logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Jak usunąć wirusa rts.dsrlte.com i sprawdzić logi na Windows 8?

milosz998 22 Wrz 2014 14:10 4278 5
REKLAMA
  • #1 13981219
    milosz998
    Poziom 10  
    Posty: 86
    Pomógł: 1
    Ocena: 4
    Witam. Potrzebuję sprawdzić logi oraz usunąć dręczącego mnie wirusa rts.dsrlte.com

    Zamieszczam scan z frst bo otl pod win 8 nie śmiga
    Załączniki:
    • Addition.txt (28.38 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • FRST.txt (20.15 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • Pomocny post
    #2 13981254
    Kolobos
    Spec od komputerów
    Posty: 85181
    Pomógł: 17174
    Ocena: 10460
    Odinstaluj:
    ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.18.159 - ASUS Cloud Corporation)
    Yahoo! Search (HKCU\...\Yahoo! Search) (Version: - Pay-By-Ads)

    Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun:
    http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    Task: {4F3C3789-92D1-463B-81D1-7EE49AC806B1} - System32\Tasks\Yahoo! Search => C:\Users\mieczysłw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe [2014-09-20] (Pay By Ads LTD)
    Task: {DB3E2B79-C9D2-4C7A-9042-C6C16AE85CFB} - System32\Tasks\Yahoo! Search Udpater => C:\Users\mieczysłw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrsetup.exe [2014-09-20] (Pay By Ads LTD)
    () C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe
    () C:\Program Files (x86)\Greener Web\bin\utilGreenerWeb.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.PurBrowse64.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASHelper.exe
    (Pay By Ads LTD) C:\Users\mieczysłw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BrowserAdapter.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BrowserAdapter64.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOASPRT.exe
    () C:\Program Files (x86)\Greener Web\bin\GreenerWeb.BOAS.exe
    HKU\S-1-5-21-1008718529-1091898024-1701920994-1001\...\Run: [Yahoo! Search] => C:\Users\mieczysBw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na
    SearchScopes: HKLM-x32 - DefaultScope value is missing.
    BHO-x32: Greener Web -> {1973d53b-7311-45d7-8270-f44571c041a0} -> C:\Program Files (x86)\Greener Web\B47DBCBD-B12A-4CC2-8ED7-BD39F04358D2.dll (Greener Web)
    FF NewTab: hxxp://rts.dsrlte.com/?m=tab&affID=na
    FF Keyword.URL: hxxp://rts.dsrlte.com/?q=
    FF SearchPlugin: C:\Users\mieczysłw\AppData\Roaming\Mozilla\Firefox\Profiles\5uyzp5on.default\searchplugins\dsrlte.xml
    FF Extension: Greener Web - C:\Users\mieczysłw\AppData\Roaming\Mozilla\Firefox\Profiles\5uyzp5on.default\Extensions\{a3f28269-ad17-41a8-b032-3e0313ef8979}.xpi [2014-09-21]
    R2 Update Greener Web; C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe [325408 2014-09-22] ()
    R2 Util Greener Web; C:\Program Files (x86)\Greener Web\bin\utilGreenerWeb.exe [325408 2014-09-22] ()
    R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys [61120 2014-07-04] (StdLib)
    2014-09-20 20:20 - 2014-09-20 20:20 - 00003504 _____ () C:\Windows\System32\Tasks\Yahoo! Search Udpater
    2014-09-20 20:20 - 2014-09-20 20:20 - 00003500 _____ () C:\Windows\System32\Tasks\Yahoo! Search
    2014-09-20 20:20 - 2014-09-20 20:20 - 00000000 ____D () C:\Users\mieczysłw\AppData\Local\Pay-By-Ads
    2014-09-22 14:57 - 2014-09-22 14:56 - 00789968 _____ ( ) C:\Users\mieczysłw\Downloads\OTL by OldTimer 3.2.70.2.exe
    2014-09-21 14:09 - 2014-06-16 12:22 - 00000000 ____D () C:\Program Files (x86)\Greener Web

    W FRST wybierz Fix.

