Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Detekovaná nákaza _ pre Vyoseka

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Detekovaná nákaza _ pre Vyoseka

#1 Příspěvek od Kovas »

Ako som Vám spomínal urobil som včera kontrolu notebooku, keďže bola nájdená nákaza v stolnom PC.

Avast detekoval :
Win32:Malware-gen
Win32:Dropper-GAG(Drp)


Po teste avastom som spustil CD s Kaspersky Rescue 10. Ten detekoval :
trojský kůň Backdoor.Win32.Poison.bqsr
trojský kůň Trojan-PSW.Win32.LdPinch.avcv
malware Constructor.Win32.MicroJoiner.n tento bol uložený D:/System Volume Information/_restore.........
Trojan.Win32.Buzus.dgcw

všetko bolo odstránené.
No je toho dosť, uff :roll:

Prikladám log RSIT :

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kovas at 2012-02-24 20:27:25
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 14 GB (46%) free of 30 GB
Total RAM: 1976 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:28:21, on 24.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fingerprint Sensor\AtService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\Program Files\Hewlett-Packard\IAM\bin\AsGHost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
D:\Programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
d:\Programy\SuperAntispyware\SASCORE.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\Programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\totalcmd\TOTALCMD.EXE
d:\Instal\RSIT\RSIT.exe
C:\Program Files\trend micro\Kovas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsof
Naposledy upravil(a) Kovas dne 24 úno 2012 20:48, celkem upraveno 1 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Jeste tam neco mame :boxed:

:arrow: Havet se usadila v bodech obnoveni - smazte je dle navodu kolegy riffa http://www.viry.cz/forum/viewtopic.php?f=11&t=47040

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#3 Příspěvek od Kovas »

