Stránka 1 z 2

Vir na flash disku - duit

Napsal: 14 led 2014 20:34
od duit
Dobrý den,

mám podobný problém. Na všech flaškách a SD kartě se mi objevila složka RECYCLER (která nejde smazat) a 4 odkazy:
Copy of Shortcut to (1)
Copy of Shortcut to (2)
Copy of Shortcut to (3)
Copy of Shortcut to (4)

Zkoušel jsem pomocí Usb fixu udělat diagnostiku:

############################## | UsbFix V 7.134 | [Deletion]

User: Do iT (Administrator) # DOIT-PC
Updated 06/09/2013 by El Desaparecido
Started at 20:23:55 | 14/01/2014

Website: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: eldesaparecido@sosvirus.net

PC: ASUSTeK Computer Inc. (K50IJ ) (X86-based PC)
CPU: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz (2001)
RAM -> [Total : 3037 | Free : 2214]
BIOS: Default System BIOS
BOOT: Normal boot

OS: Microsoft Windows 7 Ultimate (6.1.7600 32-Bit) #
WB: Windows Internet Explorer 8.0.7600.16385

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]

C:\ -> Fixed drive # 100 Mb (65 Mb free - 65%) [System Reserved] # NTFS
D:\ -> CD-ROM
E:\ (%systemdrive%) -> Fixed drive # 237 Gb (210 Mb free - 89%) [] # NTFS
F:\ -> Fixed drive # 229 Gb (6 Mb free - 3%) [Nový svazek] # NTFS
G:\ -> CD-ROM
H:\ -> Removable drive # 15 Gb (4 Mb free - 27%) [Kingston] # FAT32
I:\ -> Removable drive # 30 Gb (25 Mb free - 86%) [ADATA UFD] # FAT32
J:\ -> CD-ROM
M:\ -> Removable drive # 4 Gb (4 Mb free - 98%) [] # NTFS

################## | El Desaparecido Section |

HKLM\SOFTWARE | Run : [VirtualCloneDrive] - "E:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
HKLM\SOFTWARE | Run : [GrooveMonitor] - "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-21-610502017-2096169772-619058726-1000\SOFTWARE | Run : [QIP Internet Guardian] - E:\Users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe /p
HKU\S-1-5-21-610502017-2096169772-619058726-1000\SOFTWARE | Run : [RESTART_STICKY_NOTES] - E:\Windows\System32\StikyNot.exe
HKU\S-1-5-21-610502017-2096169772-619058726-1000\SOFTWARE | Run : [Skype] - "E:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-610502017-2096169772-619058726-1000\SOFTWARE | Run : [Infium] - "E:\Program Files\QIP 2012\qip.exe" /autorun

################## | Stopped processes |

Stopped! E:\Windows\System32\spoolsv.exe (1452)
Stopped! E:\Windows\Explorer.EXE (1492)
Stopped! E:\Windows\system32\taskhost.exe (1608)
Stopped! E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1708)
Stopped! E:\Windows\system32\HPSIsvc.exe (1752)
Stopped! E:\Program Files\Skype\Updater\Updater.exe (1888)
Stopped! E:\Windows\system32\taskeng.exe (2020)
Stopped! E:\Program Files\Google\Update\GoogleUpdate.exe (448)
Stopped! E:\Windows\system32\WUDFHost.exe (2108)
Stopped! E:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (2316)
Stopped! E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2328)
Stopped! E:\Users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe (2352)
Stopped! E:\Windows\System32\StikyNot.exe (2360)
Stopped! E:\Program Files\Skype\Phone\Skype.exe (2400)
Stopped! E:\Program Files\QIP 2012\qip.exe (2424)
Stopped! E:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (2456)
Stopped! E:\Program Files\Internet Explorer\iexplore.exe (2520)
Stopped! E:\Program Files\Internet Explorer\iexplore.exe (2540)
Stopped! E:\Windows\system32\SearchIndexer.exe (3008)
Stopped! E:\Program Files\Windows Media Player\wmpnetwk.exe (3788)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_Multiple&Prod_Card__Reader&Rev_1.00#058F63666433&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-3-3-48-2818058043-4273111735-006450761-8482\nyAmMkah.exe (3892)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_Multiple&Prod_Card__Reader&Rev_1.00#058F63666433&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-3-3-48-2818058043-4273111735-006450761-8482\JZJEwHbO.exe (3352)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_Multiple&Prod_Card__Reader&Rev_1.00#058F63666433&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-3-3-48-2818058043-4273111735-006450761-8482\JZJEwHbO.exe (4040)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_Multiple&Prod_Card__Reader&Rev_1.00#058F63666433&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-3-3-48-2818058043-4273111735-006450761-8482\JZJEwHbO.exe (4060)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_Multiple&Prod_Card__Reader&Rev_1.00#058F63666433&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-3-3-48-2818058043-4273111735-006450761-8482\VbIsoWGu.exe (916)
Stopped! \\.\STORAGE#Volume#_??_USBSTOR#Disk&Ven_FLASH&Prod_Drive_SM_USB20&Rev_1100#AA04012700017955&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\RECYCLER\S-8-7-16-6876424047-2823876534-814630025-8758\GbsMEVDO.exe (1016)

################## | Files # Infected Folders |

Deleted ! H:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482\kkohNXnN.cpl
Deleted ! H:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482
Deleted ! I:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482\exoOCbKV.cpl
Deleted ! I:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482
Deleted ! M:\Recycler\S-0-3-16-5231073347-1448215155-156132803-8810\AFaSDAKK.cpl
Deleted ! M:\Recycler\S-0-3-16-5231073347-1448215155-156132803-8810
Deleted ! M:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482\BvpAeJhq.cpl
Deleted ! M:\Recycler\S-3-3-48-2818058043-4273111735-006450761-8482
Deleted ! M:\Recycler\S-8-7-16-6876424047-2823876534-814630025-8758\AFTFfQXL.cpl
Deleted ! M:\Recycler\S-8-7-16-6876424047-2823876534-814630025-8758
Deleted ! H:\Copy of Shortcut to (1).lnk
Deleted ! H:\Copy of Shortcut to (2).lnk
Deleted ! H:\Copy of Shortcut to (3).lnk
Deleted ! H:\Copy of Shortcut to (4).lnk
Deleted ! I:\Copy of Shortcut to (1).lnk
Deleted ! I:\Copy of Shortcut to (2).lnk
Deleted ! I:\Copy of Shortcut to (3).lnk
Deleted ! I:\Copy of Shortcut to (4).lnk
Not deleted ! J:\Autorun.inf
Deleted ! M:\autorun.inf
Deleted ! M:\Copy of Shortcut to (1).lnk
Deleted ! M:\Copy of Shortcut to (2).lnk
Deleted ! M:\Copy of Shortcut to (3).lnk
Deleted ! M:\Copy of Shortcut to (4).lnk

(!) Temporary files deleted.

