Stránka 3 z 3

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 17:55
od aturk
jenom otazku. Zůstanou data na tom USB disku zachovaná?

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 17:57
od vyosek
Ano zustanou, USBFix jen prohleda disky na specificky malware, ktery se po nich velmi rad siri

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 18:31
od aturk
############################## | UsbFix 7.059 | [Deletion]

User: Ja (Administrator) # RADEK [ ]
Updated 16/09/2011 by El Desaparecido
Started at 19:06:17 | 18/09/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com

CPU: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702

Antivirus: Microsoft Security Essentials 4.0.1526.0 [(!) Disabled | Updated]
RAM -> 3582 Mb
C:\ (%systemdrive%) -> Fixed drive # 932 Gb (257 Mb free - 28%) [Win XP New] # NTFS
D:\ -> CD-ROM
E:\ -> Fixed drive # 466 Gb (419 Mb free - 90%) [Nový svazek] # NTFS
F:\ -> CD-ROM
G:\ -> Fixed drive # 233 Gb (231 Mb free - 99%) [] # NTFS
H:\ -> Removable drive # 7 Gb (426 Mb free - 6%) [] # FAT32
I:\ -> Removable drive # 7 Gb (1 Mb free - 17%) [KINGSTON] # FAT32
J:\ -> Fixed drive # 1397 Gb (84 Mb free - 6%) [SAMSUNG] # NTFS

################## | Files # Infected Folders |

Deleted ! C:\Documents and Settings\Ja\Data aplikací\BatmanAC.exe
Deleted ! I:\urDrive.exe
Deleted ! C:\Documents and Settings\Ja\Data aplikací\Temp
Deleted ! C:\Recycler\S-1-5-21-725345543-2000478354-682003330-1004
Deleted ! E:\$RECYCLE.BIN\S-1-5-21-3719735759-2485006509-828954536-1001
Deleted ! E:\Recycler\S-1-5-21-725345543-2000478354-682003330-1004
Deleted ! G:\$RECYCLE.BIN\S-1-5-21-3719735759-2485006509-828954536-1001
Deleted ! G:\Recycler\S-1-5-21-1606980848-1757981266-725345543-1005
Deleted ! G:\Recycler\S-1-5-21-725345543-2000478354-682003330-1004
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-2767345657-1762365797-1407849236-1001
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-3719735759-2485006509-828954536-1001
Deleted ! J:\Recycler\S-1-5-21-1606980848-1757981266-725345543-1005
Deleted ! J:\Recycler\S-1-5-21-1960408961-583907252-839522115-1003
Deleted ! J:\Recycler\S-1-5-21-515967899-682003330-1606980848-1004
Deleted ! J:\Recycler\S-1-5-21-725345543-2000478354-682003330-1004
Deleted ! J:\Recycler\S-1-5-21-823518204-179605362-1801674531-1004
Deleted ! I:\autorun.inf

(!) Temporary files deleted.


