![]() |
| |||||||
| Registrovať | Site Spy | Zoznam členov | Darovanie | Hľadať | Dnešné príspevky | Označiť témy ako prečítané | Pravidlá fóra |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Bol som napadnutý akúsi Spyware / Adware, som po niekoľkých nití tu uverejnených, ktoré mali podobnú vec, ale bezvýsledne. Adware: Changed my desktop s poselstvi príslovie "Spyware hrozba bola zistená, kliknite sem bežať na plný scan", tiež ju neustále vyskakovanie s bublinou v rohu mi povedať samé. Snažil som sa stiahnuť a spustiť veľa programov: SmitFraudFix ComboFix ATF-Cleaner CCleaner SpyBotSearch & Destroy Ale nikto z nich sa zdá, že majú pevné nič ... prosím pomôžte! ![]() Ja som pripojený veľa najnovších protokolov. Zelený |
|
#2
| |||
| |||
| Vitajte na CJ Greenhorn ![]() Odstrániť tieto súbory / adresáre, takto: 1. Prejsť na Začať > Plynúť > Typ Notepad.exe a kliknite OK otvorte Poznámkový blok. To musieť potrebné Poznámkový blok, WordPad nie.
Kód: Killall:: Folder:: C: \ WINDOWS \ FLEOK File:: C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ system32 \ wmsdkns.exe 4. Potom kliknite na Súbor > Uložiť 5. Názov súboru CFScript.txt - Uložte súbor do počítača 6. Potom presunieme CFScript (držte ľavé tlačidlo myši a zároveň pretiahnutím súboru) a pusť ju (uvoľnite ľavé tlačidlo myši) do ComboFix.exe, ako vidíte na obrázku nižšie. Dôležité upozornenie: Vykoná pokyny pozorne! ![]() ComboFix začne vykonávať, stačí sledovať pokyny. Po reštarte (v prípade, že požiada o reštart systému), bude produkovať záznam pre vás. Posta, že log (Combofix.txt) vo svojej budúcej odpoveď. Poznámka: Don't mouseclick ComboFix okná, ak je v chode. To môže spôsobiť váš systém zmraziť ---------- Otvorené Hijackthis a vyberte Do systému kontrolovať len. Umiestnite zatržítko vedľa týchto poznámok: (ak existuje)
Koniec Hijackthis. ---------- Stiahnite si prosím ATF Cleaner by Atribune. ATF Cleaner.exe Uistite sa, že všetko okna prehliadača sú zatvorené.
---------- Dôležité upozornenie: Odinštalovať verziu Hijackthis máte. to je stará beta verziu a my sa musíme mať na novú verziu, rovnako ako premenovanie na ostreľovača. Najprv choďte TU a to takto v poriadku. Krok tretí -- Malwarebytes' Anti-Malware (MBAM) Krok štyri -- Aktualizácia Java Krok Šesť -- HijackThis Teraz stačí spustiť novú Hijackthis skenovanie a po log spolu s ostatnými. ---------- Ďalší príspevok, prosím pridajte ComboFix log MBAM log NOVÉ Hijackthis log |
|
#3
| |||
| |||
Ahoj, vďaka za vrelé privítanie a rýchle odpovede, aj prestíž Vám za radu!Sledoval som všetky pokyny, jak jsi říkal, po pridaní skriptu comofix vírusu Zdalo sa, že zmiznú, ale aj po zvyšok rovnako krokov k makesure. Ja som aj Hijackthis! scan, ale súbory, ktoré ste ma požiadal o odstránenie už neboli tam, takže som hádať ComboFix potrebné na zbavili z nich. Bežal som Malware bytov tiež, a to našla nejaké súbory, ktoré som mal to odstrániť. Vyzerá to všetko dobre, nič viac pozadia reklamné bubliny popups, som pripojený protokoly, ako požaduje. Musel komprimovat 2 z nich, pretože oni boli nad filesize limit, stlačený s Winrar potom premenovaná. Zip, dúfam, že to v poriadku. Thanks again Evilfantasy. ComboFix 08-04-08.7 - Ashton 2008-04-09 18:21:02.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.682 [GMT 1:00] Running from: C: \ Documents and Settings \ Ashton \ Desktop \ ComboFix.exe Príkaz používa prepínače:: C: \ Documents and Settings \ Ashton \ Desktop \ CFScript.txt * Vznik nového bodu obnovenia * Tuzemského AV je aktívny POZOR-Tento stroj nemá konzoly na obnovenie namontovanom! FILE:: C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ system32 \ wmsdkns.exe . ((((((((((((((((((((((((((((((((((((((( Ostatné Vymazanie ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ Program Files \ 180search asistent C: \ Program Files \ 180search asistent \ 180sa.exe C: \ Program Files \ 180search asistent \ sau.exe C: \ Program Files \ 180searchassistant C: \ Program Files \ 180searchassistant \ saap.exe C: \ Program Files \ 180searchassistant \ sac.exe C: \ Program Files \ 180Solutions C: \ Program Files \ 180Solutions \ sais.exe C: \ Program Files \ Seekmo C: \ Program Files \ Seekmo \ seekmohook.dll C: \ Program Files \ stc C: \ Program Files \ stc \ csv5p070.exe C: \ Program Files \ Sysmnt C: \ Program Files \ Sysmnt \ Ssmgr.exe C: \ Program Files \ zango C: \ Program Files \ Zango \ zango.exe C: \ WINDOWS \ 180ax.exe C: \ WINDOWS \ 2020search.dll C: \ WINDOWS \ 2020search2.dll C: \ WINDOWS \ bjam.dll C: \ WINDOWS \ bokja.exe C: \ WINDOWS \ cdsm32.dll C: \ WINDOWS \ default.htm C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ FLEOK C: \ WINDOWS \ FLEOK \ 180ax.exe C: \ WINDOWS \ mspphe.dll C: \ WINDOWS \ mssvr.exe C: \ WINDOWS \ saiemod.dll C: \ WINDOWS \ salm.exe C: \ WINDOWS \ stcloader.exe C: \ WINDOWS \ swin32.dll C: \ WINDOWS \ system32 \ msixu.dll C: \ WINDOWS \ system32 \ wer8274.dll C: \ WINDOWS \ system32 \ wmsdkns.exe C: \ WINDOWS \ TEMP \ salm.exe C: \ WINDOWS \ updatetc.exe C: \ WINDOWS \ voiceip.dll . ((((((((((((((((((((((((( Súbory vytvorené od 2008-03-09 do 2008-04-09 ))))))))))) )))))))))))))))))))) . 2008-04-09 08:52. 2008-04-09 08:52 <DIR> d -------- C: \ Program Files \ ne. 2008-04-09 08:36. 2008-04-09 08:36 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Program Files \ Malwarebytes 'Anti-Malware 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Data aplikací \ Malwarebytes 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ Malwarebytes 2008-04-09 08:31. 2008-04-09 08:31 <DIR> d -------- C: \ Program Files \ Common Files \ Authentium 2008-04-09 08:31. 2008-04-09 18:11 53192 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_skt32.sys 2008-04-09 08:31. 2007-04-19 11:36 48.384 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_pkt32.sys 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Program Files \ Raxco 2008-04-09 08:30. 2008-04-09 18:07 <DIR> d -------- C: \ Program Files \ Common Files \ Scanner 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ Raxco 2008-04-09 08:28. 2008-04-09 08:28 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Data aplikací \ InstallShield 2008-04-09 08:25. 2008-04-09 08:30 <DIR> d -------- C: \ Program Files \ Virgin Broadband 2008-04-09 01:42. 2008-04-09 01:42 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ Yahoo! Companion 2008-04-09 01:14. 2008-04-09 01:14 <DIR> d -------- C: \ Program Files \ Yahoo! 2008-04-09 01:13. 2008-04-09 01:15 <DIR> d -------- C: \ Program Files \ CCleaner 2008-04-09 00:43. 2008-04-09 01:52 3314 - a ------ C: \ WINDOWS \ system32 \ tmp.reg 2008-04-09 00:42. 2007-09-06 00:22 289144 - a ------ C: \ WINDOWS \ system32 \ VCCLSID.exe 2008-04-09 00:42. 2006-04-27 17:49 288.417 - a ------ C: \ WINDOWS \ system32 \ SrchSTS.exe 2008-04-09 00:42. 2008-03-29 00:19 86.528 - a ------ C: \ WINDOWS \ system32 \ VACFix.exe 2008-04-09 00:42. 2008-04-08 22:44 82432 - a ------ C: \ WINDOWS \ system32 \ IEDFix.exe 2008-04-09 00:42. 2003-06-05 21:13 53248 - a ------ C: \ WINDOWS \ system32 \ Process.exe 2008-04-09 00:42. 2004-07-31 18:50 51.200 - a ------ C: \ WINDOWS \ system32 \ dumphive.exe 2008-04-09 00:42. 2007-10-04 00:36 25600 - a ------ C: \ WINDOWS \ system32 \ WS2Fix.exe 2008-04-09 00:01. 2008-04-09 00:01 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ FlexNet 2008-04-08 23:57. 2008-04-08 23:57 <DIR> d -------- C: \ Program Files \ Spybot - Search & Destroy 2008-04-08 23:57. 2008-04-09 00:46 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ Spybot - Search & Destroy 2008-04-08 23:50. 2008-04-08 23:50 <DIR> d -------- C: \ Documents and Settings \ All Users \ Data aplikací \ ALM 2008-04-08 23:47. 2008-04-08 23:47 <DIR> d -------- C: \ Program Files \ Bonjour 2008-04-08 23:29. 2008-04-08 23:29 <DIR> d -------- C: \ Program Files \ Common Files \ Macrovision Shared 2008-04-08 22:42. 2008-04-08 22:42 <DIR> d -------- C: \ Program Files \ PowerISO 2008-04-07 01:56. 2008-04-07 01:56 1110 - a ------ C: \ WINDOWS \ mozver.dat 2008-04-01 22:42. 2008-04-01 22:42 <DIR> d - h ----- C: \ Documents and Settings \ All Users \ Data aplikací \ (0E8E33D8-193a-414a-A909-0F101A142D26) 2008-04-01 22:38. 2008-04-01 22:38 <DIR> d -------- C: \ Program Files \ Stardock Games 2008-03-28 18:39. 2008-03-28 18:39 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Data aplikací \ dvdcss 2008-03-14 07:04. 2008-03-14 07:04 46.652 - a ------ C: \ WINDOWS \ system32 \ drivers \ scdemu.sys 2008-03-13 23:07. 2008-03-13 23:07 <DIR> d -------- C: \ Program Files \ Common Files \ NSV . (((((((((((((((((((((((((((((((((((((((( Find3M Správa )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-04-09 07:54 --------- d ----- w C: \ Program Files \ Java 2008-04-09 07:30 --------- d ----- w C: \ Program Files \ CA 2008-04-09 07:29 --------- d ----- w C: \ Documents and Settings \ All Users \ Data aplikací \ Virgin Broadband 2008-04-09 07:28 --------- d - h - w C: \ Program Files \ InstallShield Installation Informácie 2008-04-09 01:58 --------- d ----- w C: \ Documents and Settings \ Ashton \ Data aplikací \ Virgin Broadband 2008-04-08 22:47 --------- d ----- w C: \ Program Files \ Common Files \ Adobe 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ Ashton \ Data aplikací \ ATI 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ All Users \ Data aplikací \ ATI 2008-02-26 20:50 --------- d ----- w C: \ Program Files \ ATI Technologies 2008-02-26 01:30 --------- d ----- w C: \ Program Files \ Hry-Masters.com 2008-02-25 09:39 --------- d ----- w C: \ Program Files \ Common Files \ INCA Zdieľaná 2008-02-25 09:19 --------- d ----- w C: \ Program Files \ GameTribe 2008-02-24 03:18 --------- d ----- w C: \ Program Files \ Temp.p 2008-02-23 22:31 --------- d ----- w C: \ Program Files \ Common Files \ DirectX 2008-02-23 22:26 --------- d ----- w C: \ Documents and Settings \ All Users \ Data aplikací \ Kontiki 2008-02-23 21:42 --------- d ----- w C: \ Program Files \ OGPlanet 2008-02-22 19:06 --------- d ----- w C: \ Documents and Settings \ Ashton \ Data aplikací \ AdobeUM 2008-02-21 19:33 --------- d ----- w C: \ Program Files \ Three Rings Design 2008-02-20 22:40 --------- d ----- w C: \ Documents and Settings \ All Users \ Data aplikací \ Channel4 2008-02-15 19:17 --------- d ----- w C: \ Program Files \ Winamp 2008-02-15 18:00 --------- d ----- w C: \ Program Files \ Skryté City Games 2008-02-15 16:55 --------- d ----- w C: \ Program Files \ SealOnlineUSA 2008-02-13 21:44 --------- d ----- w C: \ Program Files \ Funcom 2007-12-23 19:41 32 ---- ar C: \ Documents and Settings \ All Users \ hash.dat 2004-02-02 10:31 236510-c - aw C: \ Documents and Settings \ Ashton \ DIAG.EXE 2004-01-30 18:21 62.480-c - aw C: \ Documents and Settings \ Ashton \ FETODI.COM 2004-01-09 14:28 51356-c - aw C: \ Documents and Settings \ Ashton \ FETND3.sys 2004-01-09 14:27 53136-c - aw C: \ Documents and Settings \ Ashton \ FETND4.sys 2004-01-09 14:24 40960-c - aw C: \ Documents and Settings \ Ashton \ FETND5A.sys 2004-01-09 14:23 42496-c - aw C: \ Documents and Settings \ Ashton \ FETND5B.sys 2003-11-27 15:01 57.344-c - aw C: \ Documents and Settings \ Ashton \ winsetup.exe 2002-10-09 16:29 147456-c - aw C: \ Documents and Settings \ Ashton \ NTUTIL.DLL 2002-02-20 11:04 15.552-c - aw C: \ Documents and Settings \ Ashton \ WINNDI.DLL . ((((((((((((((((((((((((((((( Snímka @ 2008-04-09_ 1.41.00.14 ))))))))))) )))))))))))))))))))))))))))))) . - 2008-04-08 22:11:46 29.696 ---- aw C: \ WINDOWS \ apphelp32.dll + 2008-04-09 17:08:03 9.472 ---- aw C: \ WINDOWS \ apphelp32.dll - 2008-04-08 22:11:46 14.592 ---- aw C: \ WINDOWS \ asferror32.dll + 2008-04-09 17:08:03 8.448 ---- aw C: \ WINDOWS \ asferror32.dll - 2008-04-08 22:11:46 29.952 ---- aw C: \ WINDOWS \ asycfilt32.dll + 2008-04-09 17:08:03 12.800 ---- aw C: \ WINDOWS \ asycfilt32.dll - 2008-04-08 22:11:46 20.480 ---- aw C: \ WINDOWS \ athprxy32.dll + 2008-04-09 17:08:03 18.432 ---- aw C: \ WINDOWS \ athprxy32.dll - 2008-04-08 22:11:46 17.408 ---- aw C: \ WINDOWS \ ati2dvaa32.dll + 2008-04-09 17:08:03 16.896 ---- aw C: \ WINDOWS \ ati2dvaa32.dll - 2008-04-08 22:11:46 10.752 ---- aw C: \ WINDOWS \ ati2dvag32.dll + 2008-04-09 17:08:03 20.480 ---- aw C: \ WINDOWS \ ati2dvag32.dll - 2008-04-08 22:11:46 22.016 ---- aw C: \ WINDOWS \ audiosrv32.dll + 2008-04-09 17:08:03 10.496 ---- aw C: \ WINDOWS \ audiosrv32.dll - 2008-04-08 22:11:47 22272 ---- aw C: \ WINDOWS \ autodisc32.dll + 2008-04-09 17:08:03 30.464 ---- aw C: \ WINDOWS \ autodisc32.dll - 2008-04-08 22:11:47 12288 ---- aw C: \ WINDOWS \ avifile32.dll + 2008-04-09 17:08:04 25856 ---- aw C: \ WINDOWS \ avifile32.dll - 2008-04-08 22:11:47 27392 ---- aw C: \ WINDOWS \ avisynthex32.dll + 2008-04-09 17:08:04 23296 ---- aw C: \ WINDOWS \ avisynthex32.dll - 2008-04-08 22:11:47 23808 ---- aw C: \ WINDOWS \ aviwrap32.dll + 2008-04-09 17:08:04 11776 ---- aw C: \ WINDOWS \ aviwrap32.dll - 2008-04-08 22:11:47 17920 ---- aw C: \ WINDOWS \ browserad.dll + 2008-04-09 17:08:04 18944 ---- aw C: \ WINDOWS \ browserad.dll - 2008-04-08 22:11:45 31.488 ---- aw C: \ WINDOWS \ changeurl_30.dll + 2008-04-09 17:08:03 29.696 ---- aw C: \ WINDOWS \ changeurl_30.dll - 2007-10-10 15:36:22 10134 ---- ar C: \ WINDOWS \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:00 10134 ---- ar C: \ WINDOWS \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:18 26582 ---- ar C: \ WINDOWS \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe + 2008-04-09 07:30:56 26582 ---- ar C: \ WINDOWS \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe - 2007-10-10 15:36:46 10134 ---- ar C: \ WINDOWS \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:31 10134 ---- ar C: \ WINDOWS \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 10.134 ---- ar C: \ WINDOWS \ Installer \ (3A836186-46F8-4388 do 9830-820E35C02992) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:45 10134 ---- ar C: \ WINDOWS \ Installer \ (3A836186-46F8-4388 do 9830-820E35C02992) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 25.214 ---- ar C: \ WINDOWS \ Installer \ (3A836186-46F8-4388 do 9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe + 2008-04-09 07:31:45 25214 ---- ar C: \ WINDOWS \ Installer \ (3A836186-46F8-4388 do 9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe - 2007-10-10 15:36:52 10.134 ---- ar C: \ WINDOWS \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:43 10134 ---- ar C: \ WINDOWS \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:59 10134 ---- ar C: \ WINDOWS \ Installer \ (3C441434-737C-4D54-8EAB-B409BE54E734) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:50 10134 ---- ar C: \ WINDOWS \ Installer \ (3C441434-737C-4D54-8EAB-B409BE54E734) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:00 10134 ---- ar C: \ WINDOWS \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:52 10134 ---- ar C: \ WINDOWS \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:02 10.134 ---- ar C: \ WINDOWS \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:55 10134 ---- ar C: \ WINDOWS \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:48 10.134 ---- ar C: \ WINDOWS \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:36 10134 ---- ar C: \ WINDOWS \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:50 10134 ---- ar C: \ WINDOWS \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:42 10134 ---- ar C: \ WINDOWS \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 10.134 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:07 10134 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 25.214 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe + 2008-04-09 07:30:07 25214 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe - 2007-10-10 15:35:46 25.214 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe + 2008-04-09 07:30:07 25214 ---- ar C: \ WINDOWS \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe - 2007-10-10 15:36:49 10134 ---- ar C: \ WINDOWS \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:41 10134 ---- ar C: \ WINDOWS \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:57 10.134 ---- ar C: \ WINDOWS \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:47 10134 ---- ar C: \ WINDOWS \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:07 10134 ---- ar C: \ WINDOWS \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:29 10134 ---- ar C: \ WINDOWS \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:11 10134 ---- ar C: \ WINDOWS \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:50 10134 ---- ar C: \ WINDOWS \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:32 10.134 ---- ar C: \ WINDOWS \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:10 10134 ---- ar C: \ WINDOWS \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:09 10134 ---- ar C: \ WINDOWS \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:32 10134 ---- ar C: \ WINDOWS \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:01 10134 ---- ar C: \ WINDOWS \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:53 10134 ---- ar C: \ WINDOWS \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe - 1998-10-29 16:45:06 306.688 ---- aw C: \ WINDOWS \ IsUninst.exe + 1998-10-29 15:45:06 306.688 ---- aw C: \ WINDOWS \ IsUninst.exe - 2008-04-08 