[ Príspevkov: 12 ] 
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
NapísalOffline : 15.03.2008 16:19 | PROSÍM O POMOC - VÍRUS

Prosím vás o pomoc pri odstraňovaní vírusu, ktorý mi spomaluje celý pc ale hlavne internet a stále mi všade ukazuje reklamy...

Vopred veľmi pekne ďakujem a pribalujem log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:18:30, on 15.3.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homepageinspect.com/?cm=201& ... from=icqhp
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: e404mgr Class - {03B902B1-9B25-4173-9468-56775C85A8D4} - C:\Program Files\Helper\1204409567.dll
O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27A82D47-9A2A-4B39-B4EC-792BBDFD03FA} - C:\WINDOWS\system32\xxyyvur.dll
O2 - BHO: (no name) - {3E6F9D62-4D73-447E-B12B-E4D0A26B7A92} - C:\WINDOWS\system32\ssqpo.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: e404 helper - {8F10DE2B-E923-4548-B524-4D9C5FA80777} - C:\Program Files\Helper\1205020198.dll
O2 - BHO: {26644f79-3f90-d34b-2974-7342eda8ba2e} - {e2ab8ade-2437-4792-b43d-09f397f44662} - C:\WINDOWS\system32\vcchshjk.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [VirusHeat 4.3] "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe" /h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [54a030a6] rundll32.exe "C:\WINDOWS\system32\xpkoliud.dll",b
O4 - HKLM\..\Run: [BM5793033a] Rundll32.exe "C:\WINDOWS\system32\twynrgoh.dll",s
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{50FE4732-9542-4F97-BE07-410388F1E88F}: NameServer = 85.255.116.162,85.255.112.181
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.162 85.255.112.181
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.162 85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.162 85.255.112.181
O20 - Winlogon Notify: xxyyvur - C:\WINDOWS\SYSTEM32\xxyyvur.dll
O22 - SharedTaskScheduler: auras - {f0d4f88e-e1f8-460f-a41c-6cfb7f73af79} - C:\WINDOWS\system32\xskmoqx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 6466 bytes


Offline

Užívateľ
Užívateľ
PROSÍM O POMOC - VÍRUS

Registrovaný: 14.02.08
Prihlásený: 04.01.15
Príspevky: 1276
Témy: 46 | 46
Bydlisko: Bratislava
NapísalOffline : 15.03.2008 17:49 | PROSÍM O POMOC - VÍRUS

preskenuj system antivirusom(NOD, AVAST), antyspywarem AD-Aware 2007 alebo inym , a vymaz si temp


_________________
CPU:AMD Phenom II X4 960T MB: GA-MA78GM S2H VGA: ASUS EAH4850 512MB DDR3 & AC L2 PRO RAM: 4x 1GB Kingstone 800Mhz PSU: CX400W HDD: SEAGATE Barracuda 7200.10 160GB + Seagate 320GB Monitor :19"LCD ASUS VB191T OS: Win 7 Ultimate 64 bit
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
Napísal autor témyOffline : 15.03.2008 18:00 | PROSÍM O POMOC - VÍRUS

takže systém som preskenoval avastom aj ad-awareom ale nechápem, čo myslíš tým temp????

dík


Offline

Skúsený užívateľ
Skúsený užívateľ
PROSÍM O POMOC - VÍRUS

Registrovaný: 22.03.07
Prihlásený: 14.06.14
Príspevky: 2108
Témy: 15 | 15
Bydlisko: Bratislava V
NapísalOffline : 15.03.2008 18:07 | PROSÍM O POMOC - VÍRUS

Dočasné súbory, napr. s atf cleaner. Pošli log z combofix.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 05.01.08
Prihlásený: 22.04.10
Príspevky: 310
Témy: 33 | 33
NapísalOffline : 15.03.2008 18:08 | PROSÍM O POMOC - VÍRUS

Tym mysli vymazat obsah adresaru <systemovy disk>\Documents and Settings\Local Settings\Temp\


Offline

Skúsený užívateľ
Skúsený užívateľ
PROSÍM O POMOC - VÍRUS

Registrovaný: 22.03.07
Prihlásený: 14.06.14
Príspevky: 2108
Témy: 15 | 15
Bydlisko: Bratislava V
NapísalOffline : 15.03.2008 18:13 | PROSÍM O POMOC - VÍRUS

Ešte pred combofixom použi fixwareout a pripoj log.
A odinštaluj avast, ad-aware a daj si radšej avira antivir+superantispyware.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
Napísal autor témyOffline : 15.03.2008 18:37 | PROSÍM O POMOC - VÍRUS

br4no tu je ten log z toho combofixu, ak ti to pomoze, lebo mne to nic nehovori :(

ComboFix 08-03-14.4 - PC 2008-03-15 18:15:07.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.177 [GMT 1:00]
Running from: C:\stiahnuté veci\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Program Files\Helper
C:\Program Files\Helper\1204409567.dll
C:\Program Files\Helper\1205020198.dll
C:\Program Files\Video Add-on
C:\Program Files\VirusHeat 4.3
C:\Program Files\VirusHeat 4.3\blacklist.txt
C:\Program Files\VirusHeat 4.3\Lang\English.ini
C:\Program Files\VirusHeat 4.3\msvcp71.dll
C:\Program Files\VirusHeat 4.3\msvcr71.dll
C:\Program Files\VirusHeat 4.3\uninst.exe
C:\Program Files\VirusHeat 4.3\vht.dat
C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url
C:\WINDOWS\BM5793033a.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cqdoanxw.dll
C:\WINDOWS\system32\drivers\fmtr.sys
C:\WINDOWS\system32\duilokpx.ini
C:\WINDOWS\system32\fxgrfljv.dll
C:\WINDOWS\system32\ipijfbrj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\opqss.ini
C:\WINDOWS\system32\opqss.ini2
C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\twynrgoh.dll
C:\WINDOWS\system32\vcchshjk.dll
C:\WINDOWS\system32\xdegcdom.dll
C:\WINDOWS\system32\xpkoliud.dll
C:\WINDOWS\system32\xxyyvur.dll

.
((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
.

2008-03-15 16:04 . 2008-03-15 16:04 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-13 16:41 . 2008-03-14 17:00 1,361,817 --ahs---- C:\WINDOWS\system32\fngahhob.ini
2008-03-12 16:36 . 2008-03-13 16:37 1,344,370 --ahs---- C:\WINDOWS\system32\wdwhjmff.ini
2008-03-09 17:49 . 2008-03-09 17:49 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-09 17:48 . 2008-03-10 14:00 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-04 16:42 . 2008-03-04 16:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-04 16:36 . 2008-03-04 16:36 <DIR> d-------- C:\Program Files\Yahoo!
2008-02-29 16:20 . 2008-03-09 18:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-29 16:20 . 2008-02-29 16:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-27 21:23 . 2008-03-15 15:53 <DIR> d-------- C:\Program Files\ICQToolbar
2008-02-27 21:16 . 2008-02-27 21:24 <DIR> d-------- C:\Program Files\ICQ6
2008-02-26 20:06 . 2002-12-13 10:33 2,359,350 -ra------ C:\WINDOWS\wallpaper_snowboard_1024x768.bmp
2008-02-26 20:06 . 2002-12-13 10:33 2,359,350 -ra------ C:\WINDOWS\wallpaper_football_1024x768.bmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 15:51 --------- d-----w C:\Program Files\Common Files\WinSpyControl
2008-02-02 20:36 --------- d-----w C:\Program Files\LimeWire
2008-01-26 08:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 08:01 --------- d-----w C:\Program Files\Disney Interactive
2008-01-26 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Disney Interactive
2008-01-25 18:58 --------- d-----w C:\Program Files\THQ
2008-01-25 18:49 --------- d-----w C:\Program Files\LEGO Software
2008-01-25 18:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-25 16:24 --------- d-----w C:\Program Files\DreamWorks Interactive
2007-12-28 22:10 737,280 ----a-w C:\WINDOWS\iun6002.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{23ED2206-856D-461A-BBCF-1C2466AC5AE3}"= C:\Program Files\Video Add-on\ictmdl.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{23ed2206-856d-461a-bbcf-1c2466ac5ae3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 16:09 171464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 577536 C:\WINDOWS\soundman.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 13:06 40048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{f0d4f88e-e1f8-460f-a41c-6cfb7f73af79}"= C:\WINDOWS\system32\xskmoqx.dll [2008-02-01 16:09 13312]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ssqpo.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhilipsDM]
--a------ 2006-09-28 08:32 655360 C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-09-01 14:57 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
C:\Program Files\Common Files\WinSpyControl\bm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSpyControl]
C:\Program Files\WinSpyControl\pgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=

R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 actvcomm;actvcomm;C:\WINDOWS\system32\drivers\actvcomm.sys [2004-04-28 10:30]
S3 K320bus;Sony Ericsson K320 driver (WDM);C:\WINDOWS\system32\DRIVERS\K320bus.sys [2006-08-18 10:10]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\K320mdfl.sys [2006-08-18 10:10]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\K320mdm.sys [2006-08-18 10:10]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\K320mgmt.sys [2006-08-18 10:10]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\K320obex.sys [2006-08-18 10:10]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 20:30:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-15 18:28:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2894]
-> C:\WINDOWS\system32\xskmoqx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-03-15 18:31:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-15 17:31:19


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
Napísal autor témyOffline : 15.03.2008 18:46 | PROSÍM O POMOC - VÍRUS

a tu je ten log z toho fixwareout-u


Username "PC" - 15.03.2008 18:41:45 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.162 85.255.112.181" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{50FE4732-9542-4F97-BE07-410388F1E88F}
"nameserver"="85.255.116.162,85.255.112.181" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{9B1AEEA5-EA7E-4385-9A9C-ED63B03B4468}
"DhcpNameServer"="85.255.116.162,85.255.112.181" <Value cleared.

Vyrovnávacia pamäť prekladania DNS sa úspešne vyprázdnila.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"SoundMan"="SOUNDMAN.EXE"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~


Offline

Skúsený užívateľ
Skúsený užívateľ
PROSÍM O POMOC - VÍRUS

Registrovaný: 22.03.07
Prihlásený: 14.06.14
Príspevky: 2108
Témy: 15 | 15
Bydlisko: Bratislava V
NapísalOffline : 15.03.2008 18:51 | PROSÍM O POMOC - VÍRUS

Do avengeru skopíruj:
Kód:
files to delete:
C:\WINDOWS\system32\xskmoqx.dll
C:\WINDOWS\system32\fngahhob.ini
C:\WINDOWS\system32\wdwhjmff.ini

folders to delete:
C:\Program Files\Helper
C:\Program Files\VirusHeat 4.3
C:\Program Files\NetProject
C:\Program Files\Common Files\WinSpyControl



Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
Napísal autor témyOffline : 15.03.2008 18:58 | PROSÍM O POMOC - VÍRUS

tak som to skopiroval a toto mi vyhodilo, este daco k tomu ci to je posledny krok?
Kód:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error:  file "C:\WINDOWS\system32\xxyyvur.dll" not found!
Deletion of file "C:\WINDOWS\system32\xxyyvur.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINDOWS\system32\ssqpo.dll" not found!
Deletion of file "C:\WINDOWS\system32\ssqpo.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINDOWS\system32\xpkoliud.dll" not found!
Deletion of file "C:\WINDOWS\system32\xpkoliud.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINDOWS\system32\vcchshjk.dll" not found!
Deletion of file "C:\WINDOWS\system32\vcchshjk.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  file "C:\WINDOWS\system32\twynrgoh.dll" not found!
Deletion of file "C:\WINDOWS\system32\twynrgoh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist

File "C:\WINDOWS\system32\xskmoqx.dll" deleted successfully.
File "C:\WINDOWS\system32\fngahhob.ini" deleted successfully.
File "C:\WINDOWS\system32\wdwhjmff.ini" deleted successfully.

Error:  folder "C:\Program Files\Helper" not found!
Deletion of folder "C:\Program Files\Helper" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  folder "C:\Program Files\VirusHeat 4.3" not found!
Deletion of folder "C:\Program Files\VirusHeat 4.3" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Error:  folder "C:\Program Files\NetProject" not found!
Deletion of folder "C:\Program Files\NetProject" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist

Folder "C:\Program Files\Common Files\WinSpyControl" deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.


Offline

Skúsený užívateľ
Skúsený užívateľ
PROSÍM O POMOC - VÍRUS

Registrovaný: 22.03.07
Prihlásený: 14.06.14
Príspevky: 2108
Témy: 15 | 15
Bydlisko: Bratislava V
NapísalOffline : 15.03.2008 19:01 | PROSÍM O POMOC - VÍRUS

To je koniec ďalšieho šmejda. Ešte môžeš v núdzovom režime spustiť sdfix, možno ešte niečo nájde.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 02.10.07
Prihlásený: 15.05.16
Príspevky: 61
Témy: 13 | 13
Napísal autor témyOffline : 15.03.2008 19:03 | PROSÍM O POMOC - VÍRUS

dakujem ti br4n0 za pomoc a spolupracu a za vyriesenie tychto problemov.velmo pekne dakujem


 [ Príspevkov: 12 ] 


PROSÍM O POMOC - VÍRUS



Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy.

Virus?! Prosim pomoc..

v Ostatné

5

415

21.06.2009 13:24

Tominator

V tomto fóre nie sú ďalšie neprečítané témy.

USB vírus?! prosím pomoc

[ Choď na stránku:Choď na stránku: 1, 2 ]

v Antivíry a antispywary

30

4107

25.12.2013 22:49

tatko Tom

V tomto fóre nie sú ďalšie neprečítané témy.

virus help_decrypt.....pomoc prosim

v Antivíry a antispywary

16

598

03.04.2015 13:12

tatko Tom

V tomto fóre nie sú ďalšie neprečítané témy.

Virus- Win32. Prosim pomoc!

v Antivíry a antispywary

20

1171

07.03.2010 17:14

Pistuk_14

V tomto fóre nie sú ďalšie neprečítané témy.

policajny virus...prosim pomoc

v Antivíry a antispywary

15

3502

01.12.2012 16:59

Mushuu

V tomto fóre nie sú ďalšie neprečítané témy.

Spyware alebo virus?? prosim pomoc :(

v Antivíry a antispywary

11

1543

02.03.2006 23:16

Carlos

V tomto fóre nie sú ďalšie neprečítané témy.

Prosim surne o kontrolu logu - virus

v Antivíry a antispywary

16

1089

05.04.2009 21:20

bayo15

V tomto fóre nie sú ďalšie neprečítané témy.

Trojsky kon virus - prosim o radu...

v Antivíry a antispywary

25

4125

20.11.2007 1:01

Rbot

V tomto fóre nie sú ďalšie neprečítané témy.

Virus !! pomoc!!

v Antivíry a antispywary

14

942

10.11.2011 10:50

Reverser

V tomto fóre nie sú ďalšie neprečítané témy.

Virus ? pomoc !

v Antivíry a antispywary

12

713

16.11.2011 21:47

simonka

V tomto fóre nie sú ďalšie neprečítané témy.

pomoc Virus v ramke

v Antivíry a antispywary

27

477

22.01.2013 21:11

xuit123

V tomto fóre nie sú ďalšie neprečítané témy.

LNK:FakeFolder-B Virus pomoc

v Antivíry a antispywary

12

293

26.01.2013 17:57

personal compuper

V tomto fóre nie sú ďalšie neprečítané témy.

Virus Help Your files pomoc

v Bezpečnosť a firewally

18

405

06.01.2016 21:53

tatko Tom

V tomto fóre nie sú ďalšie neprečítané témy.

Pomoc.(Asi) mám vírus v pc.

v Antivíry a antispywary

6

271

06.01.2013 19:01

personal compuper

V tomto fóre nie sú ďalšie neprečítané témy.

pomoc pomoc prosim nefunguje internet

v Ovládače

7

219

09.09.2017 20:37

Smith Wesson

V tomto fóre nie sú ďalšie neprečítané témy.

Prosim Prosim POMOC

[ Choď na stránku:Choď na stránku: 1, 2 ]

v Antivíry a antispywary

43

725

16.12.2013 19:55

Mandy



© 2005 - 2017 PCforum, edited by JanoF