Stránka 1 z 1

Facebook Virus

Napsal: 23 črc 2011 16:32
od Wyfre
Dobrý den, známá mi donesla notebook s touhle havětí a dotazem jestli nevím co s tím. Chtěl bych vás tímto poprosit o pomoc s řešením.
Přikládám log z RSIT
Logfile of random's system information tool 1.09 (written by random/random)
Run by Denni at 2011-07-23 17:22:19
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 35 GB (25%) free of 141 GB
Total RAM: 2038 MB (43% free)

HijackThis download failed

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\update.1\svchost.exe srv
WLIDSvcM.exe 1284
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Windows\update.tray-3-0\svchost.exe"
"C:\Windows\systemup.exe" stand
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\OneUpIndustries\Bins\v0.9.8.188\Bins.exe" /startup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\OneUpIndustries\Bins\v0.9.8.188\Bins32on64.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\update.2\svchost.exe srv
"C:\Windows\update.2\svchost.exe" stand
"C:\Windows\system32\wuauclt.exe"
taskeng.exe {A4607DC1-895E-42EF-956F-3834D64E7D24}
C:\Windows\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\update.5.0\svchost.exe srv
"C:\Windows\update.5.0\svchost.exe" stand
C:\Windows\ufa\ufa.exe -o http://127.0.0.1:52188
\??\C:\Windows\system32\conhost.exe "-1116381049-755200678-4959933381802757144-418818503-558953063-49458065-1903982461
C:\Windows\sysdriver32.exe srv
"C:\Windows\update.tray-3-0-lnk\svchost.exe" tray 3-0 1
"C:\Users\Denni\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Denni\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/ --channel=2588.053A6120.1106885721 /prefetch:3
"C:\Users\Denni\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --disable-client-side-phishing-detection --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/ --channel=2588.0237C7A8.1958411840 /prefetch:3 --ignored=" --type=renderer "
"C:\Users\Denni\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Denni\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7280_0\npSkypeChromePlugin.dll" --lang=cs --channel=2588.0232B0A0.1142813679 /prefetch:4
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe11_ Global\UsGthrCtrlFltPipeMssGthrPipe11 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"G:\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Denni\AppData\Roaming\Mozilla\Firefox\Profiles\xwp60oix.default

prefs.js - "browser.startup.homepage" - "http:/www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-04-15 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-11 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 165912]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 385560]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 363544]
"TNOD UP"=C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe [2010-09-05 1837056]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Denni\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-11 136176]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2009-05-28 89600]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"NBAgent"=C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-09-03 1406248]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"wxpdrv"=C:\Windows\services32.exe [2011-07-14 1094144]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-3-0\svchost.exe [2011-07-14 1094144]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"2902295.exe"=C:\Windows\Temp\2902295.exe []
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-23 247296]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-23 247296]
"7570847.exe"=C:\Users\Denni\AppData\Local\Temp\7570847.exe []
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-23 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-14 114176]
"9483752.exe"=C:\Windows\Temp\9483752.exe []
"5601563.exe"=C:\Windows\Temp\5601563.exe []
"65759421-loader2.exe"=C:\Windows\TEMP\65759421-loader2.exe [2011-07-23 249344]
"4192993.exe"=C:\Windows\TEMP\4192993.exe [2011-07-23 495616]
"8670556.exe"=C:\Windows\TEMP\8670556.exe [2011-07-23 247296]

C:\Users\Denni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2010 Screen Clipper and Launcher.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 261120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
TaskbarDockShellExt - {1984DD45-52CF-49cd-AB77-28F378FEA264} - C:\Program Files\OneUpIndustries\Bins\v0.9.8.188\TaskbarDockLoader64.dll [2011-06-26 587264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-07-23 17:22:21 ----D---- C:\Program Files\trend micro
2011-07-23 17:22:19 ----D---- C:\rsit
2011-07-23 16:45:12 ----D---- C:\Program Files\CCleaner
2011-07-14 20:17:58 ----A---- C:\Windows\system32\Řím,Vatikán,Neapol, Sorrento,Pompeje,Vesuv,ostrov CAPRI-hotel3 , polopenze i pojištění v ceně - Řím,Vatikán,Neapol, Sorrento,Pompeje,Vesuv,ostrov CAPRI-hotel3 , polopenze i pojištění v ceně - Itálie -.lnk
2011-07-14 14:58:47 ----A---- C:\Windows\gbot111.exe
2011-07-14 13:56:23 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-07-14 13:44:23 ----D---- C:\Windows\ufa
2011-07-14 13:44:23 ----D---- C:\Windows\rpcminer
2011-07-14 13:44:23 ----D---- C:\Windows\phoenix
2011-07-14 13:44:22 ----A---- C:\Windows\unrar.exe
2011-07-14 13:43:58 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-14 13:43:50 ----A---- C:\Windows\ddh_iplist.txt
2011-07-14 13:43:47 ----A---- C:\Windows\systemup.exe
2011-07-14 13:43:46 ----A---- C:\Windows\l1rezerv.exe
2011-07-14 13:43:37 ----HD---- C:\Windows\update.5.0
2011-07-14 13:43:22 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-14 13:43:02 ----A---- C:\Windows\sysdriver32_.exe
2011-07-14 13:42:57 ----HD---- C:\Windows\update.2
2011-07-14 13:42:53 ----D---- C:\Windows\av_ico
2011-07-14 13:42:53 ----A---- C:\Windows\iplist.txt
2011-07-14 13:42:48 ----A---- C:\Windows\sysdriver32.exe
2011-07-14 13:42:34 ----A---- C:\Windows\front_ip_list.txt
2011-07-14 13:41:18 ----HD---- C:\Windows\update.1
2011-07-14 13:41:16 ----HD---- C:\Windows\update.tray-3-0-lnk
2011-07-14 13:41:16 ----HD---- C:\Windows\update.tray-3-0
2011-07-14 13:29:36 ----A---- C:\Windows\winlog-ids.txt
2011-07-14 13:29:36 ----A---- C:\Windows\winlog-dirs.txt
2011-07-14 13:29:29 ----A---- C:\Windows\services32.exe
2011-07-13 18:31:44 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 18:31:44 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 18:31:43 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 18:31:42 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 18:31:41 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 18:31:36 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 18:31:31 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 18:31:31 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 18:31:31 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 18:31:31 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 18:31:30 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 18:31:30 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 18:31:30 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 18:31:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 18:31:30 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 18:31:30 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 18:31:30 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 18:31:30 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 18:31:28 ----A---- C:\Windows\SYSWOW64\user.exe
2011-06-29 10:16:29 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 10:16:29 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 10:16:28 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 10:16:27 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-29 10:16:27 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 10:16:26 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-29 10:16:25 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-29 10:16:25 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-29 10:16:24 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-29 10:16:24 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 10:16:24 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 10:16:24 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 10:16:24 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 10:16:22 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-29 10:16:21 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-29 10:16:20 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-29 10:16:20 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 10:16:18 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-29 10:09:09 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-29 10:09:09 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-29 10:09:09 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-29 10:09:09 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 10:09:08 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-27 22:49:49 ----D---- C:\Program Files (x86)\DOSBox-0.73
2011-06-25 16:36:00 ----D---- C:\Program Files (x86)\Bandoo

======List of files/folders modified in the last 1 month======

2011-07-23 17:22:21 ----RD---- C:\Program Files
2011-07-23 17:22:21 ----D---- C:\Windows\Prefetch
2011-07-23 17:21:35 ----D---- C:\Windows\Temp
2011-07-23 17:04:49 ----D---- C:\Windows
2011-07-23 17:03:27 ----SHD---- C:\Windows\Installer
2011-07-23 17:03:27 ----HD---- C:\ProgramData
2011-07-23 16:54:40 ----D---- C:\Users\Denni\AppData\Roaming\DAEMON Tools Lite
2011-07-23 16:54:30 ----D---- C:\Users\Denni\AppData\Roaming\Skype
2011-07-23 16:48:28 ----D---- C:\Windows\Logs
2011-07-23 16:48:28 ----D---- C:\Windows\debug
2011-07-23 16:44:37 ----SHD---- C:\System Volume Information
2011-07-23 16:44:33 ----D---- C:\Windows\System32
2011-07-23 16:44:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-23 16:44:32 ----D---- C:\Windows\inf
2011-07-23 16:36:27 ----D---- C:\Windows\system32\config
2011-07-23 02:19:50 ----RD---- C:\Program Files (x86)
2011-07-23 02:18:22 ----D---- C:\Program Files (x86)\Microsoft
2011-07-19 11:38:03 ----D---- C:\Windows\system32\catroot2
2011-07-18 13:31:14 ----D---- C:\Windows\Tasks
2011-07-18 13:31:14 ----D---- C:\Windows\system32\wfp
2011-07-18 13:31:12 ----D---- C:\Windows\system32\wbem
2011-07-18 13:30:26 ----D---- C:\Windows\system32\DriverStore
2011-07-18 13:30:26 ----D---- C:\Windows\system32\drivers\etc
2011-07-18 13:30:24 ----D---- C:\Windows\registration
2011-07-18 13:30:17 ----D---- C:\Users\Denni\AppData\Roaming\OneUpIndustries
2011-07-17 12:27:37 ----D---- C:\Windows\system32\LogFiles
2011-07-16 20:58:41 ----SD---- C:\Users\Denni\AppData\Roaming\Microsoft
2011-07-15 15:09:30 ----SHD---- C:\$Recycle.Bin
2011-07-15 06:48:33 ----D---- C:\Users\Denni\AppData\Roaming\BatteryBar
2011-07-14 19:42:39 ----D---- C:\Users\Denni\AppData\Roaming\ICQ
2011-07-14 17:18:09 ----D---- C:\Windows\system32\drivers
2011-07-14 14:05:48 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-14 13:56:47 ----D---- C:\Windows\winsxs
2011-07-14 13:56:46 ----D---- C:\Windows\SysWOW64
2011-07-14 10:10:37 ----D---- C:\Windows\AppPatch
2011-07-14 05:18:24 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 18:31:18 ----D---- C:\Windows\system32\catroot
2011-07-11 10:36:47 ----D---- C:\Windows\system32\NDF
2011-07-05 16:14:41 ----D---- C:\Program Files (x86)\ICQ7.5
2011-06-30 13:18:34 ----D---- C:\Windows\Microsoft.NET
2011-06-30 13:18:32 ----RSD---- C:\Windows\assembly
2011-06-29 19:27:17 ----RSD---- C:\Windows\Fonts
2011-06-27 15:38:40 ----D---- C:\ProgramData\Easybits GO
2011-06-27 12:23:36 ----D---- C:\Users\Denni\AppData\Roaming\go
2011-06-27 09:29:26 ----D---- C:\Windows\system32\wdi
2011-06-26 21:36:46 ----D---- C:\ProgramData\Skype Extras

