wirus na FB wysyła automatycznie link do wszystkich znajomych
#1
Objawy zainfekowania:
wirus na FB wysyła automatycznie wiadomość zlinkiem do pobrania do wszystkich znajomych, nie znam się na takich sprawach znalazłam jakąś instrukcję i póki co tyle zrobiłam Smile

Wykonywane działania:
OTL by Old Timer Version 3.2.6.0
farbar recovery scan tool

Logi:

[Aby zobaczyć linki, zarejestruj się tutaj]

[Aby zobaczyć linki, zarejestruj się tutaj]

[Aby zobaczyć linki, zarejestruj się tutaj]

Odpowiedz
#2
Do notatnika wklej i zapisz jako fixlist.txt

Kod:
(Bandoo Media Inc.) C:Program Files (x86)Movies ToolbarDatamngrDatamngrCoordinator.exe
() C:UsersSamsungAppDataLocalKookoskookos.exe
(Bandoo Media Inc.) C:Program Files (x86)Movies ToolbarDatamngrDatamngrCoordinator.exe
(Bandoo Media Inc.) C:Program Files (x86)Movies ToolbarDatamngrDatamngrUI.exe
(Adobe Systems Incorporated) C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe
() C:UsersSamsungAppDataRoaming 466659C.exe
() C:UsersSamsungAppDataLocalTempminerd.exe
HKUS-1-5-21-1480235242-2075340924-4091109271-1001...Run: [Kookos] - C:UsersSamsungAppDataLocalKookoskookos.exe [4043264 2012-01-15] ()
HKUS-1-5-21-1480235242-2075340924-4091109271-1001...Run: [Facebook Update] - C:UsersSamsungAppDataLocalFacebookUpdateFacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.)
HKUS-1-5-21-1480235242-2075340924-4091109271-1001...Run: [iLivid] - "C:UsersSamsungAppDataLocaliLividiLivid.exe" -autorun
AppInit_DLLs: C:PROGRA~3WincertWIN64C~1.DLL => C:ProgramDataWincertwin64cert.dll [8704 2013-11-04] ()
AppInit_DLLs: C:PROGRA~2MOVIES~1Datamngrx64mgrldr.dll => C:Program Files (x86)Movies ToolbarDatamngrx64mgrldr.dll [24064 2013-12-23] ()
AppInit_DLLs-x32: C:PROGRA~3WincertWIN32C~1.DLL => C:ProgramDataWincertwin32cert.dll [7168 2013-11-04] ()
AppInit_DLLs-x32: C:PROGRA~2MOVIES~1Datamngrmgrldr.dll => C:Program Files (x86)Movies ToolbarDatamngrmgrldr.dll [20480 2013-12-23] ()
IFEObitguard.exe: [Debugger] tasklist.exe
IFEObprotect.exe: [Debugger] tasklist.exe
IFEObpsvc.exe: [Debugger] tasklist.exe
IFEObrowsemngr.exe: [Debugger] tasklist.exe
IFEObrowserdefender.exe: [Debugger] tasklist.exe
IFEObrowsermngr.exe: [Debugger] tasklist.exe
IFEObrowserprotect.exe: [Debugger] tasklist.exe
IFEObrowsersafeguard.exe: [Debugger] tasklist.exe
IFEObundlesweetimsetup.exe: [Debugger] tasklist.exe
IFEOcltmngsvc.exe: [Debugger] tasklist.exe
IFEOdelta babylon.exe: [Debugger] tasklist.exe
IFEOdelta tb.exe: [Debugger] tasklist.exe
IFEOdelta2.exe: [Debugger] tasklist.exe
IFEOdeltainstaller.exe: [Debugger] tasklist.exe
IFEOdeltasetup.exe: [Debugger] tasklist.exe
IFEOdeltatb.exe: [Debugger] tasklist.exe
IFEOdeltatb_2501-c733154b.exe: [Debugger] tasklist.exe
IFEOiminentsetup.exe: [Debugger] tasklist.exe
IFEOprotectedsearch.exe: [Debugger] tasklist.exe
IFEOrjatydimofu.exe: [Debugger] tasklist.exe
IFEOsearchprotection.exe: [Debugger] tasklist.exe
IFEOsnapdo.exe: [Debugger] tasklist.exe
IFEOstinst32.exe: [Debugger] tasklist.exe
IFEOstinst64.exe: [Debugger] tasklist.exe
IFEOsweetimsetup.exe: [Debugger] tasklist.exe
IFEOtbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe
Startup: C:UsersSamsungAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup{71dead9f-2e43-544c-005d-e14a71dead9f}.exe (Synei )
HKLM...AppCertDlls: [x86] -> C:Program Files (x86)Movies ToolbarDatamngrapcrtldr.dll [485376 2013-12-23] () <===== ATTENTION
HKLM...AppCertDlls: [x64] -> C:Program Files (x86)Movies ToolbarDatamngrx64apcrtldr.dll [658432 2013-12-23] () <===== ATTENTION
HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-429&v=a10781-123&t=4
HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://samsung.msn.com
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=429&systemid=406&v=a10781-123&apn_uid=1695228051234708&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&q={searchTerms}&barid={634993E1-C6AA-4DF9-8082-253547484A25}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=429&systemid=406&v=a10781-123&apn_uid=1695228051234708&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&q={searchTerms}&barid={634993E1-C6AA-4DF9-8082-253547484A25}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=429&systemid=406&v=a10781-123&apn_uid=1695228051234708&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&q={searchTerms}&barid={634993E1-C6AA-4DF9-8082-253547484A25}
BHO-x32: Movies Toolbar (Dist. by Bandoo Media, Inc.) - {3d86a75b-cb6b-4764-885d-ca6336f04ba2} - C:PROGRA~2MOVIES~1DatamngrSRTOOL~1IEsearchresultsDx.dll No File
Toolbar: HKLM-x32 - Movies Toolbar (Dist. by Bandoo Media, Inc.) - {3d86a75b-cb6b-4764-885d-ca6336f04ba2} - C:PROGRA~2MOVIES~1DatamngrSRTOOL~1IEsearchresultsDx.dll No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -No File
R2 DatamngrCoordinator; C:Program Files (x86)Movies ToolbarDatamngrDatamngrCoordinator.exe [3447808 2013-12-23] (Bandoo Media Inc.)
C:UsersSamsungAppDataRoaming 574E211.exe
C:UsersSamsungAppDataRoaming 52EFA12.exe
C:UsersSamsungAppDataRoaming 4F69334.exe
C:UsersSamsungAppDataRoaming 49D6511.exe
C:UsersSamsungAppDataRoaming 49D63AA.exe
C:UsersSamsungAppDataRoaming 46665CB.exe
C:UsersSamsungAppDataRoaming 466659C.exe
C:UsersSamsungAppDataRoaming 05A4470.exe
C:UsersSamsungAppDataRoaming 02347E8.exe
C:UsersSamsungAppDataRoaming 0E12C03.exe
C:UsersSamsungAppDataRoaming 0AA32D5.exe
C:UsersSamsungAppDataRoaming 07337F3.exe
C:UsersSamsungAppDataRoaming 03C3A62.exe
C:UsersSamsungAppDataRoaming ED86120.exe
C:UsersSamsungAppDataRoaming EA07837.exe
C:UsersSamsungAppDataRoaming 9AA8C59.exe
C:UsersSamsungAppDataRoaming 9AA8C4A.exe
C:UsersSamsungAppDataRoaming 9738AE2.exe
C:UsersSamsungAppDataRoaming 93C9443.exe
C:UsersSamsungAppDataRoaming{71dead9f-2e43-544c-005d-e14a71dead9f}
C:ProgramDataDatamngr
C:Program Files (x86)Movies ToolbarDatamngrapcrtldr.dll
C:Program Files (x86)Movies ToolbarDatamngrx64apcrtldr.dll
C:UsersSamsungAppDataLocalTempBundleSweetIMSetup.exe
C:UsersSamsungAppDataLocalTempDataCard_Setup64.exe
C:UsersSamsungAppDataLocalTempDelta.exe
C:UsersSamsungAppDataLocalTempDeltaTB.exe
C:UsersSamsungAppDataLocalTemplibcurl-4.dll
C:UsersSamsungAppDataLocalTempminerd.exe
C:UsersSamsungAppDataLocalTempMybabylonTB.exe
C:UsersSamsungAppDataLocalTemppropsys.dll
C:UsersSamsungAppDataLocalTemppthreadGC2.dll
C:UsersSamsungAppDataLocalTempShortcut_Shortcut_SweetImSetup.exe
C:UsersSamsungAppDataLocalTempShortcut_SweetImSetup.exe
C:UsersSamsungAppDataLocalTempt.dll
C:UsersSamsungAppDataLocalTempWSSetup.exe
Task: {FA8941D9-8958-4DD9-878D-FC6244F95813} - System32TasksFacebookUpdateTaskUserS-1-5-21-1480235242-2075340924-4091109271-1001UA => C:UsersSamsungAppDataLocalFacebookUpdateFacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: C:windowsTasksFacebookUpdateTaskUserS-1-5-21-1480235242-2075340924-4091109271-1001Core.job => C:UsersSamsungAppDataLocalFacebookUpdateFacebookUpdate.exe
Task: C:windowsTasksFacebookUpdateTaskUserS-1-5-21-1480235242-2075340924-4091109271-1001UA.job => C:UsersSamsungAppDataLocalFacebookUpdateFacebookUpdate.exe
HKLMSYSTEMCurrentControlSetControlSafeBootNetworktvnserver => ""="Service"
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: netsh advfirewall reset


Zapisany skrypt umieść obok ściągniętego programu FRST
Następnie w programie kliknij Fix ,po wykonaniu pokaż raport z tego działania.

W przeglądarce firefox -menu Pomoc > Informacje dla pomocy technicznej > Zresetuj program Firefox. Reset nie naruszy zakładek i haseł.

Odinstaluj:

Movies Toolbar for Firefox
Movies Toolbar for Internet Explorer

Ściągnij program

[Aby zobaczyć linki, zarejestruj się tutaj]

kliknij Szukaji następnie Usuń
pokaż raport
Odpowiedz


Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości