Stránka 1 z 2

GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 07:53
od Roman Pánek
Ahoj, Spyware terminator mi našel tohoto trojana v C:/windows/system32/wscript.exe a sám terminator mi ho nebyl schopen odstranit. Jak jednoduše a efektivně odstranit genericFF-1.
Díky moc za pomoc
:o)

GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 07:55
od Roman Pánek
JO a mám nový notebook Samsung R730 s WIN7

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 08:21
od motji
Hezké dopoledne :)
Soubor otestujte na www.virustotal.com
Poprosím o log ze rsitu, viz můj podpis.

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 08:35
od Roman Pánek
AhnLab-V3 2011.05.01.00 2011.04.30 -
AntiVir 7.11.7.92 2011.04.30 -
Antiy-AVL 2.0.3.7 2011.05.01 -
Avast 4.8.1351.0 2011.04.30 -
Avast5 5.0.677.0 2011.04.30 -
AVG 10.0.0.1190 2011.04.30 -
BitDefender 7.2 2011.05.01 -
CAT-QuickHeal 11.00 2011.04.30 -
ClamAV 0.97.0.0 2011.05.01 -
Commtouch 5.3.2.6 2011.05.01 -
Comodo 8536 2011.05.01 -
DrWeb 5.0.2.03300 2011.05.01 -
Emsisoft 5.1.0.5 2011.05.01 -
eSafe 7.0.17.0 2011.04.28 -
eTrust-Vet 36.1.8299 2011.04.29 -
F-Prot 4.6.2.117 2011.05.01 -
F-Secure 9.0.16440.0 2011.05.01 -
Fortinet 4.2.257.0 2011.05.01 -
GData 22 2011.05.01 -
Ikarus T3.1.1.103.0 2011.05.01 -
Jiangmin 13.0.900 2011.04.30 -
K7AntiVirus 9.98.4527 2011.04.30 -
Kaspersky 9.0.0.837 2011.05.01 -
McAfee 5.400.0.1158 2011.05.01 -
McAfee-GW-Edition 2010.1D 2011.04.30 -
Microsoft 1.6802 2011.05.01 -
NOD32 6084 2011.05.01 -
Norman 6.07.07 2011.04.30 -
Panda 10.0.3.5 2011.04.30 -
PCTools 7.0.3.5 2011.04.29 -
Prevx 3.0 2011.05.01 -
Rising 23.55.04.03 2011.04.29 -
Sophos 4.64.0 2011.05.01 -
SUPERAntiSpyware 4.40.0.1006 2011.05.01 -
Symantec 20101.3.2.89 2011.05.01 -
TheHacker 6.7.0.1.184 2011.04.30 -
TrendMicro 9.200.0.1012 2011.05.01 -
TrendMicro-HouseCall 9.200.0.1012 2011.05.01 -
VBA32 3.12.16.0 2011.04.29 -
VIPRE 9167 2011.05.01 -
ViRobot 2011.4.30.4439 2011.04.30 -
VirusBuster 13.6.329.0 2011.04.30 -

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 08:37
od Roman Pánek
Additional informationShow all
MD5 : d1ab72db2bedd2f255d35da3da0d4b16
SHA1 : 860265276b29b42b8c4b077e5c651def9c81b6e9
SHA256: 047f3c5a7ab0ea05f35b2ca8037bf62dd4228786d07707064dbd0d46569305d0
ssdeep: 3072:f2L8uyujrWp2XTUwVo3FyXtT7uQgxeV+Wssm/CDkuIr5Txt9x:f2guyue8y10gwV+xsmhN
T5x
File size : 141824 bytes
First seen: 2009-11-20 15:32:57
Last seen : 2011-05-01 07:30:10
TrID:
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft _ Windows Script Host
description..: Microsoft _ Windows Based Script Host
original name: wscript.exe
internal name: wscript.exe
file version.: 5.8.7600.16385
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x2F3B
timedatestamp....: 0x4A5BC678 (Mon Jul 13 23:42:48 2009)
machinetype......: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x1757C, 0x17600, 6.34, 7e9730ba2ec06090e3b0cb53d017e5c1
.data, 0x19000, 0x4DC, 0x600, 0.76, f6c38d44b8319b8cf8bcc9108060f062
.rsrc, 0x1A000, 0x94B8, 0x9600, 4.21, f859f3fbaafa7a63d32f566f88931873
.reloc, 0x24000, 0x13D4, 0x1400, 6.58, 70afb83647ccee576016e3db5e11ca58

[[ 7 import(s) ]]
ADVAPI32.dll: RegCreateKeyA, RegCloseKey, RegSetValueA, RegOpenKeyA, RegQueryValueA, RegDeleteKeyA, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, RegCreateKeyExA, RegOpenKeyExW, ImpersonateLoggedOnUser, RegisterEventSourceW, GetUserNameW, LookupAccountNameW, ReportEventW, DeregisterEventSource, IsTextUnicode, RegQueryValueExA, RegEnumKeyExA, RegOpenKeyExA, RegSetValueExA
KERNEL32.dll: GetCommandLineA, lstrlenW, GetCommandLineW, HeapAlloc, HeapFree, GetProcessHeap, GetProcAddress, SearchPathW, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetLocaleInfoW, GetVersionExW, CreateFileMappingW, LoadLibraryExW, SetLastError, LoadResource, FindResourceExW, CreateFileW, GetFileSize, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, GetPrivateProfileIntW, GetPrivateProfileIntA, GetPrivateProfileStringW, GetPrivateProfileStringA, GetFullPathNameW, GetFullPathNameA, GetLocaleInfoA, LoadLibraryExA, LoadLibraryW, HeapReAlloc, GetStdHandle, GetConsoleMode, GetSystemDirectoryA, GetTempPathA, GetTempFileNameA, CreateFileA, WriteFile, FlushFileBuffers, GetUserDefaultLCID, GetCPInfo, GetFileAttributesW, FindFirstFileW, GetFileAttributesA, FindFirstFileA, FindClose, GetACP, CreateEventA, CreateThread, CloseHandle, SetEvent, FormatMessageW, LocalAlloc, LocalFree, FormatMessageA, GetVersionExA, GetModuleFileNameW, LoadLibraryA, FreeLibrary, lstrlenA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, RtlUnwind, OutputDebugStringA, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange, InterlockedDecrement, ExitProcess, GetModuleHandleA, GetStartupInfoA, GetLastError, WideCharToMultiByte, MultiByteToWideChar, GetModuleFileNameA
USER32.dll: GetMessageA, DispatchMessageA, GetActiveWindow, MessageBoxW, PostThreadMessageA, GetParent, TranslateMessage, PeekMessageA, MsgWaitForMultipleObjects, SendMessageA, PostMessageA, LoadStringW, LoadStringA, CharNextA, GetClassInfoA, RegisterClassA, CreateWindowExA, GetWindowLongA, SetWindowLongA, SetTimer, DefWindowProcA, PostQuitMessage, KillTimer, EnumThreadWindows, IsWindowVisible, GetClassNameA
msvcrt.dll: _iob, _vsnwprintf, _errno, _vsnprintf, _beginthread, memcpy, memmove, malloc, free, mbtowc, isleadbyte, _snprintf, _itoa, wctomb, ferror, _swab, wcsrchr, _itow, __badioinfo, __pioinfo, _fileno, _lseeki64, _write, _isatty, __3@YAXPAX@Z, wcsncmp, _wcsnicmp, _wcsicmp, __mb_cur_max, __2@YAPAXI@Z, memset, _endthread, bsearch
OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
ole32.dll: CLSIDFromString, CLSIDFromProgID, MkParseDisplayName, CoGetClassObject, CoInitializeSecurity, CreateFileMoniker, CreateBindCtx, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoUninitialize, CoInitialize, CoCreateInstance, CoRevokeClassObject, CoRegisterClassObject, StringFromCLSID, CoGetMalloc, CoRegisterMessageFilter
VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeA

ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 95744
CompanyName: Microsoft Corporation
EntryPoint: 0x2f3b
FileDescription: Microsoft Windows Based Script Host
FileFlagsMask: 0x0003
FileOS: Win32
FileSize: 138 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 5.8.7600.16385
FileVersionNumber: 5.8.7600.16385
ImageVersion: 6.1
InitializedDataSize: 45056
InternalName: wscript.exe
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 9.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.1
ObjectFileType: Executable application
OriginalFilename: wscript.exe
PEType: PE32
ProductName: Microsoft Windows Script Host
ProductVersion: 5.8.7600.16385
ProductVersionNumber: 5.8.7600.16385
Subsystem: Windows GUI
SubsystemVersion: 5.0
TimeStamp: 2009:07:14 01:42:48+02:00
UninitializedDataSize: 0

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 08:39
od Roman Pánek
Jsem na toto totální neuměl, tak snad jsem to udělal správně ...

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 08:40
od motji
Ještě poprosím o log ze ristu, viz můj podpis :)

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 09:04
od Roman Pánek
Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman at 2011-05-01 09:48:31
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 114 GB (80%) free of 142 GB
Total RAM: 3033 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:48:48, on 1.5.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\windows\Explorer.EXE
C:\windows\system32\Dwm.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\windows\system32\taskeng.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Spyware Terminator\SpywareTerminator.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
D:\STAŽENO SOFTWARE\RSIT.exe
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 7031 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-17 1241552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-17 1241552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-12-15 8120864]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2009-06-03 103720]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"UpdatePDRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-01-04 222504]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2009-04-15 91432]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2009-04-15 50472]
"UpdatePPShortCut"=C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2009-07-21 210216]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-02-26 1713448]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2010-08-25 136216]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2010-08-25 171032]
"Persistence"=C:\windows\system32\igfxpers.exe [2010-08-25 170520]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-30 2183680]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-04-30 3037696]

C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2010-08-25 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-05-01 09:48:31 ----D---- C:\rsit
2011-05-01 09:48:31 ----D---- C:\Program Files\trend micro
2011-04-30 17:56:17 ----D---- C:\Program Files\WinClamAVShield
2011-04-30 17:41:15 ----D---- C:\Program Files\Crawler
2011-04-30 17:40:57 ----D---- C:\Users\Roman\AppData\Roaming\Spyware Terminator
2011-04-30 17:40:57 ----D---- C:\ProgramData\Spyware Terminator
2011-04-30 17:40:57 ----A---- C:\windows\system32\drivers\sp_rsdrv2.sys
2011-04-30 17:40:51 ----D---- C:\Program Files\Spyware Terminator
2011-04-30 15:43:52 ----D---- C:\Program Files\Anti Trojan Elite
2011-04-27 08:20:11 ----A---- C:\windows\system32\prevhost.exe
2011-04-27 08:20:05 ----A---- C:\windows\system32\fsutil.exe
2011-04-27 08:20:05 ----A---- C:\windows\system32\esent.dll
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\USBSTOR.SYS
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\storport.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\nvstor.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\nvraid.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\ntfs.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\iaStorV.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\amdxata.sys
2011-04-27 08:20:05 ----A---- C:\windows\system32\drivers\amdsata.sys
2011-04-27 08:19:54 ----A---- C:\windows\system32\XpsPrint.dll
2011-04-27 08:19:53 ----A---- C:\windows\explorer.exe
2011-04-15 09:11:36 ----A---- C:\windows\system32\drivers\srv2.sys
2011-04-15 09:11:35 ----A---- C:\windows\system32\drivers\srvnet.sys
2011-04-15 09:11:35 ----A---- C:\windows\system32\drivers\srv.sys
2011-04-15 09:11:34 ----A---- C:\windows\system32\vbscript.dll
2011-04-15 09:11:34 ----A---- C:\windows\system32\jscript.dll
2011-04-15 09:11:33 ----A---- C:\windows\system32\dnsrslvr.dll
2011-04-15 09:11:33 ----A---- C:\windows\system32\dnscacheugc.exe
2011-04-15 09:11:33 ----A---- C:\windows\system32\dnsapi.dll
2011-04-15 09:11:31 ----A---- C:\windows\system32\atmlib.dll
2011-04-15 09:11:31 ----A---- C:\windows\system32\atmfd.dll
2011-04-15 09:11:22 ----A---- C:\windows\system32\mshtml.dll
2011-04-15 09:11:21 ----A---- C:\windows\system32\wininet.dll
2011-04-15 09:11:21 ----A---- C:\windows\system32\urlmon.dll
2011-04-15 09:11:21 ----A---- C:\windows\system32\ieui.dll
2011-04-15 09:11:21 ----A---- C:\windows\system32\ieframe.dll
2011-04-15 09:11:20 ----A---- C:\windows\system32\jsproxy.dll
2011-04-15 09:11:16 ----A---- C:\windows\system32\win32k.sys
2011-04-15 09:11:15 ----A---- C:\windows\system32\FXSCOVER.exe
2011-04-15 09:11:14 ----A---- C:\windows\system32\XpsGdiConverter.dll
2011-04-15 09:11:13 ----A---- C:\windows\system32\inetcomm.dll
2011-04-15 09:11:12 ----A---- C:\windows\system32\mfc42.dll
2011-04-15 09:11:11 ----A---- C:\windows\system32\mfc42u.dll
2011-04-15 09:11:09 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2011-04-15 09:11:09 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2011-04-15 09:11:09 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2011-04-15 09:11:09 ----A---- C:\windows\system32\drivers\bowser.sys
2011-04-13 19:29:08 ----D---- C:\Program Files\Common Files\Adobe
2011-04-13 19:29:08 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 months======