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-12 254528]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-12-21 170640]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-12-21 50624]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-12-21 34144]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-09-23 6180832]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-23 340992]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-23 495616]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-23 247296]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-14 1094144]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-05-11 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------
Děkuji Wyfre

Re: Facebook Virus

Napsal: 23 črc 2011 18:03
od chodnik74
Dobrý den :welcome:

Program nepoužívejte bez doporučení Rádce a pozorně se řiďte následujících pokynu,protože program netoleruje chyby a může dojít k úplnému poškození systému!!
  • :arrow: Stáhneme si Combofix Obrázek
  • Program uložíme nejlépe na Plochu
  • Vypneme všechny rezidentní štíty.Jak antiviru,tak antispywaru a firewallu
  • Vypneme všechny běžící aplikace (ICQ,prohlížeč,programy) a necháme pouze Combofix
  • Spustíme Combofix.exe s administrátorským oprávněním
    U Windows XP se přihlásíme pod účtem správce
    Ve Windows 7 a Vista klikněte pravým tlačítkem myši na Combofix.exe a dejte ,,Spustit jako správce,,)
  • Hned po startu programu na vás vyskočí licenční podmínky,tak potvrdíme tlačítkemANO
  • Pokud vám Combofix nabídne instalaci Konzoly pro zotavení,tak souhlaste a nechte nainstalovat(zde je potřeba aktivní připojení na internet)
  • Pokračujte dle pokynů programu a během skenování na nic neklikejte,na pc nepracujte(ICQ,jiné aplikace,internet..).Nechte počítač v klidu.
  • Celý sken tvá mezi 5-15 min,ale pokud je v PC hodně havěti,tak se čas může lišit.
  • Po skončení skenování(případném restartu počítače) se vám zobrazí log z Combofixu,který mi vložte sem(Kdyby se log nezobrazil,tak jej najdete zde: C:\ComboFix.txt
  • (Pokud si nevíte rady s kterýmkoliv z výše uvedených kroků,tak se ptejte nebo mrkněte na detailnější návod včetně obrázků http://www.bleepingcomputer.com/combofi ... t-combofix )

:!: Jinak co budeme dělat s nelegálním ESET? :twisted: :twisted:

Pravidla fora: č.1 a č.2, č.3

Re: Facebook Virus

Napsal: 24 črc 2011 00:42
od Wyfre
Přikládám log z combofixu a jak jsem psal v prvním topiku je to notebook co mi přinesla kolegyně takže nic o nelegálním ESETu nevím :oops:
ComboFix 11-07-23.03 - Denni 23.07.2011 19:17:27.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2038.1111 [GMT 2:00]
Spuštěný z: G:\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\TNod User & Password Finder\TNODUP.exe
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\gbot111.exe
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\services32.exe
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\TEMP\8670556.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-3-0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-23 do 2011-07-23 )))))))))))))))))))))))))))))))
.
.
2011-07-23 17:23 . 2011-07-23 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-23 15:30 . 2011-07-23 15:30 302592 ----a-w- c:\windows\SysWow64\cmd.execf
2011-07-23 15:22 . 2011-07-23 15:22 -------- d-----w- c:\program files\trend micro
2011-07-23 15:22 . 2011-07-23 15:22 -------- d-----w- C:\rsit
2011-07-23 14:45 . 2011-07-23 14:45 -------- d-----w- c:\program files\CCleaner
2011-07-16 03:59 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E67F9E03-5A0C-4F4F-80D1-D35551FBD3BC}\mpengine.dll
2011-07-14 12:05 . 2011-07-14 12:05 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-14 12:05 . 2011-07-14 12:05 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-14 11:56 . 2011-07-14 11:56 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-07-14 11:44 . 2011-07-14 11:44 -------- d-----w- c:\windows\ufa
2011-07-14 11:44 . 2011-07-14 11:44 -------- d-----w- c:\windows\rpcminer
2011-07-14 11:44 . 2011-07-14 11:44 -------- d-----w- c:\windows\phoenix
2011-07-14 11:44 . 2011-07-18 11:34 246272 ----a-w- c:\windows\unrar.exe
2011-07-14 11:42 . 2011-07-18 11:30 -------- d-----w- c:\windows\av_ico
2011-07-14 11:41 . 2011-07-23 17:22 -------- d--h--w- c:\windows\update.tray-3-0
2011-07-14 11:41 . 2011-07-14 11:41 -------- d--h--w- c:\windows\update.tray-3-0-lnk
2011-06-29 08:16 . 2011-05-04 05:25 2315776 ----a-w- c:\windows\system32\tquery.dll
2011-06-29 08:09 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 08:09 . 2011-05-24 10:40 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-29 08:09 . 2011-05-24 10:39 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-29 08:09 . 2011-05-24 10:37 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-29 08:09 . 2011-05-24 10:40 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-27 20:50 . 2011-06-27 20:50 -------- d-----w- c:\users\Denni\AppData\Local\DOSBox
2011-06-27 20:49 . 2011-06-27 20:52 -------- d-----w- c:\program files (x86)\DOSBox-0.73
2011-06-25 14:36 . 2011-06-25 14:36 -------- d-----w- c:\program files (x86)\Bandoo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-03 08:19 . 2011-05-19 15:10 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-03 05:57 . 2011-07-13 16:31 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-05-11 19:48 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-14 09:07 . 2011-05-14 09:07 159080 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin
2011-05-12 10:56 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-12 10:56 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-12 10:07 . 2011-05-12 10:07 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-12 10:07 . 2011-05-12 10:07 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-12 10:07 . 2011-05-12 10:07 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-12 10:07 . 2011-05-12 10:07 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-12 10:07 . 2011-05-12 10:07 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-12 10:07 . 2011-05-12 10:07 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-12 10:07 . 2011-05-12 10:07 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-12 10:07 . 2011-05-12 10:07 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-12 10:07 . 2011-05-12 10:07 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-12 10:07 . 2011-05-12 10:07 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-12 10:07 . 2011-05-12 10:07 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-12 10:07 . 2011-05-12 10:07 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-12 10:07 . 2011-05-12 10:07 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-12 10:07 . 2011-05-12 10:07 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-12 10:07 . 2011-05-12 10:07 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-12 10:07 . 2011-05-12 10:07 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-12 10:07 . 2011-05-12 10:07 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-12 10:07 . 2011-05-12 10:07 448512 ----a-w- c:\windows\system32\html.iec
2011-05-12 10:07 . 2011-05-12 10:07 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-12 10:07 . 2011-05-12 10:07 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-12 10:07 . 2011-05-12 10:07 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-12 10:07 . 2011-05-12 10:07 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-12 10:07 . 2011-05-12 10:07 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-12 10:07 . 2011-05-12 10:07 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-12 10:07 . 2011-05-12 10:07 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-12 10:07 . 2011-05-12 10:07 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-12 10:07 . 2011-05-12 10:07 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-12 10:07 . 2011-05-12 10:07 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-12 10:07 . 2011-05-12 10:07 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-12 10:07 . 2011-05-12 10:07 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-12 10:07 . 2011-05-12 10:07 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-12 10:07 . 2011-05-12 10:07 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-12 10:07 . 2011-05-12 10:07 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-12 10:07 . 2011-05-12 10:07 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-12 10:07 . 2011-05-12 10:07 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-12 10:07 . 2011-05-12 10:07 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-12 10:07 . 2011-05-12 10:07 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-12 10:07 . 2011-05-12 10:07 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-05-12 09:58 . 2010-06-24 09:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-05-12 07:34 . 2011-05-12 07:34 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-11 21:11 . 2011-05-11 21:11 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-03 05:29 . 2011-06-17 05:28 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-17 05:28 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-04-29 03:06 . 2011-06-17 05:28 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 03:05 . 2011-06-17 05:28 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 03:05 . 2011-06-17 05:28 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:40 . 2011-06-17 05:28 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-27 02:39 . 2011-06-17 05:28 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:39 . 2011-06-17 05:28 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-25 05:33 . 2011-06-17 05:28 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:34 . 2011-06-17 05:28 499200 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 89600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-03 1406248]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\users\Denni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-1-21 226176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000Core.job
- c:\users\Denni\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-11 19:36]
.
2011-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000UA.job
- c:\users\Denni\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-11 19:36]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF1878.cfxxe" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 363544]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-28F378FEA264}"= "c:\program files\OneUpIndustries\Bins\v0.9.8.188\TaskbarDockLoader64.dll" [2011-06-26 587264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=127.0.0.1:60606
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.30.1
FF - ProfilePath - c:\users\Denni\AppData\Roaming\Mozilla\Firefox\Profiles\xwp60oix.default\
FF - prefs.js: browser.startup.homepage - http:/www.seznam.cz
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 60606
FF - prefs.js: network.proxy.type - 1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-wxpdrv - c:\windows\services32.exe
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico0 - c:\windows\update.tray-3-0\svchost.exe
Wow6432Node-HKLM-Run-tray_ico1 - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Wow6432Node-HKLM-Run-sysdriver32.exe - c:\windows\sysdriver32.exe
Wow6432Node-HKLM-Run-sysdriver32_.exe - c:\windows\sysdriver32_.exe
Wow6432Node-HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
Wow6432Node-HKLM-Run-systemup - c:\windows\systemup.exe
HKLM-Run-TNOD UP - c:\program files (x86)\TNod User & Password Finder\TNODUP.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-23 19:30:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-23 17:30
.
Před spuštěním: Volných bajtů: 32 769 781 760
Po spuštění: Volných bajtů: 32 456 232 960
.
- - End Of File - - 54674465E231709484F635D86E379F17