################## | Registry |


################## | Mountpoints2 |


################## | Listing |

[25/11/2013 - 17:57:16 | D ] C:\$RECYCLE.BIN
[25/11/2013 - 16:56:50 | N | 0] C:\AUTOEXEC.BAT
[14/01/2014 - 20:16:40 | RASHD ] C:\Autorun.inf
[25/11/2013 - 17:45:59 | D ] C:\Boot
[25/11/2013 - 16:45:30 | N | 211] C:\Boot.BAK
[25/11/2013 - 17:45:59 | N | 355] C:\Boot.ini.saved
[25/10/2001 - 15:00:00 | N | 4952] C:\Bootfont.bin
[14/07/2009 - 02:38:58 | RASH | 383562] C:\bootmgr
[25/11/2013 - 17:46:00 | N | 8192] C:\BOOTSECT.BAK
[25/11/2013 - 16:56:50 | N | 0] C:\CONFIG.SYS
[25/11/2013 - 17:55:23 | N | 203464] C:\grldr
[04/10/2013 - 17:41:07 | N | 171136] C:\grldr.bak
[25/11/2013 - 16:56:50 | N | 0] C:\IO.SYS
[25/11/2013 - 16:56:50 | N | 0] C:\MSDOS.SYS
[13/04/2008 - 21:13:04 | N | 47564] C:\NTDETECT.COM
[13/04/2008 - 23:01:48 | N | 250576] C:\ntldr
[25/11/2013 - 17:00:55 | SHD ] C:\System Volume Information
[25/11/2013 - 17:55:25 | N | 12] C:\win7.ld
[14/01/2014 - 18:33:53 | SHD ] E:\$RECYCLE.BIN
[10/06/2009 - 22:42:20 | N | 24] E:\autoexec.bat
[14/01/2014 - 20:16:40 | RASHD ] E:\Autorun.inf
[14/01/2014 - 18:56:33 | N | 3280] E:\bootsqm.dat
[14/01/2014 - 18:34:34 | N | 5953] E:\ComboFix.txt
[10/06/2009 - 22:42:20 | N | 10] E:\config.sys
[14/01/2014 - 18:22:08 | D ] E:\dc
[14/07/2009 - 05:53:55 | SHD ] E:\Documents and Settings
[14/01/2014 - 20:22:15 | ASH | 2388463616] E:\hiberfil.sys
[25/11/2013 - 18:04:48 | D ] E:\ICQ
[25/11/2013 - 18:03:32 | RD ] E:\MSOCache
[14/01/2014 - 20:22:16 | ASH | 3184619520] E:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] E:\PerfLogs
[14/01/2014 - 18:23:27 | D ] E:\Program Files
[14/01/2014 - 16:48:41 | D ] E:\ProgramData
[14/01/2014 - 18:34:37 | D ] E:\Qoobox
[25/11/2013 - 17:55:14 | D ] E:\Recovery
[14/01/2014 - 18:10:47 | SHD ] E:\System Volume Information
[06/01/2014 - 16:44:36 | D ] E:\tapeta
[14/01/2014 - 20:25:20 | D ] E:\UsbFix
[14/01/2014 - 20:16:57 | N | 12581] E:\UsbFix [Clean 1] DOIT-PC.txt
[14/01/2014 - 20:25:40 | A | 8413] E:\UsbFix [Clean 2] DOIT-PC.txt
[25/11/2013 - 17:56:47 | D ] E:\Users
[14/01/2014 - 18:34:36 | D ] E:\Windows
[25/11/2013 - 17:57:16 | D ] F:\$RECYCLE.BIN
[14/01/2014 - 20:16:40 | RASHD ] F:\Autorun.inf
[28/10/2009 - 12:22:27 | D ] F:\dc
[09/06/2013 - 21:34:55 | D ] F:\moje
[25/11/2013 - 16:48:54 | SHD ] F:\System Volume Information
[29/06/2013 - 11:50:06 | D ] H:\Spongebob
[31/10/2013 - 18:10:10 | D ] H:\S05
[31/10/2013 - 18:12:38 | D ] H:\S06
[31/10/2013 - 18:01:46 | D ] H:\S01
[31/10/2013 - 18:03:22 | D ] H:\S02
[31/10/2013 - 18:05:20 | D ] H:\S03
[31/10/2013 - 18:07:22 | D ] H:\S04
[14/01/2014 - 20:16:42 | D ] H:\Autorun.inf
[14/01/2014 - 20:22:24 | D ] H:\RECYCLER
[06/01/2014 - 16:57:18 | D ] I:\Okresni prebor
[06/08/2010 - 09:01:56 | N | 366358528] I:\S06E12 Everybody Loves Hugo.avi
[29/08/2010 - 13:01:38 | N | 40202] I:\S06E12 Everybody Loves Hugo.srt
[12/01/2014 - 14:52:42 | N | 367411578] I:\Lost.S06E11.Happily-Ever-After.HDTV.XviD-NoTV.avi
[12/01/2014 - 15:05:32 | N | 39630] I:\Lost-s06e11---Happily-Ever-After.srt
[14/01/2014 - 20:16:42 | D ] I:\Autorun.inf
[14/01/2014 - 20:22:26 | D ] I:\RECYCLER
[19/10/2010 - 10:49:04 | R | 58] J:\Autorun.inf
[28/11/2012 - 21:37:40 | D ] J:\document
[28/11/2012 - 21:37:17 | D ] J:\drivers
[19/10/2010 - 10:49:04 | R | 4286] J:\Mobile Partner.ico
[14/01/2014 - 20:25:12 | D ] M:\RECYCLER

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
M:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F | http://www.sosvirus.net |



Chtěl jsem Vás poprosit o pomoc.

Předem děkuji.