Log z ComboFix-u

ComboFix 12-02-24.02 - Administrator 24.02.2012 21:33:10.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1976.1444 [GMT 1:00]
Spuštěný z: c:\documents and settings\Kovas\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Outpost Firewall Pro *Disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-24 do 2012-02-24 )))))))))))))))))))))))))))))))
.
.
2012-02-24 09:06 . 2004-11-30 11:28 86094 ----a-w- c:\windows\system32\ImageDrive.cpl
2012-02-23 22:59 . 2005-04-25 09:43 159616 ----a-w- c:\windows\system32\drivers\Vax347b.sys
2012-02-23 22:59 . 2004-04-30 08:33 5248 ----a-w- c:\windows\system32\drivers\Vax347s.sys
2012-02-23 20:19 . 2012-02-24 00:41 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-02-23 07:51 . 2012-02-23 07:51 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-16 17:30 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-16 17:30 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-13 20:39 . 2012-02-13 20:39 -------- d-----w- c:\documents and settings\Kovas\Local Settings\Data aplikací\Help
2012-02-11 21:07 . 2012-02-11 21:07 -------- d-----w- c:\windows\wb
2012-02-11 21:07 . 1996-08-16 11:44 87552 ----a-w- c:\windows\system\url.dll
2012-02-11 21:07 . 1996-09-30 10:32 9728 ----a-w- c:\windows\system\rnaph.dll
2012-02-07 20:00 . 2012-02-07 20:00 -------- d-----w- c:\documents and settings\Kovas\.thumbnails
2012-02-07 19:59 . 2012-02-07 20:16 -------- d-----w- c:\documents and settings\Kovas\Data aplikací\gtk-2.0
2012-02-07 19:57 . 2012-02-07 20:24 -------- d-----w- c:\documents and settings\Kovas\.gimp-2.6
2012-01-30 21:59 . 2012-01-30 23:05 -------- d-----w- c:\documents and settings\Kovas\Data aplikací\GARMIN
2012-01-30 21:59 . 2012-01-30 21:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GARMIN
2012-01-28 10:27 . 2012-01-28 10:27 -------- d-----w- c:\program files\DIFX
2012-01-28 10:27 . 2012-01-28 14:21 -------- d-----w- c:\program files\Garmin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 16:23 . 2011-02-01 23:22 41184 ----a-w- c:\windows\avastSS.scr
2012-02-23 16:23 . 2012-01-09 00:28 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-02-23 16:12 . 2012-01-09 00:29 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-23 16:12 . 2012-01-09 00:29 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-02-23 16:10 . 2012-01-09 00:29 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-02-23 16:10 . 2012-01-09 00:29 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-02-23 16:10 . 2012-01-09 00:29 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-02-23 16:10 . 2012-01-09 00:29 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-02-23 16:07 . 2012-01-09 00:29 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-20 07:36 . 2011-05-18 16:21 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 17:20 . 2004-08-17 13:44 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2004-08-17 13:49 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-17 19:42 . 2004-08-17 13:49 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2004-08-17 13:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-16 12:23 . 2004-08-17 13:44 385024 ----a-w- c:\windows\system32\html.iec
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-02-23 16:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateMes"="c:\documents and settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe" [2011-07-09 8192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-04 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-04 170008]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-04 145432]
"vspdfprsrv.exe"="d:\programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe" [2007-07-02 1179648]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2010-05-25 2814656]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2010-05-25 490760]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-3-31 576104]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programy\SuperAntispyware\SASSEH.DLL" [2012-01-09 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- d:\programy\SuperAntispyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 15:14 113152 ----a-w- c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 15:13 299520 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2010-01-18 04:59 192768 ----a-w- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CognizanceTS]
2010-01-18 04:59 24832 ----a-w- c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2007-12-22 23:03 916240 ----a-w- d:\programy\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
2010-04-13 09:40 358456 ----a-w- c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2010-02-25 14:19 287800 ------w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 ----a-w- d:\programy\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2012-01-09 19:23 4616064 ----a-w- d:\programy\SuperAntispyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
2007-02-20 10:07 199752 ----a-w- c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-04-10 17:29 37888 ----a-w- d:\programy\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2010-05-20 08:04 500792 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"HpFkCryptService"=2 (0x2)
"HP ProtectTools Service"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Programy\\Skype\\Phone\\Skype.exe"=
.
R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [5.3.2010 11:08 109288]
R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [5.3.2010 11:09 51480]
R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [5.3.2010 11:09 13032]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28.3.2008 10:14 24064]
R0 Vax347b;Vax347b;c:\windows\system32\drivers\Vax347b.sys [23.2.2012 23:59 159616]
R0 Vax347s;Vax347s;c:\windows\system32\drivers\Vax347s.sys [23.2.2012 23:59 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9.1.2012 1:29 610648]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.1.2012 1:29 337112]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [5.3.2010 11:08 12600]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [9.1.2012 1:18 713672]
R1 SASDIFSV;SASDIFSV;d:\programy\SuperAntispyware\SASDIFSV.SYS [17.2.2010 19:25 12880]
R1 SASKUTIL;SASKUTIL;d:\programy\SuperAntispyware\SASKUTIL.SYS [10.5.2010 19:41 67664]
R2 !SASCORE;SAS Core Service;d:\programy\SuperAntispyware\SASCORE.EXE [29.6.2010 18:48 116608]
R2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [3.6.2009 16:16 207400]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [17.8.2004 14:49 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Bioscrypt [17.8.2004 14:49 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.1.2012 1:29 20696]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [29.7.2009 12:43 1201400]
R2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [20.11.2009 2:46 4715880]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [9.1.2012 1:17 34280]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [9.1.2012 1:18 267624]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2.2.2011 11:23 482176]
R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [20.11.2009 2:47 7040]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [20.11.2009 2:47 24320]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [9.1.2012 1:17 2023128]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [9.1.2012 1:18 31528]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2.2.2011 18:46 227896]
S3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23.7.2008 11:31 44800]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2.2.2011 0:33 27064]
S4 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [13.4.2010 10:36 45056]
S4 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [5.3.2010 11:08 256616]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker
Bioscrypt REG_MULTI_SZ ASChannel
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 217.119.113.244 172.18.100.15
FF - ProfilePath - c:\documents and settings\Kovas\Data aplikací\Mozilla\Firefox\Profiles\2tddgd57.default\
FF - prefs.js: browser.search.selectedEngine - Vyhľadávanie Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 50
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1648)
d:\programy\SuperAntispyware\SASWINLO.DLL
c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
c:\program files\ActivIdentity\ActivClient\aclog.dll
c:\program files\ActivIdentity\ActivClient\accrypto.dll
c:\program files\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
c:\program files\Hewlett-Packard\IAM\bin\itmsg.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\program files\ActivIdentity\ActivClient\aipingui.dll
c:\program files\ActivIdentity\ActivClient\acevtsub.dll
c:\program files\ActivIdentity\ActivClient\asphat32.dll
c:\program files\ActivIdentity\ActivClient\acerrmes.dll
c:\program files\ActivIdentity\ActivClient\aiwinext.dll
c:\program files\ActivIdentity\ActivClient\aspcom.dll
c:\program files\ActivIdentity\ActivClient\aicext.dll
c:\program files\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\acunlockrc.dll
c:\program files\Hewlett-Packard\IAM\Bin\TrayIcon.dll
c:\program files\Hewlett-Packard\IAM\bin\brand.dll
c:\program files\Hewlett-Packard\IAM\bin\AsChnl.dll
c:\program files\Hewlett-Packard\IAM\Bin\HPPlugIn.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHostServices.dll
c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTStrings.dll
c:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
c:\windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_cs_b77a5c561934e089\System.Xml.resources.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\Interop.PTHstServsLib.dll
.
- - - - - - - > 'explorer.exe'(4004)
c:\program files\Hewlett-Packard\IAM\bin\APSHook.dll
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\DisplayLink Core Software\DisplayLinkUserAgent.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\DisplayLink Core Software\DisplayLinkUI.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Hewlett-Packard\IAM\bin\AsGHost.exe
d:\programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-02-24 21:42:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-24 20:42
.
Před spuštěním: Volných bajtů: 17 723 047 936
Po spuštění: Volných bajtů: 18 101 129 216
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 59F54AFFD5C5B79DE947694D6D7AC3FE