################## | Registry |

Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Adobe Reader Speed Launcher

################## | Mountpoints2 |


################## | Listing |

[11/03/2012 - 12:34:47 | D ] C:\AMD
[11/03/2012 - 16:08:06 | D ] C:\ATI
[18/08/2012 - 21:10:00 | D ] C:\BDS
[21/07/2012 - 18:32:30 | D ] C:\Boot
[16/09/2012 - 17:08:30 | N | 257] C:\Boot.bak
[16/09/2012 - 19:32:06 | N | 367] C:\boot.ini
[14/04/2008 - 14:00:00 | N | 4952] C:\Bootfont.bin
[21/11/2010 - 05:23:51 | RASH | 383786] C:\bootmgr
[21/07/2012 - 18:32:31 | N | 8192] C:\BOOTSECT.BAK
[16/09/2012 - 19:32:06 | D ] C:\cmdcons
[03/08/2004 - 23:00:04 | N | 261312] C:\cmldr
[15/10/2011 - 16:50:22 | N | 0] C:\CONFIG.SYS
[16/09/2012 - 19:29:26 | D ] C:\Documents and Settings
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10134] C:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 118] C:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.3082.txt
[17/02/2012 - 09:29:57 | D ] C:\f8527ceac9419b87d7
[07/11/2007 - 08:00:40 | N | 1110] C:\globdata.ini
[21/07/2012 - 17:43:02 | N | 203464] C:\grldr
[16/09/2012 - 11:44:22 | D ] C:\Hry
[07/11/2007 - 08:00:40 | N | 843] C:\install.ini
[07/11/2007 - 08:03:18 | N | 76304] C:\install.res.1028.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.1031.dll
[07/11/2007 - 08:03:18 | N | 91152] C:\install.res.1033.dll
[07/11/2007 - 08:03:18 | N | 97296] C:\install.res.1036.dll
[07/11/2007 - 08:03:18 | N | 95248] C:\install.res.1040.dll
[07/11/2007 - 08:03:18 | N | 81424] C:\install.res.1041.dll
[07/11/2007 - 08:03:18 | N | 79888] C:\install.res.1042.dll
[07/11/2007 - 08:03:18 | N | 75792] C:\install.res.2052.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.3082.dll
[15/10/2011 - 17:15:53 | D ] C:\Intel
[15/10/2011 - 16:50:22 | N | 0] C:\IO.SYS
[28/06/2012 - 19:04:49 | D ] C:\minecraft.bin
[15/10/2011 - 16:50:22 | N | 0] C:\MSDOS.SYS
[15/10/2011 - 22:14:04 | RD ] C:\MSOCache
[14/04/2008 - 14:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 14:00:00 | N | 250576] C:\ntldr
[18/09/2012 - 19:04:29 | ASH | 3756437504] C:\pagefile.sys
[18/09/2012 - 18:39:03 | D ] C:\Program Files
[18/09/2012 - 18:00:43 | D ] C:\Qoobox
[18/09/2012 - 19:13:50 | SHD ] C:\RECYCLER
[18/09/2012 - 18:32:01 | D ] C:\rsit
[18/09/2012 - 18:01:53 | SHD ] C:\System Volume Information
[30/12/2011 - 15:31:59 | D ] C:\Temp
[01/01/2012 - 13:54:43 | N | 413808] C:\treeinfo.wc
[18/09/2012 - 19:13:50 | D ] C:\UsbFix
[18/09/2012 - 19:14:50 | A | 2618] C:\UsbFix.txt
[07/11/2007 - 08:00:40 | N | 5686] C:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] C:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] C:\VC_RED.MSI
[21/07/2012 - 17:43:04 | N | 12] C:\win7.ld
[18/09/2012 - 19:04:40 | D ] C:\WINDOWS
[12/05/2004 - 20:38:48 | RD ] D:\BON JOVI - THIS LEFT FEELS RIGHT
[12/05/2004 - 20:39:12 | RD ] D:\BOUNCE
[12/05/2004 - 23:07:38 | RD ] D:\Bryan Adams-Rarites
[12/05/2004 - 23:01:44 | RD ] D:\Rarites
[21/07/2012 - 17:45:10 | D ] E:\$Recycle.Bin
[14/07/2009 - 07:08:56 | D ] E:\Documents and Settings
[10/09/2012 - 13:34:45 | ASH | 3220037632] E:\hiberfil.sys
[09/08/2012 - 19:51:51 | D ] E:\Hry
[10/09/2012 - 13:34:51 | N | 4293386240] E:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] E:\PerfLogs
[01/08/2012 - 06:33:03 | D ] E:\Program Files
[01/08/2012 - 15:32:04 | D ] E:\Program Files (x86)
[01/08/2012 - 05:59:24 | D ] E:\ProgramData
[21/07/2012 - 17:42:59 | D ] E:\Recovery
[18/09/2012 - 19:13:50 | SHD ] E:\RECYCLER
[09/09/2012 - 17:37:58 | SHD ] E:\System Volume Information
[30/07/2012 - 17:58:42 | N | 304] E:\user.js
[21/07/2012 - 17:43:28 | D ] E:\Users
[20/08/2012 - 22:48:45 | D ] E:\Windows
[21/07/2012 - 17:45:10 | D ] G:\$RECYCLE.BIN
[22/07/2012 - 19:45:59 | N | 528] G:\MediaID.bin
[22/07/2012 - 19:46:37 | D ] G:\RADEK-PC
[18/09/2012 - 19:13:50 | SHD ] G:\RECYCLER
[17/10/2011 - 14:42:27 | SHD ] G:\System Volume Information
[01/07/2012 - 09:00:50 | D ] H:\100OLYMP
[12/05/2012 - 09:36:48 | N | 1469005824] H:\Zraloci na sousi CZ.avi
[12/05/2012 - 10:31:50 | N | 823701504] H:\Kocour v botách.2011.BDRip.XviD.CZ.SK.avi
[14/07/2012 - 18:27:10 | D ] H:\spanělsko 08
[14/07/2012 - 18:28:30 | D ] H:\Chorvatsko 2009
[14/07/2012 - 18:29:28 | D ] H:\chorvatsko 10
[14/07/2012 - 18:31:48 | D ] H:\Nová složka
[28/07/2012 - 22:52:00 | N | 510149288] H:\Vlci_mlade_01x01_web-rip_cz_mattys.avi
[29/07/2012 - 11:29:58 | N | 327034636] H:\Vlčí mládě 1x02.avi
[29/07/2012 - 11:29:46 | N | 332805428] H:\Vlčí mládě 1x03.avi
[29/07/2012 - 11:29:34 | N | 322677642] H:\Vlčí mládě 1x04.avi
[29/07/2012 - 11:34:50 | N | 413296564] H:\cena-za-lidskost_us_01x01_web-rip_cz_mattys.avi
[08/08/2012 - 16:25:34 | N | 319227658] H:\Vlčí mládě 1x08.avi
[08/08/2012 - 16:26:06 | N | 331093572] H:\Vlčí mládě 1x09.avi
[08/08/2012 - 16:33:44 | N | 458691170] H:\Vlci mlade 1x10.avi
[08/08/2012 - 16:27:46 | N | 340475922] H:\Vlci_mlade_01x07_web-rip_cz_mattys.avi
[19/08/2012 - 08:30:34 | N | 471680228] H:\Vlci mlade 1x12.avi
[19/08/2012 - 08:17:28 | N | 332914654] H:\Vlčí-mládě-1x11.avi
[09/07/2010 - 14:14:56 | N | 70656] I:\unInstaller.exe
[22/10/2010 - 18:17:08 | D ] I:\urDrive
[03/03/2012 - 23:21:22 | D ] I:\minecraft
[17/12/2011 - 22:38:00 | N | 336603000] I:\doba-ledova-mamuti-vanoce-2011-dvdrip-xvid-ac3-czdab-v-sage.avi
[08/11/2011 - 16:28:54 | N | 834400256] I:\Auta.2.2011.BRRip.XviD.CZ.avi
[12/05/2012 - 09:38:12 | N | 1206032871] I:\---TINTINOVA DOBRODRUŽSTVÍ CZ-2011 [Vysoká kvalita a velikost].mp4
[11/05/2012 - 20:04:50 | N | 1081176796] I:\happy-feet-2-brrip-5-1-cz-warezfilm.mkv
[26/11/2011 - 09:16:44 | N | 1468246016] I:\Delfin.pribeh.snilka.DVDRip.DivX5.AC3.CZ.monnat.up.by.MiPe.avi
[12/05/2012 - 10:31:50 | N | 823701504] I:\Kocour v botách.2011.BDRip.XviD.CZ.SK.avi
[13/08/2012 - 21:31:14 | N | 3498676] I:\EGO-ft.-Robert-Burian---Žijeme-len-raz.mp3
[09/03/2012 - 18:03:18 | D ] I:\## aswSnx private storage
[05/05/2012 - 12:02:08 | N | 719773696] I:\Season.Of.The.Witch.2011.DVDRip.XviD.CZ.avi
[18/09/2012 - 19:13:49 | SHD ] J:\$RECYCLE.BIN
[02/01/2010 - 18:38:07 | D ] J:\2a36b46df611c439fa70d4
[02/01/2010 - 18:35:41 | D ] J:\7ccb7b8d91e36778fbc8cfabea
[19/07/2012 - 13:30:25 | D ] J:\Filmy
[19/07/2012 - 17:23:43 | D ] J:\Foto
[05/05/2011 - 14:04:42 | D ] J:\Hry
[19/07/2012 - 17:19:35 | D ] J:\MP3
[25/06/2011 - 20:53:03 | D ] J:\msdownld.tmp
[23/10/2011 - 18:21:57 | N | 76] J:\nmdsdcid
[11/11/2010 - 21:06:21 | D ] J:\Nová složka
[13/10/2011 - 15:43:39 | D ] J:\prog 2011
[16/04/2011 - 19:22:05 | D ] J:\Programy
[14/01/2011 - 19:31:56 | D ] J:\Recycled
[18/09/2012 - 19:13:50 | SHD ] J:\RECYCLER
[15/10/2011 - 17:17:49 | SHD ] J:\System Volume Information
[16/04/2011 - 22:50:11 | D ] J:\Tepla

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
E:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
G:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
H:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
I:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
J:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_RADEK.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.

################## | E.O.F |

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 21:23
od vyosek
Jak se chova PC, je jeste nejaky problem ci dotaz?

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 21:34
od aturk
PC se chova dobre. Jsou ty USB disky ok?A je cistej i ten poslední log po lecení?Akorat kdyz projedu kontrolu v tom SUPERAntiSpyware,tak pokazde detekuje nejaké Adware Tracking Cookie
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/18/2012 at 10:33 PM

Application Version : 5.5.1016

Core Rules Database Version : 9246
Trace Rules Database Version: 7058

Scan type : Quick Scan
Total Scan Time : 00:03:08

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 574
Memory threats detected : 0
Registry items scanned : 29207
Registry threats detected : 0
File items scanned : 6542
File threats detected : 11

Adware.Tracking Cookie
.etargetnet.com [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.toplist.cz [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
server.adformdsp.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.adformdsp.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]
.imedia.cz [ C:\DOCUMENTS AND SETTINGS\JA\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\YH4T3Z5I.DEFAULT\COOKIES.SQLITE ]

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 18 zář 2012 21:50
od vyosek
:arrow: USB disky byly nakazene, USBFix je polecil

:arrow: Cookies jsou defakto neskodne soubory
Cookies neznamenají žádné nebezpečí pro počítač jako takový. Přesto cookies mohou být nebezpečné pro ochranu soukromí. Navštívený web si totiž může ukládat do cookies jakékoliv informace, které o návštěvníkovi zjistí a může tak postupně zjišťovat zájmy konkrétního návštěvníka. Které stránky navštěvuje, jaké informace vyhledává, jak často daný web navštěvuje apod.

Těchto informací se dá posléze i bez vědomí návštěvníka využívat pro cílenou reklamu, statistické vyhodnocování chování návštěvníků, apod.

Tyto informace však lze získávat i bez cookies, proto toto jejich využití nemůže být považováno za zvlášť nebezpečné.

Cookies lze zneužít zejména tehdy, pokud získá útočník přístup k počítači uživatele, neboť cookies na počítači nejsou nijak chráněny. Pak lze předstírat např. cizí identitu.
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Ja.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 19 zář 2012 06:30
od aturk
Tak jsem provedl dle instrukcí akorat tam nebyla tato radka:O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Jinak probehlo vse ok a vypada to v pořádku.Strašně moc vám děkuji. S přáním hezkého dne Aturk

Re: Prosím o kontrolu-spybot hlasí 6 viru

Napsal: 19 zář 2012 11:15
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock: