Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Spomaleny pocitac, internet, virus cerv
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Spomaleny pocitac, internet, virus cerv
Logfile of random's system information tool 1.06 (written by random/random)
Run by Darinka at 2010-01-08 23:41:44
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 10 GB (15%) free of 67 GB
Total RAM: 895 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41:53, on 8.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Darinka\Desktop\RSIT.exe
C:\Program Files\trend micro\Darinka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cas.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-08:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ares ultra] "C:\Program Files\Ares Ultra\Ares Ultra.exe" -h
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: CCC.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.0.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {CE40C3F1-3DF5-4461-A521-810923235628} (JOJ_Explorer_Player Control) - http://www.joj.sk/fileadmin/joj_player/ ... Player.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SWIHPWMI - Sierra Wireless Inc. - C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
--
End of file - 6129 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\PCConfidential.job
C:\WINDOWS\tasks\rpc.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-05 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-01-12 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avast!"=C:\PROGRA~1\Avast4\ashDisp.exe [2009-11-25 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"ares ultra"=C:\Program Files\Ares Ultra\Ares Ultra.exe -h []
"LaunchList"=C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe []
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-10-11 1961984]
C:\Documents and Settings\Darinka\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-02-02 110592]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\Graffiti Studio 2.0 - 3\Graffiti Studio.exe"="F:\Graffiti Studio 2.0 - 3\Graffiti Studio.exe:*:Enabled:Macromedia Projector"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\InterVideoDVD7\WinDVD.exe"="C:\Program Files\InterVideoDVD7\WinDVD.exe:*:Disabled:WinDVD"
"C:\Documents and Settings\Darinka\Application Data\U3\0000184CF4714EC3\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe"="C:\Documents and Settings\Darinka\Application Data\U3\0000184CF4714EC3\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Darinka\Desktop\StrongDC.exe"="C:\Documents and Settings\Darinka\Desktop\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\Ares Ultra\Ares Ultra.exe"="C:\Program Files\Ares Ultra\Ares Ultra.exe:*:Disabled:Ares Ultra p2p for windows"
"F:\Marek Zaloha\Valve\hl.exe"="F:\Marek Zaloha\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"E:\VALVE\HL.EXE"="E:\VALVE\HL.EXE:*:Enabled:Half-Life Launcher"
"C:\Program Files\Pinnacle\Studio 11\programs\RM.exe"="C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe"="C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\Program Files\Pinnacle\Studio 11\programs\umi.exe"="C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\laucher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{537bea21-7027-11dc-96b0-000735a28f75}]
shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b9b270c-bcba-11dd-97e7-c4c73d40cb3d}]
shell\AutoRun\command - H:\laucher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82507e14-e17b-11dc-9741-adcee2cb13b8}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82507e16-e17b-11dc-9741-adcee2cb13b8}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a8c0f17-9e2e-11de-98d3-000735a28f75}]
shell\AutoRun\command - F:\Launcher.exe
======List of files/folders created in the last 1 months======
2010-01-08 23:41:44 ----D---- C:\rsit
2010-01-08 23:41:44 ----D---- C:\Program Files\trend micro
2010-01-07 13:11:58 ----SHD---- C:\Config.Msi
2010-01-06 10:57:37 ----A---- C:\WINDOWS\avisplitter.INI
2010-01-02 10:03:17 ----D---- C:\WINDOWS\WBEM
2010-01-02 10:01:08 ----HDC---- C:\WINDOWS\ie8
2010-01-02 10:01:08 ----D---- C:\WINDOWS\system32\sk-SK
2010-01-02 09:59:59 ----A---- C:\WINDOWS\system32\nlsdl.dll
2010-01-02 09:59:56 ----A---- C:\WINDOWS\system32\normaliz.dll
2010-01-02 09:59:54 ----A---- C:\WINDOWS\system32\idndl.dll
2010-01-02 09:59:49 ----A---- C:\WINDOWS\system32\msdbg2.dll
2010-01-02 09:59:48 ----A---- C:\WINDOWS\system32\ieudinit.exe
2010-01-02 09:59:44 ----N---- C:\WINDOWS\system32\WinFXDocObj.exe
2010-01-02 09:59:34 ----N---- C:\WINDOWS\system32\msrating.dll.mui
2010-01-02 09:59:24 ----N---- C:\WINDOWS\system32\mshta.exe.mui
2010-01-02 09:59:24 ----N---- C:\WINDOWS\system32\msfeedssync.exe
2010-01-02 09:59:21 ----N---- C:\WINDOWS\system32\msfeedsbs.dll
2010-01-02 09:59:19 ----N---- C:\WINDOWS\system32\msfeeds.dll
2010-01-02 09:59:02 ----N---- C:\WINDOWS\system32\ieui.dll
2010-01-02 09:58:58 ----N---- C:\WINDOWS\system32\iertutil.dll
2010-01-02 09:58:50 ----N---- C:\WINDOWS\system32\ieframe.dll.mui
2010-01-02 09:58:36 ----N---- C:\WINDOWS\system32\ieframe.dll
2010-01-02 09:58:23 ----N---- C:\WINDOWS\system32\iedkcs32.dll.mui
2010-01-02 09:58:21 ----N---- C:\WINDOWS\system32\ieapfltr.dll
2010-01-02 09:58:20 ----N---- C:\WINDOWS\system32\ie4uinit.exe.mui
2010-01-02 09:58:18 ----N---- C:\WINDOWS\system32\icardie.dll
2010-01-02 09:58:16 ----N---- C:\WINDOWS\system32\advpack.dll.mui
2010-01-01 18:42:44 ----D---- C:\Program Files\BitTorrent
2010-01-01 18:35:36 ----D---- C:\Documents and Settings\Darinka\Application Data\BitTorrent
2010-01-01 18:22:31 ----D---- C:\Documents and Settings\Darinka\Application Data\uTorrent
2010-01-01 11:52:31 ----A---- C:\WINDOWS\system32\dxva_sig.txt
2009-12-30 15:23:03 ----A---- C:\WINDOWS\ntbtlog.txt
2009-12-30 14:59:49 ----D---- C:\Documents and Settings\Darinka\Application Data\TeamViewer
2009-12-30 14:59:32 ----D---- C:\Program Files\TeamViewer
2009-12-30 13:00:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-12-30 13:00:00 ----D---- C:\Program Files\Avast4
2009-12-17 19:17:26 ----D---- C:\WINDOWS\Sun
======List of files/folders modified in the last 1 months======
2010-01-08 23:41:44 ----RD---- C:\Program Files
2010-01-08 23:39:47 ----D---- C:\Program Files\Mozilla Firefox
2010-01-08 23:24:38 ----D---- C:\WINDOWS\Temp
2010-01-08 23:24:38 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-08 23:21:07 ----D---- C:\WINDOWS\system32
2010-01-08 23:21:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-08 13:46:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-08 12:20:01 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2010-01-07 13:12:39 ----SHD---- C:\WINDOWS\Installer
2010-01-07 13:12:39 ----RSD---- C:\WINDOWS\assembly
2010-01-07 13:12:35 ----D---- C:\WINDOWS\Registration
2010-01-07 13:12:00 ----D---- C:\WINDOWS
2010-01-07 13:11:11 ----HD---- C:\WINDOWS\inf
2010-01-07 13:10:51 ----D---- C:\Program Files\Common Files
