt.exe
IFEO\Nainet.dll: [Debugger] wuauclt.exe
IFEO\naitcpp.inf: [Debugger] wuauclt.exe
IFEO\naPolicyManager.dll: [Debugger] wuauclt.exe
IFEO\naPrdMgr.exe: [Debugger] wuauclt.exe
IFEO\naPrdMgr.sig: [Debugger] wuauclt.exe
IFEO\naSPIPE.dll: [Debugger] wuauclt.exe
IFEO\naxml3_71.dll: [Debugger] wuauclt.exe
IFEO\naziplib.dll: [Debugger] wuauclt.exe
IFEO\NextProp.xml: [Debugger] wuauclt.exe
IFEO\no_symbol.png: [Debugger] wuauclt.exe
IFEO\nvpcpl.dll: [Debugger] wuauclt.exe
IFEO\OASCpl.dll: [Debugger] wuauclt.exe
IFEO\OtlkScan.dll: [Debugger] wuauclt.exe
IFEO\OtlkUI.20130924155504.dll: [Debugger] wuauclt.exe
IFEO\outbound.png: [Debugger] wuauclt.exe
IFEO\Patchw32.dll: [Debugger] wuauclt.exe
IFEO\PcrPlug.dll: [Debugger] wuauclt.exe
IFEO\pireg.exe: [Debugger] wuauclt.exe
IFEO\pkg00130283738398530000_3823725180.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130283738402590000_141706860.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130486978620150000_905842077.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130486981276420000_3922522066.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130486993533310000_2427086521.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487016472650000_2437068241.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487026266050000_104983657.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487037854760000_2400459517.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487545952870000_3180744114.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487575498580000_1637079096.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487587802080000_505750469.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487610670040000_218874406.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487645271680000_1186786167.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487672523070000_1049954230.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487683475170000_2917543291.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487705485430000_3177136656.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487739705730000_3770996762.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487769326820000_3176360642.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487781808500000_2016455484.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487804240070000_709036342.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487840052670000_1136986743.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487856184430000_3399027147.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130487867676080000_660593062.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488472348410000_1609362892.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488484738450000_2777886704.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488505740290000_3665425022.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488538686540000_1510983857.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488572528190000_1720763739.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488583410500000_751044111.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488610516290000_3335329728.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488644282870000_3692162735.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488668007880000_2077638625.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488678374570000_516215274.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488701563330000_195051264.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130488732852500000_590295132.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489304600020000_3585717127.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489460265300000_443515461.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489460367170000_3859414461.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489483567930000_1100563953.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489525328520000_2271446734.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489539788930000_2410246629.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489570908150000_3380911397.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130489596888100000_538301776.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493626822070000_3758387281.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493645766480000_1204911931.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493680537200000_3191195673.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493695915330000_855238066.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493719116360000_284180699.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493760697140000_1623165773.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493774207620000_3513265569.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493807668300000_174765869.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493834569110000_1155875258.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493853059510000_3822309134.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493888943110000_3891416026.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493898750880000_2888344145.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130493922991100000_2224162039.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130494541665580000_2147771041.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130494542448000000_2064125646.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130494566415960000_4051398629.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130494608677100000_1713622191.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130628477543890000_1178998994.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130628477544040000_3663141724.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130628477549180000_4282010264.spkg: [Debugger] wuauclt.exe
IFEO\pkg00130628477549960000_298415004.spkg: [Debugger] wuauclt.exe
IFEO\plus_sign.png: [Debugger] wuauclt.exe
IFEO\PoEvtInf.dll: [Debugger] wuauclt.exe
IFEO\PrdMgr_F-M-F-R.log: [Debugger] wuauclt.exe
IFEO\PrdMgr_F-M-F-R_error.log: [Debugger] wuauclt.exe
IFEO\PrdMgr_W530-THINK.log: [Debugger] wuauclt.exe
IFEO\PrdMgr_W530-THINK_error.log: [Debugger] wuauclt.exe
IFEO\QuarCpl.dll: [Debugger] wuauclt.exe
IFEO\readme.html: [Debugger] wuauclt.exe
IFEO\RepoKeys.ini: [Debugger] wuauclt.exe
IFEO\restartvse.exe: [Debugger] wuauclt.exe
IFEO\rule_folder_closed.png: [Debugger] wuauclt.exe
IFEO\scan32.exe: [Debugger] wuauclt.exe
IFEO\Scan64.Exe: [Debugger] wuauclt.exe
IFEO\Scheduler.dll: [Debugger] wuauclt.exe
IFEO\ScnCfg32.Exe: [Debugger] wuauclt.exe
IFEO\scriptff.dll: [Debugger] wuauclt.exe
IFEO\ScriptSn.20130924155504.dll: [Debugger] wuauclt.exe
IFEO\scriptsn.dll: [Debugger] wuauclt.exe
IFEO\SecureFrameworkFactory3.dll: [Debugger] wuauclt.exe
IFEO\Server.bin: [Debugger] wuauclt.exe
IFEO\serverDefault.xml: [Debugger] wuauclt.exe
IFEO\serverpubkey.bin: [Debugger] wuauclt.exe
IFEO\serverreqseckey.bin: [Debugger] wuauclt.exe
IFEO\ServerSiteList.xml: [Debugger] wuauclt.exe
IFEO\shcfg32.exe: [Debugger] wuauclt.exe
IFEO\shext.dll: [Debugger] wuauclt.exe
IFEO\shstat.dll: [Debugger] wuauclt.exe
IFEO\shstat.exe: [Debugger] wuauclt.exe
IFEO\shutil.dll: [Debugger] wuauclt.exe
IFEO\SignLic.Txt: [Debugger] wuauclt.exe
IFEO\sitecache.bin: [Debugger] wuauclt.exe
IFEO\SiteList.xml: [Debugger] wuauclt.exe
IFEO\SiteStat.xml: [Debugger] wuauclt.exe
IFEO\splashscreen.png: [Debugger] wuauclt.exe
IFEO\strings.bin: [Debugger] wuauclt.exe
IFEO\Subscriptions.txt: [Debugger] wuauclt.exe
IFEO\SvcMgr_F-M-F-R.log: [Debugger] wuauclt.exe
IFEO\SvcMgr_F-M-F-R_error.log: [Debugger] wuauclt.exe
IFEO\SystemCore: [Debugger] wuauclt.exe
IFEO\system_status_error_medium.png: [Debugger] wuauclt.exe
IFEO\system_status_ok_medium.png: [Debugger] wuauclt.exe
IFEO\system_status_warning_medium.png: [Debugger] wuauclt.exe
IFEO\Task: [Debugger] wuauclt.exe
IFEO\trailer.png: [Debugger] wuauclt.exe
IFEO\tray_menu_issue.png: [Debugger] wuauclt.exe
IFEO\tray_menu_okay.png: [Debugger] wuauclt.exe
IFEO\UdaterUI.exe: [Debugger] wuauclt.exe
IFEO\UdaterUI.sig: [Debugger] wuauclt.exe
IFEO\unchecked.png: [Debugger] wuauclt.exe
IFEO\UpdateHistory.ini: [Debugger] wuauclt.exe
IFEO\UpdateMain.McS: [Debugger] wuauclt.exe
IFEO\updater.Dll: [Debugger] wuauclt.exe
IFEO\UpdateSubSys.Dll: [Debugger] wuauclt.exe
IFEO\UpdPlug.Dll: [Debugger] wuauclt.exe
IFEO\UpdRes.Dll: [Debugger] wuauclt.exe
IFEO\UserSpace.Dll: [Debugger] wuauclt.exe
IFEO\V2datdet.mcs: [Debugger] wuauclt.exe
IFEO\V2engdet.mcs: [Debugger] wuauclt.exe
IFEO\V2enginstall.mcs: [Debugger] wuauclt.exe
IFEO\VirusScan Enterprise: [Debugger] wuauclt.exe
IFEO\vse880.msi: [Debugger] wuauclt.exe
IFEO\VSE880Det.McS: [Debugger] wuauclt.exe
IFEO\VsEvntUI.DLL: [Debugger] wuauclt.exe
IFEO\vsodscpl.dll: [Debugger] wuauclt.exe
IFEO\vsplugin.dll: [Debugger] wuauclt.exe
IFEO\VsTskMgr.exe: [Debugger] wuauclt.exe
IFEO\vsupdate.dll: [Debugger] wuauclt.exe
IFEO\vsupdcpl.dll: [Debugger] wuauclt.exe
IFEO\wmain.dll: [Debugger] wuauclt.exe
IFEO\WscAv.dll: [Debugger] wuauclt.exe
IFEO\wscavexe.exe: [Debugger] wuauclt.exe
IFEO\XMLWrap.Dll: [Debugger] wuauclt.exe
IFEO\{A14CD6FC-3BA8-4703-87BF-E3247CE382F5}.ini: [Debugger] wuauclt.exe
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [sugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [sugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [sugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [sugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
CustomCLSID: HKU\S-1-5-21-2094431546-3998815993-849199213-6484_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\rwi\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130924155504.dll No File
S2 smihlp2; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [X]
U4 srservice; No ImagePath
AlternateDataStreams: C:\Users\rwi:id
C:\ProgramData\anjdfkhm.ru
C:\ProgramData\Local Settings\Temp
C:\ProgramData\WinMediaManager00
C:\ProgramData\Winrar_Update
C:\Users\rwi\AppData\OICE_15_974FA576_32C1D314_B79
C:\Users\rwi\AppData\Roaming\browserup32.exe
C:\Users\rwi\AppData\Roaming\eafpajiogfiowgqa.exe
C:\Users\rwi\AppData\Roaming\pid.txt
C:\Users\rwi\AppData\Roaming\pidloc.txt
C:\Users\rwi\AppData\Roaming\WinMediaManager00
C:\Users\rwi\Desktop\hs_err_pid*.log
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
Reg: reg delete HKCU\Software\Mozilla /f
Reg: reg delete HKCU\Software\MozillaPlugins /f
Reg: reg delete HKLM\SOFTWARE\Mozilla /f
Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
CMD: for /d %f in (C:\Users\rwi\AppData\Local\{*}) do rd /s /q "%f"
CMD: dir /a C:\ProgramData
CMD: dir /a C:\Users\rwi\AppData\Roaming\Microsoft
Folder: C:\Program Files\Windows Defender
Folder: C:\Program Files (x86)\Windows Defender
EmptyTemp:

 

Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach.

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Czekaj cierpliwie, nie przerywaj działania. Gdy Fix ukończy pracę, system zostanie zresetowany. W tym samym katalogu skąd uruchamiano FRST powstanie plik fixlog.txt.

 

2. Zrób nowe logi: FRST z opcji Scan (zaznacz ponownie pole Addition) + GMER + Farbar Service Scanner. Dołącz też plik fixlog.txt.

Odnośnik do komentarza

Podaj jaki błąd zwraca uruchamianie Outlooka. Wpisy infekcji pomyślnie przetworzone, ale infekcja zniszczyła katalog C:\Program Files (x86)\Windows Defender - są w nim jakieś bełkotliwe "zastępcze" obiekty:

 

========================= Folder: C:\Program Files (x86)\Windows Defender ========================

 

2013-09-24 07:27 - 2013-05-27 04:15 - 0009216 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpAsDesc.dll.b8x0E40.7b90e

2013-09-24 07:27 - 2013-05-27 05:57 - 0392704 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpClient.dll.FCmU4.h0G9a

2013-09-24 07:27 - 2013-05-27 05:57 - 0054784 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpOAV.dll.z30d.SJ6044s

2013-09-24 07:27 - 2013-05-27 05:57 - 0004608 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MsMpLics.dll.90rF.7Tc4

2013-07-29 01:07 - 2015-01-22 14:15 - 0000000 ____D () C:\Program Files (x86)\Windows Defender\pl-PL.13407S.W2DbL5

2013-07-29 01:07 - 2013-07-29 01:07 - 0041472 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\pl-PL.13407S.W2DbL5\MpAsDesc.dll.mui.Bi718.4{2j7

2013-07-29 01:07 - 2013-07-29 01:07 - 0017920 ____N (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\pl-PL.13407S.W2DbL5\MpEvMsg.dll.mui.95kr9.VC0

 

Jest podejrzenie, że takie wtręty są też w innym miejscu na dysku. Mówiłam też, że McAfee wygląda na uszkodzony - kilka wpisów jest klasyfikowanych jako "puste". Kolejna porcja działań:

 

1. Przeinstaluj McAfee. Deinstalacja McAfee Agent i McAfee VirusScan Enterprise via Panel sterowania. Zainstaluj ponownie McAfee.

 

2. Start > w polu szukania wpisz cmd > z prawokliku Uruchom jako Administrator > wklej komendę i ENTER:

 

sfc /scannow

 

Gdy komenda ukończy działanie:

 

3. Otwórz Notatnik i wklej w nim:

 

CloseProcesses:
CMD: findstr /c:"[sR]" %windir%\logs\cbs\cbs.log
C:\ProgramData\Local Settings
C:\ProgramData\Roaming
C:\ProgramData\Mozilla
Folder: C:\Program Files (x86)\Windows Defender
Folder: C:\Users\rwitowski\AppData\Roaming\Microsoft\Outlook
Folder: C:\Users\rwitowski\AppData\Roaming\Microsoft\Signatures
Folder: C:\Users\rwitowski\AppData\Roaming\Microsoft\Word
RemoveDirectory: C:\Users\rwi\AppData\Local\Temp
EmptyTemp:

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Nastąpi restart. Przedstaw wynikowy fixlog.txt.

Odnośnik do komentarza

SFC naprawił sporo plików:

 

2015-01-29 12:10:25, Info CSI 00000230 [sR] Repairing corrupted file [ml:520{260},l:86{43}]"\??\C:\Program Files (x86)\Windows Defender"\[l:24{12}]"MpClient.dll" from store

2015-01-29 12:10:25, Info CSI 00000231 [sR] Repairing corrupted file [ml:520{260},l:86{43}]"\??\C:\Program Files (x86)\Windows Defender"\[l:24{12}]"MpAsDesc.dll" from store

2015-01-29 12:10:25, Info CSI 00000232 [sR] Repairing corrupted file [ml:520{260},l:86{43}]"\??\C:\Program Files (x86)\Windows Defender"\[l:24{12}]"MsMpLics.dll" from store

2015-01-29 12:10:25, Info CSI 00000233 [sR] Repairing corrupted file [ml:520{260},l:86{43}]"\??\C:\Program Files (x86)\Windows Defender"\[l:18{9}]"MpOAV.dll" from store

2015-01-29 12:10:25, Info CSI 00000234 [sR] Repairing corrupted file [ml:520{260},l:98{49}]"\??\C:\Program Files (x86)\Windows Defender\pl-PL"\[l:30{15}]"MpEvMsg.dll.mui" from store

2015-01-29 12:10:25, Info CSI 00000235 [sR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:30{15}]"FirewallAPI.dll" from store

2015-01-29 12:10:25, Info CSI 00000236 [sR] Repairing corrupted file [ml:520{260},l:98{49}]"\??\C:\Program Files (x86)\Windows Defender\pl-PL"\[l:32{16}]"MpAsDesc.dll.mui" from store

2015-01-29 12:10:34, Info CSI 00000288 [sR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"WerFault.exe" from store

2015-01-29 12:10:42, Info CSI 000002b2 [sR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:14{7}]"mmc.exe" from store

 

Poprawki:

 

1. Trzeba wyrzucić śmieci z naprawionego katalogu Windows Defender. Otwórz Notatnik i wklej w nim:

 

C:\Program Files (x86)\Windows Defender\MpAsDesc.dll.b8x0E40.7b90e
C:\Program Files (x86)\Windows Defender\MpClient.dll.FCmU4.h0G9a
C:\Program Files (x86)\Windows Defender\MpOAV.dll.z30d.SJ6044s
C:\Program Files (x86)\Windows Defender\MsMpLics.dll.90rF.7Tc4
C:\Program Files (x86)\Windows Defender\pl-PL.13407S.W2DbL5
C:\Users\rwi\AppData\Roaming\Microsoft\Word\STARTUP

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Pokaż wynikowy fixlog.txt.

 

2. McAfee został przeinstalowany, więc na wszelki wypadek jeszcze zrób nowy log FRST z opcji Scan (z Addition, bez Shortcut).

Odnośnik do komentarza

OK. Końcowe poprawki:

 

1. Zresetuj cache wtyczek Google Chrome, by pozbyć się pustych wpisów. W pasku adresów wpisz chrome://plugins i ENTER. Na liście wtyczek wybierz dowolną i kliknij Wyłącz. Następnie wtyczkę ponownie Włącz.

 

2. Otwórz Notatnik i wklej w nim:

 

U4 srservice; No ImagePath
DeleteQuarantine:

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Pokaż wynikowy fixlog.txt.

 

3. Dopiero po przeprowadzeniu powyższego zrób pełny skan za pomocą Malwarebytes Anti-Malware. W przypadku wykrycia czegoś dostarcz raport z wynikami.

Odnośnik do komentarza

Fix FRST nie podołał usuwaniu własnej kwarantanny. Co do błędu MBAM, to spróbujmy usunąć cały katalog Temp przy udziale komendy obchodzącej problem uprawnień. Otwórz Notatnik i wklej w nim:

 

CloseProcesses:
RemoveDirectory: C:\FRST\Quarantine
RemoveDirectory: C:\Users\rwi\AppData\Local\Temp

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Czekaj cierpliwie, ma nastąpić restart. Pokaż wynikowy fixlog.txt.

Odnośnik do komentarza

MBAM znalazł drobnostki, wszystko do wyrzucenia. Co z ostatnim Fixem FRST - kwarantanna nadal oporna?

 

 

Po tych szkodnikach mam problem z wykonaniem niektórych operacji na stronie www w palikacji która używa Java. (...) Nadal jest problem z java na stronie banku.

W której przeglądarce i jaki rodzaj problemu (jakiś błąd, brak detekcji Java)?

Odnośnik do komentarza

MBAM znalazł drobnostki, wszystko do wyrzucenia. Co z ostatnim Fixem FRST - kwarantanna nadal oporna?

 

W której przeglądarce i jaki rodzaj problemu (jakiś błąd, brak detekcji Java)?

 

Jeszcze nie zdążyłem tego zrobić.

 

W każdej, w explorer wyskakuje komunikat o pozwoleniu na włączenie wtyczki java, gdy to zrobię strona się przeładowuje od nowa.

 

W chrome aplikacja stoi w miejscu, na innych komputerach sprawdziłem i przechodzi dalej bez problemu.

 

Java z tego co widzę jest wykrywana. Rozumiem, że mam zainstalować 64 bit ?

 

Instalowałem od nowa java itp i ciągle [Filtr wulgaryzmów] zbita...

Odnośnik do komentarza
Gość
Ten temat został zamknięty. Brak możliwości dodania odpowiedzi.
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...