Re: Facebook Virus

Napsal: 24 črc 2011 10:03
od chodnik74
:arrow: Otevřeme si Poznámkový blok Obrázek
  • (stiskneme klávesovou kombinaci WIN+R a napíšeme ,,notepad,, bez úvozovek a dáme enter)
  • Vložíme do něj následující script:

    Kód: Vybrat vše

    KillAll::
    
    File::
    c:\windows\SysWow64\cmd.execf
    c:\windows\unrar.exe
    
    Folder::
    c:\users\Default\AppData\Local\temp
    c:\windows\ufa
    c:\windows\rpcminer
    c:\windows\phoenix
    c:\windows\av_ico
    c:\windows\update.tray-3-0
    c:\windows\update.tray-3-0-lnk
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "BCSSync"=-
    "SunJavaUpdateSched"=-
    "NBAgent"=-
    "Adobe ARM"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"=-
    "Persistence"=-
    
    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:60606
    
    Firefox::
    FF - ProfilePath - c:\users\Denni\AppData\Roaming\Mozilla\Firefox\Profiles\xwp60oix.default\
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 60606
    FF - prefs.js: network.proxy.type - 1
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
    
    
  • Soubor uložíme na Plochu jako CFScript.txt
  • Poté tento soubor uchopíme levým tlačítkem myši a přetáhneme na ikonu Combofixu a upustíme

    Obrázek
  • Poté Combofix provede všechny operace a udělá nový log,který sem vložte
Vložte sem jeho log a pokračujte dále..

:arrow: Stáhněte program exeHelper.com
  • Spuste program jako správce(pravým klikem myši spustit jako správce )
  • Program vytvoří log exehelperlog.txt a ten sem vložte :)
:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 2 a enter
  • Objeví se vám log a ten sem vložte

:!: Takže tu chci 3 logy :!:

Re: Facebook Virus

Napsal: 24 črc 2011 10:04
od chodnik74
Jinak ESET později nahradíme za špičkový český antivir Avast,který je zdarma :) Kolegyně se na vás zlobit nebude :)

