Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola PC po odstranění mallware

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Kontrola PC po odstranění mallware

#1 Příspěvek od PetrLe »

Dobrý den,
po startu systému se nyní objevuje hláška RUNDLL: "Chyba při načítání souboru TWEAKUI.CPL. Uvedený modul nebyl nalezen". Po potvrzení hláška zmizí.
Kontrolou Avastu(kompletní důkladný test) jsem nalezl několik malware a přesunul do truhly.
Prosím o pomoc s doléčením.
Níže posílám log ADWCleaneru(SCAN a následně CLEAN) a RSIT:


# AdwCleaner v4.102 - Report created 29/11/2014 at 09:59:50
# Updated 23/11/2014 by Xplode
# Database : 2014-11-23.7 [Local]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : oper - KANCELAR1
# Running from : C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


*************************

AdwCleaner[R0].txt - [726 octets] - [29/11/2014 09:54:45]
AdwCleaner[S0].txt - [648 octets] - [29/11/2014 09:59:50]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [707 octets] ##########







Logfile of random's system information tool 1.10 (written by random/random)
Run by oper at 2014-11-29 10:13:58
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 206 GB (86%) free of 238 GB
Total RAM: 990 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:08, on 29.11.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\oper\Plocha\RSIT.exe
C:\Program Files\trend micro\oper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.seznam.cz
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = skola.int
O17 - HKLM\Software\..\Telephony: DomainName = skola.int
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: NameServer = 192.168.77.15
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = skola.int
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6841 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\Záloha na počítač kancelar.job - C:\WINDOWS\system32\ntbackup.exe backup "@C:\Documents and Settings\nemcova\Local Settings\Data aplikací\Microsoft\Windows NT\NTBackup\data\Záloha na počítač kancelar.bks" /a /d "Sada vytvořena 23.10.2008 v 8:31" /v:no /r:no /rs:no /hc:off /m daily /j "Záloha na počítač kancelar" /l:s /f "\\Kancelar\install\Záloha-Iveta\Zaloha.bkf"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-11-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2014-11-24 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-11-29 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"NWEReboot"= []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2007-04-12 98304]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2014-11-24 5226600]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-06-01 94208]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-11-21 5282584]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDesktopCleanupWizard"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Install\NeRo_Miranda\miranda32.exe"="C:\Install\NeRo_Miranda\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe"="C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe"="C:\Program Files\HP\csiInstaller\5C069542-CA13-4f1b-B90C-28C6430F4992\Installer\hpbcsiInstaller.exe:*:Enabled:HP Networked Printer Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3acm"=l3codeca.acm
"msacm.msaudio1"=msaud32.acm
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll

======List of files/folders created in the last 1 month======

2014-11-29 10:13:58 ----D---- C:\rsit
2014-11-29 10:13:58 ----D---- C:\Program Files\trend micro
2014-11-29 09:54:42 ----D---- C:\AdwCleaner
2014-11-29 09:37:03 ----A---- C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36:53 ----A---- C:\WINDOWS\system32\java.exe
2014-11-28 09:01:04 ----D---- C:\Program Files\CCleaner
2014-11-27 08:49:59 ----D---- C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49:13 ----D---- C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:04:28 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04:26 ----A---- C:\WINDOWS\avastSS.scr
2014-10-30 16:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:06:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:05:09 ----D---- C:\Program Files\NVIDIA Corporation
2014-10-30 16:03:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:03:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 16:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 15:44:20 ----D---- C:\WINDOWS\system32\MRT
2014-10-30 15:31:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19:10 ----N---- C:\WINDOWS\system32\xp_eos.exe
2014-10-30 03:04:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:04:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-10-30 03:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$