2010-01-07 13:10:51 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2010-01-07 13:09:09 ----D---- C:\WINDOWS\system32\drivers
2010-01-07 13:09:07 ----D---- C:\WINDOWS\Prefetch
2010-01-07 13:04:54 ----D---- C:\Program Files\InterActual
2010-01-07 11:10:06 ----D---- C:\Program Files\WinRAR
2010-01-07 10:39:23 ----D---- C:\WINDOWS\system32\Restore
2010-01-06 14:18:24 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-02 20:55:26 ----D---- C:\WINDOWS\system32\appmgmt
2010-01-02 20:41:42 ----SD---- C:\WINDOWS\Tasks
2010-01-02 20:29:42 ----D---- C:\Documents and Settings
2010-01-02 11:32:29 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-02 11:01:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-02 11:01:52 ----D---- C:\WINDOWS\Help
2010-01-02 11:01:52 ----D---- C:\Program Files\Internet Explorer
2010-01-02 10:03:20 ----D---- C:\WINDOWS\system32\config
2010-01-02 10:02:46 ----D---- C:\WINDOWS\Media
2010-01-02 10:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-01 23:17:27 ----D---- C:\WINDOWS\security
2010-01-01 16:29:03 ----A---- C:\WINDOWS\imsins.BAK
2010-01-01 11:35:08 ----D---- C:\Documents and Settings\Darinka\Application Data\Download Manager
2009-12-31 14:51:48 ----D---- C:\WINDOWS\SxsCaPendDel
2009-12-31 11:57:27 ----D---- C:\Documents and Settings\Darinka\Application Data\Samsung
2009-12-31 11:56:29 ----D---- C:\WINDOWS\WinSxS
2009-12-31 11:55:38 ----D---- C:\Program Files\PC Connectivity Solution
2009-12-31 11:37:49 ----D---- C:\Program Files\Google
2009-12-31 11:24:50 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-31 10:59:58 ----D---- C:\Program Files\Common Files\Adobe
2009-12-31 10:34:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-12-17 18:01:08 ----D---- C:\WINDOWS\Minidump
2009-12-12 15:38:57 ----D---- C:\Documents and Settings\Darinka\Application Data\ICAClient
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-02-16 288768]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2007-01-02 1160320]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2007-02-02 1975296]
R3 b57w2k;Broadcom 590x 10/100 Ethernet; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2006-12-15 160256]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2004-08-03 17024]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2004-08-03 31744]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
S3 ft1000;Flarion Flash OFDM wireless service; C:\WINDOWS\System32\DRIVERS\ft1000.sys []
S3 HP24X;HP PC Card Smart Card Reader; C:\WINDOWS\system32\DRIVERS\HP24X.sys [2006-10-19 33024]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys []
S3 nowokr;nowokr; \??\C:\WINDOWS\system32\01.tmp []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 USB_RNDIS;Belkin High-Speed Mode Wireless G USB Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2007-02-02 446464]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-05 153376]
R2 SWIHPWMI;SWIHPWMI; C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [2006-12-04 292384]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 PCLEPCI;PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [2005-02-09 14165]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
-----------------EOF-----------------
Run by Darinka at 2010-01-08 23:41:44
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 10 GB (15%) free of 67 GB
Total RAM: 895 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41:53, on 8.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Darinka\Desktop\RSIT.exe
C:\Program Files\trend micro\Darinka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cas.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-08:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ares ultra] "C:\Program Files\Ares Ultra\Ares Ultra.exe" -h
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: CCC.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.0.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {CE40C3F1-3DF5-4461-A521-810923235628} (JOJ_Explorer_Player Control) - http://www.joj.sk/fileadmin/joj_player/ ... Player.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SWIHPWMI - Sierra Wireless Inc. - C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
--
End of file - 6129 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\PCConfidential.job
C:\WINDOWS\tasks\rpc.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-05 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-01-12 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avast!"=C:\PROGRA~1\Avast4\ashDisp.exe [2009-11-25 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"ares ultra"=C:\Program Files\Ares Ultra\Ares Ultra.exe -h []
"LaunchList"=C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe []
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-10-11 1961984]
C:\Documents and Settings\Darinka\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-02-02 110592]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\Graffiti Studio 2.0 - 3\Graffiti Studio.exe"="F:\Graffiti Studio 2.0 - 3\Graffiti Studio.exe:*:Enabled:Macromedia Projector"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\InterVideoDVD7\WinDVD.exe"="C:\Program Files\InterVideoDVD7\WinDVD.exe:*:Disabled:WinDVD"
"C:\Documents and Settings\Darinka\Application Data\U3\0000184CF4714EC3\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe"="C:\Documents and Settings\Darinka\Application Data\U3\0000184CF4714EC3\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Darinka\Desktop\StrongDC.exe"="C:\Documents and Settings\Darinka\Desktop\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\Ares Ultra\Ares Ultra.exe"="C:\Program Files\Ares Ultra\Ares Ultra.exe:*:Disabled:Ares Ultra p2p for windows"
"F:\Marek Zaloha\Valve\hl.exe"="F:\Marek Zaloha\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"E:\VALVE\HL.EXE"="E:\VALVE\HL.EXE:*:Enabled:Half-Life Launcher"
"C:\Program Files\Pinnacle\Studio 11\programs\RM.exe"="C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe"="C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\Program Files\Pinnacle\Studio 11\programs\umi.exe"="C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\laucher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{537bea21-7027-11dc-96b0-000735a28f75}]
shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b9b270c-bcba-11dd-97e7-c4c73d40cb3d}]
shell\AutoRun\command - H:\laucher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82507e14-e17b-11dc-9741-adcee2cb13b8}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82507e16-e17b-11dc-9741-adcee2cb13b8}]
shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a8c0f17-9e2e-11de-98d3-000735a28f75}]
shell\AutoRun\command - F:\Launcher.exe
======List of files/folders created in the last 1 months======
2010-01-08 23:41:44 ----D---- C:\rsit
2010-01-08 23:41:44 ----D---- C:\Program Files\trend micro
2010-01-07 13:11:58 ----SHD---- C:\Config.Msi