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#4 Příspěvek od vyosek »

Co jste mi udelal se RSITem, vsak je ho kousek, ja ho potrebuju celej :shock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#5 Příspěvek od Kovas »

hm... chybička se vloudila :?: . Ešte raz log z RSIT :

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kovas at 2012-02-24 20:27:25
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 14 GB (46%) free of 30 GB
Total RAM: 1976 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:28:21, on 24.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fingerprint Sensor\AtService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
C:\Program Files\Hewlett-Packard\IAM\bin\AsGHost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
D:\Programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
d:\Programy\SuperAntispyware\SASCORE.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\Programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\totalcmd\TOTALCMD.EXE
d:\Instal\RSIT\RSIT.exe
C:\Program Files\trend micro\Kovas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] D:\Programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [OutpostMonitor] "C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe" /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [UpdateMes] C:\Documents and Settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll c:\progra~1\hewlet~1\iam\bin\apshook.dll
O20 - Winlogon Notify: !SASWinLogon - d:\Programy\SuperAntispyware\SASWINLO.DLL
O20 - Winlogon Notify: ackpbsc - C:\Program Files\ActivIdentity\ActivClient\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O20 - Winlogon Notify: OneCard - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - d:\Programy\SuperAntispyware\SASCORE.EXE
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - C:\Program Files\Fingerprint Sensor\AtService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - d:\Programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 8625 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Driver Robot.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-02-23 998560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
Credential Manager for HP ProtectTools - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2010-01-18 98560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-02-23 998560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2008-03-24 884736]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2010-08-04 136216]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2010-08-04 170008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2010-08-04 145432]
""= []
"vspdfprsrv.exe"=D:\Programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe [2007-07-02 1179648]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"OutpostMonitor"=C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe [2010-05-25 2814656]
"OutpostFeedBack"=C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe [2010-05-25 490760]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-02-23 4031368]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"UpdateMes"=C:\Documents and Settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe [2011-07-09 8192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CognizanceTS]
C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2010-01-18 24832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
D:\Programy\Eraser\Eraser.exe [2007-12-23 916240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2010-04-13 358456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2010-02-25 287800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
D:\Programy\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
d:\Programy\SuperAntispyware\SUPERANTISPYWARE.EXE [2012-01-09 4616064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
D:\Programy\Winamp\winampa.exe [2009-04-10 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2010-05-20 500792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"HpFkCryptService"=2
"HP ProtectTools Service"=3

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~1\agnitum\outpos~1\wl_hook.dll c:\progra~1\hewlet~1\iam\bin\apshook.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
d:\Programy\SuperAntispyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ackpbsc]
C:\Program Files\ActivIdentity\ActivClient\ackpbsc.dll [2009-06-03 113152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\acunlock]
C:\Program Files\ActivIdentity\ActivClient\acunlock.dll [2009-06-03 299520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-05-14 214016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OneCard]
C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [2010-01-18 192768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=d:\Programy\SuperAntispyware\SASSEH.DLL [2012-01-09 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Programy\Skype\Plugin Manager\skypePM.exe"="D:\Programy\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\Programy\Pinnacle\Studio 14\Programs\RM.exe"="D:\Programy\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Programy\Pinnacle\Studio 14\Programs\Studio.exe"="D:\Programy\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
"D:\Programy\Pinnacle\Studio 14\Programs\umi.exe"="D:\Programy\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Programy\Skype\Phone\Skype.exe"="D:\Programy\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2012-02-24 00:01:09 ----A---- C:\WINDOWS\system32\BASSMOD.dll
2012-02-23 23:59:21 ----A---- C:\WINDOWS\system32\drivers\Vax347s.sys
2012-02-23 23:59:21 ----A---- C:\WINDOWS\system32\drivers\Vax347b.sys
2012-02-23 21:19:45 ----AD---- C:\Kaspersky Rescue Disk 10.0
2012-02-16 18:49:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2660465$
2012-02-16 18:48:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-02-16 18:30:53 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-02-13 21:39:54 ----D---- C:\Documents and Settings\Kovas\Data aplikací\Help
2012-02-11 22:07:23 ----D---- C:\WINDOWS\wb
2012-02-07 20:59:01 ----D---- C:\Documents and Settings\Kovas\Data aplikací\gtk-2.0
2012-01-30 22:59:20 ----D---- C:\Documents and Settings\Kovas\Data aplikací\GARMIN
2012-01-30 22:59:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\GARMIN
2012-01-28 11:27:15 ----D---- C:\Program Files\DIFX
2012-01-28 11:27:11 ----D---- C:\Program Files\Garmin

======List of files/folders modified in the last 1 months======

2012-02-24 20:28:21 ----D---- C:\WINDOWS\Prefetch
2012-02-24 20:28:17 ----D---- C:\Program Files\trend micro
2012-02-24 20:17:45 ----D---- C:\WINDOWS\Temp
2012-02-24 16:39:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-24 16:34:17 ----D---- C:\WINDOWS
2012-02-24 16:31:58 ----D---- C:\WINDOWS\system32\CatRoot2
2012-02-24 16:30:38 ----D---- C:\WINDOWS\Debug
2012-02-24 16:30:38 ----D---- C:\Documents and Settings\Kovas\Data aplikací\Winamp
2012-02-24 10:57:16 ----HD---- C:\WINDOWS\inf
2012-02-24 10:56:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-02-24 10:06:07 ----D---- C:\WINDOWS\system32
2012-02-23 23:59:33 ----SHD---- C:\WINDOWS\Installer
2012-02-23 23:59:21 ----D---- C:\WINDOWS\system32\drivers
2012-02-23 17:23:21 ----A---- C:\WINDOWS\system32\aswBoot.exe
2012-02-22 20:26:57 ----A---- C:\WINDOWS\VPlayer.INI
2012-02-20 23:50:03 ----D---- C:\Documents and Settings\Kovas\Data aplikací\Skype
2012-02-16 18:59:28 ----D---- C:\WINDOWS\Microsoft.NET
2012-02-16 18:59:15 ----RSD---- C:\WINDOWS\assembly
2012-02-16 18:53:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-02-16 18:52:53 ----D---- C:\WINDOWS\WinSxS
2012-02-16 18:49:24 ----A---- C:\WINDOWS\system32\MRT.exe
2012-02-16 18:49:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-02-16 18:49:01 ----D---- C:\Program Files\Internet Explorer
2012-02-16 18:48:48 ----D---- C:\WINDOWS\ie8updates
2012-02-16 18:48:44 ----HD---- C:\WINDOWS\$hf_mig$
2012-02-11 22:07:29 ----D---- C:\WINDOWS\system
2012-02-11 20:31:02 ----D---- C:\Documents and Settings\Kovas\Data aplikací\NwDocx
2012-02-02 22:29:36 ----RD---- C:\Program Files
2012-01-28 11:27:12 ----DC---- C:\WINDOWS\system32\DRVSTORE

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Disk Filter Driver; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2008-05-23 24624]
R0 imagedrv;imagedrv; C:\WINDOWS\System32\Drivers\imagedrv.sys [2004-03-02 5504]
R0 imagesrv;imagesrv; C:\WINDOWS\system32\DRIVERS\imagesrv.sys [2004-03-02 125184]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-08-20 44944]
R0 SafeBoot;SafeBoot; C:\WINDOWS\system32\drivers\SafeBoot.sys [2010-03-05 109288]
R0 SbAlg;SbAlg; C:\WINDOWS\system32\drivers\SbAlg.sys [2010-03-05 51480]
R0 SbFsLock;SbFsLock; C:\WINDOWS\system32\drivers\SbFsLock.sys [2010-03-05 13032]
R0 SFAUDIO;Sonic Focus DSP Driver; C:\WINDOWS\system32\drivers\sfaudio.sys [2008-03-28 24064]
R0 Vax347b;Vax347b; C:\WINDOWS\system32\DRIVERS\Vax347b.sys [2005-04-25 159616]
R0 Vax347s;Vax347s; C:\WINDOWS\System32\Drivers\Vax347s.sys [2004-04-30 5248]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-02-23 24920]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2012-02-23 35672]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-02-23 610648]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-02-23 337112]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 RsvLock;RsvLock; C:\WINDOWS\system32\drivers\RsvLock.sys [2010-03-05 12600]
R1 SandBox;SandBox; \??\C:\WINDOWS\system32\drivers\SandBox.sys []
R1 SASDIFSV;SASDIFSV; \??\d:\Programy\SuperAntispyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\d:\Programy\SuperAntispyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-02-23 20696]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-02-23 95704]
R3 Accelerometer;HP Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2008-05-23 28592]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-12-11 338944]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 afw;Agnitum firewall driver; C:\WINDOWS\system32\DRIVERS\afw.sys [2010-04-20 34280]
R3 afwcore;afwcore; C:\WINDOWS\system32\drivers\afwcore.sys [2010-05-20 267624]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver; C:\WINDOWS\System32\Drivers\ATSwpWDF.sys [2010-03-01 482176]
R3 b57w2k;Broadcom NetLink (TM) Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-11-26 187392]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2008-04-03 539512]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-04-03 37424]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-04-03 879624]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-04-03 156392]
R3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2008-04-03 55352]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-04-03 74688]
R3 DisplayLinkFilter;DisplayLinkFilter; C:\WINDOWS\system32\DRIVERS\DisplayLinkFilter.sys [2009-11-20 7040]
R3 DisplayLinkmirror;DisplayLinkmirror; C:\WINDOWS\system32\DRIVERS\DisplayLinkmirrorport.sys [2009-11-20 24320]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2010-02-25 9216]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2010-02-25 16768]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-05-14 1993472]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NETw5x32;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2010-04-05 6601216]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 ASWFilt;ASWFilt; \??\C:\WINDOWS\system32\Filt\ASWFilt.dll []
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2008-07-23 44800]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [2009-12-30 27064]
S3 Ser2pl;Prolific2 Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2005-07-25 48640]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; d:\Programy\SuperAntispyware\SASCORE.EXE [2012-01-09 116608]
R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 acssrv;Agnitum Client Security Service; C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2010-05-25 2023128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2008-03-18 13312]
R2 ASBroker;Logon Session Broker; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ASChannel;Local Communication Channel; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ATService;AuthenTec Fingerprint Service; C:\Program Files\Fingerprint Sensor\AtService.exe [2009-07-29 1201400]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-02-23 44768]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-03-31 264800]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2009-11-20 4715880]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 StarWindService;StarWind iSCSI Service; d:\Programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-08-31 710200]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S4 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S4 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2010-04-13 45056]
S4 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2010-03-05 256616]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#6 Příspěvek od vyosek »

:arrow: A proc jste jej vubec editoval, nejak mi to nejde do hlavy :?:

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Registry::
    
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    ""=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    UpdateMes"=-
    
    Collect::
    C:\Documents and Settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe
    
    Folder::
    C:\Documents and Settings\Kovas\Data aplikací\Updatem
    
    DDS::
    uInternet Settings,ProxyServer = http=;ftp=;https=;
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Kovas\Data aplikací\Mozilla\Firefox\Profiles\2tddgd57.default\
    FF - user.js: browser.blink_allowed - true
    FF - user.js: network.prefetch-next - true
    FF - user.js: nglayout.initialpaint.delay - 50
    FF - user.js: layout.spellcheckDefault - 1
    FF - user.js: browser.search.openintab - false
    FF - user.js: browser.tabs.closeButtons - 1
    FF - user.js: browser.tabs.opentabfor.middleclick - true
    FF - user.js: browser.tabs.tabMinWidth - 100
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#7 Příspěvek od Kovas »

Myslíte, že som editoval log RSIT? To nie :D Jednoducho som to robil automaticky a namiesto, že by som bol stlačil ctrl-A a celé to bezpečne vyznačil, som to jednoducho vyznačoval kurzorom no a asi som si nevšimol, že je toho viac ako som potiahol kurzorom.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#8 Příspěvek od vyosek »

OK, mrsknete tam ten log pro CF, at mame hotovo :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#9 Příspěvek od Kovas »

No mám s tým problém. Pred spustením Combofixu som vypol AV a firewall no a potom som script pretiahol na Combofix. Veštko bežalo OK. Systém sa potom reštartoval nabehol a potom sa objavilo okno Combofixu, ktoré upozorňovalo, že pracuje. Potom sa mi vyhodila modrá obrazovka a systém sa reštartoval. Znova nabehol. Neobjavil sa mi však log z Combofixu. teraz ho hľadám, kde je, ale na C:/ nie je. Nie ani v adresáry Qoobox

Tak neviem čo sa stalo.
Naposledy upravil(a) Kovas dne 25 úno 2012 16:53, celkem upraveno 1 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#10 Příspěvek od vyosek »

Zkuste jej aplikovat jeste jednou ale v nouzovem rezimu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#11 Příspěvek od Kovas »

Tak urobil som to v núdzovom režime, ale Combofix ma upozorňoval, že Avast je zapnutý aj keď som to kontroloval a spustený nebol. Nakoniec to celé zbehlo. Po reštarte systému keď Combofix ďalej pracoval, ale znova sa spúšťal firewall a Avast. Avast potom začal všetky procesy Combofixu testovať sandboxe. Ja som to zmenil, aby boli tieto procesy spustené v normálnom režime. Combofix ešte poslal na server na test súbory na podozrenie na malware. Celé to zbehlo a vyhodil log :

ComboFix 12-02-24.02 - Administrator 25.02.2012 17:20:19.3.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1976.1701 [GMT 1:00]
Spuštěný z: c:\documents and settings\Kovas\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Kovas\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Outpost Firewall Pro *Enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
.
file zipped: c:\documents and settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-25 do 2012-02-25 )))))))))))))))))))))))))))))))
.
.
2012-02-24 09:06 . 2004-11-30 11:28 86094 ----a-w- c:\windows\system32\ImageDrive.cpl
2012-02-23 22:59 . 2005-04-25 09:43 159616 ----a-w- c:\windows\system32\drivers\Vax347b.sys
2012-02-23 22:59 . 2004-04-30 08:33 5248 ----a-w- c:\windows\system32\drivers\Vax347s.sys
2012-02-23 20:19 . 2012-02-24 00:41 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-02-23 07:51 . 2012-02-23 07:51 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-16 17:30 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-16 17:30 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-13 20:39 . 2012-02-13 20:39 -------- d-----w- c:\documents and settings\Kovas\Local Settings\Data aplikací\Help
2012-02-11 21:07 . 2012-02-11 21:07 -------- d-----w- c:\windows\wb
2012-02-11 21:07 . 1996-08-16 11:44 87552 ----a-w- c:\windows\system\url.dll
2012-02-11 21:07 . 1996-09-30 10:32 9728 ----a-w- c:\windows\system\rnaph.dll
2012-02-07 20:00 . 2012-02-07 20:00 -------- d-----w- c:\documents and settings\Kovas\.thumbnails
2012-02-07 19:59 . 2012-02-07 20:16 -------- d-----w- c:\documents and settings\Kovas\Data aplikací\gtk-2.0
2012-02-07 19:57 . 2012-02-07 20:24 -------- d-----w- c:\documents and settings\Kovas\.gimp-2.6
2012-01-30 21:59 . 2012-01-30 23:05 -------- d-----w- c:\documents and settings\Kovas\Data aplikací\GARMIN
2012-01-30 21:59 . 2012-01-30 21:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GARMIN
2012-01-28 10:27 . 2012-01-28 10:27 -------- d-----w- c:\program files\DIFX
2012-01-28 10:27 . 2012-01-28 14:21 -------- d-----w- c:\program files\Garmin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 16:23 . 2011-02-01 23:22 41184 ----a-w- c:\windows\avastSS.scr
2012-02-23 16:23 . 2012-01-09 00:28 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-02-23 16:12 . 2012-01-09 00:29 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-23 16:12 . 2012-01-09 00:29 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-02-23 16:10 . 2012-01-09 00:29 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-02-23 16:10 . 2012-01-09 00:29 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-02-23 16:10 . 2012-01-09 00:29 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-02-23 16:10 . 2012-01-09 00:29 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-02-23 16:07 . 2012-01-09 00:29 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-20 07:36 . 2011-05-18 16:21 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 17:20 . 2004-08-17 13:44 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2004-08-17 13:49 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-17 19:42 . 2004-08-17 13:49 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2004-08-17 13:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-16 12:23 . 2004-08-17 13:44 385024 ----a-w- c:\windows\system32\html.iec
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-02-23 16:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateMes"="c:\documents and settings\Kovas\Data aplikací\Updatem\updatesys\updatesys.exe" [2011-07-09 8192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-04 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-04 170008]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-04 145432]
"vspdfprsrv.exe"="d:\programy\Visagesoft\eXPert PDF 5\vspdfprsrv.exe" [2007-07-02 1179648]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2010-05-25 2814656]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2010-05-25 490760]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-3-31 576104]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programy\SuperAntispyware\SASSEH.DLL" [2012-01-09 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- d:\programy\SuperAntispyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 15:14 113152 ----a-w- c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 15:13 299520 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2010-01-18 04:59 192768 ----a-w- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CognizanceTS]
2010-01-18 04:59 24832 ----a-w- c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2007-12-22 23:03 916240 ----a-w- d:\programy\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
2010-04-13 09:40 358456 ----a-w- c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2010-02-25 14:19 287800 ------w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 ----a-w- d:\programy\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2012-01-09 19:23 4616064 ----a-w- d:\programy\SuperAntispyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
2007-02-20 10:07 199752 ----a-w- c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-04-10 17:29 37888 ----a-w- d:\programy\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2010-05-20 08:04 500792 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"HpFkCryptService"=2 (0x2)
"HP ProtectTools Service"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"d:\\Programy\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Programy\\Skype\\Phone\\Skype.exe"=
.
R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [5.3.2010 11:08 109288]
R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [5.3.2010 11:09 51480]
R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [5.3.2010 11:09 13032]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28.3.2008 10:14 24064]
R0 Vax347b;Vax347b;c:\windows\system32\drivers\Vax347b.sys [23.2.2012 23:59 159616]
R0 Vax347s;Vax347s;c:\windows\system32\drivers\Vax347s.sys [23.2.2012 23:59 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9.1.2012 1:29 610648]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.1.2012 1:29 337112]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [5.3.2010 11:08 12600]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [9.1.2012 1:18 713672]
R1 SASDIFSV;SASDIFSV;d:\programy\SuperAntispyware\SASDIFSV.SYS [17.2.2010 19:25 12880]
R1 SASKUTIL;SASKUTIL;d:\programy\SuperAntispyware\SASKUTIL.SYS [10.5.2010 19:41 67664]
R2 !SASCORE;SAS Core Service;d:\programy\SuperAntispyware\SASCORE.EXE [29.6.2010 18:48 116608]
R2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [3.6.2009 16:16 207400]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [9.1.2012 1:17 2023128]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [17.8.2004 14:49 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Bioscrypt [17.8.2004 14:49 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.1.2012 1:29 20696]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [29.7.2009 12:43 1201400]
R2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [20.11.2009 2:46 4715880]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [9.1.2012 1:17 34280]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [9.1.2012 1:18 267624]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2.2.2011 11:23 482176]
R3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [20.11.2009 2:47 7040]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [20.11.2009 2:47 24320]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [9.1.2012 1:18 31528]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2.2.2011 18:46 227896]
S3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23.7.2008 11:31 44800]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2.2.2011 0:33 27064]
S4 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [13.4.2010 10:36 45056]
S4 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [5.3.2010 11:08 256616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker
Bioscrypt REG_MULTI_SZ ASChannel
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 217.119.113.244 172.18.100.15
FF - ProfilePath - c:\documents and settings\Kovas\Data aplikací\Mozilla\Firefox\Profiles\2tddgd57.default\
FF - prefs.js: browser.search.selectedEngine - Vyhľadávanie Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1664)
d:\programy\SuperAntispyware\SASWINLO.DLL
c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
c:\program files\ActivIdentity\ActivClient\aclog.dll
c:\program files\ActivIdentity\ActivClient\accrypto.dll
c:\program files\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
c:\program files\Hewlett-Packard\IAM\bin\itmsg.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\program files\ActivIdentity\ActivClient\aipingui.dll
c:\program files\ActivIdentity\ActivClient\acevtsub.dll
c:\program files\ActivIdentity\ActivClient\asphat32.dll
c:\program files\ActivIdentity\ActivClient\acerrmes.dll
c:\program files\ActivIdentity\ActivClient\aiwinext.dll
c:\program files\ActivIdentity\ActivClient\aspcom.dll
c:\program files\ActivIdentity\ActivClient\aicext.dll
c:\program files\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\acunlockrc.dll
c:\program files\Hewlett-Packard\IAM\Bin\TrayIcon.dll
c:\program files\Hewlett-Packard\IAM\bin\brand.dll
c:\program files\Hewlett-Packard\IAM\bin\AsChnl.dll
c:\program files\Hewlett-Packard\IAM\Bin\HPPlugIn.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHostServices.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTStrings.dll
c:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
c:\windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_cs_b77a5c561934e089\System.Xml.resources.dll
c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\Interop.PTHstServsLib.dll
.
- - - - - - - > 'explorer.exe'(3456)
c:\program files\Hewlett-Packard\IAM\bin\APSHook.dll
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\DisplayLink Core Software\DisplayLinkUserAgent.exe
c:\program files\DisplayLink Core Software\DisplayLinkUI.exe
c:\program files\Hewlett-Packard\IAM\bin\AsGHost.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\programy\Alkohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Celkový čas: 2012-02-25 17:33:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-25 16:33
ComboFix2.txt 2012-02-24 20:42
.
Před spuštěním: Volných bajtů: 17 959 698 432
Po spuštění: Volných bajtů: 17 935 867 904
.
- - End Of File - - 9746F5AAB6A69250177A00A21E056A1D
Nahr nˇ probŘhlo ŁspŘçnŘ

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#12 Příspěvek od vyosek »

:arrow: vypnete Avast a i jeho Sanbox

:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    UpdateMes"=-
    
    :files
    C:\Documents and Settings\Kovas\Data aplikací\Updatem
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#13 Příspěvek od Kovas »

Dobrý deň prajem.

No po skúsenosti s Avastom po spustení Combofixu som to urobil tak, že som v nástrojoch pre konfiguráciu systému vypol služby firewallu a Avastu a vypol som ich aj pri spúšťaní systému. Odpojil som notebook od netu a reštartoval. Potom som spustil OTM. Lebo ako som skúšal v Avaste aj keď ho vypnem napr. na 1 hodinu, vypnú sa tam len štíty, ale sandbox tam vždy je. Asi som ho mal vypnúť priamo v nastaveniach sandboxu. Aj keby som to bol tak urobil tak vždy po reštarte sa znova Avast zapne celý a to mi potom pri Combofixe asi neurobilo dobre. Myslím si, že týmto postupom som nič nepokazil :)

Tu je log z OTM :

All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateMes" not found.
========== FILES ==========
C:\Documents and Settings\Kovas\Data aplikací\Updatem\updatesys folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\res\html folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\res\fonts folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\res\entityTables folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\res\dtd folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\res folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\plugins folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\modules folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\greprefs folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\dictionaries folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\profile\US\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\profile\US folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\profile\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\profile folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\pref folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults\autoconfig folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\defaults folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\components folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_zupdate folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\res\html folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\res\fonts folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\res\entityTables folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\res\dtd folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\res folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\plugins folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\modules folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\greprefs folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\dictionaries folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\profile\US\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\profile\US folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\profile\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\profile folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\pref folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults\autoconfig folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\defaults folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\components folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update\chrome folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem\d_update folder moved successfully.
C:\Documents and Settings\Kovas\Data aplikací\Updatem folder moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\002699_.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Kovas
->Temp folder emptied: 1506801 bytes
->Temporary Internet Files folder emptied: 904704 bytes
->Java cache emptied: 8852 bytes
->FireFox cache emptied: 50301219 bytes
->Flash cache emptied: 748 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 51,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: Kovas
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 02272012_094551

Files moved on Reboot...
C:\Documents and Settings\Kovas\Local Settings\Temp\ima1.tmp moved successfully.
C:\Documents and Settings\Kovas\Local Settings\Temp\ima2.tmp moved successfully.

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Detekovaná nákaza _ pre Vyoseka

#14 Příspěvek od vyosek »

Zdravim :)

OTM probehlo OK, jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Kovas
Návštěvník
Návštěvník
Příspěvky: 331
Registrován: 24 pro 2008 13:10

Re: Detekovaná nákaza _ pre Vyoseka

#15 Příspěvek od Kovas »

No tak je to citeľná zmena, k lepšiemu :) Vďaka.

No a veľmi sa mi pozdáva nová verzia Avast free 7, čo som ju aktualizoval. Je veľmi dobre nastavená, až paranicky, zvlášť pre deti. Všetko podozrivé stopne.

Odpovědět