Opět policejní

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Opět policejní

#1 Příspěvek od kviki »

Chytil jsem "policejní" vir

Dávám log z FRST

Nějaká rada co s tím? Někde jsem tady našel radu HitmanPro, což nepomohlo.
Nedostanu se ani do nouz.režimu.

-------------------------------------------------------------------------------

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 01
Ran by pc (administrator) on PC-PC on 10-09-2013 22:24:53
Running from F:\
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2008-08-01] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2010-05-27] (Synaptics Incorporated)
HKLM\...\Run: [EEventManager] - C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe [591696 2008-05-07] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [167936 2008-07-07] (PowerISO Computing, Inc.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [458844 2009-07-21] (IDT, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-08-07] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1564872 2012-06-06] (Ask)
HKLM\...\Run: [MSC] - "C:\Program Files\Microsoft Security Client\Antimalware\mssecex.exe" -hide -runkey <===== ATTENTION (File name is altered)
HKLM\...\Run: [WPCUMI] - C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [EPSON39A4B5] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIENE.EXE /FU "C:\Windows\TEMP\E_S1FA0.tmp" /EF "HKCU"
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-06-02] (Google Inc.)
HKCU\...\Run: [Google Update] - C:\Users\pc\AppData\Local\Google\Update\GoogleUpdate.exe [135664 2009-11-03] (Google Inc.)
HKCU\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-07] ()
HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [960440 2012-08-07] (Samsung)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKCU\...\Run: [DivXNetworks] - C:\Users\pc\AppData\Roaming\hjcuftuf\vaeafjdi.exe [60416 2009-04-11] (The OpenSSL Project, http://www.openssl.org/)
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Run: [CrashReportUpdater] - C:\Windows\Temp\temp68.exe <===== ATTENTION
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\pc\AppData\Roaming\data.dat [199680 2013-07-09] () <==== ATTENTION
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
MountPoints2: D - D:\Setup\rsrc\autorun.exe
MountPoints2: F - F:\AutoRun.exe
MountPoints2: {6e48a3aa-e76d-11e0-a3a1-002186669958} - G:\AutoRun.exe
MountPoints2: {850c9eec-5c90-11de-b2a4-002186669958} - wdsync.exe
MountPoints2: {850c9f1a-5c90-11de-b2a4-002186669958} - setupSNK.exe
MountPoints2: {c906a883-ef2e-11de-9a61-002186669958} - F:\wdsync.exe
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Tatka\...\Run: [PC Suite Tray] - "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
HKU\Tatka\...\Policies\system: [LogonHoursAction] 2
HKU\Tatka\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk
ShortcutTarget: VPN Client.lnk -> C:\Windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico ()
Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
SearchScopes: HKCU - {82814165-738C-4170-A5F5-4F796B5CCB73} URL = http://websearch.ask.com/redirect?clien ... B5B7C188E5
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 22 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Tcpip\..\Interfaces\{B3E93011-7B2F-4501-8A15-15811757BC3C}: [NameServer]192.168.70.11

FireFox:
========
FF ProfilePath: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=en_EU&apn_uid=FAE6A7BE-5672-4133-A93E-C4D7199300BD&apn_ptnrs=U3&apn_sauid=7A1AE376-979F-4584-9B4F-BEB5B7C188E5&apn_dtid=YYYYYYYYCZ&&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=13 - C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll (Google)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/vbp;version=0.9.17 - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.17 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.17 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\pc\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\pc\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\daemon-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: No Name - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\DTToolbar@toolbarnet.com
FF Extension: feedly - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\feedly@devhd
FF Extension: Microsoft .NET Framework Assistant - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Large Thai Script - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\{8DD3BD30-C560-4679-8F5E-E1B1584FA925}
FF Extension: FoxTab - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR RestoreOnStartup: "hxxp://www.seznam.cz/"
CHR DefaultSearchURL: (DAEMON Search) - http://www.daemon-search.com/search?q={searchTerms}
CHR DefaultSuggestURL: (DAEMON Search) - "suggest_url": ""
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\pc\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\pc\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\pc\AppData\Local\Google\Chrome\Application\28.0.1500.95\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.160.1) - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U16) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Updater) - C:\Program Files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Veetle TV Player) - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle Broadcaster Plugin) - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Skype Click to Call) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR StartMenuInternet: Google Chrome - C:\Users\pc\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

S2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [81920 2009-03-02] (Andrea Electronics Corporation)
S2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1524512 2007-07-16] (Cisco Systems, Inc.)
S2 gupdate1c9e33e9cab46c1; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-02] (Google Inc.)
S2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [243056 2007-10-15] ()
S2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\STacSV.exe [221266 2009-07-21] (IDT, Inc.)
S2 MsMpSvc; "C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [x]
S3 NisSrv; "C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [x]
U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\???\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

==================== Drivers (Whitelisted) ====================

R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
S2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306299 2007-07-16] (Cisco Systems, Inc.)
S3 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [127376 2007-01-31] (Deterministic Networks, Inc.)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
S1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165760 2011-10-05] (Microsoft Corporation)
S3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-10-05] (Microsoft Corporation)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-01-22] (Duplex Secure Ltd.)
S2 {95808DC4-FA4A-4C74-92FE-5B863F82066B}; C:\Program Files\CyberLink\PowerDVD\000.fcl [41456 2008-01-30] (Cyberlink Corp.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S1 phindutm; \??\C:\Windows\system32\drivers\phindutm.sys [x]
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-10 21:07 - 2013-09-10 21:07 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-09 22:11 - 2013-09-10 22:19 - 00033047 _____ C:\Windows\WindowsUpdate.log
2013-09-09 21:55 - 2013-09-10 22:18 - 00000004 _____ C:\Users\pc\AppData\Roaming\settings.ini
2013-08-29 08:36 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 18:03 - 2013-08-14 18:05 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 17:52 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 17:52 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 17:52 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 17:52 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 17:52 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 17:52 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 17:52 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 17:52 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 17:52 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 17:52 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 17:52 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-14 17:52 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 17:52 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 17:52 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 17:52 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 17:51 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 17:23 - 2013-07-05 05:20 - 00914880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 17:23 - 2013-07-05 03:43 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2013-08-14 17:23 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-14 17:23 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 17:22 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 17:21 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 17:17 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 17:17 - 2013-07-09 14:10 - 00199680 _____ C:\Users\pc\AppData\Roaming\data.dat
2013-08-14 17:17 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 17:17 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 17:17 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 17:17 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 17:17 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 17:17 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-12 19:54 - 2013-08-12 19:55 - 00017883 _____ C:\Users\pc\Desktop\Tisk_20130812075338.txt
2013-08-12 19:51 - 2013-08-12 19:52 - 00095980 _____ C:\Users\pc\Downloads\MojeBanka.htm
2013-08-12 19:51 - 2013-08-12 19:52 - 00000000 ____D C:\Users\pc\Downloads\MojeBanka_soubory

==================== One Month Modified Files and Folders =======

2013-09-10 22:24 - 2013-09-10 22:24 - 00000000 ____D C:\FRST
2013-09-10 22:24 - 2006-11-02 12:33 - 01539208 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-10 22:19 - 2013-09-09 22:11 - 00033047 _____ C:\Windows\WindowsUpdate.log
2013-09-10 22:19 - 2009-01-19 13:56 - 00002140 _____ C:\Windows\bthservsdp.dat
2013-09-10 22:19 - 2006-11-02 15:01 - 00032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-10 22:19 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-10 22:18 - 2013-09-09 21:55 - 00000004 _____ C:\Users\pc\AppData\Roaming\settings.ini
2013-09-10 22:17 - 2009-06-30 07:11 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-10 22:17 - 2009-06-02 06:56 - 00000972 _____ C:\Windows\Tasks\Google Software Updater.job
2013-09-10 22:17 - 2009-03-12 22:27 - 00243434 _____ C:\ProgramData\nvModes.dat
2013-09-10 22:15 - 2009-03-13 10:31 - 00243434 _____ C:\ProgramData\nvModes.001
2013-09-10 22:15 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 22:15 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 21:39 - 2012-04-14 21:17 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-10 21:30 - 2009-06-30 07:11 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-10 21:21 - 2009-12-31 18:52 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3178253891-3216347629-3950034059-1000UA.job
2013-09-10 21:18 - 2009-01-19 14:04 - 00000680 _____ C:\Users\pc\AppData\Local\d3d9caps.dat
2013-09-10 21:07 - 2013-09-10 21:07 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-09 21:54 - 2009-02-15 23:28 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2013-09-09 21:54 - 2009-02-15 23:27 - 00000000 ____D C:\Program Files\Google
2013-09-09 15:47 - 2012-10-14 09:45 - 00000000 ____D C:\Users\pc\Desktop\Domácí Výdaje
2013-09-08 13:21 - 2009-12-31 18:52 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3178253891-3216347629-3950034059-1000Core.job
2013-09-03 20:36 - 2012-05-29 09:59 - 00000396 ____H C:\Windows\Tasks\Norton Security Scan for pc.job
2013-09-03 20:30 - 2010-04-09 15:05 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-09-03 07:51 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\LogFiles
2013-09-01 13:08 - 2009-01-21 22:10 - 00145920 _____ C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-01 10:47 - 2010-04-02 16:03 - 00000000 ____D C:\ProgramData\AlawarWrapper
2013-08-21 19:39 - 2012-04-14 21:17 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-21 19:39 - 2011-05-19 18:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-18 12:40 - 2009-01-19 14:04 - 00000000 ____D C:\Users\pc
2013-08-14 18:48 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-14 18:33 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-08-14 18:05 - 2013-08-14 18:03 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:03 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-14 18:01 - 2009-01-21 19:48 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-13 14:55 - 2013-08-04 11:11 - 00000000 ____D C:\Users\pc\Desktop\foto taťka
2013-08-12 19:55 - 2013-08-12 19:54 - 00017883 _____ C:\Users\pc\Desktop\Tisk_20130812075338.txt
2013-08-12 19:53 - 2009-01-21 21:01 - 00002675 _____ C:\Users\pc\Desktop\Microsoft Office Word 2007.lnk
2013-08-12 19:52 - 2013-08-12 19:51 - 00095980 _____ C:\Users\pc\Downloads\MojeBanka.htm
2013-08-12 19:52 - 2013-08-12 19:51 - 00000000 ____D C:\Users\pc\Downloads\MojeBanka_soubory

Files to move or delete:
====================
ZeroAccess:
C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
ZeroAccess:
C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
C:\Users\pc\Kies_2.2.0.12014_18_7.exe
C:\Users\pc\seznam-firefox-win32-cs-4.0.0.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Microsoft Security Client\AMEventConsumer_Cleanup.mof => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client


LastRegBack: 2013-09-10 21:13

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Zkousel jste tento HitmanPro with KickStart http://forum.viry.cz/viewtopic.php?f=29&t=132523

:arrow: Je tam hodne nakazy, zkuste prosim Hitmana jak jsem dal odkaz vyse, pres FRST bych se do toho pustil posleze
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#3 Příspěvek od kviki »

Zkoušel, nabootovalo mi to, ale pak to po spuštění psalo selhalo připojení k síti. A našlo 0 věci.
Nevím jak síť nakonfigurovat, když se nedostanu do systému.
A připadalo mi to, že to bez sítě scan neprovádí.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#4 Příspěvek od vyosek »

:arrow: Ano, Hitman potrebuje sit, jelikoz ma databaze na serveru

:arrow: Zkusime to tedy pres FRST, snad se zadari, je to hoooodne zaprasene :boxed:

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
    URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    SearchScopes: HKCU - {82814165-738C-4170-A5F5-4F796B5CCB73} URL = http://websearch.ask.com/redirect?clien ... &src=kw&q={searchTerms}&locale=en_EU&apn_ptnrs=U3&apn_dtid=YYYYYYYYCZ&apn_uid=FAE6A7BE-5672-4133-A93E-C4D7199300BD&apn_sauid=7A1AE376-979F-4584-9B4F-BEB5B7C188E5
    SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
    BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    Toolbar: HKCU -DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    
    FF DefaultSearchEngine: Ask.com
    FF SearchEngineOrder.1: Ask.com
    FF Keyword.URL: hxxp://websearch.ask.com/redirect?clien ... YYYYCZ&&q=
    FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\askcom.xml
    FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\daemon-search.xml
    FF Extension: No Name - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\DTToolbar@toolbarnet.com
    
    CHR DefaultSearchURL: (DAEMON Search) - http://www.daemon-search.com/search?q={searchTerms}
    CHR DefaultSuggestURL: (DAEMON Search) - "suggest_url": ""
    
    U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\???\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
    
    C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
    ZeroAccess:
    C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
    C:\Users\pc\Kies_2.2.0.12014_18_7.exe
    C:\Users\pc\seznam-firefox-win32-cs-4.0.0.exe
    C:\Program Files\Ask.com
    C:\Users\pc\AppData\Roaming\data.dat
    C:\Windows\Temp\temp68.exe
    C:\Program Files\DAEMON Tools Toolbar
    
    DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client
    
    Hosts:
    CMD: shutdown /r /f /t 2
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny log na flashku k FRST
:arrow: Spustte znovu FRST.exe na tom poskozenem PC
  • Kliknete na Fix
  • Probehne oprava a na flash disku se vytvori log Fixlog.txt
:arrow: Pokuste se nastartovat do bezneho rezimu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#5 Příspěvek od kviki »

Tak jsem už v systemu na daném PC. Hláška nevyskakuje. Co dál?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#6 Příspěvek od vyosek »

:arrow: Dejte mi sem fixlog.txt, ktery se vytvoril na flash disku

:arrow: Dame si dalsi skript pro FRST, opet vytvorte fixlist.txt, postup jako minule

Kód: Vybrat vše

Start
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 22 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
CMD: netsh winsock reset

CMD: shutdown /r /f /t 2
End
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#7 Příspěvek od kviki »

Požadovaný log:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-09-2013 01
Ran by pc at 2013-09-10 23:48:44 Run:1
Running from F:\
Boot Mode: Safe Mode (minimal)

==============================================

Content of fixlist:
*****************
Start
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
SearchScopes: HKCU - {82814165-738C-4170-A5F5-4F796B5CCB73} URL = http://websearch.ask.com/redirect?clien ... &src=kw&q={searchTerms}&locale=en_EU&apn_ptnrs=U3&apn_dtid=YYYYYYYYCZ&apn_uid=FAE6A7BE-5672-4133-A93E-C4D7199300BD&apn_sauid=7A1AE376-979F-4584-9B4F-BEB5B7C188E5
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()

FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF Keyword.URL: hxxp://websearch.ask.com/redirect?clien ... YYYYCZ&&q=
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\daemon-search.xml
FF Extension: No Name - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\DTToolbar@toolbarnet.com

CHR DefaultSearchURL: (DAEMON Search) - http://www.daemon-search.com/search?q={searchTerms}
CHR DefaultSuggestURL: (DAEMON Search) - "suggest_url": ""

U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\???\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
ZeroAccess:
C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}
C:\Users\pc\Kies_2.2.0.12014_18_7.exe
C:\Users\pc\seznam-firefox-win32-cs-4.0.0.exe
C:\Program Files\Ask.com
C:\Users\pc\AppData\Roaming\data.dat
C:\Windows\Temp\temp68.exe
C:\Program Files\DAEMON Tools Toolbar

DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client

Hosts:
CMD: shutdown /r /f /t 2
End
*****************

HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} => Value deleted successfully.
HKCR\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} => Key deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{82814165-738C-4170-A5F5-4F796B5CCB73} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{82814165-738C-4170-A5F5-4F796B5CCB73} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully.
HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully.
HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully.
HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully.
HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key not found.
Firefox DefaultSearchEngine deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox Keyword.URL deleted successfully.
C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\askcom.xml => Moved successfully.
C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\searchplugins\daemon-search.xml => Moved successfully.
C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\Extensions\DTToolbar@toolbarnet.com => Moved successfully.
CHR DefaultSearchURL: (DAEMON Search) - http://www.daemon-search.com/search?q={searchTerms} ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSuggestURL: (DAEMON Search) - "suggest_url": "" ==> The Chrome "Settings" can be used to fix the entry.
*etadpug => Service deleted successfully.

"C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}" directory move:

Could not move "C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}" directory. => Scheduled to move on reboot.


"C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}" directory move:

Could not move "C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}" directory. => Scheduled to move on reboot.

C:\Users\pc\Kies_2.2.0.12014_18_7.exe => Moved successfully.
C:\Users\pc\seznam-firefox-win32-cs-4.0.0.exe => Moved successfully.
C:\Program Files\Ask.com => Moved successfully.
C:\Users\pc\AppData\Roaming\data.dat => Moved successfully.
"C:\Windows\Temp\temp68.exe" => File/Directory not found.
C:\Program Files\DAEMON Tools Toolbar => Moved successfully.
"C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking started.
"C:\Program Files\Microsoft Security Client\AMEventConsumer_Cleanup.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\AmMonitoringInstall.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\AMMonitoringProvider.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\AmStatusInstall.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\Antimalware" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\Backup" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\CleanUpPolicy.xml" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\ClientWMIInstall.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\ConfigSecurityPolicy.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\DcmNotifier.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\en-us" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\eppmanifest.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FepUnregister.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallConfigurationNamespace.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallConfigurationProfile.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallConfigurationProvider.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallConfigurationRule.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallConfigurationUninstall.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallStateInstall.mof" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\FirewallStateProvider.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\MpProvider.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\MsMpRes.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\msseces.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\MsseWat.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\setup.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\setupres.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\shellext.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\sqmapi.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client\WindowsFirewallConfigurationProvider.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking completed.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#8 Příspěvek od vyosek »

Fajn, ted udelejte druhy fix a dejte opet log :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#9 Příspěvek od kviki »

Log po provedení scriptu:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-09-2013 01
Ran by pc at 2013-09-11 09:20:05 Run:2
Running from F:\
Boot Mode: Safe Mode (minimal)

==============================================

Content of fixlist:
*****************
Start
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
Winsock: Catalog9 22 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation)
CMD: netsh winsock reset

CMD: shutdown /r /f /t 2
End
*****************

Winsock: Catalog5 entry 000000000002\\LibraryPath was set successfully to %SystemRoot%\system32\napinsp.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 => Key deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000022 => Key deleted successfully.

========= netsh winsock reset =========

Spu�t�n� inicializa�n� funkce InitHelperDll v NSHHTTP.DLL se nezda�ilo s k�dem chyby 10107.

Katalog Winsock byl �sp��n� resetov�n.
K dokon�en� resetov�n� je nutn� restartovat po��ta�.


========= End of CMD: =========


========= shutdown /r /f /t 2 =========


========= End of CMD: =========


==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#10 Příspěvek od vyosek »

Fajn, jdeme dale :James008:

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#11 Příspěvek od kviki »

Rkill nejde spustit ani jednim souborem :-(

Mam zkusit v nouzaku?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#12 Příspěvek od vyosek »

Ano, zkuste nouzovy rezim, pripadne pokracujte ComboFixem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#13 Příspěvek od kviki »

V nouzaku to šlo. Provedeno - log a jdu na CF.
----
Rkill 2.6.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/11/2013 10:28:44 AM in x86 mode. (Safe Mode)
Windows Version: Windows Vista (TM) Home Premium Service Pack 2

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Modified HKCU\...\Winlogon: [Shell] => explorer.exe,C:\Users\pc\AppData\Roaming\data.dat

* ALERT: ZEROACCESS rootkit symptoms found!

