logo elektroda
logo elektroda
X
logo elektroda

Remove Viruses: Comprehensive Guide on Using FRST - Fixlist.txt Configuration & Attached Files

GigantAnorektyk 2340 3
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16237130
    GigantAnorektyk
    Level 2  
    Hello,
    by my inattention, I downloaded a file that had installed many unwanted programs on my computer, including my wife. I've already found discussions on this forum that you should use FRST to get rid of this crap. However, I do not fully understand what exactly should I put in the fixlist.txt file (which is to be preceded by pressing FIX), could I ask someone for help with this?
    I am attaching two files created by FRST. Thanks for the help in advance.
  • ADVERTISEMENT
  • Helpful post
    #2 16237205
    Kolobos
    IT specialist
    Odinstaluj:
    Browser-Security
    McAfee Security Scan Plus
    trotux - Uninstall
    youndoo - Uninstall
    Youtube AdBlock

    Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun: http://www.bleepingcomputer.com/download/adwcleaner/

    Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
    CloseProcesses:
    WMI_ActiveScriptEventConsumer_ASEC: C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://fanli90.cn/
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://fanli90.cn/
    2017-01-29 12:40 - 2017-01-29 12:40 - 00289792 ____H () C:\Program Files (x86)\Suvocult Update\local64spl.dll
    2017-01-29 12:41 - 2017-01-29 12:41 - 00524696 _____ () C:\Program Files\żěŃą\X64\KZipShell.dll
    2016-09-22 19:07 - 2016-06-20 15:51 - 02548944 _____ () C:\Users\HP\AppData\Roaming\Browser-Security\s768.exe
    2017-01-29 12:41 - 2017-01-29 12:41 - 02072064 _____ () C:\Users\HP\AppData\Local\Temp\00008548\msiql.exe
    2017-01-29 12:40 - 2017-01-29 12:40 - 00302032 _____ () C:\Program Files (x86)\Youtube AdBlock\IEEF\dQvnGQ.exe
    2017-01-29 12:41 - 2017-01-29 12:41 - 00219032 _____ () c:\program files\żěńą\x86\kuaizipupdatechecker.dll
    2017-01-29 12:40 - 2017-01-29 12:40 - 00149504 _____ () c:\program files (x86)\sewasemhient\phhuwardactioncll.dll
    2017-01-29 12:40 - 2017-01-29 12:40 - 00259536 _____ () C:\Program Files (x86)\Youtube AdBlock\IEEF\iYyq2FBZ.dll
    2017-01-29 12:40 - 2017-01-29 12:40 - 00548864 _____ () C:\Program Files (x86)\Youtube AdBlock\IEEF\iWnCXgI.DLL
    () C:\Users\HP\AppData\Roaming\Browser-Security\s768.exe
    () C:\Users\HP\AppData\Local\Temp\00008548\msiql.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.474\SSScheduler.exe
    () C:\Program Files (x86)\Youtube AdBlock\IEEF\dQvnGQ.exe
    HKLM\...\Run: [vnlgp] => C:\Users\HP\AppData\Roaming\vnlgp\vnlgp.exe [1546752 2016-12-16] () {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\żěŃą\X64\KZipShell.dll [2017-01-29] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-01-05]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.474\SSScheduler.exe (McAfee, Inc.)
    GroupPolicy: Ograniczenia - Windows Defender {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\10M1wX.dll [2017-01-29] ()
    BHO-x32: Youtube AdBlock -> {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\iYyq2FBZ.dll [2017-01-29] ()
    FF user.js: detected! => C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\hpszk8lf.default\user.js [2016-09-22]
    FF NewTab: Mozilla\Firefox\Profiles\hpszk8lf.default -> hxxp://www.youndoo.com/?z=6ccecf3e5aa93f01d6a530ag3z9b2w8q9t2e3c9w1w&from=amz&uid=HGSTXHTS725050A7E630_RC250A1T02660T02660TX&type=hp
    FF DefaultSearchEngine: Mozilla\Firefox\Profiles\hpszk8lf.default -> youndoo
    FF SelectedSearchEngine: Mozilla\Firefox\Profiles\hpszk8lf.default -> youndoo
    FF Homepage: Mozilla\Firefox\Profiles\hpszk8lf.default -> hxxp://www.youndoo.com/?z=6ccecf3e5aa93f01d6a530ag3z9b2w8q9t2e3c9w1w&from=amz&uid=HGSTXHTS725050A7E630_RC250A1T02660T02660TX&type=hp
    FF Extension: (Browser-Security) - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\hpszk8lf.default\Extensions\firefox@browser-security.de.xpi [2016-09-23]
    FF Extension: (Adblock Plus) - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\hpszk8lf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
    FF SearchPlugin: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\hpszk8lf.default\searchplugins\2ivem3nh.xml [2017-01-29]
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    R2 KuaizipUpdateChecker; C:\Program Files\żěŃą\X86\kuaizipUpdateChecker.dll [219032 2017-01-29] ()
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.474\McCHSvc.exe [329480 2016-12-14] (McAfee, Inc.)
    R2 Timcultgrrocult; C:\Program Files (x86)\Sewasemhient\phhuwardactioncll.dll [149504 2017-01-29] () [Brak podpisu cyfrowego]
    R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [92832 2017-01-29] (WinMount International Inc)
    S5 ucdrv;
  • ADVERTISEMENT
  • Helpful post
    #4 16237323
    Kolobos
    IT specialist
    New Fixlist.txt for FRST:
    R2 ibtsiva; % SystemRoot% \ system32 \ ibtsiva [X]
    S1 HWiNFO32; \ ?? \ C: \ WINDOWS \ SysWoW64 \ drivers \ HWiNFO64A.SYS [X]
    2017-01-29 14:59 - 2017-01-29 15:02 - 00000000 ____D C: \ AdwCleaner
    C: \ Users \ Public \ VOIP.dat

    After doing it, delete the directory C: \ FRST and that's it.
ADVERTISEMENT