Re: Vir na flash disku - duit

Napsal: 14 led 2014 20:37
od vyosek
Zdravim :)

:arrow: Prispevek jsem Vam oddelil do samostatneho tematu, do cizich se nevstupuje

:arrow: Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=130786

Re: Vir na flash disku - duit

Napsal: 14 led 2014 20:48
od duit
Omlouvám se za vstup do cizího tématu.


log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Do iT at 2014-01-14 20:45:55
Microsoft Windows 7 Ultimate
System drive E: has 215 GB (89%) free of 243 GB
Total RAM: 3037 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:46:00, on 14.1.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
E:\Windows\system32\Dwm.exe
E:\Windows\System32\rundll32.exe
E:\Windows\Explorer.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Skype\Phone\Skype.exe
E:\Windows\system32\SearchFilterHost.exe
E:\Users\Do iT\Desktop\RSIT.exe
E:\Program Files\trend micro\Do iT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "E:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [QIP Internet Guardian] E:\Users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] E:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Skype] "E:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Infium] "E:\Program Files\QIP 2012\qip.exe" /autorun
O4 - Startup: ftvbpxtt.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = E:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP SI Service (HPSIService) - HP - E:\Windows\system32\HPSIsvc.exe
O23 - Service: QipGuard - QIP.ru - E:\Program Files\QipGuard\QipGuard.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4300 bytes

======Scheduled tasks folder======

E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
E:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - E:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-18 194128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - E:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll [2013-11-25 1001936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-18 194128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"=E:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]
"GrooveMonitor"=E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe ARM"=E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"QIP Internet Guardian"=E:\Users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe [2013-05-02 430656]
"RESTART_STICKY_NOTES"=E:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"Skype"=E:\Program Files\Skype\Phone\Skype.exe [2013-11-14 20584608]
"Infium"=E:\Program Files\QIP 2012\qip.exe [2013-01-10 8378408]

E:\Users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ftvbpxtt.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - E:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=E:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=E:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - E:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-01-14 20:45:56 ----D---- E:\Program Files\trend micro
2014-01-14 20:45:55 ----D---- E:\rsit
2014-01-14 20:25:40 ----RASHD---- E:\Autorun.inf
2014-01-14 20:23:55 ----A---- E:\UsbFix [Clean 2] DOIT-PC.txt
2014-01-14 20:13:00 ----N---- E:\UsbFix [Clean 1] DOIT-PC.txt
2014-01-14 20:12:53 ----D---- E:\UsbFix
2014-01-14 18:56:33 ----N---- E:\bootsqm.dat
2014-01-14 18:34:36 ----D---- E:\Windows\temp
2014-01-14 18:34:34 ----N---- E:\ComboFix.txt
2014-01-14 18:33:53 ----SHD---- E:\$RECYCLE.BIN
2014-01-14 18:10:03 ----A---- E:\Windows\zip.exe
2014-01-14 18:10:03 ----A---- E:\Windows\SWSC.exe
2014-01-14 18:10:03 ----A---- E:\Windows\SWREG.exe
2014-01-14 18:10:03 ----A---- E:\Windows\sed.exe
2014-01-14 18:10:03 ----A---- E:\Windows\PEV.exe
2014-01-14 18:10:03 ----A---- E:\Windows\NIRCMD.exe
2014-01-14 18:10:03 ----A---- E:\Windows\MBR.exe
2014-01-14 18:10:03 ----A---- E:\Windows\grep.exe
2014-01-14 18:09:50 ----D---- E:\Qoobox
2014-01-14 18:09:30 ----D---- E:\Windows\erdnt
2014-01-14 16:48:47 ----D---- E:\Users\Do iT\AppData\Roaming\Malwarebytes
2014-01-14 16:48:41 ----D---- E:\ProgramData\Malwarebytes
2014-01-14 15:54:11 ----D---- E:\Program Files\Pendrive Virus Remover
2014-01-14 15:17:53 ----D---- E:\ProgramData\Spybot - Search & Destroy
2014-01-14 15:17:46 ----D---- E:\Program Files\Spybot - Search & Destroy 2
2014-01-13 17:56:19 ----D---- E:\Users\Do iT\AppData\Roaming\Audacity
2014-01-13 17:56:04 ----D---- E:\Program Files\Audacity
2014-01-13 17:55:13 ----D---- E:\Users\Do iT\AppData\Roaming\rmi
2013-12-25 15:05:02 ----D---- E:\Users\Do iT\AppData\Roaming\Google
2013-12-22 09:22:07 ----D---- E:\Users\Do iT\AppData\Roaming\Skype
2013-12-22 09:21:58 ----RD---- E:\Program Files\Skype
2013-12-22 09:21:58 ----D---- E:\Program Files\Common Files\Skype
2013-12-22 09:21:46 ----D---- E:\ProgramData\Skype
2013-12-16 17:27:32 ----D---- E:\tapeta

======List of files/folders modified in the last 1 month======

2014-01-14 20:45:56 ----D---- E:\Program Files
2014-01-14 20:42:11 ----D---- E:\Windows\system32\Tasks
2014-01-14 18:34:36 ----D---- E:\Windows
2014-01-14 18:33:20 ----A---- E:\Windows\system.ini
2014-01-14 18:31:05 ----D---- E:\Windows\system32\drivers
2014-01-14 18:31:05 ----D---- E:\Windows\System32
2014-01-14 18:31:05 ----D---- E:\Windows\AppPatch
2014-01-14 18:31:04 ----D---- E:\Program Files\Common Files
2014-01-14 18:22:39 ----D---- E:\Windows\inf
2014-01-14 18:22:08 ----D---- E:\Windows\security
2014-01-14 18:22:08 ----D---- E:\dc
2014-01-14 18:18:44 ----D---- E:\Windows\system32\drivers\etc
2014-01-14 18:10:47 ----SHD---- E:\System Volume Information
2014-01-14 18:04:53 ----A---- E:\Windows\system32\PerfStringBackup.INI
2014-01-14 17:52:45 ----D---- E:\Users\Do iT\AppData\Roaming\vlc
2014-01-14 16:59:05 ----SD---- E:\ProgramData\Microsoft
2014-01-14 16:48:41 ----D---- E:\ProgramData
2014-01-14 15:32:29 ----SD---- E:\Users\Do iT\AppData\Roaming\Microsoft
2014-01-14 15:26:49 ----D---- E:\Windows\Panther
2014-01-14 15:26:49 ----D---- E:\Windows\Minidump
2014-01-14 15:26:49 ----D---- E:\Windows\debug
2014-01-13 17:55:58 ----D---- E:\Windows\Prefetch
2014-01-12 18:53:52 ----D---- E:\Windows\system32\config
2013-12-22 09:22:08 ----SHD---- E:\Windows\Installer
2013-12-18 20:36:32 ----D---- E:\Windows\system32\catroot2

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; E:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; E:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; E:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ElbyCDIO;ElbyCDIO Driver; E:\Windows\System32\Drivers\ElbyCDIO.sys [2013-03-04 30616]
R1 vwififlt;Virtual WiFi Filter Driver; E:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; E:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 igfx;igfx; E:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); E:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-13 47104]
R3 VClone;VClone; E:\Windows\system32\DRIVERS\VClone.sys [2013-07-24 29696]
S2 Parvdm;Parvdm; E:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; E:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; E:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; E:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; E:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\E:\Users\DOIT~1\AppData\Local\Temp\catchme.sys []
S3 mvusbews;USB EWS Device; E:\Windows\System32\Drivers\mvusbews.sys [2012-08-21 17408]
S3 RDPDR;Terminal Server Device Redirector Driver; E:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; E:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; E:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; E:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; E:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; E:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; E:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; E:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; E:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; E:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 HPSIService;HP SI Service; E:\Windows\system32\HPSIsvc.exe [2012-08-31 100256]
S2 AdobeARMservice;Adobe Acrobat Update Service; E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-09-05 65640]
S2 gupdate;Služba Google Update (gupdate); E:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-25 116648]
S2 QipGuard;QipGuard; E:\Program Files\QipGuard\QipGuard.exe [2013-05-02 430656]
S2 SkypeUpdate;Skype Updater; E:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AppMgmt;@appmgmts.dll,-3250; E:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); E:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-25 116648]
S3 gusvc;Google Software Updater; E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-11-25 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; E:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; E:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; E:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; E:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; E:\Windows\System32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------

Re: Vir na flash disku - duit

Napsal: 14 led 2014 20:49
od vyosek
:arrow: Jen se zeptam pouzivate legalni operacni system, nejvyssi licence Ultimate zrovna neni bezna doamci verze :?:

Re: Vir na flash disku - duit

Napsal: 14 led 2014 20:53
od duit
Ano,

na VŠ běžel projekt, kde byla možnost legálně obstarat ws.

Re: Vir na flash disku - duit

Napsal: 14 led 2014 20:54
od vyosek
:arrow:Co se tyce ComboFixu, ktery jste pouzil, tak na zaklade licence a pravidel fora ptam, umite s nim pracovat (spusteni, rozlusteni logu, napsani skriptu)?

:arrow: Licencni podminky ComboFixu hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"
Obrázek

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal

Re: Vir na flash disku - duit

Napsal: 14 led 2014 21:02
od duit
Jsem plně seznámen s nebezpečím používáním CF, nicméně rád bych se zbavil mého problému.

Spustit CF a rozluštit kód by snad neměl být problém, spíš bych viděl problém v napsání skriptu...

Re: Vir na flash disku - duit

Napsal: 14 led 2014 21:05
od vyosek
:arrow: Takze jej pouzivate svevolne bez doporuceni zkusene osoby = poruseni podminek. Jelikoz zkusena osoba umi nejen rozlustit log, ale i napsat skript

:arrow: Ale nechapu, ze kdyz umite rozlustit log = vim co je spatne, tak uz snad si najdu prikazy abych to opravil ne :?:

:arrow: Jak Vas mam zbavit problemu, dkyz mi pomazete stopy :?:

:arrow: Dejte sem log z CF a upozornuji, ze pri pristim svevolnem pouziti Cf muze byt pomoc odmitnuta

Re: Vir na flash disku - duit

Napsal: 14 led 2014 21:17
od duit
zde:

ComboFix 14-01-13.01 - Do iT 14.01.2014 21:08:29.3.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3037.1696 [GMT 1:00]
Spuštěný z: e:\users\Do iT\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-14 do 2014-01-14 )))))))))))))))))))))))))))))))
.
.
2014-01-14 20:13 . 2014-01-14 20:13 -------- d-----w- e:\users\Default\AppData\Local\temp
2014-01-14 19:45 . 2014-01-14 19:46 -------- d-----w- e:\program files\trend micro
2014-01-14 19:45 . 2014-01-14 19:46 -------- d-----w- E:\rsit
2014-01-14 19:12 . 2014-01-14 19:25 -------- d-----w- E:\UsbFix
2014-01-14 14:17 . 2014-01-14 15:59 -------- d-----w- e:\programdata\Spybot - Search & Destroy
2014-01-14 14:17 . 2014-01-14 17:22 -------- d-----w- e:\program files\Spybot - Search & Destroy 2
2014-01-13 16:56 . 2014-01-13 17:07 -------- d-----w- e:\users\Do iT\AppData\Roaming\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\program files\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\users\Do iT\AppData\Local\Programs
2014-01-13 16:55 . 2014-01-13 16:55 -------- d-----w- e:\users\Do iT\AppData\Roaming\rmi
2014-01-13 16:00 . 2014-01-14 17:28 108544 --s---w- e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ftvbpxtt.exe
2013-12-22 08:22 . 2014-01-14 19:41 -------- d-----w- e:\users\Do iT\AppData\Roaming\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----w- e:\program files\Common Files\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----r- e:\program files\Skype
2013-12-22 08:21 . 2013-12-22 08:22 -------- d-----w- e:\programdata\Skype
2013-12-16 16:27 . 2014-01-06 15:44 -------- d-----w- E:\tapeta
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-25 17:27 . 2013-11-25 17:27 119808 ----a-r- e:\users\Do iT\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2013-11-18 00:28 . 2013-11-25 17:15 7772552 ----a-w- e:\programdata\Microsoft\Windows Defender\Definition Updates\{92829D96-68DD-41B5-92B5-7A5F2A843F1B}\mpengine.dll
2013-11-11 04:50 . 2013-11-25 17:14 230048 ------w- e:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP Internet Guardian"="e:\users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe" [2013-05-02 430656]
"RESTART_STICKY_NOTES"="e:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"Skype"="e:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"Infium"="e:\program files\QIP 2012\qip.exe" [2013-01-10 8378408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="e:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2013-03-10 88984]
"GrooveMonitor"="e:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ftvbpxtt.exe [2014-1-14 108544]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - e:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
R2 QipGuard;QipGuard;e:\program files\QipGuard\QipGuard.exe [2013-05-02 430656]
R2 SkypeUpdate;Skype Updater;e:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 mvusbews;USB EWS Device;e:\windows\system32\Drivers\mvusbews.sys [2012-08-21 17408]
S2 HPSIService;HP SI Service;e:\windows\system32\HPSIsvc.exe [2012-08-31 100256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 11:12 1210320 ----a-w- e:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-14 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2013-11-25 17:00]
.
2014-01-14 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2013-11-25 17:00]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-RunOnce-<NO NAME> - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4040)
e:\windows\System32\ieframe.dll
e:\program files\Microsoft Office\Office12\1029\GrooveIntlResource.dll
e:\windows\system32\wpdshext.dll
.
Celkový čas: 2014-01-14 21:14:30
ComboFix-quarantined-files.txt 2014-01-14 20:14
ComboFix2.txt 2014-01-14 17:34
ComboFix3.txt 2014-01-14 17:20
.
Před spuštěním: Volných bajtů: 225 717 354 496
Po spuštění: Volných bajtů: 225 438 846 976
.
- - End Of File - - 8D89BF508E3094014B250009D5924A86
A36C5E4F47E84449FF07ED3517B43A31

Re: Vir na flash disku - duit

Napsal: 14 led 2014 21:41
od vyosek
Proc jste ten ComboFix spoustel dneska 3x :???:

Re: Vir na flash disku - duit

Napsal: 14 led 2014 21:53
od duit
Mel jsem doma kamarada "experta", ktery tvrdil ze vi co dela... Jak vidite, tak nevedel aproto jsem vecer zkusil toto forum.

Re: Vir na flash disku - duit

Napsal: 14 led 2014 22:18
od vyosek
:arrow: Experta s prominutim nakopat vite kam. Navic vy jste psal ze s CF umite, proc jste mu nerekl co zpusobuje opakovane spusteni CF :?:

:arrow: Najdete tento soubor c:\windows\system32\cmd.exe, kliknete na nej pravym mysidlem a dejte Run As Administrator ci Spustit jako spravce, pak napiste CACLS "C:\Qoobox\BackEnv" /T /E /G Everyone:F - enter

:arrow: Zabalte mi obsah slozky c:\qoobox a uploadnete na LP http://leteckaposta.cz/

Re: Vir na flash disku - duit

Napsal: 15 led 2014 15:37
od duit
Dobrý den,

omlouvám se, že píši až teď. dřív jsem nemohl.

Zde je link na LP, kde najdete zabalenou složku Qoobox:

http://leteckaposta.cz/169295939

Re: Vir na flash disku - duit

Napsal: 15 led 2014 16:28
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    e:\windows\system32\drivers\ltcpvba.sys
    e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ftvbpxtt.exe
    
    Rootkit::
    e:\windows\system32\drivers\ltcpvba.sys
    
    Folder::
    e:\program files\Pendrive Virus Remover
    e:\programdata\Spybot - Search & Destroy
    e:\program files\Spybot - Search & Destroy 2
    e:\users\Do iT\AppData\Roaming\QipGuard
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QIP Internet Guardian"=-
    "Skype"=-
    "Infium"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "VirtualCloneDrive"=-
    "GrooveMonitor"=-
    "Adobe ARM"=-
    "AutorunRemover.exe"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes Anti-Malware (cleanup)"=-
    
    Driver::
    QipGuard
    
    File::
    e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    DDS::
    uDefault_Search_URL = hxxp://search.qip.ru
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Vir na flash disku - duit

Napsal: 15 led 2014 16:52
od duit
zde je log:



ComboFix 14-01-13.01 - Do iT 15.01.2014 16:37:42.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3037.1459 [GMT 1:00]
Spuštěný z: e:\users\Do iT\Desktop\ComboFix.exe
Použité ovládací přepínače :: e:\users\Do iT\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"e:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"e:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
file zipped: e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ftvbpxtt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
e:\program files\Pendrive Virus Remover
e:\program files\Pendrive Virus Remover\asycfilt.dll
e:\program files\Spybot - Search & Destroy 2
e:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe.log
e:\programdata\Spybot - Search & Destroy
e:\programdata\Spybot - Search & Destroy\ClientCount.bin
e:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
e:\programdata\Spybot - Search & Destroy\Logs\Checks.140114-1519.txt
e:\programdata\Spybot - Search & Destroy\Logs\Checks.140114-1532.txt
e:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
e:\programdata\Spybot - Search & Destroy\Logs\Updates.log
e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ftvbpxtt.exe
e:\users\Do iT\AppData\Roaming\QipGuard
e:\users\Do iT\AppData\Roaming\QipGuard\cache
e:\users\Do iT\AppData\Roaming\QipGuard\chrome.dll
e:\users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe
e:\users\Do iT\AppData\Roaming\QipGuard\sqlite3.dll
e:\users\Do iT\AppData\Roaming\QipGuard\updater.exe
e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_QipGuard
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-15 do 2014-01-15 )))))))))))))))))))))))))))))))
.
.
2014-01-15 15:44 . 2014-01-15 15:44 -------- d-----w- e:\users\Default\AppData\Local\temp
2014-01-14 19:45 . 2014-01-14 19:46 -------- d-----w- e:\program files\trend micro
2014-01-14 19:45 . 2014-01-14 19:46 -------- d-----w- E:\rsit
2014-01-14 19:12 . 2014-01-14 19:25 -------- d-----w- E:\UsbFix
2014-01-14 15:48 . 2014-01-14 15:48 -------- d-----w- e:\users\Do iT\AppData\Roaming\Malwarebytes
2014-01-14 15:48 . 2014-01-14 15:48 -------- d-----w- e:\programdata\Malwarebytes
2014-01-13 16:56 . 2014-01-13 17:07 -------- d-----w- e:\users\Do iT\AppData\Roaming\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\program files\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\users\Do iT\AppData\Local\Programs
2014-01-13 16:55 . 2014-01-13 16:55 -------- d-----w- e:\users\Do iT\AppData\Roaming\rmi
2013-12-22 08:22 . 2014-01-15 15:45 -------- d-----w- e:\users\Do iT\AppData\Roaming\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----w- e:\program files\Common Files\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----r- e:\program files\Skype
2013-12-22 08:21 . 2013-12-22 08:22 -------- d-----w- e:\programdata\Skype
2013-12-16 16:27 . 2014-01-06 15:44 -------- d-----w- E:\tapeta
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-25 17:27 . 2013-11-25 17:27 119808 ----a-r- e:\users\Do iT\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2013-11-18 00:28 . 2013-11-25 17:15 7772552 ----a-w- e:\programdata\Microsoft\Windows Defender\Definition Updates\{92829D96-68DD-41B5-92B5-7A5F2A843F1B}\mpengine.dll
2013-11-11 04:50 . 2013-11-25 17:14 230048 ------w- e:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"="e:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - e:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
R2 SkypeUpdate;Skype Updater;e:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 CFcatchme;CFcatchme;e:\users\DOIT~1\AppData\Local\Temp\CFcatchme.sys [x]
R3 mvusbews;USB EWS Device;e:\windows\system32\Drivers\mvusbews.sys [2012-08-21 17408]
S2 HPSIService;HP SI Service;e:\windows\system32\HPSIsvc.exe [2012-08-31 100256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 11:12 1210320 ----a-w- e:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-QipGuard - e:\users\Do iT\AppData\Roaming\QipGuard\QipGuard.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
e:\windows\system32\taskhost.exe
e:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
e:\program files\Google\Update\GoogleUpdate.exe
e:\windows\system32\WUDFHost.exe
e:\windows\system32\conhost.exe
e:\windows\system32\sppsvc.exe
e:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2014-01-15 16:50:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-15 15:50
ComboFix2.txt 2014-01-14 20:14
ComboFix3.txt 2014-01-14 17:34
ComboFix4.txt 2014-01-14 17:20
.
Před spuštěním: Volných bajtů: 225 428 070 400
Po spuštění: Volných bajtů: 225 285 677 056
.
- - End Of File - - 5508DD9C00233720AF44996B60C9D166
A36C5E4F47E84449FF07ED3517B43A31