* C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ [ZA Dir]
* C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \ [ZA Dir]
* C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\ [ZA Dir]
* C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\ﯹ๛\ [ZA Dir]
* C:\Program Files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ \...\ﯹ๛\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ [ZA Dir]
* C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ [ZA Dir]
* C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\❤≸⋙\ [ZA Dir]
* C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\❤≸⋙\Ⱒ☠⍨\ [ZA Dir]
* C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\ [ZA Dir]
* C:\Users\pc\AppData\Local\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\ [ZA Dir]

* ALERT: ZEROACCESS Reparse Point/Junction found!

* C:\Program Files\Microsoft Security Client\AMEventConsumer_Cleanup.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\AmMonitoringInstall.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\AMMonitoringProvider.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\AmStatusInstall.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\Antimalware => c:\windows\system32\config\ [Dir]
* C:\Program Files\Microsoft Security Client\Backup => c:\windows\system32\config\ [Dir]
* C:\Program Files\Microsoft Security Client\CleanUpPolicy.xml => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\ClientWMIInstall.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\ConfigSecurityPolicy.exe => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\DcmNotifier.exe => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\en-us => c:\windows\system32\config\ [Dir]
* C:\Program Files\Microsoft Security Client\eppmanifest.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FepUnregister.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallConfigurationNamespace.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallConfigurationProfile.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallConfigurationProvider.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallConfigurationRule.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallConfigurationUninstall.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallStateInstall.mof => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\FirewallStateProvider.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\MpProvider.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\MsMpRes.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\msseces.exe => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\MsseWat.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\setup.exe => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\setupres.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\shellext.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\sqmapi.dll => c:\windows\system32\config [File]
* C:\Program Files\Microsoft Security Client\WindowsFirewallConfigurationProvider.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\cs-CZ => c:\windows\system32\config\ [Dir]
* C:\Program Files\Windows Defender\MpAsDesc.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpClient.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpCmdRun.exe => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpEvMsg.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpOAV.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpRtMon.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpRtPlug.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpSigDwn.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpSoftEx.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MpSvc.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MSASCui.exe => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MsMpCom.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MsMpLics.dll => c:\windows\system32\config [File]
* C:\Program Files\Windows Defender\MsMpRes.dll => c:\windows\system32\config [File]

Checking Windows Service Integrity:

* Systém událostí COM+ (EventSystem) is not Running.
Startup Type set to: Automatic

* Windows Update (wuauserv) is not Running.
Startup Type set to: Automatic (Delayed Start)

* Ovladač ověření brány firewall systému Windows (mpsdrv) is not Running.
Startup Type set to: Manual

* BFE [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* PcaSvc [Missing Service]
* PolicyAgent [Missing Service]
* RemoteAccess [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]

* SharedAccess [Missing ImagePath]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 09/11/2013 10:33:45 AM
Execution time: 0 hours(s), 5 minute(s), and 1 seconds(s)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Opět policejní

#14 Příspěvek od vyosek »

OK, pustte tam ComboFix, je to zaliskane jak jetel, od sklepa az na pudu :arcisit:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kviki
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 11 Črv 2007 10:23

Re: Opět policejní

#15 Příspěvek od kviki »

Log z CF:

