Stránka 2 z 2
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 13:04
od stell
sluzby win netreba babrat,napisem ti script a vycistime programy po spusteni a startup.
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 13:26
od stell
Stiahnes>>
OTMoveIt3 by OldTimer >.podla navodu vloz text a klik-Moveit>>log po restarte vloz sem,a odskusaj pc:
Kód: Vybrat vše
:processes
explorer.exe
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMax]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XeroxRegistation]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acrobat Assistant.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jhavel^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
:commands
[emptytemp]
[start explorer]
[Reboot]
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 14:13
od kilan
rychlost se moc nezvedla,ale ve startupu je procesu mene.diky
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMax\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XeroxRegistation\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acrobat Assistant.lnk\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jhavel^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk\ deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: jhavel
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33269 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 37680103 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6743373 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 42,00 mb
OTM by OldTimer - Version 3.1.7.0 log created on 01292010_140305
Files moved on Reboot...
Registry entries deleted on Reboot...
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 15:00
od stell
spravil si vsetko co som napisal??pod CFScript??
a to:
Webcureit
Zmenit hesla.
sprav este defrag,a ak uz nemas problem tot vse,
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 17:29
od kilan
no to jsme mozna trochu podcenil. hesla jsme bohuzel nemenil. poradne jsme tomu ukolu neporozumel. pokavad to byla jen nejaka funkce v combofixu tak jsem ji rovnez neudelal.
defrag dam prez vikend
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 18:08
od stell
comu tu nerozumies>.
Hesla treba zmenit preto,lebo Mebroot ukradol ti vsetky dolezite data aj hesla,,
link na WebCureit,,tam je vsetko napisane.Mebroot sa spusta skor ako os,AV,nakolko je priamo v MBR.[bol]takze mal pristup vsade..a odosielal citlive ifa z pc.asi takto,

Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 29 led 2010 21:08
od kilan
Dr.web Curelt jsem pouzil jiz pred tim dle navodu a pc projel. nic nenasel.
hesla jsem nemenil ale vypadato ze mi nic jineho nezbyva.bohuzel)
Re: NOD nasel Win32/Mebroot v operacni pameti
Napsal: 30 led 2010 08:18
od stell
ok,podla mna mozeme to ukoncit,,ak uz nemas ziaden problem s pc Tot vse.