Stránka 1 z 2

asi ransomware

Napsal: 09 pro 2020 20:56
od jozunost
Zdravím,najednou jsem zjistil že u uložených odkazů které mám na druhém diskovém oddílu z poradny zive.cz se mi u všech těchto odkazů změnily koncovky tak že tam navíc : .url.domn. Nejdou otevřít. Vypadá to na ransomware ale jak my bylo sděleno že přý to nebude ransomware to prý se nezabývá žádnýmy bezcenými url adresami - co si o tom myslíte? Používám jeden z nejkvalitnějších antivirů Bytdefender.Díky všem za doporučení.

Re: asi ransomware

Napsal: 09 pro 2020 21:12
od Diallix
Dobry den.

Ja som napisal testovaci ransomware, ktory menil subory aj inych koncoviek, url nevynimajuc, takze informacie o tom, ze ich nemoze menit su zavadzajuce.


:arrow: Stiahnite si na plochu nastroj AdwCleaner, link. na stiahnutie tu: https://toolslib.net/downloads/finish/1/
Pred spustenim nastroja povypinajte vsetke beziace okna programov, to su vsetke beziace programy pod desktopom.
Kliknite pravym tlacidlom mysi na program -> spustit ako Administrator.
Pokracujte kliknutim na tlacidlo Prehladaj teraz (Scan now) a pockajte, kym sa system doskenuje.
Po skene nechajte oznacene vsetky chlieviky, pripadne najdene hrozieby a pokracujte v dolnom pravom rohu tlacidlom Vycistit Teraz (Clean and Repair).
Po restartovani PC sa spusti nastroj AdwCleaner, kliknite na Zobrazit soubor protokolu.
Spusti sa log, jeho obsah skopirujte sem.

Re: asi ransomware

Napsal: 10 pro 2020 12:42
od jozunost
zdravím můj log nejde odeslat protože obsahuje více znaků než je povoleno- jak mám postupovat-díky za radu.....

Re: asi ransomware

Napsal: 10 pro 2020 18:14
od Diallix
Zkomprimovat do vinraru napr. a nahrat ho do temy.

Re: asi ransomware

Napsal: 11 pro 2020 12:48
od jozunost
posílám požadovaný log který jsdem zkomprimoval:
AdwCleaner[C14].zip
(1.41 KiB) Staženo 54 x

Re: asi ransomware

Napsal: 11 pro 2020 14:03
od Diallix
Preskenujte pocitac s FRST - navod tu: https://forum.viry.cz/viewtopic.php?f=24&t=132509, skopirujte FRST.log + Addition log sem.

Re: asi ransomware

Napsal: 11 pro 2020 16:28
od jozunost
posílám logy z FRST:
1)-
Addition.zip
(16.54 KiB) Staženo 55 x
2-==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: asi ransomware

Napsal: 11 pro 2020 18:12
od Diallix
Poslal ste len Addition. Potrebujem aj FRST :]]

Re: asi ransomware

Napsal: 11 pro 2020 18:12
od Diallix
Poslal ste len Addition. Potrebujem aj FRST :]]

Re: asi ransomware

Napsal: 11 pro 2020 19:06
od jozunost
to tam je taky v originál souboru a není komprimován č.2:
==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: asi ransomware

Napsal: 11 pro 2020 19:26
od jozunost
uděl jsem test znovu a posílám správný
FRST.zip
(18.13 KiB) Staženo 56 x
log z FRST

Re: asi ransomware

Napsal: 12 pro 2020 08:23
od Diallix
Ten log. Chyba polka logu

Re: asi ransomware

Napsal: 12 pro 2020 13:20
od jozunost
FRST.zip
(18.13 KiB) Staženo 54 x
FRST.zip
(18.13 KiB) Staženo 54 x

Re: asi ransomware

Napsal: 12 pro 2020 14:53
od Diallix
Vas FRST log zacina :


FireFox:

Chyba vam cely zaciatok.
Napriklad takyto:

Kód: Vybrat vše

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-12-2020
Ran by Toshiba (administrator) on TOSHIBA-NTB (TOSHIBA SATELLITE C660) (09-12-2020 08:41:33)
Running from C:\Users\Toshiba\Desktop
Loaded Profiles: Toshiba
Platform: Windows 10 Home Version 2004 19041.630 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <5>
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_652655c5335c62da\DSDFunctionKeyCtlService.exe <2>
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_652655c5335c62da\dynabookSystemService.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_652655c5335c62da\RMService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe <27>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\MKCHelper.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2010.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\ProgramData\Wondershare\Service\InstallAssistService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18381792 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1489920 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [117344 2020-11-30] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-2809505068-1317491045-446298891-1001\...\Run: [Google Update] => C:\Users\Toshiba\AppData\Local\Google\Update\1.3.36.52\GoogleUpdateCore.exe [219592 2020-12-04] (Google LLC -> Google LLC)
HKU\S-1-5-21-2809505068-1317491045-446298891-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Toshiba\AppData\Local\Microsoft\Teams\Update.exe [1790192 2019-09-09] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2809505068-1317491045-446298891-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30885360 2020-03-04] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-2809505068-1317491045-446298891-1001\...\Policies\system: [DisableLockWorkstation] 0
HKLM\...\Windows x64\Print Processors\BJ Print Processor4: C:\Windows\System32\spool\prtprocs\x64\CNBPP4.DLL [84992 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\Canon MP520 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD94.DLL [27648 2007-05-22] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\BJ Language Monitor4: C:\WINDOWS\system32\CNBLM4.DLL [267776 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP520 series: C:\WINDOWS\system32\CNMLM94.DLL [258560 2007-05-22] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-08] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0B68C980-1561-4063-8474-584707A8FE64} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4010416 2020-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {11EEA050-2DAC-48B3-A588-CA9C0056449B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4010416 2020-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {163A5E2F-02FC-497D-BBE9-9778B6DB3FBF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1919760 2018-07-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {1E3ABA4E-65F1-456E-B5FC-288FAF1FCBC9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {3DA64527-B57D-4349-AA35-956992C212BD} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116584 2020-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {4CC67B87-C6E6-4993-B466-55B6B2D44E4A} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2558224 2018-07-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {5A4E1B2A-EC60-48D2-B4FE-E2AF133C6C0A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116584 2020-12-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {6143AF6A-432B-4972-89E3-A59AEEFD760C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2809505068-1317491045-446298891-1001UA => C:\Users\Toshiba\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-06-18] (Google Inc -> Google Inc.)
Task: {61602B71-BB32-47A8-8A55-20632C497C71} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-14] (Google Inc -> Google Inc.)
Task: {6418F6FE-AFC5-4CA4-A8FE-D1F9AF98CFA1} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4617832 2020-11-30] (Avast Software s.r.o. -> AVAST Software)
Task: {682CE095-389F-4E9E-AE5A-F78D06E5244C} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [1992936 2018-07-19] (Microsoft Corporation -> Microsoft)
Task: {8B4BEBA8-B776-42DA-86BB-9E09FEA073C1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {97AC12F9-3EEC-472A-AC0B-18BC65265E0F} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40432 2020-03-04] (Garmin International, Inc. -> )
Task: {99107D1E-BADE-48A4-B6EF-B832CA310368} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1741416 2020-09-18] (Avast Software s.r.o. -> Avast Software)
Task: {A1EBB786-140C-43FD-8002-C696A395F18B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2809505068-1317491045-446298891-1001Core => C:\Users\Toshiba\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-06-18] (Google Inc -> Google Inc.)
Task: {A7E32B8C-7E45-4783-9345-BBCB2226443D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {AC26F91C-0630-4D1E-98C2-0D9FA523AD03} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2558224 2018-07-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {B70CB737-37BE-4AAE-BD99-E096666DA78F} - System32\Tasks\Microsoft_MKC_Logon_Task_ceip.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ceip.exe [39664 2018-07-19] (Microsoft Corporation -> Microsoft)
Task: {BA1353BC-B565-47DF-84C8-A582812527D3} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1919760 2018-07-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {C0B9807E-636F-4A9F-9D1C-6A10E2032FA6} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1706496 2020-05-29] () [File not signed]
Task: {DA27C774-6810-42B2-A212-3DEE5936EF84} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [670928 2020-11-20] (Mozilla Corporation -> Mozilla Foundation)
Task: {e2537644-4598-481c-b576-5ab79cfca472} - no filepath
Task: {E51C4865-7DD6-41EA-A505-4296A352F96D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054216 2020-12-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {F47549AF-63ED-402B-AEA8-8CFE16DEE0A0} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_453_Plugin.exe [1502776 2020-11-16] (Adobe Inc. -> Adobe)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{428761a9-0a55-4347-b8b6-407f26bdd7b1}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{b54c79c2-4565-4927-96a5-57c4fa7e211f}: [DhcpNameServer] 192.168.0.1 0.0.0.0

Edge: 
======
Edge Profile: C:\Users\Toshiba\AppData\Local\Microsoft\Edge\User Data\Default [2020-12-07]


Re: asi ransomware

Napsal: 12 pro 2020 15:15
od jozunost
omlouvám se -udělám log znovu a pošlu ho .....