2010-01-06 10:57:37 ----A---- C:\WINDOWS\avisplitter.INI
2010-01-02 10:03:17 ----D---- C:\WINDOWS\WBEM
2010-01-02 10:01:08 ----HDC---- C:\WINDOWS\ie8
2010-01-02 10:01:08 ----D---- C:\WINDOWS\system32\sk-SK
2010-01-02 09:59:59 ----A---- C:\WINDOWS\system32\nlsdl.dll
2010-01-02 09:59:56 ----A---- C:\WINDOWS\system32\normaliz.dll
2010-01-02 09:59:54 ----A---- C:\WINDOWS\system32\idndl.dll
2010-01-02 09:59:49 ----A---- C:\WINDOWS\system32\msdbg2.dll
2010-01-02 09:59:48 ----A---- C:\WINDOWS\system32\ieudinit.exe
2010-01-02 09:59:44 ----N---- C:\WINDOWS\system32\WinFXDocObj.exe
2010-01-02 09:59:34 ----N---- C:\WINDOWS\system32\msrating.dll.mui
2010-01-02 09:59:24 ----N---- C:\WINDOWS\system32\mshta.exe.mui
2010-01-02 09:59:24 ----N---- C:\WINDOWS\system32\msfeedssync.exe
2010-01-02 09:59:21 ----N---- C:\WINDOWS\system32\msfeedsbs.dll
2010-01-02 09:59:19 ----N---- C:\WINDOWS\system32\msfeeds.dll
2010-01-02 09:59:02 ----N---- C:\WINDOWS\system32\ieui.dll
2010-01-02 09:58:58 ----N---- C:\WINDOWS\system32\iertutil.dll
2010-01-02 09:58:50 ----N---- C:\WINDOWS\system32\ieframe.dll.mui
2010-01-02 09:58:36 ----N---- C:\WINDOWS\system32\ieframe.dll
2010-01-02 09:58:23 ----N---- C:\WINDOWS\system32\iedkcs32.dll.mui
2010-01-02 09:58:21 ----N---- C:\WINDOWS\system32\ieapfltr.dll
2010-01-02 09:58:20 ----N---- C:\WINDOWS\system32\ie4uinit.exe.mui
2010-01-02 09:58:18 ----N---- C:\WINDOWS\system32\icardie.dll
2010-01-02 09:58:16 ----N---- C:\WINDOWS\system32\advpack.dll.mui
2010-01-01 18:42:44 ----D---- C:\Program Files\BitTorrent
2010-01-01 18:35:36 ----D---- C:\Documents and Settings\Darinka\Application Data\BitTorrent
2010-01-01 18:22:31 ----D---- C:\Documents and Settings\Darinka\Application Data\uTorrent
2010-01-01 11:52:31 ----A---- C:\WINDOWS\system32\dxva_sig.txt
2009-12-30 15:23:03 ----A---- C:\WINDOWS\ntbtlog.txt
2009-12-30 14:59:49 ----D---- C:\Documents and Settings\Darinka\Application Data\TeamViewer
2009-12-30 14:59:32 ----D---- C:\Program Files\TeamViewer
2009-12-30 13:00:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-12-30 13:00:00 ----D---- C:\Program Files\Avast4
2009-12-17 19:17:26 ----D---- C:\WINDOWS\Sun
======List of files/folders modified in the last 1 months======
2010-01-08 23:41:44 ----RD---- C:\Program Files
2010-01-08 23:39:47 ----D---- C:\Program Files\Mozilla Firefox
2010-01-08 23:24:38 ----D---- C:\WINDOWS\Temp
2010-01-08 23:24:38 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-08 23:21:07 ----D---- C:\WINDOWS\system32
2010-01-08 23:21:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-08 13:46:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-08 12:20:01 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2010-01-07 13:12:39 ----SHD---- C:\WINDOWS\Installer
2010-01-07 13:12:39 ----RSD---- C:\WINDOWS\assembly
2010-01-07 13:12:35 ----D---- C:\WINDOWS\Registration
2010-01-07 13:12:00 ----D---- C:\WINDOWS
2010-01-07 13:11:11 ----HD---- C:\WINDOWS\inf
2010-01-07 13:10:51 ----D---- C:\Program Files\Common Files
2010-01-07 13:10:51 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2010-01-07 13:09:09 ----D---- C:\WINDOWS\system32\drivers
2010-01-07 13:09:07 ----D---- C:\WINDOWS\Prefetch
2010-01-07 13:04:54 ----D---- C:\Program Files\InterActual
2010-01-07 11:10:06 ----D---- C:\Program Files\WinRAR
2010-01-07 10:39:23 ----D---- C:\WINDOWS\system32\Restore
2010-01-06 14:18:24 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-02 20:55:26 ----D---- C:\WINDOWS\system32\appmgmt
2010-01-02 20:41:42 ----SD---- C:\WINDOWS\Tasks
2010-01-02 20:29:42 ----D---- C:\Documents and Settings
2010-01-02 11:32:29 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-02 11:01:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-02 11:01:52 ----D---- C:\WINDOWS\Help
2010-01-02 11:01:52 ----D---- C:\Program Files\Internet Explorer
2010-01-02 10:03:20 ----D---- C:\WINDOWS\system32\config
2010-01-02 10:02:46 ----D---- C:\WINDOWS\Media
2010-01-02 10:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-01 23:17:27 ----D---- C:\WINDOWS\security
2010-01-01 16:29:03 ----A---- C:\WINDOWS\imsins.BAK
2010-01-01 11:35:08 ----D---- C:\Documents and Settings\Darinka\Application Data\Download Manager
2009-12-31 14:51:48 ----D---- C:\WINDOWS\SxsCaPendDel
2009-12-31 11:57:27 ----D---- C:\Documents and Settings\Darinka\Application Data\Samsung
2009-12-31 11:56:29 ----D---- C:\WINDOWS\WinSxS
2009-12-31 11:55:38 ----D---- C:\Program Files\PC Connectivity Solution
2009-12-31 11:37:49 ----D---- C:\Program Files\Google
2009-12-31 11:24:50 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-31 10:59:58 ----D---- C:\Program Files\Common Files\Adobe
2009-12-31 10:34:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-12-17 18:01:08 ----D---- C:\WINDOWS\Minidump
2009-12-12 15:38:57 ----D---- C:\Documents and Settings\Darinka\Application Data\ICAClient
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-02-16 288768]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2007-01-02 1160320]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2007-02-02 1975296]
R3 b57w2k;Broadcom 590x 10/100 Ethernet; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2006-12-15 160256]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2004-08-03 17024]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2004-08-03 31744]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
S3 ft1000;Flarion Flash OFDM wireless service; C:\WINDOWS\System32\DRIVERS\ft1000.sys []
S3 HP24X;HP PC Card Smart Card Reader; C:\WINDOWS\system32\DRIVERS\HP24X.sys [2006-10-19 33024]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys []
S3 nowokr;nowokr; \??\C:\WINDOWS\system32\01.tmp []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 USB_RNDIS;Belkin High-Speed Mode Wireless G USB Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 12672]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2007-02-02 446464]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-05 153376]
R2 SWIHPWMI;SWIHPWMI; C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [2006-12-04 292384]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 PCLEPCI;PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [2005-02-09 14165]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
-----------------EOF-----------------
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
Dobrý den
pošlete ještě log z Combofix
Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
pošlete ještě log z Combofix
Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
Dakujem, posielam vam log z COMBOFIX, dufam ze som to urobil spravne
ComboFix 10-01-14.02 - Darinka 14.01.2010 21:53:05.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.895.486 [GMT 1:00]
Running from: c:\documents and settings\Darinka\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100114-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Thumbs.db
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))
.
