Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Mpc Cleaner - Usunięcie Windows 8

mactros 25 Gru 2016 13:45 537 11
  • Pomocny post
    #2 25 Gru 2016 14:29
    krzychupar
    Poziom 40  

    Odinstaluj:
    AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.3.6.255 - AVG Technologies)
    WinZip

    Otwórz notatnik systemowy i wklej:
    Task: {549B361C-21FD-4A6F-9463-1B912BB4B393} - System32\Tasks\Opera scheduled Autoupdate 1479967016 => C:\Program Files (x86)\Opera\launcher.exe [2016-12-19] (Opera Software)
    Task: {899148AE-716B-408D-B503-3CFBC7490223} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
    Hosts
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-567633283-798231980-3828430520-1001\...\MountPoints2: {87e14237-7e0a-11e4-8263-54353035fc8e} - "G:\pushinst.exe"
    ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => -> Brak pliku
    ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (WinZip Computing, S.L.)
    ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (WinZip Computing, S.L.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-11-24]
    ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    GroupPolicy\User: Ograniczenia <======= UWAGA
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKU\S-1-5-21-567633283-798231980-3828430520-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {d4fee3d1-1014-4db8-a824-573bf9ab51c7} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-567633283-798231980-3828430520-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-567633283-798231980-3828430520-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
    BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll => Brak pliku
    CHR HKLM-x32\...\Chrome\Extension: [bbiilhoacmmppcmcogfmaailncbelbgn] - hxxps://clients2.google.com/service/update2/crx
    R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [355808 2016-08-31] (DotC United Inc) <==== UWAGA
    S3 MBAMSwissArmy; Brak ImagePath
    R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-08-31] (DotC United Inc) <==== UWAGA
    S2 NEWDRIVER; Brak ImagePath
    S3 BTATH_BUS; \SystemRoot\System32\drivers\btath_bus.sys [X]
    S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
    2016-12-25 12:36 - 2016-12-25 12:36 - 00001806 _____ C:\Users\Public\Desktop\MPC Desktop.lnk
    2016-12-25 12:36 - 2016-12-25 12:36 - 00001749 _____ C:\Users\Public\Desktop\MPC Cleaner.lnk
    2016-12-25 12:36 - 2016-12-25 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
    2016-12-25 12:36 - 2016-12-25 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
    2016-12-24 09:50 - 2016-08-15 18:51 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
    2016-11-27 14:58 - 2016-11-21 23:00 - 00000000 ____D C:\ProgramData\WinZip
    C:\Windows\System32\iexpress.exe
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • #3 25 Gru 2016 15:42
    Kolobos
    Spec od komputerów

    Po wykonaniu zamiesc nowe logi z FRST, ze skanowania.

    0
  • #5 25 Gru 2016 16:33
    krzychupar
    Poziom 40  

    Przeskanuj jeszcze raz i zamieść nowe logi. Log Frst.txt jest pusty.

    0
  • Pomocny post
    #7 26 Gru 2016 10:57
    Kolobos
    Spec od komputerów

    Zamiesc screen z menadzera urzadzen.

    Uruchom z prawami administratora plik C:\Program Files (x86)\MPC Cleaner\uninstall.exe

    Odinstaluj:
    Spybot - Search & Destroy
    Superb Game Boost

    Uzyj https://sourceforge.net/projects/adobeflashup...an%20Remover/RemoveMcAfee_silent.exe/download i usun TrueKey.

    Nowy Fixlist.txt dla FRST:
    Task: {3F302E4C-BA58-4045-9091-E8E03B4158B1} - System32\Tasks\cFos\Registration Tasks\Open Browser => Firefox.exe -osint -url "hxxp://www.cfos.de/pl/cfosspeed/expiration.htm?sw-10.08.2216&amp;days=-38&amp;ret=11&amp;raw=13&amp;exp=101"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service"
    Hosts:
    (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    Task: {732E2761-E21B-48DB-B1FE-27146C627F0F} - System32\Tasks\Driver Booster SkipUAC (Win8) => C:\Program Files (x86)\IObit\Driver Booster\4.1.0\DriverBooster.exe
    HKU\S-1-5-21-567633283-798231980-3828430520-1001\...\Run: [BingSvc] => C:\Users\Win8\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2016-01-02] (© 2015 Microsoft Corporation)
    HKU\S-1-5-21-567633283-798231980-3828430520-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
    Task: {EA8E497E-1054-495D-95BF-6EFDEC643B88} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe
    SearchScopes: HKLM -> DefaultScope - brak wartości
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
    R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
    R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [355808 2016-08-31] (DotC United Inc) <==== UWAGA
    R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-08-31] (DotC United Inc) <==== UWAGA
    S3 cpuz138; \??\C:\Users\Win8\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X]
    2016-12-26 10:29 - 2016-12-26 10:29 - 00001806 _____ C:\Users\Public\Desktop\MPC Desktop.lnk
    2016-12-26 10:29 - 2016-12-26 10:29 - 00001749 _____ C:\Users\Public\Desktop\MPC Cleaner.lnk
    2016-12-26 10:29 - 2016-12-26 10:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
    2016-12-25 16:18 - 2016-12-25 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
    2016-12-24 11:01 - 2016-12-24 12:11 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2016-12-24 11:01 - 2016-12-24 11:15 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2016-12-24 11:01 - 2016-12-24 11:01 - 00001427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2016-12-24 11:01 - 2016-12-24 11:01 - 00001415 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2016-12-24 11:01 - 2016-12-24 11:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2016-12-24 11:01 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
    2016-12-24 10:28 - 2016-12-24 10:28 - 00000000 _____ C:\autoexec.bat
    2016-12-24 09:31 - 2016-12-24 09:31 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
    2016-12-24 09:50 - 2016-08-15 18:51 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
    2016-12-24 09:50 - 2016-04-14 20:31 - 00000000 ____D C:\ProgramData\Nico Mak Computing


    Po wykonaniu zamiesc nowe logi z FRST, ze skanowania.

    0
  • #8 26 Gru 2016 12:35
    mactros
    Poziom 9  

    Nie mam pliku "uninstall.exe".
    Screen z menedżera urządzeń. Mpc Cleaner - Usunięcie Windows 8
    RemoveMcAfee_silent nie chce sie uruchomić.
    Dziękuje kolegom za chęć pomocy ja jednak odpuszczam sobie ten temat. Za cienki jestem :-)

    0
  • Pomocny post
    #9 26 Gru 2016 13:39
    Kolobos
    Spec od komputerów

    Za cienki do czego? Przeciez niczego nie robisz sam, a polecania chyba potrafisz wykonac?


    Wykonaj taki Fixlist.txt:

    RestoreQuarantine:

    Po wykonaniu sprawdz czy masz plik uninstall w C:\Program Files (x86)\MPC Cleaner\.
    Jezeli bedzie to go uruchom i odinstaluj MPC. Nastepnie wykonaj ponownie oba podane Fixlist.txt.

    Jezeli nie to bedziesz musial ponownie wykonac oba Fixlist oraz uruchomic FRST z poziomu WinRe: http://www.fixitpc.pl/topic/4414-diagnostyka-infekcji-na-niestartujących-windows/
    i tam wykonac taki Fixlist.txt:
    R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [355808 2016-08-31] (DotC United Inc) <==== UWAGA
    R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-08-31] (DotC United Inc) <==== UWAGA
    C:\Windows\System32\DRIVERS\MPCKpt.sys
    C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
    2016-12-26 10:29 - 2016-12-26 10:29 - 00001806 _____ C:\Users\Public\Desktop\MPC Desktop.lnk
    2016-12-26 10:29 - 2016-12-26 10:29 - 00001749 _____ C:\Users\Public\Desktop\MPC Cleaner.lnk
    2016-12-26 10:29 - 2016-12-26 10:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
    2016-12-25 16:18 - 2016-12-25 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
    2016-12-24 11:01 - 2016-12-24 12:11 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2016-12-24 11:01 - 2016-12-24 11:15 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2016-12-24 11:01 - 2016-12-24 11:01 - 00001427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2016-12-24 11:01 - 2016-12-24 11:01 - 00001415 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2016-12-24 11:01 - 2016-12-24 11:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2016-12-24 11:01 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
    2016-12-24 10:28 - 2016-12-24 10:28 - 00000000 _____ C:\autoexec.bat
    2016-12-24 09:31 - 2016-12-24 09:31 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
    2016-12-24 09:50 - 2016-08-15 18:51 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner


    Po wykonaniu zamiesc nowe logi z FRST, ze skanowania, z trybu normalnego.

    > RemoveMcAfee_silent nie chce sie uruchomić.

    Co sie wyswietla? Moze antywirus cos blokuje? Wylacz i sprawdz czy sie wlaczy.

    0
  • Pomocny post
    #11 28 Gru 2016 11:48
    Kolobos
    Spec od komputerów

    Nowy Fixlist.txt dla FRST:
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    GroupPolicy\User: Ograniczenia <======= UWAGA
    SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
    2016-12-26 12:03 - 2016-03-05 14:55 - 00000000 ____D C:\AdwCleaner
    2016-12-26 11:41 - 2016-04-14 20:27 - 00000000 ____D C:\Program Files\Common Files\McAfee
    2016-12-26 11:32 - 2016-04-14 20:27 - 00000000 ____D C:\Program Files (x86)\McAfee
    2016-12-26 11:32 - 2015-01-26 12:55 - 00000000 ____D C:\ProgramData\McAfee
    C:\Windows\System32\iexpress.exe

    Po wykonaniu usun katalog C:\FRST i to wszystko.

    0
  • #12 28 Gru 2016 13:17
    mactros
    Poziom 9  

    Załatwione :-) Dziękuje uprzejmie. Wypiję za Wasze zdrowie :-)

    0