Re: problém s papras.cx trojan
Napsal: 13 bře 2014 13:46
tak tady posílám, v průběhu toho RSFT.exe, my tam naskákaly další trojany,teda aspoň mi to hlásil Eset...... ach jo to je děs....a to si dávám pozor kam chodím a co otvírám.....
Díky moc
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014
Ran by Hanule at 2014-03-13 13:43:48 Run:1
Running from C:\Users\Hanule\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [LaunchList] - G:\programy\Pinacle\LaunchList2.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [] - [X]
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [Akamai NetSession Interface] - C:\Users\Hanule\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [nzqjvywm] - regsvr32.exe "C:\ProgramData\nzqjvywm.dat"
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [kanivghd] - regsvr32.exe "C:\ProgramData\kanivghd.dat"
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {3d26ba94-a253-11e0-8e18-001999555c0f} - E:\StartVMCLite.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {5ff43746-dcb8-11e0-9d0e-001999555c0f} - E:\DPFMate.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {8373fd8f-efc0-11df-9deb-001999555c0f} - G:\InstallTomTomHOME.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {cf3dfbdd-7119-11e1-81f7-001999555c0f} - H:\setup.exe
AppInit_DLLs: ከ鴴纣k輀⁈鴲纣r耀 => ከ鴴纣k輀⁈鴲纣r耀 File Not Found
IFEO\chrome.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
IFEO\teamviewer.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
2014-03-13 11:01 - 2014-03-13 11:01 - 00522240 _____ (OldTimer Tools) C:\Users\Hanule\Desktop\OTM.exe
2014-03-13 09:47 - 2014-03-13 09:47 - 00000000 ____D () C:\Users\Hanule\AppData\Local\{04944841-E680-43DE-B54F-795BEB2CA8B5}
2014-03-12 21:46 - 2014-03-12 21:46 - 00000000 ____D () C:\Users\Hanule\AppData\Local\{42A245EA-862E-4893-B929-3F48D40F1B5C}
2014-03-12 19:00 - 2014-03-12 19:03 - 00227126 _____ () C:\Users\Hanule\Desktop\JRT.txt
2014-03-12 18:07 - 2014-03-12 18:07 - 00003277 _____ () C:\Users\Hanule\Desktop\AdwCleaner[S0].txt
2014-03-12 18:02 - 2014-03-12 18:03 - 01949184 _____ () C:\Users\Hanule\Desktop\adwcleaner.exe
2014-03-12 17:54 - 2014-03-12 17:54 - 01037734 _____ (Thisisu) C:\Users\Hanule\Desktop\JRT.exe
2014-02-20 18:53 - 2014-02-20 18:53 - 00001531 ____N () C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_185319.txt
2014-02-20 18:45 - 2014-02-20 18:45 - 00002520 ____N () C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_184557.txt
2014-02-20 18:39 - 2014-02-20 18:39 - 03817984 _____ () C:\Users\Hanule\Downloads\RogueKiller (1).exe
2014-02-20 18:24 - 2014-02-20 18:45 - 00000000 ____D () C:\Users\Hanule\Desktop\RK_Quarantine
2014-02-20 18:24 - 2014-02-20 18:24 - 03809280 _____ () C:\Users\Hanule\Downloads\RogueKiller.exe
2014-02-20 18:22 - 2014-02-20 18:22 - 02347384 _____ (ESET) C:\Users\Hanule\Downloads\esetsmartinstaller_csy.exe
2014-03-13 11:21 - 2014-03-13 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Hanule\Desktop\FRSTLauncher.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => G:\programy\Wise Disk Cleaner\WiseDiskCleaner.exe
C:\ProgramData\kanivghd.dat
C:\ProgramData\nzqjvywm.dat
Hosts:
End
*****************
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LaunchList => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\nzqjvywm => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\kanivghd => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d26ba94-a253-11e0-8e18-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{3d26ba94-a253-11e0-8e18-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5ff43746-dcb8-11e0-9d0e-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{5ff43746-dcb8-11e0-9d0e-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8373fd8f-efc0-11df-9deb-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{8373fd8f-efc0-11df-9deb-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cf3dfbdd-7119-11e1-81f7-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{cf3dfbdd-7119-11e1-81f7-001999555c0f} => Key not found.
"ከ鴴纣k輀⁈鴲纣r耀" => Value Data removed successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\chrome.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\teamviewer.exe => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
C:\Users\Hanule\Desktop\OTM.exe => Moved successfully.
C:\Users\Hanule\AppData\Local\{04944841-E680-43DE-B54F-795BEB2CA8B5} => Moved successfully.
C:\Users\Hanule\AppData\Local\{42A245EA-862E-4893-B929-3F48D40F1B5C} => Moved successfully.
C:\Users\Hanule\Desktop\JRT.txt => Moved successfully.
C:\Users\Hanule\Desktop\AdwCleaner[S0].txt => Moved successfully.
C:\Users\Hanule\Desktop\adwcleaner.exe => Moved successfully.
C:\Users\Hanule\Desktop\JRT.exe => Moved successfully.
C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_185319.txt => Moved successfully.
C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_184557.txt => Moved successfully.
C:\Users\Hanule\Downloads\RogueKiller (1).exe => Moved successfully.
C:\Users\Hanule\Desktop\RK_Quarantine => Moved successfully.
C:\Users\Hanule\Downloads\RogueKiller.exe => Moved successfully.
C:\Users\Hanule\Downloads\esetsmartinstaller_csy.exe => Moved successfully.
C:\Users\Hanule\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => Moved successfully.
C:\ProgramData\kanivghd.dat => Moved successfully.