    Zrob pelny skan przy pomocy Mbam:
    http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

    Usun katalog C:\FRST i to wszystko.
  • REKLAMA
  • Pomocny post
    #3 13981269
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    OTL nie jest potrzebny.Odinstaluj ASUS WebStorage Sync Agent,Greener Web,Yahoo! Search.Otwórz Notatnik i wklej:

    Cytat:
    Task: {4F3C3789-92D1-463B-81D1-7EE49AC806B1} - System32\Tasks\Yahoo! Search => C:\Users\mieczysłw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe [2014-09-20] (Pay By Ads LTD)
    Task: {DB3E2B79-C9D2-4C7A-9042-C6C16AE85CFB} - System32\Tasks\Yahoo! Search Udpater => C:\Users\mieczysłw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrsetup.exe [2014-09-20] (Pay By Ads LTD)
    HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
    HKU\S-1-5-21-1008718529-1091898024-1701920994-1001\...\Run: [Yahoo! Search] => C:\Users\mieczysBw\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na
    SearchScopes: HKLM-x32 - DefaultScope value is missing.
    SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO-x32: Greener Web -> {1973d53b-7311-45d7-8270-f44571c041a0} -> C:\Program Files (x86)\Greener Web\B47DBCBD-B12A-4CC2-8ED7-BD39F04358D2.dll (Greener Web)
    FF NewTab: hxxp://rts.dsrlte.com/?m=tab&affID=na
    FF Keyword.URL: hxxp://rts.dsrlte.com/?q=
    FF SearchPlugin: C:\Users\mieczysłw\AppData\Roaming\Mozilla\Firefox\Profiles\5uyzp5on.default\searchplugins\dsrlte.xml
    FF Extension: Greener Web - C:\Users\mieczysłw\AppData\Roaming\Mozilla\Firefox\Profiles\5uyzp5on.default\Extensions\{a3f28269-ad17-41a8-b032-3e0313ef8979}.xpi [2014-09-21]
    R2 Update Greener Web; C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe [325408 2014-09-22] ()
    R2 Util Greener Web; C:\Program Files (x86)\Greener Web\bin\utilGreenerWeb.exe [325408 2014-09-22] ()
    R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed]
    R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys [61120 2014-07-04] (StdLib)
    2014-09-20 20:20 - 2014-09-20 20:20 - 00003504 _____ () C:\Windows\System32\Tasks\Yahoo! Search Udpater
    2014-09-20 20:20 - 2014-09-20 20:20 - 00003500 _____ () C:\Windows\System32\Tasks\Yahoo! Search
    2014-09-20 20:20 - 2014-09-20 20:20 - 00000000 ____D () C:\Users\mieczysłw\AppData\Local\Pay-By-Ads
    2014-09-21 14:09 - 2014-06-16 12:22 - 00000000 ____D () C:\Program Files (x86)\Greener Web
    C:\ProgramData\SetStretch.exe
    C:\ProgramData\SetStretch.VBS
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom FRST i kliknij w Fix.
  • REKLAMA
  • #4 13981367
    milosz998
    Poziom 10  
    Posty: 86
    Pomógł: 1
    Ocena: 4
    Dzięki panowie! Zaraz dam plusiki. Tak przy okazji by nie zaśmiecać forum nowym tematem, moglibyście zerknąć na logi z win 7?
    Załączniki:
    • Addition.txt (30.49 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • FRST.txt (29.23 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • Pomocny post
    #5 13981420
    Kolobos
    Spec od komputerów
    Posty: 85181
    Pomógł: 17174
    Ocena: 10460
    Odinstaluj: Yet Another Cleaner!

    Fixlist.txt dla FRST:
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc2.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeTray.exe
    () C:\Program Files (x86)\iSafe\ipcdl.exe
    () C:\Program Files (x86)\ClearThink\bin\utilClearThink.exe
    () C:\Program Files (x86)\ClearThink\updateClearThink.exe
    () C:\Program Files (x86)\ClearThink\bin\ClearThink.PurBrowse64.exe
    () C:\Program Files (x86)\ClearThink\bin\ClearThink.BrowserAdapter.exe
    () C:\Program Files (x86)\ClearThink\bin\ClearThink.BrowserAdapter64.exe
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
    BHO-x32: ClearThink -> {7e6d4e3e-fc66-4036-9799-ce5c625c4c56} -> C:\Program Files (x86)\ClearThink\ClearThinkbho.dll (ClearThink)
    FF Extension: Widget context - C:\Users\Miły\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2013-12-17]
    FF Extension: ClearThink - C:\Users\Miły\AppData\Roaming\Mozilla\Firefox\Profiles\z9p8qs4k.default\Extensions\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}.xpi [2014-08-13]
    CHR Extension: (ClearThink) - C:\Users\Miły\AppData\Local\Google\Chrome\User Data\Default\Extensions\epaphgdmipnghjhhebklgdchejelobkg [2014-09-22]
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    R2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [118048 2014-08-08] (Elex do Brasil Participações Ltda)
    R2 Update ClearThink; C:\Program Files (x86)\ClearThink\updateClearThink.exe [325360 2014-09-22] ()
    R2 Util ClearThink; C:\Program Files (x86)\ClearThink\bin\utilClearThink.exe [325360 2014-09-22] ()
    R1 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [247488 2014-08-08] (Elex do Brasil Participações Ltda)
    S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45248 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlKit; C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [78016 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlR3; C:\Program Files (x86)\iSafe\iSafeKrnlR3.sys [65216 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [49320 2014-08-06] (Elex do Brasil Participações Ltda)
    R1 {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64; C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys [61584 2014-08-12] (StdLib)
    2014-08-27 14:50 - 2014-09-22 14:55 - 00000000 ____D () C:\Program Files (x86)\iSafe
    2014-08-27 14:50 - 2014-08-31 11:13 - 00000000 ____D () C:\Users\Miły\AppData\Roaming\iSafe
    2014-08-27 14:50 - 2014-08-27 14:50 - 00001780 _____ () C:\Users\Public\Desktop\YAC.lnk
    2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
    2014-08-27 14:50 - 2014-08-08 08:24 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
    2014-08-27 14:49 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Miły\AppData\Roaming\eCyber
    2014-08-27 14:49 - 2014-08-27 14:49 - 00865480 _____ (Elex do Brasil Participações Ltda) C:\Users\Miły\Downloads\yet_another_cleaner_matf.exe
    C:\Program Files (x86)\ClearThink\


    Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun:
    http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner

    Zrob pelny skan przy pomocy Mbam:
    http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

    Usun katalog C:\FRST i to wszystko.
  • Pomocny post
    #6 13981447
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    Odinstaluj Yet Another Cleaner!,ClearThink .Otwórz Notatnik i wklej:

    Cytat:
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
    BHO-x32: ClearThink -> {7e6d4e3e-fc66-4036-9799-ce5c625c4c56} -> C:\Program Files (x86)\ClearThink\ClearThinkbho.dll (ClearThink)
    FF Extension: ClearThink - C:\Users\Miły\AppData\Roaming\Mozilla\Firefox\Profiles\z9p8qs4k.default\Extensions\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}.xpi [2014-08-13]
    CHR Extension: (ClearThink) - C:\Users\Miły\AppData\Local\Google\Chrome\User Data\Default\Extensions\epaphgdmipnghjhhebklgdchejelobkg [2014-09-22]
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    R2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [118048 2014-08-08] (Elex do Brasil Participações Ltda)
    R2 Update ClearThink; C:\Program Files (x86)\ClearThink\updateClearThink.exe [325360 2014-09-22] ()
    R2 Util ClearThink; C:\Program Files (x86)\ClearThink\bin\utilClearThink.exe [325360 2014-09-22] ()
    R1 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [247488 2014-08-08] (Elex do Brasil Participações Ltda)
    S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45248 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlKit; C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [78016 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlR3; C:\Program Files (x86)\iSafe\iSafeKrnlR3.sys [65216 2014-08-08] (Elex do Brasil Participações Ltda)
    R1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [49320 2014-08-06] (Elex do Brasil Participações Ltda)
    R1 {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64; C:\Windows\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys [61584 2014-08-12] (StdLib)
    2014-09-22 14:56 - 2014-09-22 14:56 - 00000000 ____D () C:\Users\Miły\Downloads\FRST-OlderVersion
    2014-08-27 14:50 - 2014-09-22 14:55 - 00000000 ____D () C:\Program Files (x86)\iSafe
    2014-08-27 14:50 - 2014-08-31 11:13 - 00000000 ____D () C:\Users\Miły\AppData\Roaming\iSafe
    2014-08-27 14:50 - 2014-08-27 14:50 - 00001780 _____ () C:\Users\Public\Desktop\YAC.lnk
    2014-08-27 14:50 - 2014-08-27 14:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
    2014-08-27 14:50 - 2014-08-08 08:24 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
    2014-08-27 14:49 - 2014-08-27 14:51 - 00000000 ____D () C:\Users\Miły\AppData\Roaming\eCyber
    2014-08-27 14:49 - 2014-08-27 14:49 - 00865480 _____ (Elex do Brasil Participações Ltda) C:\Users\Miły\Downloads\yet_another_cleaner_matf.exe
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom FRST i kliknij w Fix.
REKLAMA