report po prohledání a smazání:
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora :
http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky :
http://tigzy.geekstogo.com/roguekiller.php
:
http://tigzyrk.blogspot.com/
Operační systém : Windows XP (5.1.2600 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Mourek [Práva správce]
Mód : Odebrat -- Datum : 06/08/2013 12:29:13
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 6 ¤¤¤
[SUSP PATH] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 16 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\Run : SpywareTerminator2012Setup (C:\Documents and Settings\All Users\Data aplikací\SpywareTerminator2012Upgrade\ST2012UpgradeSetup.exe) [7] -> VYMAZÁNO
[RUN][SUSP PATH] HKLM\[...]\RunOnce : A0 (cmd /c "C:\Documents and Settings\Mourek\Plocha\mbar\mbar.exe" /r /s) [7] -> VYMAZÁNO
[Services][ROGUE ST] HKLM\[...]\ControlSet002\Services\MEMSWEEP2 (C:\WINDOWS\system32\51.tmp) [x] -> VYMAZÁNO
[Services][ROGUE ST] HKLM\[...]\ControlSet003\Services\71189497 (C:\WINDOWS\system32\DRIVERS\71189497.sys) -> VYMAZÁNO
[Services][ROGUE ST] HKLM\[...]\ControlSet003\Services\72508374 (C:\WINDOWS\system32\DRIVERS\72508374.sys) -> VYMAZÁNO
[Services][ROGUE ST] HKLM\[...]\ControlSet003\Services\MEMSWEEP2 (C:\WINDOWS\system32\51.tmp) [x] -> VYMAZÁNO
[STARTUP][SUSP PATH] _uninst_71189497.lnk @Mourek : C:\Documents and Settings\Mourek\Local Settings\Temp\_uninst_71189497.bat [-] -> VYMAZÁNO
[STARTUP][SUSP PATH] _uninst_72508374.lnk @Mourek : C:\Documents and Settings\Mourek\Local Settings\Temp\_uninst_72508374.bat [-] -> VYMAZÁNO
[DNS] HKLM\[...]\ControlSet001\Services\Tcpip\Interfaces\{BAB3551F-2E0C-4CA0-9BB7-776AC2996C36} : NameServer (10.255.255.10,10.255.255.20) -> NEBYLO ODSTRANĚNO, POUŽIJTE DNSFIX
[DNS] HKLM\[...]\ControlSet002\Services\Tcpip\Interfaces\{BAB3551F-2E0C-4CA0-9BB7-776AC2996C36} : NameServer (10.255.255.10,10.255.255.20) -> NEBYLO ODSTRANĚNO, POUŽIJTE DNSFIX
[DNS] HKLM\[...]\ControlSet003\Services\Tcpip\Interfaces\{BAB3551F-2E0C-4CA0-9BB7-776AC2996C36} : NameServer (10.255.255.10,10.255.255.20) -> NEBYLO ODSTRANĚNO, POUŽIJTE DNSFIX
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> VYMAZÁNO
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[SAFEBOOT] HKLM\[...]\ControlSet002\SafeBoot : AlternateShell () -> NAHRAZENO (cmd.exe)
[SAFEBOOT] HKLM\[...]\ControlSet003\SafeBoot : AlternateShell () -> NAHRAZENO (cmd.exe)
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
SSDT[122] : NtOpenProcess @ 0x80581C68 -> HOOKED (\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys @ 0xADB49C4C)
SSDT[128] : NtOpenThread @ 0x80598726 -> HOOKED (\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys @ 0xADB49D3C)
¤¤¤ Externí včelstvo: ¤¤¤
-> D:\windows\system32\config\SOFTWARE
-> D:\windows\system32\config\SYSTEM
¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: WDC WD3200AAKS-00SBA0 +++++
--- User ---
[MBR] 35c0d60517f6a20238ab833defa4c16e
[BSP] 8d68cfe028c987550ab8c1866ad23d40 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 15 | Size: 100000 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 204800400 | Size: 205243 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[4]_D_06082013_02d1229.txt >>
RKreport[1]_S_06082013_02d1217.txt ; RKreport[2]_S_06082013_02d1219.txt ; RKreport[3]_S_06082013_02d1228.txt ; RKreport[4]_D_06082013_02d1229.txt
report po opravě host
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora :
http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky :
http://tigzy.geekstogo.com/roguekiller.php
:
http://tigzyrk.blogspot.com/
Operační systém : Windows XP (5.1.2600 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Mourek [Práva správce]
Mód : Oprava HOSTS -- Datum : 06/08/2013 12:29:37
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 6 ¤¤¤
[SUSP PATH] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
[RESIDUE] BrowserDefender.exe -- C:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
-> D:\windows\system32\config\SOFTWARE
-> D:\windows\system32\config\SYSTEM
¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts
¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost
Dokončeno : << RKreport[5]_H_06082013_02d1229.txt >>
RKreport[1]_S_06082013_02d1217.txt ; RKreport[2]_S_06082013_02d1219.txt ; RKreport[3]_S_06082013_02d1228.txt ; RKreport[4]_D_06082013_02d1229.txt ; RKreport[5]_H_06082013_02d1229.txt