22:11:49 14080 ---- aw C: \ WINDOWS \ msa64chk.dll + 2008-04-09 17:08:06 11.776 ---- aw C: \ WINDOWS \ msa64chk.dll - 2008-04-08 22:11:49 26368 ---- aw C: \ WINDOWS \ msapasrc.dll + 2008-04-09 17:08:06 26.624 ---- aw C: \ WINDOWS \ msapasrc.dll - 2008-04-08 22:11:48 25.344 ---- aw C: \ WINDOWS \ ntnut.exe + 2008-04-09 17:08:05 8960 ---- aw C: \ WINDOWS \ ntnut.exe - 2008-04-08 22:11:47 18432 ---- aw "C: \ WINDOWS \ shdocpe.dll + 2008-04-09 17:08:05 32000 ---- aw C: \ WINDOWS \ shdocpe.dll - 2008-04-08 22:11:48 21.504 ---- aw C: \ WINDOWS \ shdocpl.dll + 2008-04-09 17:08:05 27904 ---- aw C: \ WINDOWS \ shdocpl.dll - 2007-09-24 22:30:28 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe + 2008-02-22 00:23:35 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe - 2007-09-24 22:30:30 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe + 2008-02-22 00:23:39 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe - 2007-09-24 23:31:42 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe + 2008-02-22 01:33:32 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe - 2008-04-08 22:11:50 9.984 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll + 2008-04-09 17:08:07 14.336 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll - 2008-04-08 22:11:48 31.488 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe + 2008-04-09 17:08:05 28928 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe - 2008-04-08 22:11:48 21.760 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll + 2008-04-09 17:08:05 26880 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll - 2008-04-08 22:11:48 19.712 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll + 2008-04-09 17:08:06 30.720 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll - 2008-04-08 22:11:47 12800 ---- aw C: \ WINDOWS \ winsb.dll + 2008-04-09 17:08:04 18432 ---- aw C: \ WINDOWS \ winsb.dll - 2007-10-10 15:35:42 1233920 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ msxml4.dll + 2008-04-09 07:30:03 1233920 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ msxml4.dll - 2007-10-10 15:35:42 82432 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll + 2008-04-09 07:30:03 82432 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll . - Snapshot reset na aktuálny dátum -- . ((((((((((((((((((((((((((((((((((((( Reg Načítavam Body )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Poznámka * prázdné záznamy & dôveryhodne východiskové údaje nie sú zobrazené REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curr ntVersion \ Run] "Centrum.cz Oznamovač" = "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" [2007-01-19 12:54 5674352] "SB Audigy 2 Startup Menu" = "/ L: ENG" [] "CTFMON.EXE" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-04 08:56 15360] [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curr ntVersion \ RunOnce] "IndexCleaner" = "C: \ Program Files \ Panny Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2004-03-15 01:04 122933] "UpdateManager" = "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" [2003-08-19 01:01 110592] "CTSysVol" = "C: \ Program Files \ Creative \ SBAudigy2 \ Surround Mixer \ CTSysVol.exe" [2002-10-29 09:18 49152] "CTDVDDet" = "C: \ Program Files \ Creative \ SBAudigy2 \ DVDAudio \ CTDVDDet.EXE" [2002-09-30 01:00 45056] "CTHelper" = "CTHELPER.EXE" [2003-02-20 23:45 28672 C: \ WINDOWS \ system32 \ CTHELPER.EXE] "AsioReg" = "regsvr32.exe" [2004-08-04 08:56 11776 C: \ WINDOWS \ system32 \ regsvr32.exe] "UpdReg" = "C: \ WINDOWS \ UpdReg.EXE" [2000-05-11 01:00 90112] "Ctfmon.exe" = "C: \ Program Files \ ATI Technologies \ ATI Control Panel \ atiptaxx.exe" [2004-05-25 22:35 335872] "BJCFD" = "C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe" [2003-01-27 17:16 376912] "SynTPEnh" = "C: \ Program Files \ Winamp \ winampa.exe" [2008-01-15 23:54 37376] "StartCCC" = "C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statické \ CLIStart.exe" [2006-11-10 13:35 90112] "SunJavaUpdateSched" = "C: \ Program Files \ PowerISO \ SunJavaUpdateSched" [2008-03-15 00:50 233472] "workflow" = "D: \ instalace \ workflow.exe" [] "Broadbandadvisor.exe" = "C: \ Program Files \ Panny Broadband \ poradca \ Broadbandadvisor.exe" [2007-08-07 18:49 2061552] "PCguard" = "C: \ Program Files \ Panny Broadband \ PCguard \ Rps.exe" [2007-09-05 14:10 310000] "-FreedomNeedsReboot" = "C: \ Program Files \ Panny Broadband \ PCguard \ ZkRunOnceR.exe" [2007-09-05 14:10 13552] "SunJavaUpdateSched" = "C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ jusched.exe" [2008-02-22 04:25 144784] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ RunOnce] "IndexCleaner" = "C: \ Program Files \ Panny Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "CTFMON.EXE" = "C: \ WINDOWS \ system32 \ CTFMON.EXE" [2004-08-04 08:56 15360] C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Reader Speed Launch.lnk - C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ Reader_sl.exe [2004-12-14 05:44:06 29696] Microsoft Office.lnk - C: \ Program Files \ Microsoft Office \ Office \ OSA9.EXE [2000-01-21 09:15:54 65588] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ drivers32] "VIDC.X264" = x264vfw.dll "msacm.ac3acm" = AC3ACM.acm "msacm.scg726" = scg726.acm "msacm.alf2cd" = alf2cd.acm "vidc.dvsd" = mcdvd_32.dll [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ zdieľané tools \ msconfig \ startupreg \ DAEMON Tools] - A ------ 2007-08-29 16:09 171464 C: \ Program Files \ DAEMON Tools Lite \ daemon.exe [HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ AuthorizedApplications \ List] "% Windir% \ \ system32 \ \ Sessmgr.exe" = "C: \ \ Program Files \ \ Messenger \ \ Msmsgs.exe" = "% Windir% \ \ Network Diagnostické \ \ xpnetdiag.exe" = "C: \ \ Program Files \ \ Skype \ \ Telefón \ \ Skype.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ livecall.exe" = "C: \ \ Program Files \ \ Stardock Games \ \ Sins of Solar Empire \ \ Sins of Solar Empire.exe" = "C: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" = [HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ GloballyOpenPorts \ List] "15808: TCP" = 15808: TCP: BitComet 15808 TCP "15808: UDP" = 15808: UDP: BitComet 15808 UDP "3724: TCP" = 3724: TCP: Blizzard Downloader: 3724 S3 iadusb; GlobespanVirata USB IAD LAN Modem C: \ WINDOWS \ system32 \ DRIVERS \ glauiad.sys [2004-07-02 09:20] S3 Radialpoint bezpečnostné služby; Virgin Broadband PCguard C: \ WINDOWS \ system32 \ dllhost.exe [2004-08-04 08:56] S3 XDva037; XDva037 C: \ WINDOWS \ system32 \ XDva037.sys [] . Obsah tejto 'Naplánované úlohy' priečinku "2008-04-03 19:15:02 C: \ WINDOWS \ Tasks \ AppleSoftwareUpdate.job" - C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe . ************************************************** ************************ catchme 0.3.1351 W2K/XP/Vista - rootkit / stealth malware detektor by Gmer, http://www.gmer.net Rootkit scan 2008-04-09 18:26:36 Windows 5.1.2600 Service Pack 2 NTFS skenování skrytých procesov ... skenování skrytých položiek autostart ... skenování skrytých súborov ... scan úspešne dokončená skryté súbory: 0 ************************************************** ************************ . ------------------------ Iné spustených procesov ----------------------- -- . C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Program Files \ Panny Broadband \ PCguard \ Fws.exe C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Program Files \ Bonjour \ mDNSResponder.exe C: \ WINDOWS \ system32 \ CTsvcCDA.exe C: \ Program Files \ Common Files \ Authentium \ AntiVirus \ dvpapi.exe C: \ Program Files \ CA \ PPRT \ bin \ ITMRTSVC.exe C: \ Program Files \ Raxco \ PerfectDisk \ PDAgent.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ Program Files \ Analog Devices \ SoundMAX \ spkrmon.exe C: \ WINDOWS \ system32 \ wdfmgr.exe C: \ WINDOWS \ system32 \ MsPMSPSv.exe C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statické \ MOM.EXE C: \ Program Files \ Raxco \ PerfectDisk \ PDEngine.exe C: \ Program Files \ Panny Broadband \ poradca \ BroadbandadvisorComHandler.exe C: \ Program Files \ Panny Broadband \ PCguard \ rpsupdaterR.exe C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statické \ ccc.exe C: \ Program Files \ MSN Messenger \ usnsvc.exe . ************************************************** ************************ . Celkový čas: 2008-04-09 18:31:56 - počítač bol reštartuje ComboFix-quarantined-files.txt 2008-04-09 17:31:47 ComboFix2.txt 2008-04-09 00:59:01 ComboFix3.txt 2008-04-09 00:41:25 Pre-Run: 12340674560 bytes zadarmo Post-Run: 12324302848 bytes zadarmo . 2008-03-22 04:20:29 --- EOF --- |
|
#4
| |||
| |||
| Vyzerá to dobre. Teraz stačí spustiť ATF Cleaner opäť zbaviť škodlivých súborov v temp zložky. Dal som záznam do Combofix post. Som si istý, môžete vidieť toto: POZOR-Tento stroj nemá konzoly na obnovenie namontovanom! To je spoločné a možno nainštalovať konzolu na obnovenie, ak si vyberiete podľa návodu TU Čas urobiť nejaké očisty a bezpečnú prácu máte hotovo.
![]() Vyššie uvedený postup:
1. Dvojitým kliknutím OTMoveIt2.exe začať ju. Vista užívateľov kliknite pravým tlačidlom myši a vybrať Spustiť ako správca 2. Kliknite na CleanUp! tlačidlo. 3. OTMoveIt2 stiahne zoznam z Internetu, je-li váš firewall alebo iné obrannej programy výstrahy vám umožňujú prístup. 4. Kliknite ÁNO na ďalšie riadku (zoznam stiahnuť Chcete začať cleanup procesu?)
Nastavenie nového bodu obnovenia po vyčistení Vášho systému umožní, aby počítače na roll-späť na čisté pracovné stave v prípade potreby.
Zastaralý softvér má chyby zabezpečenia, že malware môže využiť.
Pozri tiež Pomalý počítač? Nemusí to byť Malware zdarma čistenie a údržba nástrojov, ktoré pomôžu udržať počítač spustený hladké. Dajte mi vedieť, keď príde niečo iné. |
![]() |
|
| Záložky |
Podobné témy | ||||
| Nitka | Thread Odľahčenú | Fórum | Odpovede | Posledný príspevok |
| Infikované počítače | duskmon10 | Virus, spyware a bezpečnosť | 20 | 26.novembra 2009 17:18 |
| Môj počítač infikovaný vírusom, myslím, že? Mohol by niekto pomôcť? | lawt555 | Virus, spyware a bezpečnosť | 5 | 16. marca 2009 04:59 |
| Deti infikovaných PC? | redden137 | Virus, spyware a bezpečnosť | 6 | 4. január 2009 15:10 |
| Nie som si istý, či môj počítač je infikovaný alebo nie | Rob1 | Virus, spyware a bezpečnosť | 4 | 4. februára 2008 15:14 |
| Thread Tools | |
| |