ComboFix 13-09-10.03 - pc 11.09.2013 11:13:46.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3068.2490 [GMT 2:00]
Spuštěný z: c:\users\pc\Desktop\ComboFix.exe
AV: System Center 2012 Endpoint Protection *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: System Center 2012 Endpoint Protection *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Desktop\Install
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\@
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\GoogleUpdate.exe
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\U\00000001.@
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\U\00000002.@
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\U\80000000.@
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\U\80000001.@
c:\program files\Google\Desktop\Install\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\0103~1\7154~1\CFFE~1\{383a3bb6-7259-b9bc-16a7-8a972f260a94}\U\800000cb.@
c:\users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-11 do 2013-09-11 )))))))))))))))))))))))))))))))
.
.
2013-09-11 09:19 . 2013-09-11 09:19 -------- d-----w- c:\users\pc\AppData\Local\temp
2013-09-11 09:19 . 2013-09-11 09:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-11 08:20 . 2013-09-11 08:20 -------- d-----w- c:\windows\Logs
2013-09-11 05:17 . 2013-09-11 05:17 60872 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DFDAEA27-4840-40F1-8D99-0472F9DF4461}\offreg.dll
2013-09-10 20:24 . 2013-09-11 07:19 -------- d-----w- C:\FRST
2013-09-10 19:07 . 2013-09-10 19:07 -------- d-----w- c:\programdata\HitmanPro
2013-09-08 04:40 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DFDAEA27-4840-40F1-8D99-0472F9DF4461}\mpengine.dll
2013-08-29 06:36 . 2013-08-02 04:09 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-14 16:03 . 2013-08-14 16:05 -------- d-----w- c:\windows\system32\MRT
2013-08-14 15:23 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2013-08-14 15:23 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-14 15:23 . 2013-07-05 03:20 914880 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-14 15:23 . 2013-07-05 01:43 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-08-14 15:22 . 2013-07-17 19:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-14 15:21 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-14 15:17 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-14 15:17 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2013-08-14 15:17 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-14 15:17 . 2013-07-08 04:20 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-08-14 15:17 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-14 15:17 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll
2013-08-14 15:17 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-11 05:17 . 2012-04-14 19:17 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-11 05:17 . 2011-05-19 16:30 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-06 07:28 . 2012-11-26 10:30 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-02 39408]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-08-07 21432]
"KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2012-08-07 960440]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-01-08 3674320]
"DivXNetworks"="c:\users\pc\AppData\Roaming\hjcuftuf\vaeafjdi.exe" [2009-04-11 60416]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-08-07 3524536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
.
c:\users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico -user_logon [2011-2-11 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2008-01-30 17:47 91432 ----a-w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON PX700W Series]
2008-04-07 06:00 188928 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIENE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-11-03 07:16 135664 ----atw- c:\users\pc\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-10-11 11:06 62760 ------w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2012-03-08 16:50 4280184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2008-01-22 13:23 81920 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-06-02 04:56 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [2009-03-02 81920]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 05:17]
.
2013-09-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-15 04:32]
.
2013-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-02 04:57]
.
2013-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-02 04:57]
.
2013-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3178253891-3216347629-3950034059-1000Core.job
- c:\users\pc\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-31 07:16]
.
2013-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3178253891-3216347629-3950034059-1000UA.job
- c:\users\pc\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-31 07:16]
.
2013-09-03 c:\windows\Tasks\Norton Security Scan for pc.job
- c:\progra~1\NORTON~2\Engine\372~1.5\Nss.exe [2012-05-29 01:30]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 93.91.240.101 192.169.1.1
TCP: Interfaces\{B3E93011-7B2F-4501-8A15-15811757BC3C}: NameServer = 192.168.70.11
FF - ProfilePath - c:\users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\t937d1t2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF - Ext: feedly: feedly@devhd - %profile%\extensions\feedly@devhd
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Large Thai Script: {8DD3BD30-C560-4679-8F5E-E1B1584FA925} - %profile%\extensions\{8DD3BD30-C560-4679-8F5E-E1B1584FA925}
FF - Ext: FoxTab: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} - %profile%\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
HKLM-Run-MSC - c:\program files\Microsoft Security Client\Antimalware\mssecex.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-11 11:19
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\users\pc\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD2500BEVS-60UST0 rev.01.01A01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
Binary file temp00 matches
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2013-09-11 11:21:43
ComboFix-quarantined-files.txt 2013-09-11 09:21
.
Před spuštěním: Volných bajtů: 136 820 121 600
Po spuštění: Volných bajtů: 136 409 575 424
.
- - End Of File - - C753590A1B462F00BCA684E53A42E87A
5C616939100B85E558DA92B899A0FC36

Odpovědět