Stránka 1 z 1

problémy s viry

Napsal: 09 led 2011 15:46
od fitzink
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 5487

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

9.1.2011 15:23:22
mbam-log-2011-01-09 (15-23-12).txt

Typ kontroly: Rychlý test
Testované objekty: 199218
Uplynulý čas: 14 minut, 47 sekund

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 3
Infikované datové položky v registru: 0
Infikované složky: 12
Infikované soubory: 17

Infikované procesy v paměti:
c:\WINDOWS\nvsvc32.exe (Backdoor.Bot) -> 2796 -> No action taken.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{064C57B4-B9EC-425F-B9B3-BCEFFEEA74D9} (Adware.SmartShopper) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Backdoor.Bot) -> Value: NVIDIA driver monitor -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Backdoor.Bot) -> Value: NVIDIA driver monitor -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Malware.Trace) -> Value: NVIDIA driver monitor -> No action taken.

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
c:\documents and settings\fitz\data aplikací\smartshopper (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\res1 (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\res1 (Adware.SmartShopper) -> No action taken.

Infikované soubory:
c:\WINDOWS\nvsvc32.exe (Backdoor.Bot) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\Config.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db\Aliases.dbs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db\Sites.dbs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld\phishinglist.xip (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld\whitelist.xip (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report\aggr_storage.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report\send_storage.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\res1\whitelist.dbs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\Config.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db\Aliases.dbs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db\Sites.dbs (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld\phishinglist.xip (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld\whitelist.xip (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report\aggr_storage.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report\send_storage.xml (Adware.SmartShopper) -> No action taken.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\res1\whitelist.dbs (Adware.SmartShopper) -> No action taken.

Re: problémy s viry

Napsal: 09 led 2011 16:22
od Rudy
Vše, co MBAM nalezl, smažte.

Re: problémy s viry

Napsal: 09 led 2011 17:04
od fitzink
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 5487

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

9.1.2011 16:33:28
mbam-log-2011-01-09 (16-33-28).txt

Typ kontroly: Rychlý test
Testované objekty: 199218
Uplynulý čas: 14 minut, 47 sekund

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 3
Infikované datové položky v registru: 0
Infikované složky: 12
Infikované soubory: 17

Infikované procesy v paměti:
c:\WINDOWS\nvsvc32.exe (Backdoor.Bot) -> 2796 -> Unloaded process successfully.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{064C57B4-B9EC-425F-B9B3-BCEFFEEA74D9} (Adware.SmartShopper) -> Quarantined and deleted successfully.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Backdoor.Bot) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Backdoor.Bot) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Malware.Trace) -> Value: NVIDIA driver monitor -> Quarantined and deleted successfully.

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
c:\documents and settings\fitz\data aplikací\smartshopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\res1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\res1 (Adware.SmartShopper) -> Quarantined and deleted successfully.

Infikované soubory:
c:\WINDOWS\nvsvc32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\Config.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db\Aliases.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\db\Sites.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld\phishinglist.xip (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\dwld\whitelist.xip (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report\aggr_storage.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\report\send_storage.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\fitz\data aplikací\smartshopper\cs\res1\whitelist.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\Config.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db\Aliases.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\db\Sites.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld\phishinglist.xip (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\dwld\whitelist.xip (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report\aggr_storage.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\report\send_storage.xml (Adware.SmartShopper) -> Quarantined and deleted successfully.
c:\documents and settings\MÍŠA\data aplikací\smartshopper\cs\res1\whitelist.dbs (Adware.SmartShopper) -> Quarantined and deleted successfully.

Re: problémy s viry

Napsal: 09 led 2011 17:19
od Rudy
Vše smazáno. Thread je právě toto místo, do něhož píšeme. Mám to v podpisu proto, aby někdo nechtěl řešit přednostně problém třeba přes SZ, nebo ICQ. :)

Re: problémy s viry

Napsal: 09 led 2011 17:26
od fitzink
AHA. Děkuju

Re: problémy s viry

Napsal: 09 led 2011 17:38
od Rudy
Nemáte zač!