2011-05-01 09:48:48 ----D---- C:\windows\Prefetch
2011-05-01 09:48:39 ----D---- C:\windows\Temp
2011-05-01 09:48:31 ----RD---- C:\Program Files
2011-05-01 08:29:32 ----D---- C:\windows\system32\catroot2
2011-05-01 08:29:30 ----SHD---- C:\System Volume Information
2011-04-30 23:45:28 ----D---- C:\windows\system32\config
2011-04-30 19:43:38 ----D---- C:\windows\rescache
2011-04-30 18:05:39 ----D---- C:\ProgramData\McAfee
2011-04-30 18:05:36 ----D---- C:\Program Files\McAfee
2011-04-30 18:05:27 ----D---- C:\Program Files\Common Files\McAfee
2011-04-30 18:03:47 ----D---- C:\windows\System32
2011-04-30 18:02:31 ----D---- C:\windows\system32\drivers
2011-04-30 18:02:27 ----D---- C:\windows\system32\DriverStore
2011-04-30 18:02:27 ----D---- C:\windows\system32\catroot
2011-04-30 18:02:27 ----D---- C:\windows\inf
2011-04-30 17:40:57 ----HD---- C:\ProgramData
2011-04-28 15:52:23 ----SD---- C:\Users\Roman\AppData\Roaming\Microsoft
2011-04-28 15:00:05 ----D---- C:\windows\winsxs
2011-04-28 14:59:03 ----D---- C:\windows\AppPatch
2011-04-28 14:59:01 ----D---- C:\windows\system32\cs-CZ
2011-04-28 00:10:41 ----D---- C:\Windows
2011-04-24 14:52:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-04-23 22:20:27 ----SHD---- C:\windows\Installer
2011-04-23 08:05:22 ----D---- C:\Program Files\Microsoft Silverlight
2011-04-18 15:46:44 ----A---- C:\windows\system32\MRT.exe
2011-04-16 20:35:53 ----D---- C:\windows\Microsoft.NET
2011-04-16 20:35:51 ----RSD---- C:\windows\assembly
2011-04-16 08:38:52 ----D---- C:\windows\system32\migration
2011-04-16 08:38:52 ----D---- C:\Program Files\Internet Explorer
2011-04-16 08:23:18 ----D---- C:\ProgramData\Microsoft Help
2011-04-13 19:37:32 ----D---- C:\windows\Logs
2011-04-13 19:29:16 ----D---- C:\ProgramData\Adobe
2011-04-13 19:29:08 ----D---- C:\Program Files\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-10-13 331288]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 SABI;SAMSUNG Kernel Driver For Windows 7; \??\C:\windows\system32\Drivers\SABI.sys [2010-03-31 10752]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\windows\system32\drivers\sp_rsdrv2.sys [2011-04-30 142592]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2010-11-23 1249792]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2010-08-25 9024512]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHDA.sys [2009-12-15 2977248]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\windows\system32\drivers\IntcHdmi.sys [2009-07-10 122880]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-02-26 242992]
S2 ATE_PROCMON;ATE_PROCMON; \??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S3 rtport;rtport; \??\C:\windows\system32\drivers\rtport.sys [2010-11-11 15656]
S3 sisagp;Filtr SIS sběrnice AGP; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2009-07-07 247152]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-30 488960]

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 09:23
od motji
:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.