C:\ProgramData\nzqjvywm.dat => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
==== End of Fixlog ====
Díky moc
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014
Ran by Hanule at 2014-03-13 13:43:48 Run:1
Running from C:\Users\Hanule\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [LaunchList] - G:\programy\Pinacle\LaunchList2.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [] - [X]
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [Akamai NetSession Interface] - C:\Users\Hanule\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [nzqjvywm] - regsvr32.exe "C:\ProgramData\nzqjvywm.dat"
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [kanivghd] - regsvr32.exe "C:\ProgramData\kanivghd.dat"
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {3d26ba94-a253-11e0-8e18-001999555c0f} - E:\StartVMCLite.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {5ff43746-dcb8-11e0-9d0e-001999555c0f} - E:\DPFMate.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {8373fd8f-efc0-11df-9deb-001999555c0f} - G:\InstallTomTomHOME.exe
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\...\MountPoints2: {cf3dfbdd-7119-11e1-81f7-001999555c0f} - H:\setup.exe
AppInit_DLLs: ከ鴴纣k輀⁈鴲纣r耀 => ከ鴴纣k輀⁈鴲纣r耀 File Not Found
IFEO\chrome.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
IFEO\teamviewer.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
2014-03-13 11:01 - 2014-03-13 11:01 - 00522240 _____ (OldTimer Tools) C:\Users\Hanule\Desktop\OTM.exe
2014-03-13 09:47 - 2014-03-13 09:47 - 00000000 ____D () C:\Users\Hanule\AppData\Local\{04944841-E680-43DE-B54F-795BEB2CA8B5}
2014-03-12 21:46 - 2014-03-12 21:46 - 00000000 ____D () C:\Users\Hanule\AppData\Local\{42A245EA-862E-4893-B929-3F48D40F1B5C}
2014-03-12 19:00 - 2014-03-12 19:03 - 00227126 _____ () C:\Users\Hanule\Desktop\JRT.txt
2014-03-12 18:07 - 2014-03-12 18:07 - 00003277 _____ () C:\Users\Hanule\Desktop\AdwCleaner[S0].txt
2014-03-12 18:02 - 2014-03-12 18:03 - 01949184 _____ () C:\Users\Hanule\Desktop\adwcleaner.exe
2014-03-12 17:54 - 2014-03-12 17:54 - 01037734 _____ (Thisisu) C:\Users\Hanule\Desktop\JRT.exe
2014-02-20 18:53 - 2014-02-20 18:53 - 00001531 ____N () C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_185319.txt
2014-02-20 18:45 - 2014-02-20 18:45 - 00002520 ____N () C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_184557.txt
2014-02-20 18:39 - 2014-02-20 18:39 - 03817984 _____ () C:\Users\Hanule\Downloads\RogueKiller (1).exe
2014-02-20 18:24 - 2014-02-20 18:45 - 00000000 ____D () C:\Users\Hanule\Desktop\RK_Quarantine
2014-02-20 18:24 - 2014-02-20 18:24 - 03809280 _____ () C:\Users\Hanule\Downloads\RogueKiller.exe
2014-02-20 18:22 - 2014-02-20 18:22 - 02347384 _____ (ESET) C:\Users\Hanule\Downloads\esetsmartinstaller_csy.exe
2014-03-13 11:21 - 2014-03-13 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Hanule\Desktop\FRSTLauncher.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => G:\programy\Wise Disk Cleaner\WiseDiskCleaner.exe
C:\ProgramData\kanivghd.dat
C:\ProgramData\nzqjvywm.dat
Hosts:
End
*****************
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LaunchList => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\nzqjvywm => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\kanivghd => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup => Value deleted successfully.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d26ba94-a253-11e0-8e18-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{3d26ba94-a253-11e0-8e18-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5ff43746-dcb8-11e0-9d0e-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{5ff43746-dcb8-11e0-9d0e-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8373fd8f-efc0-11df-9deb-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{8373fd8f-efc0-11df-9deb-001999555c0f} => Key not found.
HKU\S-1-5-21-1038337379-1371219172-3291653938-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cf3dfbdd-7119-11e1-81f7-001999555c0f} => Key deleted successfully.
HKCR\CLSID\{cf3dfbdd-7119-11e1-81f7-001999555c0f} => Key not found.
"ከ鴴纣k輀⁈鴲纣r耀" => Value Data removed successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\chrome.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\teamviewer.exe => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
C:\Users\Hanule\Desktop\OTM.exe => Moved successfully.
C:\Users\Hanule\AppData\Local\{04944841-E680-43DE-B54F-795BEB2CA8B5} => Moved successfully.
C:\Users\Hanule\AppData\Local\{42A245EA-862E-4893-B929-3F48D40F1B5C} => Moved successfully.
C:\Users\Hanule\Desktop\JRT.txt => Moved successfully.
C:\Users\Hanule\Desktop\AdwCleaner[S0].txt => Moved successfully.
C:\Users\Hanule\Desktop\adwcleaner.exe => Moved successfully.
C:\Users\Hanule\Desktop\JRT.exe => Moved successfully.
C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_185319.txt => Moved successfully.
C:\Users\Hanule\Desktop\RKreport[0]_S_02202014_184557.txt => Moved successfully.
C:\Users\Hanule\Downloads\RogueKiller (1).exe => Moved successfully.
C:\Users\Hanule\Desktop\RK_Quarantine => Moved successfully.
C:\Users\Hanule\Downloads\RogueKiller.exe => Moved successfully.
C:\Users\Hanule\Downloads\esetsmartinstaller_csy.exe => Moved successfully.
C:\Users\Hanule\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => Moved successfully.
C:\ProgramData\kanivghd.dat => Moved successfully.
C:\ProgramData\nzqjvywm.dat => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
==== End of Fixlog ====