Stránka 2 z 2

Re: Prosím o kontrolu, podezření infekce

Napsal: 08 pro 2013 19:15
od vyosek
:arrow: Tema tedy nebudu zamykat, ale potreba docistit

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58390E22-D31D-4D0E-8FB3-ACC9ACDCBCCA}\MpKslecde95af.sys -- (MpKslecde95af)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62C41AE0-EBB0-4578-9F0B-3904CDF3AB0F}\MpKsld262e734.sys -- (MpKsld262e734)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{021336F9-B9C0-4FCA-8652-2068A345CC88}\MpKslb5af0d96.sys -- (MpKslb5af0d96)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8247754-1CDB-40C6-8484-32FF807A083D}\MpKsl98d94021.sys -- (MpKsl98d94021)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8B946F8-601E-4929-BC8A-DC3A9D3C702D}\MpKsl7b2e7f35.sys -- (MpKsl7b2e7f35)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17FEE885-D32B-4B25-8C1D-9755AD8C54BE}\MpKsl5f4e8aaa.sys -- (MpKsl5f4e8aaa)
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A179688-0F0E-4007-AD62-E49062822F71}\MpKsl0811d670.sys -- (MpKsl0811d670)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LVMVDrv.sys -- (LVMVDrv)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LVcKap.sys -- (LVcKap)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Garena Plus\Room\safedrv.sys -- (GGSAFERDriver)
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 A0 35 9F D0 9A CA 01 [binary data]
    IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =937811&p={searchTerms}
    IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPB_cs
    O4 - HKLM..\Run: [] File not found
    O13 - gopher Prefix: missing
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O33 - MountPoints2\{6866fb66-cf0d-11e0-8c65-4061860524c7}\Shell - "" = AutoRun
    [2013.12.07 10:44:43 | 001,110,034 | ---- | M] () -- C:\Users\doma\Desktop\adwcleaner (1).exe
    [2013.12.07 23:06:31 | 000,110,166 | ---- | M] () -- C:\Users\doma\Desktop\Bez názvu.jpg
    [2013.12.07 23:03:36 | 000,015,327 | ---- | M] () -- C:\Users\doma\Desktop\LM.bat
    [2013.12.07 22:54:24 | 003,186,060 | ---- | M] () -- C:\Users\doma\Desktop\Bez názvu.png
    [2013.12.07 22:52:52 | 001,060,157 | ---- | M] (Farbar) -- C:\Users\doma\Desktop\FRST.exe
    [2013.12.07 22:48:16 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013.12.07 22:41:53 | 000,112,640 | ---- | M] (forum.viry.cz) -- C:\Users\doma\Desktop\FRSTLauncher.exe
    [11 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
    [1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
    [2013.12.08 08:26:01 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
    [2013.12.08 08:19:47 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    [2013.12.07 22:48:16 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    
    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Prosím o kontrolu, podezření infekce

Napsal: 22 pro 2013 12:24
od Bender2009
Files\Folders moved on Reboot...
C:\Users\doma\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Prosím o kontrolu, podezření infekce

Napsal: 22 pro 2013 19:36
od Bender2009
Ahoj jsem Zpátky, akorát ten OTL mi nevypsal log.. jen to co je výše uvedeno :)

Re: Prosím o kontrolu, podezření infekce

Napsal: 22 pro 2013 20:38
od vyosek
Provedte prosim jeste jednou opravu ale v nouzovem rezimu...

Re: Prosím o kontrolu, podezření infekce

Napsal: 23 pro 2013 10:55
od Bender2009
All processes killed
========== OTL ==========
Error: No service named MpKslecde95af was found to stop!
Service\Driver key MpKslecde95af not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58390E22-D31D-4D0E-8FB3-ACC9ACDCBCCA}\MpKslecde95af.sys not found.
Error: No service named MpKsld262e734 was found to stop!
Service\Driver key MpKsld262e734 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62C41AE0-EBB0-4578-9F0B-3904CDF3AB0F}\MpKsld262e734.sys not found.
Error: No service named MpKslb5af0d96 was found to stop!
Service\Driver key MpKslb5af0d96 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{021336F9-B9C0-4FCA-8652-2068A345CC88}\MpKslb5af0d96.sys not found.
Error: No service named MpKsl98d94021 was found to stop!
Service\Driver key MpKsl98d94021 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8247754-1CDB-40C6-8484-32FF807A083D}\MpKsl98d94021.sys not found.
Error: No service named MpKsl7b2e7f35 was found to stop!
Service\Driver key MpKsl7b2e7f35 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8B946F8-601E-4929-BC8A-DC3A9D3C702D}\MpKsl7b2e7f35.sys not found.
Error: No service named MpKsl5f4e8aaa was found to stop!
Service\Driver key MpKsl5f4e8aaa not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17FEE885-D32B-4B25-8C1D-9755AD8C54BE}\MpKsl5f4e8aaa.sys not found.
Error: No service named MpKsl0811d670 was found to stop!
Service\Driver key MpKsl0811d670 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A179688-0F0E-4007-AD62-E49062822F71}\MpKsl0811d670.sys not found.
Error: No service named LVPr2Mon was found to stop!
Service\Driver key LVPr2Mon not found.
File system32\drivers\LVPr2Mon.sys not found.
Error: No service named LVMVDrv was found to stop!
Service\Driver key LVMVDrv not found.
File system32\DRIVERS\LVMVDrv.sys not found.
Error: No service named LVcKap was found to stop!
Service\Driver key LVcKap not found.
File system32\DRIVERS\LVcKap.sys not found.
Error: No service named GGSAFERDriver was found to stop!
Service\Driver key GGSAFERDriver not found.
File C:\Program Files\Garena Plus\Room\safedrv.sys not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}\ not found.
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6866fb66-cf0d-11e0-8c65-4061860524c7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6866fb66-cf0d-11e0-8c65-4061860524c7}\ not found.
File C:\Users\doma\Desktop\adwcleaner (1).exe not found.
File C:\Users\doma\Desktop\Bez názvu.jpg not found.
File C:\Users\doma\Desktop\LM.bat not found.
File C:\Users\doma\Desktop\Bez názvu.png not found.
File C:\Users\doma\Desktop\FRST.exe not found.
File C:\Windows\tasks\GoogleUpdateTaskMachineUA.job not found.
File C:\Users\doma\Desktop\FRSTLauncher.exe not found.
File/Folder C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp not found.
File/Folder C:\Windows\Installer\*.tmp not found.
File/Folder C:\Windows\Temp\*.tmp not found.
File C:\Windows\Tasks\Adobe Flash Player Updater.job not found.
File C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job not found.
File C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job not found.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg not found.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\msdownld.tmp folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: doma
->Temp folder emptied: 214212 bytes
->Temporary Internet Files folder emptied: 407157 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 251450729 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6396 bytes
RecycleBin emptied: 1863784748 bytes

Total Files Cleaned = 2 018,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: doma
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: doma
->Java cache emptied: 0 bytes

User: Public

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12232013_105202

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Prosím o kontrolu, podezření infekce

Napsal: 24 pro 2013 10:24
od vyosek
Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|

Re: Prosím o kontrolu, podezření infekce

Napsal: 25 pro 2013 11:30
od Bender2009
Ok hotovo. děkuji, příjemné svátky a šťastný nový rok ! _:) :153: :154: :156: :151: :150: :152:

Re: Prosím o kontrolu, podezření infekce

Napsal: 25 pro 2013 12:29
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

Klidne svatky a pohodovy vstup do nadchazejiciho roku :thumbsup:



A na zaklade Pravidla o zamykani temat :lock: