Skočiť na obsah


Fotografia
- - - - -

Bojím sa, že mám rootkit alebo niečo v kompe

hijackthis

  • Prosím prihláste sa ak chcete odpovedať
Téma má 3 príspevkov

#1 Jovzin

Jovzin

    Junior :D

  • FS Members
  • PipPipPipPipPip
  • 788 príspevkov
  • 60 tém

Príspevok bol napísaný: 11. March 2015 - 11:12:19

Custe.

Mam blby pocit ci nahodou nebudem musiet robit format HDD.

 

Po kazdom restarte sa mi zjavi v  Users/Jovzin/Appdata/Roaming subor s nazvom .mono

 

Jedine co som naiel o tom stranku je toto: http://www.tomshardw...er-roaming.html

 

Dal som uz hlboky scan s NODom ale nic nenaslo.

Spustil som i par aniroorkit veci od Avastu a Kasperski a tiez hlasi ze nic nenaslo.

 

Mam sa zacat bat ? Alebo radsej pre istotu zabit zase cely den preinstalaciou winu ? 

Hijack mi ukazuje iba toto a tiez tam nic nevidim:

 

 

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:11:13, on 11. 3. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!

FIREFOX: 36.0.1 (x86 en-GB)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
D:\Instal\HijackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [ghost] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O15 - Trusted IP range: http://127.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 5374 bytes

 


  • 0

#2 D'Ady

D'Ady

    pozemský drak

  • Advanced Members
  • PipPipPipPipPipPipPipPip
  • 5314 príspevkov
  • 10 tém

Príspevok bol napísaný: 11. March 2015 - 13:00:25

skus vyuzit poradnu vo fore na viry.cz
 


  • 0

#3 Jovzin

Jovzin

    Junior :D

  • FS Members
  • PipPipPipPipPip
  • 788 príspevkov
  • 60 tém

Príspevok bol napísaný: 13. March 2015 - 16:40:41

No format som spravil zabil tym den. A nakoniec zistim ze ta nova hra Cities Skylines to vytvorila lebo pouziva to pre ten Unity engine a nejake databazu ci co. Takze zbytocne som sa stresoval :(
  • 0

#4 D'Ady

D'Ady

    pozemský drak

  • Advanced Members
  • PipPipPipPipPipPipPipPip
  • 5314 príspevkov
  • 10 tém

Príspevok bol napísaný: 15. March 2015 - 02:59:43

na nete sa da pomerne lahko zistit, ci niektory subor moze (alebo obvykle je) virus
1. dat do vyhladavaca nestandardny subor, resp. a priamo Uja Googla opytat, ku akemu programu patri dany typ suboru (search filetype *)

1a. da sa na to pouzit stranka filext.com

2. pouzit sluzbu virustotal.com

 

ja som teraz dva dni cistil comp od tych reklam, co pisem v nej teme...
keby som mal formatovat, tak potom instalujem tyzden...


  • 0