Re: Facebook Virus

Napsal: 24 črc 2011 13:58
od Wyfre
Takže zde přidávám logy
Combofix ->

Kód: Vybrat vše

ComboFix 11-07-23.03 - Denni 24.07.2011  14:42:11.2.2 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1250.420.1029.18.2038.1044 [GMT 2:00]
Spuštěný z: E:\ComboFix.exe
Použité ovládací přepínače :: c:\users\Denni\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\SysWow64\cmd.execf"
"c:\windows\unrar.exe"
.
.
(((((((((((((((((((((((((((((((((((((((   Ostatní výmazy   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Default\AppData\Local\temp
c:\windows\av_ico
c:\windows\av_ico\ico_NOD_SS_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\SysWow64\cmd.execf
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-3-0-lnk
c:\windows\update.tray-3-0-lnk\svchost.exe
c:\windows\update.tray-3-0
.
.
(((((((((((((((((((((((((   Soubory vytvořené od 2011-06-24 do 2011-07-24  )))))))))))))))))))))))))))))))
.
.
2011-07-23 15:22 . 2011-07-23 15:22	--------	d-----w-	c:\program files\trend micro
2011-07-23 15:22 . 2011-07-23 15:22	--------	d-----w-	C:\rsit
2011-07-23 14:45 . 2011-07-23 14:45	--------	d-----w-	c:\program files\CCleaner
2011-07-16 03:59 . 2011-06-07 17:10	8873296	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{E67F9E03-5A0C-4F4F-80D1-D35551FBD3BC}\mpengine.dll
2011-07-14 12:05 . 2011-07-14 12:05	2106216	----a-w-	c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-07-14 12:05 . 2011-07-14 12:05	1998168	----a-w-	c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-07-14 11:56 . 2011-07-14 11:56	--------	d-----w-	c:\program files (x86)\MSXML 4.0
2011-06-29 08:16 . 2011-05-04 05:25	2315776	----a-w-	c:\windows\system32\tquery.dll
2011-06-29 08:09 . 2011-05-24 11:42	404480	----a-w-	c:\windows\system32\umpnpmgr.dll
2011-06-29 08:09 . 2011-05-24 10:40	44544	----a-w-	c:\windows\SysWow64\devrtl.dll
2011-06-29 08:09 . 2011-05-24 10:39	145920	----a-w-	c:\windows\SysWow64\cfgmgr32.dll
2011-06-29 08:09 . 2011-05-24 10:37	252928	----a-w-	c:\windows\SysWow64\drvinst.exe
2011-06-29 08:09 . 2011-05-24 10:40	64512	----a-w-	c:\windows\SysWow64\devobj.dll
2011-06-27 20:50 . 2011-06-27 20:50	--------	d-----w-	c:\users\Denni\AppData\Local\DOSBox
2011-06-27 20:49 . 2011-06-27 20:52	--------	d-----w-	c:\program files (x86)\DOSBox-0.73
2011-06-25 14:36 . 2011-06-25 14:36	--------	d-----w-	c:\program files (x86)\Bandoo
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M výpis   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-03 08:19 . 2011-05-19 15:10	404640	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-03 05:57 . 2011-07-13 16:31	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-05-11 19:48	270720	------w-	c:\windows\system32\MpSigStub.exe
2011-05-14 09:07 . 2011-05-14 09:07	159080	----a-w-	c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin
2011-05-12 10:56 . 2009-07-14 02:36	175616	----a-w-	c:\windows\system32\msclmd.dll
2011-05-12 10:56 . 2009-07-14 02:36	152576	----a-w-	c:\windows\SysWow64\msclmd.dll
2011-05-12 10:07 . 2011-05-12 10:07	86528	----a-w-	c:\windows\SysWow64\iesysprep.dll
2011-05-12 10:07 . 2011-05-12 10:07	76800	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-12 10:07 . 2011-05-12 10:07	74752	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-12 10:07 . 2011-05-12 10:07	74752	----a-w-	c:\windows\SysWow64\iesetup.dll
2011-05-12 10:07 . 2011-05-12 10:07	63488	----a-w-	c:\windows\SysWow64\tdc.ocx
2011-05-12 10:07 . 2011-05-12 10:07	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2011-05-12 10:07 . 2011-05-12 10:07	367104	----a-w-	c:\windows\SysWow64\html.iec
2011-05-12 10:07 . 2011-05-12 10:07	161792	----a-w-	c:\windows\SysWow64\msls31.dll
2011-05-12 10:07 . 2011-05-12 10:07	1126912	----a-w-	c:\windows\SysWow64\wininet.dll
2011-05-12 10:07 . 2011-05-12 10:07	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2011-05-12 10:07 . 2011-05-12 10:07	91648	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2011-05-12 10:07 . 2011-05-12 10:07	89088	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2011-05-12 10:07 . 2011-05-12 10:07	85504	----a-w-	c:\windows\system32\iesetup.dll
2011-05-12 10:07 . 2011-05-12 10:07	76800	----a-w-	c:\windows\system32\tdc.ocx
2011-05-12 10:07 . 2011-05-12 10:07	603648	----a-w-	c:\windows\system32\vbscript.dll
2011-05-12 10:07 . 2011-05-12 10:07	49664	----a-w-	c:\windows\system32\imgutil.dll
2011-05-12 10:07 . 2011-05-12 10:07	48640	----a-w-	c:\windows\system32\mshtmler.dll
2011-05-12 10:07 . 2011-05-12 10:07	448512	----a-w-	c:\windows\system32\html.iec
2011-05-12 10:07 . 2011-05-12 10:07	420864	----a-w-	c:\windows\SysWow64\vbscript.dll
2011-05-12 10:07 . 2011-05-12 10:07	35840	----a-w-	c:\windows\SysWow64\imgutil.dll
2011-05-12 10:07 . 2011-05-12 10:07	30720	----a-w-	c:\windows\system32\licmgr10.dll
2011-05-12 10:07 . 2011-05-12 10:07	23552	----a-w-	c:\windows\SysWow64\licmgr10.dll
2011-05-12 10:07 . 2011-05-12 10:07	222208	----a-w-	c:\windows\system32\msls31.dll
2011-05-12 10:07 . 2011-05-12 10:07	173056	----a-w-	c:\windows\system32\ieUnatt.exe
2011-05-12 10:07 . 2011-05-12 10:07	165888	----a-w-	c:\windows\system32\iexpress.exe
2011-05-12 10:07 . 2011-05-12 10:07	160256	----a-w-	c:\windows\system32\wextract.exe
2011-05-12 10:07 . 2011-05-12 10:07	152064	----a-w-	c:\windows\SysWow64\wextract.exe
2011-05-12 10:07 . 2011-05-12 10:07	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2011-05-12 10:07 . 2011-05-12 10:07	1492992	----a-w-	c:\windows\system32\inetcpl.cpl
2011-05-12 10:07 . 2011-05-12 10:07	142848	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2011-05-12 10:07 . 2011-05-12 10:07	1427456	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2011-05-12 10:07 . 2011-05-12 10:07	1389056	----a-w-	c:\windows\system32\wininet.dll
2011-05-12 10:07 . 2011-05-12 10:07	135168	----a-w-	c:\windows\system32\IEAdvpack.dll
2011-05-12 10:07 . 2011-05-12 10:07	12288	----a-w-	c:\windows\system32\mshta.exe
2011-05-12 10:07 . 2011-05-12 10:07	11776	----a-w-	c:\windows\SysWow64\mshta.exe
2011-05-12 10:07 . 2011-05-12 10:07	114176	----a-w-	c:\windows\system32\admparse.dll
2011-05-12 10:07 . 2011-05-12 10:07	111616	----a-w-	c:\windows\system32\iesysprep.dll
2011-05-12 10:07 . 2011-05-12 10:07	101888	----a-w-	c:\windows\SysWow64\admparse.dll
2011-05-12 09:58 . 2010-06-24 09:33	18328	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-05-12 07:34 . 2011-05-12 07:34	254528	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-11 21:11 . 2011-05-11 21:11	472808	----a-w-	c:\windows\SysWow64\deployJava1.dll
2011-05-03 05:29 . 2011-06-17 05:28	976896	----a-w-	c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-17 05:28	741376	----a-w-	c:\windows\SysWow64\inetcomm.dll
2011-04-29 03:06 . 2011-06-17 05:28	467456	----a-w-	c:\windows\system32\drivers\srv.sys
2011-04-29 03:05 . 2011-06-17 05:28	410112	----a-w-	c:\windows\system32\drivers\srv2.sys
2011-04-29 03:05 . 2011-06-17 05:28	168448	----a-w-	c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:40 . 2011-06-17 05:28	158208	----a-w-	c:\windows\system32\drivers\mrxsmb.sys
2011-04-27 02:39 . 2011-06-17 05:28	289280	----a-w-	c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:39 . 2011-06-17 05:28	128000	----a-w-	c:\windows\system32\drivers\mrxsmb20.sys
.
.
(((((((((((((((((((((((((((((   SnapShot@2011-07-23_17.25.20   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2011-07-24 12:50	36200              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-05-11 19:31 . 2011-07-24 12:50	7964              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2215680527-3719048136-2781696047-1000_UserData.bin
- 2011-07-23 17:25 . 2011-07-23 17:25	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-24 12:48 . 2011-07-24 12:48	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-23 17:25 . 2011-07-23 17:25	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-24 12:48 . 2011-07-24 12:48	2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-05-11 19:26 . 2011-07-24 06:10	234492              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2011-07-23 17:24	385004              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-24 12:47	385004              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
((((((((((((((((((((((((((((((((((   Spouštěcí body v registru   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowBatteryBar"="c:\program files\BatteryBar\ShowBatteryBar.exe" [2009-05-28 89600]
.
c:\users\Denni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-1-21 226176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000Core.job
- c:\users\Denni\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-11 19:36]
.
2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2215680527-3719048136-2781696047-1000UA.job
- c:\users\Denni\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-11 19:36]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 363544]
"TNOD UP"="c:\program files (x86)\TNod User & Password Finder\TNODUP.exe" [BU]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-28F378FEA264}"= "c:\program files\OneUpIndustries\Bins\v0.9.8.188\TaskbarDockLoader64.dll" [2011-06-26 587264]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.30.1
FF - ProfilePath - c:\users\Denni\AppData\Roaming\Mozilla\Firefox\Profiles\xwp60oix.default\
FF - prefs.js: browser.startup.homepage - http:/www.seznam.cz
.
.
Celkový čas: 2011-07-24  14:53:32 - počítač byl restartován
ComboFix-quarantined-files.txt  2011-07-24 12:53
ComboFix2.txt  2011-07-23 17:30
.
Před spuštěním: Volných bajtů: 31 557 472 256
Po spuštění: Volných bajtů: 32 064 397 312
.
- - End Of File - - 4D029647B2B9BBC6BAAB657787D10A5A
Exehelper log ->