Budu tu večer :)

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 20:05
od Roman Pánek
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 6484

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

1.5.2011 20:51:13
mbam-log-2011-05-01 (20-51-13).txt

Typ kontroly: Úplný test (C:\|D:\|)
Testované objekty: 232671
Uplynulý čas: 24 minut, 56 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 20:17
od Roman Pánek
Nic to nenašlo,jak je to možné?
Je ten Spyware Terminator vůbec k něčemu?
Neudělá mi v systému, díky označení škodlivosti softwaru, který je ale potřeba k chodu systému, víc škody než užitku?

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 21:00
od motji
Terminátor je v poslední době poněkud paranoidní, ale i tak si raději něco ověřím.

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 22:39
od Roman Pánek
ComboFix 11-04-30.06 - Roman 01.05.2011 23:27:30.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3033.2249 [GMT 2:00]
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-01 do 2011-05-01 )))))))))))))))))))))))))))))))
.
.
2011-05-01 21:33 . 2011-05-01 21:33 -------- d-----w- c:\users\Roman\AppData\Local\temp
2011-05-01 21:33 . 2011-05-01 21:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-01 18:25 . 2011-05-01 18:25 -------- d-----w- c:\users\Roman\AppData\Roaming\Malwarebytes
2011-05-01 18:24 . 2011-05-01 18:24 -------- d-----w- c:\programdata\Malwarebytes
2011-05-01 18:24 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-01 18:24 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 18:24 . 2011-05-01 18:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-01 07:48 . 2011-05-01 07:48 -------- d-----w- C:\rsit
2011-05-01 07:48 . 2011-05-01 07:48 -------- d-----w- c:\program files\trend micro
2011-04-30 20:12 . 2011-04-18 07:15 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1C5A9D98-7DB3-416A-8DFB-0785F54BB693}\mpengine.dll
2011-04-30 15:56 . 2011-05-01 08:15 -------- d-----w- c:\program files\WinClamAVShield
2011-04-30 15:40 . 2011-05-01 18:32 -------- d-----w- c:\programdata\Spyware Terminator
2011-04-30 15:40 . 2011-05-01 07:45 -------- d-----w- c:\users\Roman\AppData\Roaming\Spyware Terminator
2011-04-30 15:40 . 2011-04-30 15:40 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-04-30 15:40 . 2011-05-01 18:32 -------- d-----w- c:\program files\Spyware Terminator
2011-04-30 13:43 . 2011-04-30 15:29 -------- d-----w- c:\program files\Anti Trojan Elite
2011-04-27 06:20 . 2011-02-18 05:39 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-27 06:20 . 2011-03-11 05:39 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-04-27 06:20 . 2011-03-11 05:39 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-04-27 06:20 . 2011-03-11 05:39 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-04-27 06:20 . 2011-03-11 05:39 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-04-27 06:20 . 2011-03-11 05:38 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-04-27 06:20 . 2011-03-11 05:38 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-04-27 06:20 . 2011-03-11 05:38 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-04-27 06:20 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\system32\esent.dll
2011-04-27 06:20 . 2011-03-11 05:31 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-04-27 06:19 . 2011-03-12 11:23 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-27 06:19 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2011-04-13 17:29 . 2011-04-13 17:29 -------- d-----w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-19 08:54 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-02-19 06:30 . 2011-03-09 12:53 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:30 . 2011-03-09 12:53 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:30 . 2011-03-09 12:53 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-03 05:54 . 2011-03-03 19:13 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-02 16:11 . 2011-03-07 16:49 222080 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-04-30 3037696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-15 8120864]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-03 103720]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-15 91432]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-15 50472]
"UpdatePPShortCut"="c:\program files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2009-07-21 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-04-30 2183680]
.
c:\users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMon.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-03 1343400]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2010-03-31 10752]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-04-30 142592]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-07-10 122880]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
.
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-05-01 23:35:54
ComboFix-quarantined-files.txt 2011-05-01 21:35
.
Před spuštěním: Volných bajtů: 119 331 201 024
Po spuštění: Volných bajtů: 119 202 344 960
.
- - End Of File - - 67948D50499B137E13B0364A08BB61DC

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 22:42
od motji
Fajn, nic nevidím jak to vypadá s pc?

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?

Re: GenericFF-1 trojan jak se ho zbavit ?

Napsal: 01 kvě 2011 22:47
od Roman Pánek
Dík za optání :) PC je asi v pohodě, akorát se mi zdá že internet se vleče jako šnek.
Teď jsem odinstaloval Combofix a pokračuji dále.