Keresés

Hirdetés

Új hozzászólás Aktív témák

  • mr.tamasbiro

    őstag

    Ezt találta a vírusírtó:
    Valaki segítene megérteni nekem,hogy mit töröljek ki?

    Saved date: 2014.01.06. 19:22:59
    Files detected: 13
    Files scanned: 1 886
    Processes scanned: 73
    Modules scanned: 654
    ASEPs scanned: 444
    Downloads scanned: 0
    Deep analysis: 4
    ---------------------------------------------------------------------------------

    Files

    ---------------------------------------------------------------------------------

    File path: c:\program files (x86)\cyberlink\power2go8\msvcr71.dll
    Publisher: Microsoft Corporation
    Signer: CyberLink
    MD5: a1a6fc56a1d0dadc164637fe43c40605
    SHA-1: 2c66dea7b3062113ee644a03c01c4c115036dc80
    Created: 2013.05.25. 9:15:20
    Detections: 1
    Determination: Ignore
    - Bkav FE as HW32.Laneul (Undefined malware)

    ---------------------------------------------------------------------------------

    File path: c:\programdata\samsung\sw update service\swmagent.exe
    Publisher: Samsung Electronics CO., LTD.
    Signer: Samsung Electronics CO., LTD.
    MD5: c8bcd5c6bacf41b849f2646611a0007e
    SHA-1: 667b2935598b1af2c6dd5b6241fa28e1fecf0097
    Created: 2013.10.21. 22:07:30
    Detections: 1
    Determination: Ignore
    - Boost by Reason as UnneededApp.Service.SamsungElectronicsCO.I

    ---------------------------------------------------------------------------------

    File path: c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
    Publisher: Adobe Systems Incorporated
    Signer: Adobe Systems, Incorporated
    MD5: adda5e1951b90d3d23c56d3cf0622adc
    SHA-1: e2d0df9db9bedfb5866efb3f9aa1c09562e51730
    Created: 2013.09.03. 7:53:50
    Detections: 1
    Determination: Ignore
    - Boost by Reason as UnneededApp.Service.AdobeSystemsorporated.G

    ---------------------------------------------------------------------------------

    File path: c:\windows\system32\drivers\intcdaud.sys
    Publisher: Intel(R) Corporation
    MD5: f5495b38bfb9149925f54f65ab40efbf
    SHA-1: 3fbef8ee216245a0b26e3fb24f6345605a0b440b
    Created: 2013.01.23. 4:22:50
    Detections: 1
    Determination: Ignore
    - Emsisoft Anti-Malware as Gen:Variant.Adware.SMSHoax.95 (Adware)

    ---------------------------------------------------------------------------------

    File path: c:\windows\system32\drivers\nisx64\1501000.012\symefa64.sys
    Publisher: Symantec Corporation
    Signer: Symantec Corporation
    MD5: 08af51153e441687130b759a8f6892ed
    SHA-1: 622de21939f7b2d86efb81da037b1f347609e41f
    Created: 2013.12.25. 19:56:26
    Detections: 1
    Determination: Ignore
    - McAfee Web Gateway as Heuristic.BehavesLike.Win32.Suspicious-BAY.K (Ignore)

    ---------------------------------------------------------------------------------

    File path: c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
    Publisher: Adobe Systems Incorporated
    Signer: Adobe Systems, Incorporated
    MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
    SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
    Created: 2012.04.04. 7:53:50
    Detections: 2
    Determination: Ignore
    - Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined malware)
    - Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\w3fsomn3\mamstub[1].exe
    Publisher: Conduit
    Signer: Conduit Ltd.
    MD5: 83be9e0a3599148fe5095430b269dd2d
    SHA-1: 72490de574849be1c39bd98ea1e24b5e78697de7
    Created: 2013.12.25. 10:52:59
    Detections: 5
    Determination: Adware
    - Reason Anti.Crapware as Adware.Conduit.H (Adware)
    - Malwarebytes as PUP.Optional.Conduit.A (Adware)
    - Trend Micro House Call as TROJ_GEN.F47V1120 (Undefined malware)
    - Dr.Web as Adware.Conduit.8 (Adware)
    - VIPRE Antivirus as Conduit (fs) (Undefined malware)

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\w3fsomn3\spsetup[1].exe
    Publisher: Conduit
    Signer: Conduit Ltd.
    MD5: 1d3f20871da10baba6bf2e2b9ddd2ba6
    SHA-1: c35a0b3af06f6ad199122599237b5aa67ceeb876
    Created: 2013.12.25. 10:53:00
    Detections: 9
    Determination: Adware
    - Reason Anti.Crapware as PUP.SearchProtect.Conduit.H (Adware)
    - Malwarebytes as PUP.Optional.Conduit.A (Adware)
    - avast! as Win32:SearchProtect-C [Adw] (Undefined malware)
    - Bkav FE as W32.Clod710.Trojan (Undefined malware)
    - Trend Micro House Call as TROJ_GEN.F47V1128 (Undefined malware)
    - Dr.Web as Adware.Conduit.6 (Adware)
    - VIPRE Antivirus as Conduit (fs) (Undefined malware)
    - G Data as Win32.Trojan.Agent.8O9SV1 (Undefined malware)
    - Boost by Reason as PUP.SearchProtect.Conduit.H

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\qdzvpw8l\setup[1].exe
    Publisher:
    Signer: Somoto Israel
    MD5: 8f4ed9a53703c50dc5b62f04d49f504a
    SHA-1: a5eeced5d0a893334f8b79f5a6fd7bfa01005860
    Created: 2013.12.25. 10:43:40
    Detections: 2
    Determination: Adware
    - SUPERAntiSpyware as Trojan.Agent/Gen-Downloader (Undefined malware)
    - Reason Anti.Crapware as Trojan.Adw.Installer.SomotoIsrael.F (Adware)

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\ivpg3jp2\spstub[1].exe
    Publisher: Conduit
    Signer: Conduit Ltd.
    MD5: d9a6b27733c2c7b638870ba4ef69b304
    SHA-1: e7fcba9a04fb26f350f33b178d14c9cc5d7e3e3d
    Created: 2013.12.25. 10:52:53
    Detections: 6
    Determination: Adware
    - Reason Anti.Crapware as Adware.SearchProtect.Conduit.G (Adware)
    - Malwarebytes as PUP.Optional.Conduit.A (Adware)
    - Dr.Web as Adware.Conduit.6 (Adware)
    - VIPRE Antivirus as Conduit (fs) (Undefined malware)
    - G Data as Win32.Application.ConduitBrothersoftTB (Undefined malware)
    - Boost by Reason as UnneededApp.Conduit.G

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\ivpg3jp2\valueapps[1].exe
    Publisher:
    Signer: Conduit Ltd.
    MD5: e9d0c6c9d87dc330bccaccd0158e52c7
    SHA-1: 9e3833212e56ef15405d5a104d644092f3aac71e
    Created: 2013.12.25. 10:53:29
    Detections: 5
    Determination: Adware
    - Malwarebytes as PUP.Optional.ValueApps.A (Adware)
    - Trend Micro House Call as TROJ_GEN.F47V1224 (Undefined malware)
    - VIPRE Antivirus as Conduit (fs) (Undefined malware)
    - G Data as Win32.Application.ConduitBrothersoftTB (Undefined malware)
    - Reason Anti.Crapware as Adware.Conduit.G (Adware)

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\arb9lbxz\checktbexist[1].exe
    Publisher: Conduit
    Signer: Conduit Ltd.
    MD5: 9b25be61beb0e8867768150d88bac0e6
    SHA-1: 42c73865a3e78e6c2b0d8597de47810cd4e82446
    Created: 2013.12.25. 10:53:11
    Detections: 7
    Determination: Adware
    - Boost by Reason as PUP.Conduit.C
    - Malwarebytes as PUP.Optional.Conduit (Adware)
    - Dr.Web as Adware.Conduit.3 (Adware)
    - VIPRE Antivirus as Conduit (fs) (Undefined malware)
    - ESET NOD32 as Win32/Toolbar.Conduit (Adware)
    - Reason Anti.Crapware as Adware.Conduit.C (Adware)
    - herdProtect (fuzzy) as a variant of afeb93edc00552d0c48f1c8843c28fc7d1b2935b (Ignore)

    ---------------------------------------------------------------------------------

    File path: c:\users\bíró family\appdata\local\microsoft\windows\temporary internet files\content.ie5\qdzvpw8l\bitool[1].dll
    Publisher:
    Signer: Somoto Ltd.
    MD5: 13a09becabce7ce7de02d42d9c00a250
    SHA-1: 40ce0a58e99858007e5dcd0bb5bf6a122686a917
    Created: 2013.12.25. 10:43:37
    Detections: 7
    Determination: Adware
    - Bkav FE as W32.Clod332.Trojan (Undefined malware)
    - Malwarebytes as PUP.Optional.Somoto (Adware)
    - avast! as Win32:Somoto-J [PUP] (Adware)
    - Dr.Web as Adware.Somoto.15 (Adware)
    - Emsisoft Anti-Malware as Application.Win32.InstallAd (Undefined malware)
    - ESET NOD32 as Win32/Somoto (Undefined malware)
    - Reason Anti.Crapware as Trojan.Adw.Somoto.G (Adware)

    [ Szerkesztve ]

  • mr.tamasbiro

    őstag

    válasz micafighter #25985 üzenetére

    A mások vizsgálóval az eredmény.

    Malwarebytes Anti-Malware (Próba) 1.75.0.1300
    www.malwarebytes.org

    Adatbázis verzió: v2014.01.06.06

    Windows 8 x64 NTFS
    Internet Explorer 10.0.9200.16750
    Bíró family :: OTTHONI-PC [rendszergazda]

    Védelem: Engedélyezve

    2014.01.06. 21:22:27
    MBAM-log-2014-01-06 (21-31-39).txt

    Vizsgálat típusa: Gyorsvizsgálat
    Engedélyezett vizsgálati beállítások: Memória | Indítópult | Rendszerleíró | Rendszerfájlok | Heurisztikus/Extra | Heurisztikus/Shuriken | PUP | PUM
    Letiltott vizsgálati beállítások: P2P
    Átvizsgált objektumok: 221270
    Eltelt idő: 8 perc, 45 másodperc

    Fertőzött memóriafolyamatok: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött memória modulok: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött Rendszerleíró kulcsok: 4
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{93DBF2BB-A2B3-4683-A92E-57E60751F346} (PUP.Optional.ValueApps.A) -> Nem történt semmi.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{93DBF2BB-A2B3-4683-A92E-57E60751F346} (PUP.Optional.ValueApps.A) -> Nem történt semmi.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346} (PUP.Optional.ValueApps.A) -> Nem történt semmi.
    HKCU\Software\Conduit\ValueApps (PUP.Optional.ValueApps.A) -> Nem történt semmi.

    Fertőzött Rendszerleíró értékek: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött Rendszerleíró adatelemek: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött mappák: 3
    C:\Program Files\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Nem történt semmi.
    C:\Program Files (x86)\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Nem történt semmi.
    C:\Users\Bíró family\AppData\Local\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Nem történt semmi.

    Fertőzött fájlok: 7
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\ARB9LBXZ\checktbexist[1].exe (PUP.Optional.Conduit) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\ARB9LBXZ\ValueApps[1].exe (PUP.Optional.Conduit.A) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\IVPG3JP2\spstub[1].exe (PUP.Optional.Conduit.A) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\IVPG3JP2\ValueApps[1].exe (PUP.Optional.ValueApps.A) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\QDZVPW8L\BiTool[1].dll (PUP.Optional.Somoto) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\W3FSOMN3\mamstub[1].exe (PUP.Optional.Conduit.A) -> Nem történt semmi.
    C:\Users\Bíró family\Local Settings\Temporary Internet Files\Content.IE5\W3FSOMN3\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Nem történt semmi.

    (befejezés)

  • mr.tamasbiro

    őstag

    válasz mr.tamasbiro #26004 üzenetére

    Potential Unwanted Programs _________________________________________________

    C:\Program Files (x86)\Conduit\ (Conduit)
    C:\Program Files\Conduit\ (Conduit)
    C:\Users\Bíró family\AppData\Local\Conduit\ (Rocketfuel)
    HKLM\SOFTWARE\Classes\AppID\secman.DLL\ (Babylon)
    HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}\ (Babylon)
    HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}\ (Babylon)
    HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}\ (Babylon)
    HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1\ (Babylon)
    HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager\ (Babylon)
    HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\secman.DLL\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}\ (Babylon)
    HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}\ (Babylon)
    HKU\S-1-5-21-2477250400-576603731-3406066007-1001\Software\Conduit\ (Conduit)
    HKU\S-1-5-21-2477250400-576603731-3406066007-1001\Software\Softonic\ (Softonic)
    [L:/dl/upc/2014-01/07/108876_banqeqbu3kzh2ckk_imag0874.jpg](IMG:/dl/upc/2014-01/07/108876_banqeqbu3kzh2ckk_imag0874.thumb.jpg)(/IMG)[/L]

  • mr.tamasbiro

    őstag

    A mozillán a schokwave flash bővítményem mindig beakasztja a gépet.
    Kinek mi van fent?

    [ Szerkesztve ]

  • mr.tamasbiro

    őstag

    Win 8-ra milyen vírusírtót tegyek ami ingyenes,tudom hülye kérdés de senki sem írt olyat,hogy dönteni tudjak.
    Szinte csak internetezés van,játék nagyon kevés.

  • mr.tamasbiro

    őstag

    Win 8-ra a gyári defender mellé milyen védelmet ajánlatok?
    Internet megy szinte fél délután.

Új hozzászólás Aktív témák