Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

DNS Unlocker - usuwanie - logi.

lemmy1 28 Lut 2016 18:48 768 5
  • #2 28 Lut 2016 20:03
    Acorus 20
    Spec od komputerów

    Odinstaluj Spybot - Search & Destroy. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {7F4A2C07-4FCE-4AFD-BB9D-240B0EA5E43D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
    Task: {90FB4260-BA14-43A2-A7C6-BCE4E8D87548} - System32\Tasks\{B96DC34B-2F08-46B2-B6E3-5799E84BB5FC} => pcalua.exe -a C:\Users\Jacek\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
    Task: {AF302CC9-C24D-491B-A974-D4FD2F0E1748} - System32\Tasks\{31F1C285-61B6-5C0F-149D-380BDFCB7C11} => /s /n /i:"/rt" "C:\PROGRA~2\d1eed363\d8f3ffc9.dll"
    Task: {B2E769FA-BC17-460E-95C3-463F8303CF86} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
    Task: {DEB13DE5-FAB3-40E8-8691-00BC7F2BD381} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
    Task: {E1DF2DF4-CDDC-491D-9506-8061A403474E} - System32\Tasks\Run_Bobby_Browser => C:\Users\Jacek\AppData\Local\BoBrowser\Application\bobrowser.exe <==== UWAGA
    HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-4221920454-2136291565-1895869734-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
    HKU\S-1-5-21-4221920454-2136291565-1895869734-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0...AFQMFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlEmRFdoLlZP
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\S-1-5-21-4221920454-2136291565-1895869734-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0...AFQMFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlEmRFdoLlZP
    SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfWpdAEsSSWJGInJWDk4=&q={searchTerms}




    SearchScopes: HKLM -> OldSearch URL = hxxp://uk.yhs4.search.yahoo.com/yhs/search?hs...%3D27542657%26a%3Dwny_ir_15_14%26os%3DWindows 8 Pro&p={searchTerms}
    SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfWpdAEsSSWJGInJWDk4=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-4221920454-2136291565-1895869734-1001 -> DefaultScope {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfWpdAEsSSWJGInJWDk4=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-4221920454-2136291565-1895869734-1001 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfWpdAEsSSWJGInJWDk4=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-4221920454-2136291565-1895869734-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL =
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\d1eed363
    2016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\0b389d14-58c3-0
    2016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\0b389d14-0173-0
    2016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\{2cdea10d-112c-0}
    2016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\{0f9667dd-412c-0}
    2016-02-28 15:00 - 2016-02-28 15:00 - 00000000 ____D C:\ProgramData\{09239e25-412c-1}
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Masz zainfekowany router-wykonaj https://www.elektroda.pl/rtvforum/topic2874173.html#13841246

    0
  • Pomocny post
    #4 28 Lut 2016 21:32
    Kolobos
    Spec od komputerów

    Trzeba jeszcze usunac to co juz masz dodane.

    Fixlist.txt dla FRST:
    Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134
    Tcpip\..\Interfaces\{3DD29A13-94DE-4156-8EEF-4C35B2637681}: [NameServer] 82.163.142.7 95.211.158.134
    Tcpip\..\Interfaces\{3DD29A13-94DE-4156-8EEF-4C35B2637681}: [DhcpNameServer] 82.163.142.7
    Tcpip\..\Interfaces\{BBEAE355-2897-4F94-A756-6A5CA79B75E3}: [NameServer] 82.163.142.7 95.211.158.134
    Tcpip\..\Interfaces\{F49DF30B-7217-40BD-8BED-09B72141DAD0}: [NameServer] 82.163.142.7 95.211.158.134

    Mam nadzieje, ze zablokowales dostep do panelu routera z internetu, w przeciwnym razie zaraz znowu bedziesz mial zmienione dnsy.

    0
  • #5 28 Lut 2016 22:57
    lemmy1
    Poziom 2  

    Dziękuję bardzo, wszystko naprawione. Dostęp zdalny zablokowany.

    Przestała mi za to działać usługa Windows Update (nie może się połączyć, kod błędu 800700E). Czy może to być w jakikolwiek sposób związane z usuwaniem i blokowaniem?

    0