======List of files/folders modified in the last 1 month======

2014-11-29 10:14:06 ----D---- C:\WINDOWS\Prefetch
2014-11-29 10:13:58 ----D---- C:\Program Files
2014-11-29 10:06:10 ----SHD---- C:\WINDOWS\Installer
2014-11-29 10:06:10 ----SD---- C:\WINDOWS\Tasks
2014-11-29 10:06:10 ----D---- C:\WINDOWS\Temp
2014-11-29 10:02:30 ----D---- C:\WINDOWS
2014-11-29 10:01:28 ----D---- C:\Program Files\Google
2014-11-29 10:00:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-11-29 10:00:15 ----D---- C:\WINDOWS\system32\CatRoot2
2014-11-29 09:46:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:37:13 ----HD---- C:\Config.Msi
2014-11-29 09:37:12 ----D---- C:\Program Files\Common Files\Java
2014-11-29 09:37:04 ----D---- C:\WINDOWS\system32
2014-11-29 09:33:01 ----SHD---- C:\RECYCLER
2014-11-29 09:27:38 ----D---- C:\WINDOWS\security
2014-11-28 12:21:12 ----SHD---- C:\WINDOWS\CSC
2014-11-28 09:17:03 ----D---- C:\WINDOWS\Debug
2014-11-28 09:17:02 ----D---- C:\WINDOWS\Minidump
2014-11-28 08:52:14 ----HD---- C:\WINDOWS\inf
2014-11-28 07:15:55 ----D---- C:\gordic
2014-11-27 14:21:35 ----D---- C:\POKARC
2014-11-27 14:15:38 ----D---- C:\KDFARC
2014-11-27 09:31:28 ----D---- C:\Program Files\Internet Explorer
2014-11-27 09:31:21 ----A---- C:\WINDOWS\system.ini
2014-11-27 09:29:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-11-27 09:04:37 ----SD---- C:\Documents and Settings\oper\Data aplikací\Microsoft
2014-11-26 14:09:16 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-25 06:50:55 ----D---- C:\WINDOWS\system32\drivers
2014-11-18 08:32:32 ----D---- C:\Program Files\Messenger
2014-11-12 15:21:17 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-31 14:56:19 ----D---- C:\UCRARC
2014-10-31 07:30:02 ----RSD---- C:\WINDOWS\assembly
2014-10-31 07:30:02 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-30 16:05:02 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03:33 ----D---- C:\WINDOWS\ie8updates
2014-10-30 15:56:34 ----D---- C:\WINDOWS\WinSxS
2014-10-30 15:56:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-11-24 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-11-24 206248]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-01-27 99584]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-03-11 20640]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-11-24 55240]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-11-24 787800]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-11-24 423784]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-11-24 57928]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-11-24 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-11-24 70384]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 HidBatt;Ovladač baterie zdroje UPS standardu HID; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2008-04-13 20352]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2003-08-04 6912]
S3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2003-08-04 11392]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2014-11-24 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-11-29 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2010-04-12 142336]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-01-24 131139]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26 267440]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola PC po odstranění mallware

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Re: Kontrola PC po odstranění mallware

#3 Příspěvek od PetrLe »

Po restartu ta hláška ohledně nenalezeného objektu je tam stále. Co kdybych odebral z registru položku:
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

Co vůbec Tweakui.cpl dělá?

Níže poíslám log Zoek:




Zoek.exe v5.0.0.0 Updated 28-11-2014
Tool run by oper on so 29.11.2014 at 12:49:03,65.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\oper\Plocha\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

29.11.2014 12:50:44 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Suspicious Entries Found ======================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP"="3389:TCP:*:Enabled:@xpsp2res.dll,-22009"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Program Files\ComPlus Applications deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ezsid.dat deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [24.11.2014 12:04]

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[24.11.2014 12:04]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... RA_csCZ448"

==== Reset Google Chrome ======================

Nothing found to reset

==== Empty IE Cache ======================

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\bistep\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\gio\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\hlava\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\kancelar\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\nemcova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\pergerova\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\skolnik\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2 folders=1 210 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\oper\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\oper\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on so 29.11.2014 at 13:06:49,84 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola PC po odstranění mallware

#4 Příspěvek od vyosek »

:arrow: Je to pozustatek reklamniho SW, odstranime nasledne

:arrow: Dejte log z FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Re: Kontrola PC po odstranění mallware

#5 Příspěvek od PetrLe »

OK.
Níže je log FRST:


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01
Ran by oper (administrator) on KANCELAR1 on 29-11-2014 13:48:26
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Čeština
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\WINDOWS\system32\logon.scr
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAShCut.exe [61952 2004-10-27] (Windows (R) Server 2003 DDK provider)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [925696 2005-05-20] (Analog Devices, Inc.)
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
SearchScopes: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-898712048-2085054343-697575874-1365 -> &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdat ... /opuc4.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.77.11 192.168.77.12
Tcpip\..\Interfaces\{AE8A2405-2D22-419B-934B-E4B9ABD498CD}: [NameServer] 192.168.77.15

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-09-27]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-06-21]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
S2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [142336 2010-04-12] (HP) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-11-29] (Oracle Corporation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AEAudioService; C:\WINDOWS\System32\drivers\AEAudio.sys [127872 2005-03-04] (Andrea Electronics Corporation)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [42496 2005-03-09] (Advanced Micro Devices)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-11-24] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2014-11-24] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55240 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-11-24] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [787800 2014-11-24] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [423784 2014-11-24] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57928 2014-11-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [206248 2014-11-24] ()
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows (R) Server 2003 DDK provider)
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [99584 2006-01-27] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [34176 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13056 2006-02-17] (NVIDIA Corporation)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-03-11] (Sonic Solutions) [File not signed]
R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [393088 2005-08-11] (Sensaura)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:47 - 2014-11-29 13:48 - 00000000 ____D () C:\FRST
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:38 - 2014-11-29 13:47 - 01109504 _____ (Farbar) C:\Documents and Settings\oper\Plocha\FRST.exe
2014-11-29 13:02 - 2014-11-29 13:48 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Temp
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
2014-11-29 09:46 - 2014-11-29 09:46 - 00020328 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2014-11-29 09:41 - 2014-11-29 09:41 - 00000000 __SHD () C:\Documents and Settings\oper\IECompatCache
2014-11-29 09:39 - 2014-11-29 09:39 - 00000000 __SHD () C:\Documents and Settings\oper\PrivacIE
2014-11-29 09:37 - 2014-11-29 09:37 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Temp
2014-11-29 09:37 - 2014-11-29 09:36 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-11-29 09:36 - 2014-11-29 09:36 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-11-28 09:01 - 2014-11-28 09:01 - 00000682 _____ () C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-28 09:01 - 2014-11-28 09:01 - 00000000 ____D () C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2014-11-27 09:09 - 2014-11-27 09:09 - 00012818 ____N () C:\Documents and Settings\oper\Dokumenty\Gordic Reporter - POKS0004.mdi
2014-11-27 09:02 - 2014-11-27 09:02 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WKdf.lnk
2014-11-27 08:59 - 2014-11-27 08:59 - 00012822 ____N () C:\Documents and Settings\oper\Plocha\Gordic Reporter - POKS0001.mdi
2014-11-27 08:54 - 2014-11-27 08:54 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Sun
2014-11-27 08:49 - 2014-11-27 09:10 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\Gordic
2014-11-27 08:49 - 2014-11-27 08:49 - 00000448 _____ () C:\Documents and Settings\oper\Plocha\Zástupce - WPOK.lnk
2014-11-27 08:49 - 2014-11-27 08:49 - 00000000 ____D () C:\Documents and Settings\oper\Data aplikací\AVAST Software
2014-11-24 12:05 - 2014-11-24 12:05 - 00001742 _____ () C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2014-11-24 12:04 - 2014-11-24 12:04 - 00291352 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-11-24 12:04 - 2014-11-24 12:04 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-30 16:07 - 2014-10-30 16:07 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2922229$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$
2014-10-30 16:06 - 2014-10-30 16:06 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-10-30 16:05 - 2014-10-30 16:06 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb0.bin
2014-10-30 16:05 - 2014-10-30 16:06 - 00000001 _____ () C:\WINDOWS\system32\nvdrssel.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 01072544 _____ () C:\WINDOWS\system32\nvdrsdb1.bin
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-30 16:05 - 2014-10-30 16:05 - 00000000 _____ () C:\WINDOWS\system32\nvdrswr.lk
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2929961$
2014-10-30 16:03 - 2014-10-30 16:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2898715$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2930275$
2014-10-30 16:02 - 2014-10-30 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904266$
2014-10-30 15:44 - 2014-11-12 15:27 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2893294$
2014-10-30 15:31 - 2014-10-30 15:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2892075$
2014-10-30 15:26 - 2014-10-30 15:26 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____N (Microsoft Corporation) C:\WINDOWS\system32\xp_eos.exe
2014-10-30 12:19 - 2014-02-27 00:28 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xp_eos.exe
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2014-10-30 03:04 - 2014-10-30 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2868626$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2876331$
2014-10-30 03:02 - 2014-10-30 03:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2862152$