Kód: Vybrat vše

exeHelper by Raktor
Build 20100414
Run at 14:54:44 on 07/24/11
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--

A rogue killer log ->

Kód: Vybrat vše

RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Denni [Admin rights]
Mode: Remove -- Date : 07/24/2011 14:56:18

Bad processes: 0

Registry Entries: 4
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

HOSTS File:
127.0.0.1       localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt




Re: Facebook Virus

Napsal: 24 črc 2011 14:37
od chodnik74
:arrow: Otevřeme si Poznámkový blok Obrázek
  • (stiskneme klávesovou kombinaci WIN+R a napíšeme ,,notepad,, bez úvozovek a dáme enter)
  • Vložíme do něj následující script:

    Kód: Vybrat vše

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"=-
    "Persistence"=-
    "TNOD UP"=-
    
  • Soubor uložíme jako oprava.reg (při ukládání nastavte Uložit jako typ:Všechny soubory)
  • Poté tento soubor spustíme a potvrdíme :)

:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 3 a 4 a enter
  • Objeví se vám log a ten sem vložte

Re: Facebook Virus

Napsal: 24 črc 2011 15:12
od Wyfre
První část logu

Kód: Vybrat vše

RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Denni [Admin rights]
Mode: HOSTSFix --  Date : 07/24/2011 16:10:05

Bad processes: 0

HOSTS File:
127.0.0.1       localhost


Resetted HOSTS:
127.0.0.1	localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Druhá část logu

Kód: Vybrat vše

RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Denni [Admin rights]
Mode: ProxyFix -- Date : 07/24/2011 16:10:47

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[5].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt

Re: Facebook Virus

Napsal: 24 črc 2011 16:30
od chodnik74
jak se chová pc?

Re: Facebook Virus

Napsal: 24 črc 2011 17:42
od Wyfre
Už se vše tváří OK, mockrát děkuji za semnou strávený čas a pomoc s problémem :)

Re: Facebook Virus

Napsal: 25 črc 2011 14:54
od chodnik74
:arrow: Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění a zkopírujte a vložte sem následujíci text: Combofix /Uninstall a dejte enter


:arrow: Obrázek OTC
  • Spustíme,zmáčkneme CleanUp a potvrdíme YES :) Program uklidí a následně restartuje
:arrow: ObrázekT-Cleaner
  • Spustíme,zmáčkneme klávesu A a potvrdíme ENTER(některé antiviry mohou detekovat utilitu jako vir-jedá se o falešný poplach,proto IGNOROVAT nebo dočasně vypnout antivir )
  • po použití T-Cleaner smažte ;-)


:arrow: Obrázek TFC
  • Stáhneme a spustíme program
  • Klikneme na Start a potvrdíme OK
  • Program začne uklízet,poté restartuje pc
  • po použití program smažte

Poté preventivně porozhlédneme po další havěti :)

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:

Údržba PC:

1)Čištění dočasných složek + neplatné registry
:arrow: ObrázekCcleaner
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • ČISTIČ
    Windows zde necháme vše jak je (pokud používáme IE,tak odškrkneme jeho položky) a zaškrkneme položky Start Menu zástupci a Zástupci na ploše
    Aplikace - necháme jak je,ale pokud používáme nějaký prohlížeč (Google chrome,Firefox,Opera..) tak odškrkneme jeho položky
    >Stiskeneme tlačítko Analyzovat a poté Spustit Cleaner
  • Registry
    >Stiskneme tlačítko Hledej problémy,program začne hledat neplatné registry..podé zvolíme Opravit vybrané problémy..
    >Program se zeptá,zda chceme vytvořit zálohu registrů,zvolíme ano a uložíme si někde zálohu(kdyby byli po opravení registru s něčím problémy,tak zálohu obnovíme tak,že spustíme uloženou zálohu a potvrdíme ano),dále zvolíme Opravit všechny problémy a Zavřít
    >opakujte dokud nebude registr bez problémů
  • Program používáme 1x 14dní (záleží na používání pc,můžeme i jednou týdně)
2)Defragmentace disku
:arrow: ObrázekDefraggler
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • Vybereme disk ( C:,D:..prostě který používáme)
  • Pokud je ve sloupci Fragmentace více než 5% dejte Defragmentovat
  • Proveďte se všemi používanými disky
  • Provádíme 1x za měsíc
3)Aktualizace programů
:arrow: ObrázekFileHippo.com Update Checker
  • Stáhneme a nainstalujeme program(Při instalaci odškrkneme volbu Run at Startup )
  • Spustíme program
  • Program vyhledá nainstalované programy v PC a zjistí dostupné aktualizace
  • Poté se vám otevře internetová stránka,kde budou nabídnuté aplikace k aktualizování
    >X Updates Detected..to jsou dostupné aktualizace..
    > klikneme na zelenou šipečku a stáhneme program,poté nainstalujeme jeho aktuální verzi
    > :!: X Beta Updates Detected..tyto aktualizace nestahujte,jedná se o betaverze,které jsou ve vývoji a jsou nestabilní :)
  • Provádíme 1x za 14 dní nebo jednou za měsíc
:arrow: Jak se chová PC :???: + nový RSIT