2010-01-08 22:41 . 2010-01-11 10:00 -------- d-----w- c:\program files\trend micro
2010-01-08 22:41 . 2010-01-08 22:41 -------- d-----w- C:\rsit
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-01-02 19:30 . 2010-01-02 19:30 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-02 12:35 . 2010-01-02 12:35 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-01-02 11:32 . 2010-01-02 11:32 -------- d-sh--w- c:\documents and settings\Darinka\PrivacIE
2010-01-02 10:08 . 2010-01-02 10:08 -------- d-sh--w- c:\documents and settings\Darinka\IETldCache
2010-01-02 09:01 . 2010-01-02 09:03 -------- dc-h--w- c:\windows\ie8
2010-01-02 09:01 . 2010-01-02 09:03 -------- d-----w- c:\windows\system32\sk-SK
2010-01-01 17:42 . 2010-01-01 17:50 -------- d-----w- c:\program files\BitTorrent
2010-01-01 17:35 . 2010-01-06 22:35 -------- d-----w- c:\documents and settings\Darinka\Application Data\BitTorrent
2010-01-01 17:22 . 2010-01-01 17:39 -------- d-----w- c:\documents and settings\Darinka\Application Data\uTorrent
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\program files\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\temp
2009-12-30 12:01 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-30 12:01 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-30 12:01 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-30 12:01 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-30 12:01 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-30 12:01 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-30 12:01 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-30 12:01 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-30 12:00 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-30 12:00 . 2009-12-30 13:49 -------- d-----w- c:\program files\Avast4
2009-12-17 18:17 . 2009-12-17 18:17 -------- d-----w- c:\windows\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 12:10 . 2007-11-07 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 12:04 . 2007-09-21 07:04 -------- d-----w- c:\program files\InterActual
2010-01-01 10:35 . 2009-12-04 18:20 -------- d-----w- c:\documents and settings\Darinka\Application Data\Download Manager
2009-12-31 10:57 . 2009-09-25 07:38 -------- d-----w- c:\documents and settings\Darinka\Application Data\Samsung
2009-12-31 10:55 . 2009-09-25 07:37 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-31 10:37 . 2007-07-13 08:44 -------- d-----w- c:\program files\Google
2009-12-31 10:24 . 2007-07-13 06:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 09:59 . 2008-02-28 20:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-12 14:38 . 2009-06-11 09:58 -------- d-----w- c:\documents and settings\Darinka\Application Data\ICAClient
2009-12-06 12:08 . 2007-07-18 13:56 -------- d-----w- c:\documents and settings\Darinka\Application Data\MSN6
2009-12-05 18:05 . 2009-12-05 18:05 -------- d-----w- c:\program files\Citrix
2009-12-05 17:58 . 2007-07-13 06:20 -------- d-----w- c:\program files\ESET
2009-12-05 17:29 . 2009-12-05 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-05 17:28 . 2009-12-05 17:28 -------- d-----w- c:\program files\Java
2009-12-04 19:59 . 2009-12-04 19:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\Citrix
2009-12-04 19:49 . 2009-12-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-27 07:38 . 2007-10-01 14:19 -------- d-----w- c:\documents and settings\Darinka\Application Data\U3
2009-11-24 08:20 . 2009-11-24 08:20 0 ----a-w- c:\documents and settings\Darinka\MobilityManager.tmp
2008-07-22 14:15 . 2008-07-22 14:15 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-10-05 13:49 . 2007-10-05 13:48 48 --sha-w- c:\windows\S22C12A45.tmp
2008-01-12 18:25 . 2008-01-12 18:25 56 --sh--r- c:\windows\system32\7175C926D2.sys
2008-01-12 18:25 . 2008-01-12 18:25 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Darinka\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6965:TCP"= 6965:TCP:gcfin
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30.12.2009 13:01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.12.2009 13:01 20560]
R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [4.12.2006 15:13 292384]
S2 edvstbnnw;Support Center;c:\windows\system32\svchost.exe -k netsvcs [23.8.2001 13:00 14336]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [25.9.2009 8:38 36608]
S3 ft1000;Flarion Flash OFDM wireless service;c:\windows\system32\DRIVERS\ft1000.sys --> c:\windows\system32\DRIVERS\ft1000.sys [?]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [19.7.2007 8:15 33024]
S3 nowokr;nowokr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
edvstbnnw
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cas.sk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy-01-08:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {CE40C3F1-3DF5-4461-A521-810923235628} - hxxp://www.joj.sk/fileadmin/joj_player/JOJ_Explorer_Player.cab
FF - ProfilePath - c:\documents and settings\Darinka\Application Data\Mozilla\Firefox\Profiles\h5fjwc1c.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.cas.sk
FF - prefs.js: keyword.URL -
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-ares ultra - c:\program files\Ares Ultra\Ares Ultra.exe
HKCU-Run-LaunchList - c:\program files\Pinnacle\Studio 11\LaunchList2.exe
ActiveSetup-ccc-core-static - msiexec
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 21:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nowokr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\edvstbnnw]
"ServiceDll"="c:\windows\system32\okhqukw.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\ćHőwć*]
"DisplayName"="???\17?\11\09"
"DeviceDesc"="???\17?\11\09"
"ProviderName"="???\11\08??\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.7"
"DeviceInstanceIds"=multi:"c:\\swsetup\\sp35359\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-01-14 22:00:00
ComboFix-quarantined-files.txt 2010-01-14 20:59
Pre-Run: 9 875 124 224 bytes free
Post-Run: 10 adresárov, 11 477 536 768 voľných bajtov
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 01529D1AF3CFF47A618D1E5156E3835D
ComboFix 10-01-14.02 - Darinka 14.01.2010 21:53:05.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.895.486 [GMT 1:00]
Running from: c:\documents and settings\Darinka\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100114-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Thumbs.db
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))
.
2010-01-08 22:41 . 2010-01-11 10:00 -------- d-----w- c:\program files\trend micro
2010-01-08 22:41 . 2010-01-08 22:41 -------- d-----w- C:\rsit
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-01-02 19:30 . 2010-01-02 19:30 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-02 12:35 . 2010-01-02 12:35 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-01-02 11:32 . 2010-01-02 11:32 -------- d-sh--w- c:\documents and settings\Darinka\PrivacIE
2010-01-02 10:08 . 2010-01-02 10:08 -------- d-sh--w- c:\documents and settings\Darinka\IETldCache
2010-01-02 09:01 . 2010-01-02 09:03 -------- dc-h--w- c:\windows\ie8
2010-01-02 09:01 . 2010-01-02 09:03 -------- d-----w- c:\windows\system32\sk-SK
2010-01-01 17:42 . 2010-01-01 17:50 -------- d-----w- c:\program files\BitTorrent
2010-01-01 17:35 . 2010-01-06 22:35 -------- d-----w- c:\documents and settings\Darinka\Application Data\BitTorrent
2010-01-01 17:22 . 2010-01-01 17:39 -------- d-----w- c:\documents and settings\Darinka\Application Data\uTorrent
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\program files\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\temp
2009-12-30 12:01 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-30 12:01 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-30 12:01 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-30 12:01 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-30 12:01 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-30 12:01 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-30 12:01 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-30 12:01 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-30 12:00 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-30 12:00 . 2009-12-30 13:49 -------- d-----w- c:\program files\Avast4
2009-12-17 18:17 . 2009-12-17 18:17 -------- d-----w- c:\windows\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 12:10 . 2007-11-07 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 12:04 . 2007-09-21 07:04 -------- d-----w- c:\program files\InterActual
2010-01-01 10:35 . 2009-12-04 18:20 -------- d-----w- c:\documents and settings\Darinka\Application Data\Download Manager
2009-12-31 10:57 . 2009-09-25 07:38 -------- d-----w- c:\documents and settings\Darinka\Application Data\Samsung
2009-12-31 10:55 . 2009-09-25 07:37 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-31 10:37 . 2007-07-13 08:44 -------- d-----w- c:\program files\Google
2009-12-31 10:24 . 2007-07-13 06:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 09:59 . 2008-02-28 20:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-12 14:38 . 2009-06-11 09:58 -------- d-----w- c:\documents and settings\Darinka\Application Data\ICAClient
2009-12-06 12:08 . 2007-07-18 13:56 -------- d-----w- c:\documents and settings\Darinka\Application Data\MSN6
2009-12-05 18:05 . 2009-12-05 18:05 -------- d-----w- c:\program files\Citrix
2009-12-05 17:58 . 2007-07-13 06:20 -------- d-----w- c:\program files\ESET
2009-12-05 17:29 . 2009-12-05 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-05 17:28 . 2009-12-05 17:28 -------- d-----w- c:\program files\Java
2009-12-04 19:59 . 2009-12-04 19:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\Citrix
2009-12-04 19:49 . 2009-12-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-27 07:38 . 2007-10-01 14:19 -------- d-----w- c:\documents and settings\Darinka\Application Data\U3
2009-11-24 08:20 . 2009-11-24 08:20 0 ----a-w- c:\documents and settings\Darinka\MobilityManager.tmp
2008-07-22 14:15 . 2008-07-22 14:15 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-10-05 13:49 . 2007-10-05 13:48 48 --sha-w- c:\windows\S22C12A45.tmp
2008-01-12 18:25 . 2008-01-12 18:25 56 --sh--r- c:\windows\system32\7175C926D2.sys
2008-01-12 18:25 . 2008-01-12 18:25 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Darinka\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6965:TCP"= 6965:TCP:gcfin
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30.12.2009 13:01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.12.2009 13:01 20560]
R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [4.12.2006 15:13 292384]
S2 edvstbnnw;Support Center;c:\windows\system32\svchost.exe -k netsvcs [23.8.2001 13:00 14336]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [25.9.2009 8:38 36608]
S3 ft1000;Flarion Flash OFDM wireless service;c:\windows\system32\DRIVERS\ft1000.sys --> c:\windows\system32\DRIVERS\ft1000.sys [?]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [19.7.2007 8:15 33024]
S3 nowokr;nowokr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
edvstbnnw
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cas.sk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy-01-08:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {CE40C3F1-3DF5-4461-A521-810923235628} - hxxp://www.joj.sk/fileadmin/joj_player/JOJ_Explorer_Player.cab
FF - ProfilePath - c:\documents and settings\Darinka\Application Data\Mozilla\Firefox\Profiles\h5fjwc1c.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.cas.sk
FF - prefs.js: keyword.URL -
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-ares ultra - c:\program files\Ares Ultra\Ares Ultra.exe
HKCU-Run-LaunchList - c:\program files\Pinnacle\Studio 11\LaunchList2.exe
ActiveSetup-ccc-core-static - msiexec
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 21:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nowokr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\edvstbnnw]
"ServiceDll"="c:\windows\system32\okhqukw.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\ćHőwć*]
"DisplayName"="???\17?\11\09"
"DeviceDesc"="???\17?\11\09"
"ProviderName"="???\11\08??\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.7"
"DeviceInstanceIds"=multi:"c:\\swsetup\\sp35359\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-01-14 22:00:00
ComboFix-quarantined-files.txt 2010-01-14 20:59
Pre-Run: 9 875 124 224 bytes free
Post-Run: 10 adresárov, 11 477 536 768 voľných bajtov
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 01529D1AF3CFF47A618D1E5156E3835D
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
zapojte do PC všechny přenosné usb disky (klíčenky)
otevřte poznámkový blok (Notepad) a zkopírujte do něj následující text:
spustí se ComboFix a vykoná příkaz ze skriptu - potom pošlete nový log
otevřte poznámkový blok (Notepad) a zkopírujte do něj následující text:
Soubor uložte na plochu jako CFScript.txt a podle obrázku přetáhněte nad ComboFixKillAll::
Driver::
edvstbnnw
nowokr
NetSvc::
edvstbnnw
File::
c:\windows\system32\01.tmp
c:\windows\system32\okhqukw.dll
Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nowokr]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\edvstbnnw]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6965:TCP"=-
RegNull::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\ćHőwć*]
Extra::
Firefox::
FF - ProfilePath - c:\documents and settings\Darinka\Application Data\Mozilla\Firefox\Profiles\h5fjwc1c.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: keyword.URL -
spustí se ComboFix a vykoná příkaz ze skriptu - potom pošlete nový log
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
Vsetko prebehlo v poriadku, akurat teraz pri pisani tejto spravy mi vyhodilo ze avast nasiel rootkit na zlozke system32 a subor X.
Dakujeme za pomoc zatial
ComboFix 10-01-14.06 - Darinka 15.01.2010 16:32:12.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.895.486 [GMT 1:00]
Running from: c:\documents and settings\Darinka\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Darinka\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100115-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\system32\01.tmp"
"c:\windows\system32\okhqukw.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EDVSTBNNW
-------\Service_edvstbnnw
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-08 22:41 . 2010-01-11 10:00 -------- d-----w- c:\program files\trend micro
2010-01-08 22:41 . 2010-01-08 22:41 -------- d-----w- C:\rsit
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-01-02 19:30 . 2010-01-02 19:30 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-02 12:35 . 2010-01-02 12:35 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-01-02 11:32 . 2010-01-02 11:32 -------- d-sh--w- c:\documents and settings\Darinka\PrivacIE
2010-01-02 10:08 . 2010-01-02 10:08 -------- d-sh--w- c:\documents and settings\Darinka\IETldCache
2010-01-02 09:01 . 2010-01-02 09:03 -------- dc-h--w- c:\windows\ie8
2010-01-02 09:01 . 2010-01-02 09:03 -------- d-----w- c:\windows\system32\sk-SK
2010-01-01 17:42 . 2010-01-01 17:50 -------- d-----w- c:\program files\BitTorrent
2010-01-01 17:35 . 2010-01-06 22:35 -------- d-----w- c:\documents and settings\Darinka\Application Data\BitTorrent
2010-01-01 17:22 . 2010-01-01 17:39 -------- d-----w- c:\documents and settings\Darinka\Application Data\uTorrent
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\program files\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\temp
2009-12-30 12:01 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-30 12:01 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-30 12:01 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-30 12:01 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-30 12:01 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-30 12:01 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-30 12:01 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-30 12:01 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-30 12:00 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-30 12:00 . 2009-12-30 13:49 -------- d-----w- c:\program files\Avast4
2009-12-17 18:17 . 2009-12-17 18:17 -------- d-----w- c:\windows\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 12:10 . 2007-11-07 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 12:04 . 2007-09-21 07:04 -------- d-----w- c:\program files\InterActual
2010-01-01 10:35 . 2009-12-04 18:20 -------- d-----w- c:\documents and settings\Darinka\Application Data\Download Manager
2009-12-31 10:57 . 2009-09-25 07:38 -------- d-----w- c:\documents and settings\Darinka\Application Data\Samsung
2009-12-31 10:55 . 2009-09-25 07:37 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-31 10:37 . 2007-07-13 08:44 -------- d-----w- c:\program files\Google
2009-12-31 10:24 . 2007-07-13 06:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 09:59 . 2008-02-28 20:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-12 14:38 . 2009-06-11 09:58 -------- d-----w- c:\documents and settings\Darinka\Application Data\ICAClient
2009-12-06 12:08 . 2007-07-18 13:56 -------- d-----w- c:\documents and settings\Darinka\Application Data\MSN6
2009-12-05 18:05 . 2009-12-05 18:05 -------- d-----w- c:\program files\Citrix
2009-12-05 17:58 . 2007-07-13 06:20 -------- d-----w- c:\program files\ESET
2009-12-05 17:29 . 2009-12-05 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-05 17:28 . 2009-12-05 17:28 -------- d-----w- c:\program files\Java
2009-12-04 19:59 . 2009-12-04 19:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\Citrix
2009-12-04 19:49 . 2009-12-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-27 07:38 . 2007-10-01 14:19 -------- d-----w- c:\documents and settings\Darinka\Application Data\U3
2009-11-24 08:20 . 2009-11-24 08:20 0 ----a-w- c:\documents and settings\Darinka\MobilityManager.tmp
2008-07-22 14:15 . 2008-07-22 14:15 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-10-05 13:49 . 2007-10-05 13:48 48 --sha-w- c:\windows\S22C12A45.tmp
2008-01-12 18:25 . 2008-01-12 18:25 56 --sh--r- c:\windows\system32\7175C926D2.sys
2008-01-12 18:25 . 2008-01-12 18:25 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-01-14_20.58.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-15 15:38 . 2010-01-15 15:38 16384 c:\windows\Temp\Perflib_Perfdata_7bc.dat
- 2010-01-14 20:19 . 2010-01-14 20:19 16384 c:\windows\Temp\Perflib_Perfdata_620.dat
+ 2010-01-15 15:38 . 2010-01-15 15:38 16384 c:\windows\Temp\Perflib_Perfdata_620.dat
+ 2010-01-15 07:51 . 2010-01-15 07:51 16384 c:\windows\Temp\Perflib_Perfdata_608.dat
+ 2001-08-23 12:00 . 2010-01-15 07:55 58930 c:\windows\system32\perfc009.dat
- 2001-08-23 12:00 . 2010-01-14 20:23 58930 c:\windows\system32\perfc009.dat
+ 2001-08-23 12:00 . 2010-01-15 07:55 392630 c:\windows\system32\perfh009.dat
- 2001-08-23 12:00 . 2010-01-14 20:23 392630 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Darinka\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30.12.2009 13:01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.12.2009 13:01 20560]
R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [4.12.2006 15:13 292384]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [25.9.2009 8:38 36608]
S3 ft1000;Flarion Flash OFDM wireless service;c:\windows\system32\DRIVERS\ft1000.sys --> c:\windows\system32\DRIVERS\ft1000.sys [?]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [19.7.2007 8:15 33024]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cas.sk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy-01-08:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {CE40C3F1-3DF5-4461-A521-810923235628} - hxxp://www.joj.sk/fileadmin/joj_player/JOJ_Explorer_Player.cab
FF - ProfilePath - c:\documents and settings\Darinka\Application Data\Mozilla\Firefox\Profiles\h5fjwc1c.default\
FF - prefs.js: browser.startup.homepage - www.cas.sk
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 16:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\ćHőwć*]
"DisplayName"="???\17?\11\09"
"DeviceDesc"="???\17?\11\09"
"ProviderName"="???\11\08??\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.7"
"DeviceInstanceIds"=multi:"c:\\swsetup\\sp35359\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3804)
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avast4\aswUpdSv.exe
c:\program files\Avast4\ashServ.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Avast4\ashMaiSv.exe
c:\program files\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-01-15 16:42:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 15:42
ComboFix2.txt 2010-01-14 21:00
Pre-Run: 11 395 497 984 bytes free
Post-Run: 10 adresárov, 11 344 785 408 voľných bajtov
- - End Of File - - 8BB797FCF8746C3E47A0B356500344EC
Dakujeme za pomoc zatial
ComboFix 10-01-14.06 - Darinka 15.01.2010 16:32:12.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.895.486 [GMT 1:00]
Running from: c:\documents and settings\Darinka\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Darinka\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100115-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\system32\01.tmp"
"c:\windows\system32\okhqukw.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EDVSTBNNW
-------\Service_edvstbnnw
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-08 22:41 . 2010-01-11 10:00 -------- d-----w- c:\program files\trend micro
2010-01-08 22:41 . 2010-01-08 22:41 -------- d-----w- C:\rsit
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2010-01-02 19:31 . 2010-01-02 19:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-01-02 19:30 . 2010-01-02 19:30 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-02 12:35 . 2010-01-02 12:35 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-01-02 11:32 . 2010-01-02 11:32 -------- d-sh--w- c:\documents and settings\Darinka\PrivacIE
2010-01-02 10:08 . 2010-01-02 10:08 -------- d-sh--w- c:\documents and settings\Darinka\IETldCache
2010-01-02 09:01 . 2010-01-02 09:03 -------- dc-h--w- c:\windows\ie8
2010-01-02 09:01 . 2010-01-02 09:03 -------- d-----w- c:\windows\system32\sk-SK
2010-01-01 17:42 . 2010-01-01 17:50 -------- d-----w- c:\program files\BitTorrent
2010-01-01 17:35 . 2010-01-06 22:35 -------- d-----w- c:\documents and settings\Darinka\Application Data\BitTorrent
2010-01-01 17:22 . 2010-01-01 17:39 -------- d-----w- c:\documents and settings\Darinka\Application Data\uTorrent
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\program files\TeamViewer
2009-12-30 13:59 . 2009-12-30 13:59 -------- d-----w- c:\documents and settings\Darinka\temp
2009-12-30 12:01 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-30 12:01 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-30 12:01 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-30 12:01 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-30 12:01 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-30 12:01 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-30 12:01 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-30 12:01 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-30 12:00 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-30 12:00 . 2009-12-30 13:49 -------- d-----w- c:\program files\Avast4
2009-12-17 18:17 . 2009-12-17 18:17 -------- d-----w- c:\windows\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 12:10 . 2007-11-07 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 12:04 . 2007-09-21 07:04 -------- d-----w- c:\program files\InterActual
2010-01-01 10:35 . 2009-12-04 18:20 -------- d-----w- c:\documents and settings\Darinka\Application Data\Download Manager
2009-12-31 10:57 . 2009-09-25 07:38 -------- d-----w- c:\documents and settings\Darinka\Application Data\Samsung
2009-12-31 10:55 . 2009-09-25 07:37 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-31 10:37 . 2007-07-13 08:44 -------- d-----w- c:\program files\Google
2009-12-31 10:24 . 2007-07-13 06:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 09:59 . 2008-02-28 20:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-12 14:38 . 2009-06-11 09:58 -------- d-----w- c:\documents and settings\Darinka\Application Data\ICAClient
2009-12-06 12:08 . 2007-07-18 13:56 -------- d-----w- c:\documents and settings\Darinka\Application Data\MSN6
2009-12-05 18:05 . 2009-12-05 18:05 -------- d-----w- c:\program files\Citrix
2009-12-05 17:58 . 2007-07-13 06:20 -------- d-----w- c:\program files\ESET
2009-12-05 17:29 . 2009-12-05 17:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-05 17:28 . 2009-12-05 17:28 -------- d-----w- c:\program files\Java
2009-12-04 19:59 . 2009-12-04 19:59 -------- d-----w- c:\documents and settings\Darinka\Application Data\Citrix
2009-12-04 19:49 . 2009-12-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-27 07:38 . 2007-10-01 14:19 -------- d-----w- c:\documents and settings\Darinka\Application Data\U3
2009-11-24 08:20 . 2009-11-24 08:20 0 ----a-w- c:\documents and settings\Darinka\MobilityManager.tmp
2008-07-22 14:15 . 2008-07-22 14:15 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-10-05 13:49 . 2007-10-05 13:48 48 --sha-w- c:\windows\S22C12A45.tmp
2008-01-12 18:25 . 2008-01-12 18:25 56 --sh--r- c:\windows\system32\7175C926D2.sys
2008-01-12 18:25 . 2008-01-12 18:25 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-01-14_20.58.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-15 15:38 . 2010-01-15 15:38 16384 c:\windows\Temp\Perflib_Perfdata_7bc.dat
- 2010-01-14 20:19 . 2010-01-14 20:19 16384 c:\windows\Temp\Perflib_Perfdata_620.dat
+ 2010-01-15 15:38 . 2010-01-15 15:38 16384 c:\windows\Temp\Perflib_Perfdata_620.dat
+ 2010-01-15 07:51 . 2010-01-15 07:51 16384 c:\windows\Temp\Perflib_Perfdata_608.dat
+ 2001-08-23 12:00 . 2010-01-15 07:55 58930 c:\windows\system32\perfc009.dat
- 2001-08-23 12:00 . 2010-01-14 20:23 58930 c:\windows\system32\perfc009.dat
+ 2001-08-23 12:00 . 2010-01-15 07:55 392630 c:\windows\system32\perfh009.dat
- 2001-08-23 12:00 . 2010-01-14 20:23 392630 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Darinka\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30.12.2009 13:01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.12.2009 13:01 20560]
R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [4.12.2006 15:13 292384]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [25.9.2009 8:38 36608]
S3 ft1000;Flarion Flash OFDM wireless service;c:\windows\system32\DRIVERS\ft1000.sys --> c:\windows\system32\DRIVERS\ft1000.sys [?]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [19.7.2007 8:15 33024]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cas.sk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy-01-08:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {CE40C3F1-3DF5-4461-A521-810923235628} - hxxp://www.joj.sk/fileadmin/joj_player/JOJ_Explorer_Player.cab
FF - ProfilePath - c:\documents and settings\Darinka\Application Data\Mozilla\Firefox\Profiles\h5fjwc1c.default\
FF - prefs.js: browser.startup.homepage - www.cas.sk
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 16:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\ćHőwć*]
"DisplayName"="???\17?\11\09"
"DeviceDesc"="???\17?\11\09"
"ProviderName"="???\11\08??\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.7"
"DeviceInstanceIds"=multi:"c:\\swsetup\\sp35359\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3804)
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avast4\aswUpdSv.exe
c:\program files\Avast4\ashServ.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Avast4\ashMaiSv.exe
c:\program files\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-01-15 16:42:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 15:42
ComboFix2.txt 2010-01-14 21:00
Pre-Run: 11 395 497 984 bytes free
Post-Run: 10 adresárov, 11 344 785 408 voľných bajtov
- - End Of File - - 8BB797FCF8746C3E47A0B356500344EC
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
napište sem přesný název a umístění toho souboru - např.:Darinka píše:Vsetko prebehlo v poriadku, akurat teraz pri pisani tejto spravy mi vyhodilo ze avast nasiel rootkit na zlozke system32 a subor X.
c:\windows\system32\aswBoot.exe
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
C:\WINDOWS\system32\x
Subor nema ziadnu priponu.
..je mozne, ze je este aj niekde inde..
Subor nema ziadnu priponu.
..je mozne, ze je este aj niekde inde..
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
soubor otestujte na www.virustotal.com a vložte sem odkaz na výsledky (pokud to napíše, že soubor už byl testován, klikněte na otestovat znovu)
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
posielam odkaz
analisis/9a63d9eca7bfd6a34f0f5dcbb404029ff652132729571dd9152d862c6b23411c-1263176545
analisis/9a63d9eca7bfd6a34f0f5dcbb404029ff652132729571dd9152d862c6b23411c-1263176545
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
stáhněte a nainstalujte Malwarebytes' Anti-Malware - http://www.slunecnice.cz/sw/malwarebytes-anti-malware/
program aktualizujte - toto určitě proveďte, je to důležité
zavřete všechny spuštěné aplikace, nechte zaškrtnuté "Rychlá kontrola" a klikněte na "Spustit kontrolu" - po skončení skenování (3 - 15 minut, někdy i déle) klikněte na Zobrazit výsledky, nechte zaškrtnutá všechna políčka a klikněte na Odstranit vybrané, potom na OK a restartujte PC - znovu spusťte Malwarebytes', otevřte záložku Záznamy a vložte sem aktuální log
program aktualizujte - toto určitě proveďte, je to důležité
zavřete všechny spuštěné aplikace, nechte zaškrtnuté "Rychlá kontrola" a klikněte na "Spustit kontrolu" - po skončení skenování (3 - 15 minut, někdy i déle) klikněte na Zobrazit výsledky, nechte zaškrtnutá všechna políčka a klikněte na Odstranit vybrané, potom na OK a restartujte PC - znovu spusťte Malwarebytes', otevřte záložku Záznamy a vložte sem aktuální log
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
Malware som stiaho, nainstaloval, aktualizoval, spustil kontrolu, nenaslo mik ziadny inf. subor, tak som to restartoval, opať spustil malware a nenaslo mi opat nic. Je to zaujimave
Posielam log
Malwarebytes' Anti-Malware 1.44
Verzia databázy: 3570
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
15.1.2010 19:18:56
mbam-log-2010-01-15 (19-18-56).txt
Typ kontroly: Rýchla
Objektov kontrolovaných: 114613
Uplynutý cas: 9 minute(s), 14 second(s)
Infikovaných procesov pamäte: 0
Infikovaných modulov pamäte: 0
Infikovaných registracných klúcov: 0
Infikovaných registracných hodnôt: 0
Infikovaných registracných údajov položiek: 0
Infikovaných priecinkov: 0
Infikovaných súborov: 0
Infikovaných procesov pamäte:
(Žiadne škodlivé položky)
Infikovaných modulov pamäte:
(Žiadne škodlivé položky)
Infikovaných registracných klúcov:
(Žiadne škodlivé položky)
Infikovaných registracných hodnôt:
(Žiadne škodlivé položky)
Infikovaných registracných údajov položiek:
(Žiadne škodlivé položky)
Infikovaných priecinkov:
(Žiadne škodlivé položky)
Infikovaných súborov:
(Žiadne škodlivé položky)
Posielam log
Malwarebytes' Anti-Malware 1.44
Verzia databázy: 3570
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
15.1.2010 19:18:56
mbam-log-2010-01-15 (19-18-56).txt
Typ kontroly: Rýchla
Objektov kontrolovaných: 114613
Uplynutý cas: 9 minute(s), 14 second(s)
Infikovaných procesov pamäte: 0
Infikovaných modulov pamäte: 0
Infikovaných registracných klúcov: 0
Infikovaných registracných hodnôt: 0
Infikovaných registracných údajov položiek: 0
Infikovaných priecinkov: 0
Infikovaných súborov: 0
Infikovaných procesov pamäte:
(Žiadne škodlivé položky)
Infikovaných modulov pamäte:
(Žiadne škodlivé položky)
Infikovaných registracných klúcov:
(Žiadne škodlivé položky)
Infikovaných registracných hodnôt:
(Žiadne škodlivé položky)
Infikovaných registracných údajov položiek:
(Žiadne škodlivé položky)
Infikovaných priecinkov:
(Žiadne škodlivé položky)
Infikovaných súborov:
(Žiadne škodlivé položky)
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
stáhněte OTMoveIt3 - http://www.viry.cz/forum/viewtopic.php?f=15&t=72743 a použijte tento script:
vložte sem log, který program vytvoří:files
C:\WINDOWS\system32\x
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
:commands
[purity]
[emptytemp]
[reboot]
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\x not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\002252_.tmp moved successfully.
C:\WINDOWS\S22C12A45.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET7.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Darinka
->Temp folder emptied: 2622832 bytes
->Temporary Internet Files folder emptied: 79099381 bytes
->Java cache emptied: 3726492 bytes
->FireFox cache emptied: 88444647 bytes
User: Default User
->Temp folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 1711190 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 358016 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4998597 bytes
Total Files Cleaned = 173,00 mb
OTM by OldTimer - Version 3.1.6.0 log created on 01152010_202833
Files moved on Reboot...
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
File C:\WINDOWS\temp\Perflib_Perfdata_630.dat not found!
Registry entries deleted on Reboot...
========== FILES ==========
File/Folder C:\WINDOWS\system32\x not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\002252_.tmp moved successfully.
C:\WINDOWS\S22C12A45.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET7.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Darinka
->Temp folder emptied: 2622832 bytes
->Temporary Internet Files folder emptied: 79099381 bytes
->Java cache emptied: 3726492 bytes
->FireFox cache emptied: 88444647 bytes
User: Default User
->Temp folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 1711190 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 358016 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4998597 bytes
Total Files Cleaned = 173,00 mb
OTM by OldTimer - Version 3.1.6.0 log created on 01152010_202833
Files moved on Reboot...
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
File C:\WINDOWS\temp\Perflib_Perfdata_630.dat not found!
Registry entries deleted on Reboot...
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: Spomaleny pocitac, internet, virus cerv
OK, a teď Avast hlásí co?
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
Re: Spomaleny pocitac, internet, virus cerv
Avast mi vypisuje stale, ze v PC je cerv.
mozem poslat foto co vypisuje avast, potrebujem e meil.
mozem poslat foto co vypisuje avast, potrebujem e meil.