problém s fb

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#16 Příspěvek od marsellita »

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: Remove -- Date : 08/24/2011 17:59:18

Bad processes: 0

Registry Entries: 3
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

Particular Files / Folders:

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: HOSTSFix -- Date : 08/24/2011 18:00:22

Bad processes: 0

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt



RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: ProxyFix -- Date : 08/24/2011 18:00:53

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: DNSFix -- Date : 08/24/2011 18:01:14

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#17 Příspěvek od marsellita »

když chci instalovat combofix dle návodu...otvírá se mi aro 2011, které na mě na konci chce buy now a nebo odstanit něco....tak nevím, jestli jsem správně....jinak logy z rogue kollier:

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: Remove -- Date : 08/24/2011 17:59:18

Bad processes: 0

Registry Entries: 3
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

Particular Files / Folders:

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt



RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: HOSTSFix -- Date : 08/24/2011 18:00:22

Bad processes: 0

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: ProxyFix -- Date : 08/24/2011 18:00:53

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[3].txt >RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: DNSFix -- Date : 08/24/2011 18:01:14

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#18 Příspěvek od marsellita »

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User: Marcelka [Admin rights]
Mode: DNSFix -- Date : 08/24/2011 18:01:14

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: problém s fb

#19 Příspěvek od motji »

A ještě ten combofix.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#20 Příspěvek od marsellita »

<?xml version="1.0" encoding="UTF-8" ?>
- <AROScanLog>
<AROVersion>6.0.793.824</AROVersion>
<ScanningDate>Wed. August 24, 2011. 08:09 PM</ScanningDate>
<TotalRegErrorsFound>534</TotalRegErrorsFound>
<TotalJunkErrorsFound>2011</TotalJunkErrorsFound>
<TotalSecErrorsFound>1</TotalSecErrorsFound>
- <Scanning Section="File types">
<Description>File types pointing to programs that are no longer on your system.</Description>
<ErrorsInThisSection>50 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>ResBun.GetResource.4</Entry>
<Details>The key HKEY_CLASSES_ROOT\ResBun.GetResource.4\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{8EC4AB44-CBA9-4C93-8A87-087AF11FEEEF}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ResLiveUpdt.GetResource.2</Entry>
<Details>The key HKEY_CLASSES_ROOT\ResLiveUpdt.GetResource.2\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{818F5933-A4E0-4B83-BDF6-5081496A24FA}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ResSchdlr.GetResource.45</Entry>
<Details>The key HKEY_CLASSES_ROOT\ResSchdlr.GetResource.45\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{136088D2-7654-445C-9DEF-BEE07DB87EE1}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Rights Management File</Entry>
<Details>The file type points to the missing program in the key HKEY_CLASSES_ROOT\AcroExch.RMFFile\shell\Read\command.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:File Transfer Protocol</Entry>
<Details>The file type points to the missing program in the key HKEY_CLASSES_ROOT\ftp\shell\open\command.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:HyperText Transfer Protocol</Entry>
<Details>The file type points to the missing program in the key HKEY_CLASSES_ROOT\http\shell\open\command.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:HyperText Transfer Protocol</Entry>
<Details>The key HKEY_CLASSES_ROOT\Firefox.Url\shell is incomplete because the subkey shell1 is missing. For this reason, the action shell does not work for this file type.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:HyperText Transfer Protocol</Entry>
<Details>Thy key HKEY_CLASSES_ROOT\http\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:HyperText Transfer Protocol with Privacy</Entry>
<Details>The file type points to the missing program in the key HKEY_CLASSES_ROOT\https\shell\open\command.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:HyperText Transfer Protocol with Privacy</Entry>
<Details>Thy key HKEY_CLASSES_ROOT\https\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedBWTCompression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.BWTCompression.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{1EF89628-358F-11D5-8071-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedBWTCompression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.BWTCompression\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{1EF89628-358F-11D5-8071-0060082AE372}.</Details

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#21 Příspěvek od marsellita »

</EntryDetails>
- <EntryDetails>
<Entry>XceedBZip2CompressionFormat Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.BZip2CompressionFormat.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{43FD1596-3A84-11D5-8077-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedBZip2CompressionFormat Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.BZip2CompressionFormat\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{43FD1596-3A84-11D5-8077-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedDeflate64Compression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Deflate64Compression.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{8913C82B-385B-48c1-8AE0-5D837DB4ADC5}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedDeflate64Compression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Deflate64Compression\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{8913C82B-385B-48c1-8AE0-5D837DB4ADC5}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedDeflateCompression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.DeflateCompression.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{1EF89626-358F-11D5-8071-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedDeflateCompression Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.DeflateCompression\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{1EF89626-358F-11D5-8071-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedEncryption ActiveX</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Encryption.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A0A61B00-96A6-457F-AA5E-AFA5167852E5}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedEncryption ActiveX</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Encryption\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A0A61B00-96A6-457F-AA5E-AFA5167852E5}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedGZipCompressionFormat Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.GZipCompressionFormat.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{43FD1592-3A84-11D5-8077-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedGZipCompressionFormat Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.GZipCompressionFormat\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{43FD1592-3A84-11D5-8077-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedHashing Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Hashing.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{7EC04D5B-19A8-45EE-BCB0-6FE0067F9468}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedHashing Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Hashing\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{7EC04D5B-19A8-45EE-BCB0-6FE0067F9468}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedHavalHashingMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.HavalHashingMethod.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A02A65C1-50E4-4E5D-B9D0-625D5DEBC671}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedHavalHashingMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.HavalHashingMethod\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A02A65C1-50E4-4E5D-B9D0-625D5DEBC671}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRijndaelEncryptionMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RijndaelEncryptionMethod.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{BBA63CAC-9913-4A13-9212-E97BB70C05C9}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRijndaelEncryptionMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RijndaelEncryptionMethod\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{BBA63CAC-9913-4A13-9212-E97BB70C05C9}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRSAEncryptionMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RSAEncryptionMethod.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{C3271080-C57A-4520-8066-337AD212D7E0}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRSAEncryptionMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RSAEncryptionMethod\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{C3271080-C57A-4520-8066-337AD212D7E0}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRSASigningMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RSASigningMethod.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{90FDB7BD-EB76-4AC9-8385-D1EE80BBCDCD}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedRSASigningMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.RSASigningMethod\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{90FDB7BD-EB76-4AC9-8385-D1EE80BBCDCD}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedSHAHashingMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.SHAHashingMethod.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{231D1CF6-C578-411D-9B9B-48264355805D}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedSHAHashingMethod Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.SHAHashingMethod\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{231D1CF6-C578-411D-9B9B-48264355805D}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedSigning Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Signing.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D865F1E7-BAC6-4ECA-B37B-0A5DDFF2D031}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedSigning Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.Signing\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D865F1E7-BAC6-4ECA-B37B-0A5DDFF2D031}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>XceedStandardCompressionFormat Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\Xceed.StandardCompressionFormat.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{47D7ED16-3901-11D5-8074-0060082AE372}.</Details>
</EntryDetails>
- <EntryDetails>

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#22 Příspěvek od marsellita »

žádný jiný log jsem nikde nenašla....ani si nejsem jistá zda to ARO 2011 je správný....

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: problém s fb

#23 Příspěvek od motji »

:?: to není on, combofix proběhl? Poprosím o nový log ze rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#24 Příspěvek od marsellita »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Marcelka at 2011-08-24 22:29:47
Microsoft® Windows Vista™ Home Basic
System drive C: has 11 GB (21%) free of 52 GB
Total RAM: 1526 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:29:52, on 24.8.2011
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Marcelka\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\Marcelka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UL7NE7H1\RSIT[1].exe
C:\Program Files\trend micro\Marcelka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cs.intl.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\ARO 2011\ARO.exe -rem
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Users\Marcelka\AppData\LocalLow\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - (no file)
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - (no file)
O15 - Trusted Zone: http://www.sipkovafitness.cz
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL, avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AVG WatchDog (avg9wd) - Unknown owner - C:\Program Files\AVG\AVG9\avgwdsvc.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ddservice - Unknown owner - C:\Windows\update.7.1\svchostdriver.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10279 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-12-09 333192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
CescrtHlpr Object - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll [2010-11-07 225720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar.dll [2009-02-23 745472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2008-06-12 1111904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Windows\system32\eDStoolbar.dll [2007-04-25 151552]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-12-09 333192]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar.dll [2009-02-23 745472]
{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} -
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll [2010-11-07 184760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2007-07-25 1006264]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-05-29 4472832]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-10-23 815104]
"Acer Tour"= []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2007-04-05 138008]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2007-04-05 154392]
"Persistence"=C:\Windows\system32\igfxpers.exe [2007-04-05 133912]
"eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2007-04-25 457216]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2007-06-15 850704]
"eRecoveryService"= []
"WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe /a /m C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll []
"SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2008-06-12 991584]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"BabylonToolbar"=C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe [2010-11-07 286720]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-13 1232896]
"Acer Tour Reminder"= []
"AROReminder"=C:\Program Files\ARO 2011\ARO.exe [2011-01-25 2312048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-03-08 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\au]
C:\Program Files\Dealio\DealioAU.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-11 30192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL, avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2007-03-30 204800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableSecureUIAPaths"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2011-08-24 18:08:52 ----D---- C:\Users\Marcelka\AppData\Roaming\Sammsoft
2011-08-24 18:05:44 ----D---- C:\Program Files\ARO 2011
2011-08-24 10:53:18 ----D---- C:\Users\Marcelka\AppData\Roaming\Malwarebytes
2011-08-24 10:52:11 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-08-24 10:52:09 ----D---- C:\ProgramData\Malwarebytes
2011-08-24 10:52:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-24 10:52:06 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-08-24 09:30:17 ----D---- C:\rsit
2011-08-24 09:30:17 ----D---- C:\Program Files\trend micro
2011-08-20 19:34:39 ----D---- C:\Windows\ufa
2011-08-20 19:34:39 ----D---- C:\Windows\phoenix
2011-08-20 19:33:02 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-20 19:31:49 ----HD---- C:\Windows\update.5.0
2011-08-20 19:31:36 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-20 19:31:02 ----HD---- C:\Windows\update.2
2011-08-20 19:30:40 ----A---- C:\Windows\unrar.exe
2011-08-20 19:30:26 ----HD---- C:\Windows\update.7.1
2011-08-20 19:30:10 ----A---- C:\Windows\iplist.txt
2011-08-20 19:28:49 ----A---- C:\Windows\front_ip_list.txt
2011-08-20 19:27:33 ----ASH---- C:\hiberfil.sys
2011-08-20 19:14:42 ----D---- C:\Windows\av_ico
2011-08-20 19:12:51 ----HD---- C:\Windows\update.1
2011-08-20 19:12:41 ----HD---- C:\Windows\update.tray-9-0-lnk
2011-08-20 19:12:41 ----HD---- C:\Windows\update.tray-9-0
2011-08-20 19:12:41 ----HD---- C:\Windows\update.tray-12-0-lnk
2011-08-20 19:12:41 ----HD---- C:\Windows\update.tray-12-0
2011-08-20 19:00:58 ----A---- C:\Windows\winlog-ids.txt
2011-08-20 19:00:58 ----A---- C:\Windows\winlog-dirs.txt
2011-08-18 08:04:30 ----D---- C:\Program Files\rajce

======List of files/folders modified in the last 1 month======

2011-08-24 22:29:52 ----D---- C:\Windows\Prefetch
2011-08-24 22:29:45 ----D---- C:\Windows\Temp
2011-08-24 20:24:47 ----AD---- C:\Windows\System32
2011-08-24 20:24:46 ----D---- C:\Windows\inf
2011-08-24 20:24:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-24 20:17:55 ----D---- C:\Windows\system32\config
2011-08-24 20:08:46 ----D---- C:\Windows\system32\catroot2
2011-08-24 20:08:40 ----SHD---- C:\System Volume Information
2011-08-24 18:05:44 ----RD---- C:\Program Files
2011-08-24 14:38:07 ----D---- C:\Windows\system
2011-08-24 14:38:07 ----AD---- C:\Windows\system32\drivers
2011-08-24 14:35:53 ----D---- C:\Windows
2011-08-24 14:35:52 ----D---- C:\Program Files\Dealio
2011-08-24 10:52:09 ----HD---- C:\ProgramData
2011-08-20 19:31:30 ----D---- C:\Windows\system32\drivers\etc
2011-08-20 19:26:36 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-08-20 19:13:43 ----D---- C:\Windows\system32\drivers\Avg
2011-08-11 08:46:12 ----SHD---- C:\Windows\Installer
2011-08-11 08:46:11 ----D---- C:\ProgramData\Microsoft Help
2011-08-11 08:38:26 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-02-17 161800]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-07-12 305176]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2007-04-25 20776]
R0 PSDNServ;PSDNSERVER; C:\Windows\system32\drivers\PSDNServ.sys [2007-04-25 16680]
R0 psdvdisk;psdvdisk; C:\Windows\system32\drivers\psdvdisk.sys [2007-04-25 60712]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-02-02 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-02-17 28424]
R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-02-17 360584]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2007-03-02 76584]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2006-11-02 95744]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-20 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-29 8192]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 534016]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2007-06-15 21264]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-12-22 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-12-22 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-03-30 1671680]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-05-31 1780576]
R3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2006-11-02 30720]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2007-11-23 82432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-10-23 179896]
R3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2007-05-02 290816]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-12-22 659968]
S1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-09 179712]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 534016]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-07-25 6144]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2006-11-02 429056]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BcmSqlStartupSvc;Služba spouštění serveru SQL Server aplikace Business Contact Manager; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 ddservice;ddservice; C:\Windows\update.7.1\svchostdriver.exe [2011-08-20 382464]
R2 eDataSecurity Service;eDSService.exe; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [2007-04-25 457512]
R2 eLockService;eLock Service; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [2007-04-23 24576]
R2 eNet Service;eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [2007-06-13 135168]
R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-07-03 53248]
R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-06-28 24576]
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 107008]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WMIService;ePower Service; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-06-13 167936]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-11-29 386560]
S2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe []
S2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe /m C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll []
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-11 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

-----------------EOF-----------------

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#25 Příspěvek od marsellita »

když jsem spustila ten combofix....nainstalovalo se mi "Check Pc for Erorrs" a pak ten ARO 2011.....tak nevím jestli proběhl??? poznáte to z toho rsitu?

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: problém s fb

#26 Příspěvek od motji »

Já tam combofix vůbec nevidím :?:
STahovala jste ho odtud?
http://www.bleepingcomputer.com/downloa ... s/combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#27 Příspěvek od marsellita »

z tohoto odkazu ne, ale z toho viz výe poslaného....mám stáhnout tento? a ten druhý pro visty?

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: problém s fb

#28 Příspěvek od motji »

Prosím Vás z jakého odkazu?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#29 Příspěvek od marsellita »


marsellita
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 24 Srp 2011 08:16

Re: problém s fb

#30 Příspěvek od marsellita »

tak asi z toho stejného, ale bylo tam zeleně download....tak jestli to nebyla nějská reklama....

Odpovědět