Stránka 2 z 2
Re: Prosím o kontrolu, podezření infekce
Napsal: 08 pro 2013 19:15
od vyosek

Tema tedy nebudu zamykat, ale potreba docistit

Spustte znovu
OTL
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
:otl
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58390E22-D31D-4D0E-8FB3-ACC9ACDCBCCA}\MpKslecde95af.sys -- (MpKslecde95af)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62C41AE0-EBB0-4578-9F0B-3904CDF3AB0F}\MpKsld262e734.sys -- (MpKsld262e734)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{021336F9-B9C0-4FCA-8652-2068A345CC88}\MpKslb5af0d96.sys -- (MpKslb5af0d96)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8247754-1CDB-40C6-8484-32FF807A083D}\MpKsl98d94021.sys -- (MpKsl98d94021)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8B946F8-601E-4929-BC8A-DC3A9D3C702D}\MpKsl7b2e7f35.sys -- (MpKsl7b2e7f35)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17FEE885-D32B-4B25-8C1D-9755AD8C54BE}\MpKsl5f4e8aaa.sys -- (MpKsl5f4e8aaa)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A179688-0F0E-4007-AD62-E49062822F71}\MpKsl0811d670.sys -- (MpKsl0811d670)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LVMVDrv.sys -- (LVMVDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LVcKap.sys -- (LVcKap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Garena Plus\Room\safedrv.sys -- (GGSAFERDriver)
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 A0 35 9F D0 9A CA 01 [binary data]
IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =937811&p={searchTerms}
IE - HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPB_cs
O4 - HKLM..\Run: [] File not found
O13 - gopher Prefix: missing
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\{6866fb66-cf0d-11e0-8c65-4061860524c7}\Shell - "" = AutoRun
[2013.12.07 10:44:43 | 001,110,034 | ---- | M] () -- C:\Users\doma\Desktop\adwcleaner (1).exe
[2013.12.07 23:06:31 | 000,110,166 | ---- | M] () -- C:\Users\doma\Desktop\Bez názvu.jpg
[2013.12.07 23:03:36 | 000,015,327 | ---- | M] () -- C:\Users\doma\Desktop\LM.bat
[2013.12.07 22:54:24 | 003,186,060 | ---- | M] () -- C:\Users\doma\Desktop\Bez názvu.png
[2013.12.07 22:52:52 | 001,060,157 | ---- | M] (Farbar) -- C:\Users\doma\Desktop\FRST.exe
[2013.12.07 22:48:16 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.12.07 22:41:53 | 000,112,640 | ---- | M] (forum.viry.cz) -- C:\Users\doma\Desktop\FRSTLauncher.exe
[11 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[2013.12.08 08:26:01 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013.12.08 08:19:47 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.12.07 22:48:16 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[EMPTYJAVA]
- Nasledne kliknete na Opravit
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Prosím o kontrolu, podezření infekce
Napsal: 22 pro 2013 12:24
od Bender2009
Files\Folders moved on Reboot...
C:\Users\doma\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Re: Prosím o kontrolu, podezření infekce
Napsal: 22 pro 2013 19:36
od Bender2009
Ahoj jsem Zpátky, akorát ten OTL mi nevypsal log.. jen to co je výše uvedeno

Re: Prosím o kontrolu, podezření infekce
Napsal: 22 pro 2013 20:38
od vyosek
Provedte prosim jeste jednou opravu ale v nouzovem rezimu...
Re: Prosím o kontrolu, podezření infekce
Napsal: 23 pro 2013 10:55
od Bender2009
All processes killed
========== OTL ==========
Error: No service named MpKslecde95af was found to stop!
Service\Driver key MpKslecde95af not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58390E22-D31D-4D0E-8FB3-ACC9ACDCBCCA}\MpKslecde95af.sys not found.
Error: No service named MpKsld262e734 was found to stop!
Service\Driver key MpKsld262e734 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62C41AE0-EBB0-4578-9F0B-3904CDF3AB0F}\MpKsld262e734.sys not found.
Error: No service named MpKslb5af0d96 was found to stop!
Service\Driver key MpKslb5af0d96 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{021336F9-B9C0-4FCA-8652-2068A345CC88}\MpKslb5af0d96.sys not found.
Error: No service named MpKsl98d94021 was found to stop!
Service\Driver key MpKsl98d94021 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8247754-1CDB-40C6-8484-32FF807A083D}\MpKsl98d94021.sys not found.
Error: No service named MpKsl7b2e7f35 was found to stop!
Service\Driver key MpKsl7b2e7f35 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8B946F8-601E-4929-BC8A-DC3A9D3C702D}\MpKsl7b2e7f35.sys not found.
Error: No service named MpKsl5f4e8aaa was found to stop!
Service\Driver key MpKsl5f4e8aaa not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{17FEE885-D32B-4B25-8C1D-9755AD8C54BE}\MpKsl5f4e8aaa.sys not found.
Error: No service named MpKsl0811d670 was found to stop!
Service\Driver key MpKsl0811d670 not found.
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A179688-0F0E-4007-AD62-E49062822F71}\MpKsl0811d670.sys not found.
Error: No service named LVPr2Mon was found to stop!
Service\Driver key LVPr2Mon not found.
File system32\drivers\LVPr2Mon.sys not found.
Error: No service named LVMVDrv was found to stop!
Service\Driver key LVMVDrv not found.
File system32\DRIVERS\LVMVDrv.sys not found.
Error: No service named LVcKap was found to stop!
Service\Driver key LVcKap not found.
File system32\DRIVERS\LVcKap.sys not found.
Error: No service named GGSAFERDriver was found to stop!
Service\Driver key GGSAFERDriver not found.
File C:\Program Files\Garena Plus\Room\safedrv.sys not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKU\S-1-5-21-2134363999-2576545968-1981469542-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3217CD8A-3039-42C6-AFC4-F47FDA4B7696}\ not found.
Registry key HKEY_USERS\S-1-5-21-2134363999-2576545968-1981469542-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6866fb66-cf0d-11e0-8c65-4061860524c7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6866fb66-cf0d-11e0-8c65-4061860524c7}\ not found.
File C:\Users\doma\Desktop\adwcleaner (1).exe not found.
File C:\Users\doma\Desktop\Bez názvu.jpg not found.
File C:\Users\doma\Desktop\LM.bat not found.
File C:\Users\doma\Desktop\Bez názvu.png not found.
File C:\Users\doma\Desktop\FRST.exe not found.
File C:\Windows\tasks\GoogleUpdateTaskMachineUA.job not found.
File C:\Users\doma\Desktop\FRSTLauncher.exe not found.
File/Folder C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp not found.
File/Folder C:\Windows\Installer\*.tmp not found.
File/Folder C:\Windows\Temp\*.tmp not found.
File C:\Windows\Tasks\Adobe Flash Player Updater.job not found.
File C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job not found.
File C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job not found.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg not found.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\msdownld.tmp folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: doma
->Temp folder emptied: 214212 bytes
->Temporary Internet Files folder emptied: 407157 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 251450729 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6396 bytes
RecycleBin emptied: 1863784748 bytes
Total Files Cleaned = 2 018,00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: doma
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0,00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: doma
->Java cache emptied: 0 bytes
User: Public
Total Java Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12232013_105202
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Re: Prosím o kontrolu, podezření infekce
Napsal: 24 pro 2013 10:24
od vyosek
Re: Prosím o kontrolu, podezření infekce
Napsal: 25 pro 2013 11:30
od Bender2009
Re: Prosím o kontrolu, podezření infekce
Napsal: 25 pro 2013 12:29
od vyosek
Nemate zac, rad jsem pomohl

Zase nekdy
Klidne svatky a pohodovy vstup do nadchazejiciho roku
A na zaklade Pravidla o zamykani temat