Stránka 2 z 2

Re: Virus

Napsal: 26 úno 2013 06:57
od cernohous13
:arrow: Většinou doporučujeme odinstalaci Advanced SystemCare - už jsme tu viděli pár nabořených systémů (pokud bys na něm trval, tak si ho po čištění přeinstaluj)
Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“ (pro Vistu a Win7 – pravým a „Run As Administrator“).
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „Moveit!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\ - dej mi ho sem na kontrolu
Script OTM

Kód: Vybrat vše

:Commands
[emptytemp]
[emptyflash]
[emptyjava]
[clearallrestorepoints]

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ASC6_PerformanceMonitor.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
C:\AdwCleaner[S1].txt
C:\AdwCleaner[R2].txt
C:\AdwCleaner[R1].txt
C:\Program Files\IObit

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
"SunJavaUpdateSched"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"=-

:Services
AdvancedSystemCareService6
JavaQuickStarterService
gupdate
gupdatem

Re: Virus

Napsal: 01 bře 2013 13:21
od mobidick
All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: fsc-d610
->Temp folder emptied: 2147575 bytes
->Temporary Internet Files folder emptied: 7372299 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 59811754 bytes
->Google Chrome cache emptied: 7652547 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 610 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 100172509 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 3870737 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33273 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 65409401 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 235,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: fsc-d610
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: All Users

User: Default User

User: fsc-d610
->Java cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0,00 mb


Restore point Set: OTM Restore Point
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13D.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP140.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP141.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP184.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP213.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP238.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP250.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP32C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP341.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3B.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3D0.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP44C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP47F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6F9.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCB.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDB.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI10.tmp moved successfully.
C:\WINDOWS\Installer\MSI101.tmp moved successfully.
C:\WINDOWS\Installer\MSI12.tmp moved successfully.
C:\WINDOWS\Installer\MSI12A.tmp moved successfully.
C:\WINDOWS\Installer\MSI13.tmp moved successfully.
C:\WINDOWS\Installer\MSI13E.tmp moved successfully.
C:\WINDOWS\Installer\MSI178.tmp moved successfully.
C:\WINDOWS\Installer\MSI18.tmp moved successfully.
C:\WINDOWS\Installer\MSI199.tmp moved successfully.
C:\WINDOWS\Installer\MSI1A7.tmp moved successfully.
C:\WINDOWS\Installer\MSI1AC.tmp moved successfully.
C:\WINDOWS\Installer\MSI3CC.tmp moved successfully.
C:\WINDOWS\Installer\MSI3E7.tmp moved successfully.
C:\WINDOWS\Installer\MSI8C.tmp moved successfully.
C:\WINDOWS\Installer\MSI8F.tmp moved successfully.
C:\WINDOWS\Installer\MSI95.tmp moved successfully.
C:\WINDOWS\Installer\MSI991.tmp moved successfully.
C:\WINDOWS\Installer\MSI994.tmp moved successfully.
C:\WINDOWS\Installer\MSI9F.tmp moved successfully.
C:\WINDOWS\Installer\MSIA7.tmp moved successfully.
C:\WINDOWS\Installer\MSIB8.tmp moved successfully.
C:\WINDOWS\Installer\MSIC.tmp moved successfully.
C:\WINDOWS\Installer\MSID5.tmp moved successfully.
C:\WINDOWS\Installer\MSID6.tmp moved successfully.
C:\WINDOWS\Installer\MSIF.tmp moved successfully.
C:\WINDOWS\tasks\Adobe Flash Player Updater.job moved successfully.
C:\WINDOWS\tasks\AppleSoftwareUpdate.job moved successfully.
C:\WINDOWS\tasks\ASC6_PerformanceMonitor.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk moved successfully.
C:\AdwCleaner[S1].txt moved successfully.
C:\AdwCleaner[R2].txt moved successfully.
C:\AdwCleaner[R1].txt moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Update folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Toolbox_Language folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\skin folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\LatestNews folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Language folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Images folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_x86 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_amd64 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_x86 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_amd64 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_x86 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_amd64 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_x86 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_amd64 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\drivers folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Database folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\images folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\ascsurfingprotection@iobit.com\chrome\content folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\ascsurfingprotection@iobit.com\chrome folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\ascsurfingprotection@iobit.com folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Boottime\BootTimeData folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Boottime\Backup folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Boottime folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Backup folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6 folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 3\Update\Skin\White folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 3\Update\Skin\Black folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 3\Update\Skin folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 3\Update folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 3 folder moved successfully.
C:\Program Files\IObit folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 6 deleted successfully.
========== SERVICES/DRIVERS ==========
Service AdvancedSystemCareService6 stopped successfully!
Service AdvancedSystemCareService6 deleted successfully!
Service JavaQuickStarterService stopped successfully!
Service JavaQuickStarterService deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!

OTM by OldTimer - Version 3.1.21.0 log created on 03012013_130255

Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Virus

Napsal: 01 bře 2013 14:10
od cernohous13
Ještě je nějaký problém? Popiš jej a dej nový RSIT.
Jestli je vše OK, tak budeme uklízet :wink:

Re: Virus

Napsal: 01 bře 2013 14:14
od mobidick
Vsetko uz vyzera byt v poriadku.

Re: Virus

Napsal: 01 bře 2013 14:36
od cernohous13
:arrow: Spusť opět OTM -> CleanUp! - odinstaluje a vyčistí po sobě.

:arrow: MBAM odinstaluj

:arrow: AdwCleaner odinstaluj/smaž

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:wink: a máme hotovo

Re: Virus

Napsal: 01 bře 2013 14:38
od mobidick
Oukej a diky moc za pomoc :)

Re: Virus

Napsal: 01 bře 2013 14:39
od cernohous13
Nemáš zač - rádo se stalo a jsme tady i příště :fez: