Mysz nie reaguje - spowolniony komputer, wirusy - proszę o pomoc
#1
Exclamation 
Objawy zainfekowania: 
Myszka nie reaguje zawsze na klikanie, komputer się zawiesza, internet jest spowolniony, w Chrome pisze (ciemność widzę, brak pamięci i wtyczki ulegają awarii).

Wykonywane działania:
Skan 360 IS

Logi:

Addition:
Kod:
http://wklej.org/id/1693239/

FRST:
Kod:
http://wklej.org/id/1693233/

Shortcut:
Kod:
http://wklej.org/id/1693237/
Odpowiedz
#2
Do notatnika wklej i zapisz jako fixlist.txt


Kod:
CloseProcesses:

CreateRestorePoint:
HKLM-x32\...\Run: [Smart File Advisor] => C:\Program Files (x86)\Smart File Advisor\sfa.exe [282384 2015-03-22] (Filefacts.net)
HKLM-x32\...\Run: [SFAUpdater] => C:\Program Files (x86)\Smart File Advisor\SFAUpdater.exe [656144 2015-03-18] (Filefacts.net)
C:\Program Files (x86)\Temp
C:\temp
Task: {39697FA9-236B-4FD4-93C2-70F4B5355A5B} - System32\Tasks\Uninstaller_SkipUac_GrzegorzPC => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-01-20] (IObit)
Task: {4BA9436E-D152-4A6A-B903-861479B1E8B1} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-04-07] (IObit)
Task: {52D82FBD-512D-491B-A6F7-2801F64BB244} - System32\Tasks\ASC8_SkipUac_GrzegorzPC => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2015-04-09] (IObit)
Task: {5F445D12-A12F-442C-BAAB-E4FB7025CF3E} - System32\Tasks\SlimDrivers Startup => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [2015-02-27] (SlimWare Utilities, Inc.)
Task: {86CC0933-5AB3-4DF9-B0C6-E5309B547852} - System32\Tasks\Driver Booster SkipUAC (GrzegorzPC) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-04-07] (IObit)
Task: {C16B8F59-0C5B-4D35-9480-6634D888A5F8} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-03-30] (IObit)
Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
CMD: ipconfig /flushdns
EmptyTemp:

Zapisany skrypt umieść obok ściągniętego programu FRST 
Następnie w programie kliknij Fix,po wykonaniu pokaż raport z tego działania.

Odinstaluj:


Advanced SystemCare 8
Driver Booster 2.3
IObit Uninstaller
Smart File Advisor 1.1.8
Surfing Protection

Napisz jak jest teraz.
Odpowiedz
#3
Nie wiem Czy pomogło ale Dalem FIX w tym FRST,cos tam usunelo,ale nadal jest problem,tereaz z kolei przy próbie uruchamiania jakis aplikacji pisze ze Explorator przestał działać i ekran wywala i wraca spowrotem.
Odpowiedz
#4
Może użyj funkcji "przywracanie systemu"? A tak na przyszłość to od razu po instlacji systemu i sterowników zrób jego backup, po to by w przyszłości gdy wystąpią problemy se go przywrócić. Możesz użyć do tego programu Acronis True Image 2013 czy tam 2011. Możesz też w msconfig wyłączyć zbędne śmieci startujące z systemem.

Notatka od nikita, 21.04.2015 23:20:

Dziękujemy za informacje, ale zapoznaj się jeszcze raz z regulaminem działu - szczególnie z ostatnim zdaniem. Przymykam oko ze względu na wskazówkę i brak zaleceń związanych z dodatkowymi działaniami.

Odpowiedz
#5
Fixloga nie pokazałeś i czy odinstalowałeś programy które wskazałem ?

Jeśli tak to odinstaluj dodatkowo na chwilę obecną 360 Total Security , Privatefirewall 7.0 uruchom komputer ponownie.

Zrób nowe logi i przedstaw z FRST.txt > Addition.txt
Odpowiedz
#6
ADDITION :

[Aby zobaczyć linki, zarejestruj się tutaj]

FRST :

[Aby zobaczyć linki, zarejestruj się tutaj]

Odpowiedz
#7
Chłopie ty się ogarnij,instalowałeś wszystko jak leciało. Gdzie ja napisałem o instalacji różnej maści programów zabezp. + do tego RogueKiller,brakuje tylko combofixa.

Do notatnika wklej i zapisz jako fixlist.txt

Kod:
CloseProcesses:
CreateRestorePoint:
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\...\MountPoints2: {58f22aa7-e68d-11e4-98bd-c860005552c0} - G:\autorun.exe
HKU\S-1-5-18\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0
ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} =>  No File
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [103752 2015-04-21] (Zemana Ltd.)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X]
U0 SR; No ImagePath
U2 srservice; No ImagePath
C:\Program Files (x86)\Zemana AntiMalware
C:\Users\GrzegorzPC\AppData\Local\Zemana
C:\Users\GrzegorzPC\AppData\Roaming\AVG2015
C:\$AVG
C:\ProgramData\AVG2015
C:\Users\GrzegorzPC\AppData\Roaming\TuneUp Software
C:\ProgramData\MFAData
C:\Users\GrzegorzPC\AppData\Local\MFAData
C:\ProgramData\AVAST Software
C:\ProgramData\Baidu Security
C:\Windows\system32\HWLook.log
C:\$360Section
C:\Users\GrzegorzPC\AppData\Local\Privatefirewall
C:\Users\GrzegorzPC\Doctor Web
C:\ProgramData\360Quarant
C:\ProgramData\360safe
C:\Qoobox
RemoveDirectory: C:\AdwCleaner
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-941347282-3359972568-2491682694-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
EmptyTemp:

Zapisany skrypt umieść obok ściągniętego programu FRST
Następnie w programie kliknij Fix,po wykonaniu pokaż raport z tego działania.
Odpowiedz
#8
Fixlog :

[Aby zobaczyć linki, zarejestruj się tutaj]

Odpowiedz
#9
Zrób nowe logi FRST.txt+Addition.txt i napisz jakie są ogólnie rezultaty.
Odpowiedz
#10
FRST :

[Aby zobaczyć linki, zarejestruj się tutaj]

Addition :

[Aby zobaczyć linki, zarejestruj się tutaj]


Ogólnie Jest Dobrze Wink Dzieki Za Pomoc
Odpowiedz
#11
Ściągnij

[Aby zobaczyć linki, zarejestruj się tutaj]

Zapisz na pulpicie,uruchom i zaznacz Remove disinfection tools,następnie kliknij Run
Program do usuwania wszelkich użytych narzędzi typu OTL.ADW.FRST i innych.
Odpowiedz


Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości