Prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Key3
nováček
Příspěvky: 18
Registrován: květen 14
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Key3 » 21 kvě 2014 16:58

Malwarebytes Anti-Malware mi našel nějakou další hrozbu. Mám ji jen smazat? Přikládám z toho log. Nějak se mi to nelíbí.


Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 21.5.2014
Scan Time: 16:54:35
Logfile: 1111.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.21.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: user

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 271342
Time Elapsed: 28 min, 1 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.DefaultSearch.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://www.google.cz/", "http://www.default-search.net?sid=476&aid=113&itype=a&ver=12521&tm=296&src=hmp" ],), ,[aa5fc88caecd02348bdd106dfb09f808]

Physical Sectors: 0
(No malicious items detected)


(end)

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 21 kvě 2014 18:49

Smaž.

Stáhni si program OTM (by OldTimer)
a ulož si ho na disk C a spusť ho.
- Do levého sloupce (Paste Instructions for Items to be Moved) zkopíruj tyto cesty:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\Program Files\Mafia
C:\Program Files (x86)\Mafia
C:\Program Files (x86)\DMC
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_DMC-DevilMayCry
C:\Users\user\Desktop\FAKIN\Hry\DMC
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Mafia
C:\Users\user\Desktop\FAKIN\Hry\Mafia

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď.
C:\_OTMoveIt\MovedFiles\********_******.log

*********************************************************************************************************************************************
Start-spustit , a napiš do okénka :
regedit
dej OK

Nahoře--úpravy--najít.
do okénka napiš:
Mafia
a klikni na "najít další"
začně sken.

Vlevo ve stromu se objeví složka s názvem Mafia, kterou smaž.

dej najít další a pak znovu smaž. pokračuj dál až do doby než systém další nenajde.


Vše zopakuj s DMC , případně s DEVILMAYCRY.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Key3
nováček
Příspěvky: 18
Registrován: květen 14
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Key3 » 21 kvě 2014 19:45

Všechno smazáno.

Mockrát děkuji za pomoc. :-)

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\WINDOWS\System32\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job moved successfully.
c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job moved successfully.
File/Folder C:\*.tmp not found.
File/Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File/Folder C:\Program Files\*.tmp not found.
File/Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File/Folder C:\Windows\SysNative\drivers\*.tmp not found.
File/Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File/Folder C:\Program Files (x86)\*.tmp not found.
File/Folder C:\Windows\SysWow64\*.tmp not found.
File/Folder C:\Windows\SysNative\*.tmp not found.
File/Folder C:\Program Files (x86)\*.tmp not found.
C:\Program Files\Mafia\savegame folder moved successfully.
C:\Program Files\Mafia folder moved successfully.
C:\Program Files (x86)\Mafia\savegame folder moved successfully.
C:\Program Files (x86)\Mafia folder moved successfully.
C:\Program Files (x86)\DMC\redist folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Stats folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Splash\PCConsole folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Splash folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Shaders\Binaries folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Shaders folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\RUS folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\PTB folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\POL folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\ITA folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\INT folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\FRA folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\ESN folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\DUT folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization\DEU folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Localization folder moved successfully.
C:\Program Files (x86)\DMC\Engine\Config folder moved successfully.
C:\Program Files (x86)\DMC\Engine folder moved successfully.
C:\Program Files (x86)\DMC\directx_Jun2010_redist folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\RUS folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\POR folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\POL folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\JPN folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\ITA folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\INT folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\FRA folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\ESN folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\DUT folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization\DEU folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal\Localization folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content\DLCDanteOriginal folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published\Content folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Published folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Movies folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\RUS folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\PTB folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\POL folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\ITA folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\INT folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\FRA folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\ESN folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\DUT folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization\DEU folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Localization folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\CookedPCConsole folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame\Config folder moved successfully.
C:\Program Files (x86)\DMC\DevilGame folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\Win32\Editor\Release folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\Win32\Editor folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\Win32 folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\NTJobCode\windows\submission folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\NTJobCode\windows folder moved successfully.
C:\Program Files (x86)\DMC\Binaries\NTJobCode folder moved successfully.
C:\Program Files (x86)\DMC\Binaries folder moved successfully.
C:\Program Files (x86)\DMC folder moved successfully.
File/Folder C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_DMC-DevilMayCry not found.
File/Folder C:\Users\user\Desktop\FAKIN\Hry\DMC not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia folder moved successfully.
File/Folder C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Mafia not found.
C:\Users\user\Desktop\FAKIN\Hry\Mafia\MafiaGame\savegame folder moved successfully.
C:\Users\user\Desktop\FAKIN\Hry\Mafia\MafiaGame\EAX3 folder moved successfully.
C:\Users\user\Desktop\FAKIN\Hry\Mafia\MafiaGame\Crack folder moved successfully.
C:\Users\user\Desktop\FAKIN\Hry\Mafia\MafiaGame folder moved successfully.
C:\Users\user\Desktop\FAKIN\Hry\Mafia folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: user
->Temp folder emptied: 13627200 bytes
->Temporary Internet Files folder emptied: 1417643 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 15792755 bytes
->Google Chrome cache emptied: 372662472 bytes
->Flash cache emptied: 780 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1908342 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 387,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 05212014_190343

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod Orcus » 21 kvě 2014 20:32

OK, za nás čisto. Pokud to je vše, téma můžeš označit jako vyřešené.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 89 hostů