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-29 13:48 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper\Plocha
2014-11-29 13:40 - 2007-04-06 08:11 - 00000000 ___HD () C:\Documents and Settings\oper\Local Settings\Data aplikací
2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-29 13:06 - 2006-03-02 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-11-29 13:05 - 2007-03-30 15:00 - 01790245 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-29 13:04 - 2007-04-06 08:09 - 00000112 _____ () C:\WINDOWS\system32\config\netlogon.ftl
2014-11-29 13:04 - 2007-03-30 15:04 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-29 13:02 - 2007-04-06 08:11 - 00000272 ___SH () C:\Documents and Settings\oper\ntuser.ini
2014-11-29 13:02 - 2007-03-30 15:04 - 00032512 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-29 12:57 - 2007-03-30 16:35 - 00000000 __RHD () C:\Documents and Settings\All Users\Data aplikací
2014-11-29 12:00 - 2008-10-23 07:31 - 00000826 _____ () C:\WINDOWS\Tasks\Záloha na počítač kancelar.job
2014-11-29 10:06 - 2011-09-05 08:23 - 00000000 ____D () C:\Program Files\Google
2014-11-29 10:05 - 2009-03-04 07:27 - 00000966 __RSH () C:\Documents and Settings\oper\ntuser.pol
2014-11-29 10:05 - 2007-04-06 08:11 - 00000000 ____D () C:\Documents and Settings\oper
2014-11-29 09:46 - 2012-06-19 08:50 - 00000000 ____D () C:\Documents and Settings\oper\Local Settings\Data aplikací\Google
2014-11-29 09:46 - 2011-09-05 08:23 - 00000000 ____D () C:\Documents and Settings\All Users\Data aplikací\Google
2014-11-29 09:46 - 2007-04-06 08:11 - 00000000 __RHD () C:\Documents and Settings\oper\Data aplikací
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ___RD () C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-11-29 09:45 - 2007-03-30 16:35 - 00000000 ____D () C:\Documents and Settings\All Users\Plocha
2014-11-29 09:37 - 2012-08-08 10:07 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-11-29 09:37 - 2009-08-31 08:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-11-29 09:36 - 2009-08-31 08:19 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-11-29 09:27 - 2007-03-30 16:23 - 00000000 ____D () C:\WINDOWS\security
2014-11-28 12:24 - 2009-03-04 07:21 - 00000272 ___SH () C:\Documents and Settings\pergerova\ntuser.ini
2014-11-28 12:23 - 2009-03-04 07:44 - 00000000 ____D () C:\Documents and Settings\pergerova\Data aplikací\Skype
2014-11-28 12:22 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Local Settings\Temp
2014-11-28 12:21 - 2007-04-06 08:11 - 00000000 __SHD () C:\WINDOWS\CSC
2014-11-28 09:17 - 2009-08-26 15:31 - 00000000 ____D () C:\WINDOWS\Minidump
2014-11-28 09:16 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova
2014-11-28 08:09 - 2010-12-09 14:24 - 00039424 _____ () C:\Documents and Settings\pergerova\Dokumenty\Čerpání přímé 2010.xls
2014-11-28 08:09 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Dokumenty
2014-11-28 07:25 - 2012-10-15 12:52 - 00028160 _____ () C:\Documents and Settings\pergerova\Dokumenty\Kontrola čerpání rozpočtu z provozní dotace - starší verze excelu.xls
2014-11-28 07:15 - 2007-04-11 11:23 - 00000000 ____D () C:\gordic
2014-11-28 07:02 - 2012-02-06 12:47 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled příjmů a výdajů ŠJ za měsíc 2012.xls
2014-11-27 14:21 - 2009-12-17 14:38 - 00000000 ____D () C:\POKARC
2014-11-27 14:15 - 2009-12-17 14:41 - 00000000 ____D () C:\KDFARC
2014-11-27 10:45 - 2012-02-06 12:56 - 00018944 _____ () C:\Documents and Settings\pergerova\Dokumenty\Uzaverka SJ - formular 2012.xls
2014-11-27 09:35 - 2009-03-04 07:21 - 00000000 __RHD () C:\Documents and Settings\pergerova\Data aplikací
2014-11-27 09:33 - 2009-03-04 07:21 - 00000000 ____D () C:\Documents and Settings\pergerova\Plocha
2014-11-27 09:32 - 2009-03-04 07:21 - 00000000 ___RD () C:\Documents and Settings\pergerova\Nabídka Start\Programy
2014-11-27 09:31 - 2006-03-02 13:00 - 00001300 _____ () C:\WINDOWS\system.ini
2014-11-27 09:09 - 2007-04-06 08:11 - 00000000 ___RD () C:\Documents and Settings\oper\Dokumenty
2014-11-26 14:09 - 2013-05-15 06:22 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-11-26 14:09 - 2013-05-15 06:22 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-11-24 12:05 - 2011-06-21 10:07 - 00787800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-11-24 12:05 - 2010-08-26 10:19 - 00423784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2014-11-24 12:04 - 2014-08-04 06:46 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00206248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00070384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-11-24 12:04 - 2013-03-18 07:04 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00057928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-11-24 12:04 - 2010-08-26 10:19 - 00055240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-11-20 10:39 - 2009-03-04 08:08 - 00715264 _____ () C:\Documents and Settings\pergerova\Dokumenty\FKSP příspěvky.xls
2014-11-20 07:06 - 2009-03-04 07:21 - 00000000 ___HD () C:\Documents and Settings\pergerova\Local Settings\Data aplikací
2014-11-18 08:32 - 2007-03-30 14:57 - 00000000 ____D () C:\Program Files\Messenger
2014-11-12 15:21 - 2007-04-06 08:53 - 100445232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-05 12:56 - 2012-02-06 12:43 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Převod nákladů na DČ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00019968 _____ () C:\Documents and Settings\pergerova\Dokumenty\Výpočet DPH za ŠJ 2012.xls
2014-11-05 12:55 - 2012-02-06 12:45 - 00016384 _____ () C:\Documents and Settings\pergerova\Dokumenty\Tržby Šj 2012.xls
2014-11-03 10:41 - 2009-03-04 08:08 - 00017920 _____ () C:\Documents and Settings\pergerova\Dokumenty\Přehled o hosp. ŠJ.xls
2014-10-31 14:56 - 2008-04-10 11:45 - 00000000 ____D () C:\UCRARC
2014-10-31 07:30 - 2011-09-23 07:48 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-10-31 06:57 - 2007-03-30 16:34 - 00122928 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-30 16:05 - 2007-04-02 06:24 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups
2014-10-30 16:03 - 2012-06-19 08:59 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-10-30 16:02 - 2007-04-06 08:53 - 00875892 _____ () C:\WINDOWS\system32\TZLog.log
2014-10-30 15:56 - 2007-03-30 16:36 - 01186406 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-30 12:14 - 2007-04-06 08:12 - 00002588 __RSH () C:\Documents and Settings\All Users\ntuser.pol
2014-10-30 07:02 - 2007-04-02 06:28 - 00043531 _____ () C:\WINDOWS\system32\nvapps.xml

Some content of TEMP:
====================
C:\Documents and Settings\gio\Local Settings\Temp\nerodeltmp.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\setup_wm.exe
C:\Documents and Settings\nemcova\Local Settings\Temp\SkypeSetup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplpat_c.dll
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u33-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-6u35-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\PKIComponent-KBExt-setup.exe
C:\Documents and Settings\pergerova\Local Settings\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola PC po odstranění mallware

#6 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    
    HKLM\...\Run: [NWEReboot] => [X]
    HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
    HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
    HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
    HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
    HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
    HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
    
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
    
    DisableService: JavaQuickStarterService
    
    2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
    2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
    2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
    2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
    2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
    2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
    2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
    2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
    2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
    2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
    2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
    2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe
    
    2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
    2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
    2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Re: Kontrola PC po odstranění mallware

#7 Příspěvek od PetrLe »

Super, zdá se to být OK.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-11-2014 01
Ran by oper at 2014-11-29 14:36:39 Run:1
Running from C:\Documents and Settings\oper\Plocha
Loaded Profile: oper (Available profiles: gio & Administrator & bistep & kancelar & pergerova & oper & hlava & skolnik)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [QuickTime Task] => C:\WINDOWS\system32\qttask.exe [98304 2007-04-12] (Apple Computer, Inc.)
HKLM\...\Run: [Tweak UI] => RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [94208 2006-06-01] (Nero AG)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-898712048-2085054343-697575874-1365\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File

DisableService: JavaQuickStarterService

2014-11-29 13:48 - 2014-11-29 13:48 - 00011221 _____ () C:\Documents and Settings\oper\Plocha\FRST.txt
2014-11-29 13:40 - 2014-11-29 13:40 - 00029696 _____ () C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE
2014-11-29 13:40 - 2014-11-29 13:40 - 00015327 _____ () C:\Documents and Settings\oper\Plocha\LM.bat
2014-11-29 13:39 - 2014-11-29 13:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe
2014-11-29 13:02 - 2014-11-29 12:48 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-29 12:50 - 2014-11-29 13:06 - 00008542 _____ () C:\zoek-results.log
2014-11-29 12:48 - 2014-11-29 12:57 - 00000000 ____D () C:\zoek_backup
2014-11-29 12:48 - 2014-11-29 12:48 - 01294848 _____ () C:\Documents and Settings\oper\Plocha\zoek.exe
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\rsit
2014-11-29 10:13 - 2014-11-29 10:14 - 00000000 ____D () C:\Program Files\trend micro
2014-11-29 09:54 - 2014-11-29 09:59 - 00000000 ____D () C:\AdwCleaner
2014-11-29 09:53 - 2014-11-29 09:53 - 01107968 _____ () C:\Documents and Settings\oper\Plocha\RSIT.exe
2014-11-29 09:51 - 2014-11-29 09:51 - 02148864 _____ () C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe

2014-11-29 13:09 - 2013-05-15 06:22 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-29 13:06 - 2012-07-09 06:54 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-10-31 06:58 - 2014-11-29 13:06 - 00000230 _____ () C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2014-10-31 06:58 - 2014-11-03 06:46 - 00000224 _____ () C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NWEReboot => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Tweak UI => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-898712048-2085054343-697575874-1365\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk => Moved successfully.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key not found.
JavaQuickStarterService service was disabled
C:\Documents and Settings\oper\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\oper\Local Settings\Data aplikací\MSGBOX.EXE => Moved successfully.
C:\Documents and Settings\oper\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\oper\Plocha\FRSTLauncher.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Documents and Settings\oper\Plocha\zoek.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Documents and Settings\oper\Plocha\RSIT.exe => Moved successfully.
C:\Documents and Settings\oper\Plocha\adwcleaner_4.102.exe => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.5 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola PC po odstranění mallware

#8 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remote disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Re: Kontrola PC po odstranění mallware

#9 Příspěvek od PetrLe »

Nedaří se mně stáhnout z výše uvedeného odkazu DelFix.
Nedá se stáhnout odjinud? Případně uklidit jinak?

PetrLe
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 263
Registrován: 05 bře 2007 12:35

Re: Kontrola PC po odstranění mallware

#10 Příspěvek od PetrLe »

Podařilo se mně ho stáhnout od jinud.
Takže mám uklizeno a vyčištěno CCleanerem.

Děkuji moc za pomoc a přeji pěkný den.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola PC po odstranění mallware

#11 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno