Skocz do zawartości

budar

Użytkownicy
  • Postów

    11
  • Dołączył

  • Ostatnia wizyta

Odpowiedzi opublikowane przez budar

  1. Witam. Bardzo dziękuję za udzieloną bezpłatną pomoc. Parę groszy wysłałem także, bardzo mi pomogliście nie wiedziałem, że tacy wspaniali ludzie istnieją w świecie internetu. Jesteście bardzo zdolni, że wam się chce z nami takimi internetowymi laikami i zieleniakami jak my męczyć to na prawdę, chylę czoła. Pozdrawiam i życzę powodzenia.

  2. (MpSvc + bfe + SharedAccess) - wszystko zakńczone sukcesem

     

    log z FSS

     

    Farbar Service Scanner Version: 22-07-2012

    Ran by Damon (administrator) on 26-07-2012 at 23:21:17

    Running from "D:\Pobrane"

    Microsoft® Windows Vista™ Business Service Pack 2 (X86)

    Boot Mode: Normal

    ****************************************************************

     

    Internet Services:

    ============

     

    Connection Status:

    ==============

    Localhost is accessible.

    LAN connected.

    Google IP is accessible.

    Google.com is accessible.

    Yahoo IP is accessible.

    Yahoo.com is accessible.

     

     

    Windows Firewall:

    =============

    MpsSvc Service is not running. Checking service configuration:

    The start type of MpsSvc service is OK.

    The ImagePath of MpsSvc service is OK.

    The ServiceDll of MpsSvc service is OK.

     

    bfe Service is not running. Checking service configuration:

    The start type of bfe service is OK.

    The ImagePath of bfe service is OK.

    The ServiceDll of bfe service is OK.

     

     

    Firewall Disabled Policy:

    ==================

     

     

    System Restore:

    ============

     

    System Restore Disabled Policy:

    ========================

     

     

    Security Center:

    ============

     

    Windows Update:

    ============

     

    Windows Autoupdate Disabled Policy:

    ============================

     

     

    Windows Defender:

    ==============

     

    Other Services:

    ==============

     

    sharedaccess Service is not running. Checking service configuration:

    The start type of sharedaccess service is set to Disabled

    The ImagePath of sharedaccess service is OK.

    The ServiceDll of sharedaccess service is OK.

     

     

    File Check:

    ========

    C:\Windows\system32\nsisvc.dll => MD5 is legit

    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit

    C:\Windows\system32\dhcpcsvc.dll => MD5 is legit

    C:\Windows\system32\Drivers\afd.sys

    [2011-06-16 12:22] - [2011-04-21 15:58] - 0273408 ____A (Microsoft Corporation)

     

    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit

    C:\Windows\system32\Drivers\tcpip.sys

    [2012-05-12 20:10] - [2012-03-30 14:39] - 0905600 ____A (Microsoft Corporation) 27D470DABC77BC60D0A3B0E4DEB6CB91

     

    C:\Windows\system32\dnsrslvr.dll => MD5 is legit

    C:\Windows\system32\mpssvc.dll => MD5 is legit

    C:\Windows\system32\bfe.dll => MD5 is legit

    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit

    C:\Windows\system32\SDRSVC.dll => MD5 is legit

    C:\Windows\system32\vssvc.exe

    [2009-09-24 09:43] - [2009-04-11 08:28] - 1055232 ____A (Microsoft Corporation)

     

    C:\Windows\system32\wscsvc.dll => MD5 is legit

    C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit

    C:\Windows\system32\wuaueng.dll => MD5 is legit

    C:\Windows\system32\qmgr.dll => MD5 is legit

    C:\Windows\system32\es.dll => MD5 is legit

    C:\Windows\system32\cryptsvc.dll => MD5 is legit

    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

    C:\Windows\system32\ipnathlp.dll

    [2008-06-20 22:04] - [2008-01-19 09:34] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165

     

    C:\Windows\system32\svchost.exe => MD5 is legit

    C:\Windows\system32\rpcss.dll => MD5 is legit

     

     

    **** End of log ****

     

    Jeszcze zrobie restart i zobacze czy działa juz zapora

     

    wygląda to tak

     

    wiec chyba dobrze

     

    zaporajpg_rqprnsq.jpg

  3. Jak na razie udało mi się wywalczyć tyle ...

     

    Farbar Service Scanner Version: 22-07-2012

    Ran by Damon (administrator) on 26-07-2012 at 22:05:57

    Running from "D:\Pobrane"

    Microsoft® Windows Vista™ Business Service Pack 2 (X86)

    Boot Mode: Normal

    ****************************************************************

     

    Internet Services:

    ============

     

    Connection Status:

    ==============

    Localhost is accessible.

    LAN connected.

    Google IP is accessible.

    Google.com is accessible.

    Yahoo IP is accessible.

    Yahoo.com is accessible.

     

     

    Windows Firewall:

    =============

    MpsSvc Service is not running. Checking service configuration:

    The start type of MpsSvc service is OK.

    The ImagePath of MpsSvc service is OK.

    The ServiceDll of MpsSvc service is OK.

     

    bfe Service is not running. Checking service configuration:

    The start type of bfe service is OK.

    The ImagePath of bfe service is OK.

    The ServiceDll of bfe service is OK.

     

     

    Firewall Disabled Policy:

    ==================

     

     

    System Restore:

    ============

     

    System Restore Disabled Policy:

    ========================

     

     

    Security Center:

    ============

     

    Windows Update:

    ============

     

    Windows Autoupdate Disabled Policy:

    ============================

     

     

    Windows Defender:

    ==============

     

    Other Services:

    ==============

     

    sharedaccess Service is not running. Checking service configuration:

    The start type of sharedaccess service is set to Disabled

    The ImagePath of sharedaccess service is OK.

    The ServiceDll of sharedaccess service is OK.

     

     

    File Check:

    ========

    C:\Windows\system32\nsisvc.dll => MD5 is legit

    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit

    C:\Windows\system32\dhcpcsvc.dll => MD5 is legit

    C:\Windows\system32\Drivers\afd.sys => MD5 is legit

    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit

    C:\Windows\system32\Drivers\tcpip.sys

    [2012-05-12 20:10] - [2012-03-30 14:39] - 0905600 ____A (Microsoft Corporation) 27D470DABC77BC60D0A3B0E4DEB6CB91

     

    C:\Windows\system32\dnsrslvr.dll => MD5 is legit

    C:\Windows\system32\mpssvc.dll => MD5 is legit

    C:\Windows\system32\bfe.dll => MD5 is legit

    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit

    C:\Windows\system32\SDRSVC.dll => MD5 is legit

    C:\Windows\system32\vssvc.exe => MD5 is legit

    C:\Windows\system32\wscsvc.dll => MD5 is legit

    C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit

    C:\Windows\system32\wuaueng.dll => MD5 is legit

    C:\Windows\system32\qmgr.dll => MD5 is legit

    C:\Windows\system32\es.dll => MD5 is legit

    C:\Windows\system32\cryptsvc.dll => MD5 is legit

    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

    C:\Windows\system32\ipnathlp.dll

    [2008-06-20 22:04] - [2008-01-19 09:34] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165

     

    C:\Windows\system32\svchost.exe => MD5 is legit

    C:\Windows\system32\rpcss.dll => MD5 is legit

     

     

    **** End of log ****

  4. SystemLook 30.07.11 by jpshortstuff

    Log created at 20:02 on 26/07/2012 by Damon

    Administrator - Elevation successful

     

    ========== reg ==========

     

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}]

    (Unable to open key - key not found)

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}]

    @="Microsoft WBEM New Event Subsystem"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32]

    @="%systemroot%\system32\wbem\wbemess.dll"

    "ThreadingModel"="Both"

     

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}]

    @="MruPidlList"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    @="%SystemRoot%\system32\shell32.dll"

    "ThreadingModel"="Apartment"

     

     

    ========== filefind ==========

     

    Searching for "services.exe"

    C:\Windows\System32\services.exe --a---- 279552 bytes [07:43 24/09/2009] [06:27 11/04/2009] 8737764F4FD36D6808EE80578409C843

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe --a---- 279552 bytes [08:35 02/11/2006] [09:45 02/11/2006] 329CF3C97CE4C19375C8ABCABAE258B0

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe --a---- 279040 bytes [20:05 20/06/2008] [07:33 19/01/2008] 2B336AB6286D6C81FA02CBAB914E3C6C

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe --a---- 279552 bytes [07:43 24/09/2009] [06:27 11/04/2009] D4E6D91C1349B7BFB3599A6ADA56851B

     

    -= EOF =-

  5. SystemLook 30.07.11 by jpshortstuff

    Log created at 16:26 on 26/07/2012 by Damon

    Administrator - Elevation successful

     

    ========== reg ==========

     

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}]

    (No values found)

     

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32]

    "ThreadingModel"="Both"

    @="C:\Users\Damon\AppData\Local\{15f78bb6-436f-e39b-8142-28de3f6757e5}\n."

     

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}]

    @="Microsoft WBEM New Event Subsystem"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32]

    @="%systemroot%\system32\wbem\wbemess.dll"

    "ThreadingModel"="Both"

     

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}]

    @="MruPidlList"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    @="%SystemRoot%\system32\shell32.dll"

    "ThreadingModel"="Apartment"

     

     

    ========== filefind ==========

     

    Searching for "services.exe"

    C:\Windows\System32\services.exe --a---- 279552 bytes [07:43 24/09/2009] [06:27 11/04/2009] 8737764F4FD36D6808EE80578409C843

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe --a---- 279552 bytes [08:35 02/11/2006] [09:45 02/11/2006] 329CF3C97CE4C19375C8ABCABAE258B0

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe --a---- 279040 bytes [20:05 20/06/2008] [07:33 19/01/2008] 2B336AB6286D6C81FA02CBAB914E3C6C

    C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe --a---- 279552 bytes [07:43 24/09/2009] [06:27 11/04/2009] D4E6D91C1349B7BFB3599A6ADA56851B

     

    -= EOF =-

     

    Czekam na dalsze instrukcje, mam nadzieję, że o to chodziło.

  6. -Nazwa problemu jak w tytule, nie działa praktycznie nic ani internet, ani nie można uruchomić żadnych aplikacji, w panelu sterowania także praktycznie nic nie działa.

     

    -Niczym nie skanowałem, nic nie mogłem uruchomić nic ani z profilu użytkownika, ani z jako administrator. Dopiero cokolwiek działa po "bezpiecznym uruchomieniu"

     

    -OTL:

    http://wklej.org/id/797830/

    -GMER:

    http://wklej.org/id/798098/

     

    Przepraszam z góry jeśli coś mieszam, jestem w temacie zielony. Z góry dziekuję bardzo za każdą pomoc.

×
×
  • Dodaj nową pozycję...