Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zavirovaný PC, Autorun,inf

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#16 Příspěvek od Domeek »

Tady je screenshot z Avastu, jsou to přesně ty soubory, o kterých jsem hovořil. Na usb discích ve složce, která nemá název. Divné. :shock:
avast.rar
(26.39 KiB) Staženo 34 x

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#17 Příspěvek od Domeek »

Avastem jsem uvedené soubory zavřel po skenu do truhly.
Jeden jsem obnovil a projel na Virustotal, zde je výsledek
https://www.virustotal.com/file/e65c89e ... 360504557/

Screen z Huntera:
hunter.rar
(41.08 KiB) Staženo 39 x
Jinak ta "divna" slozka bez nazvu na usb discich, je jejich obsah pred zavirovanim.

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#18 Příspěvek od Domeek »

Tady je obsah usb s breberkou.

http://leteckaposta.cz/643943823

Můžu usb disky naformátovat? Abych se podíval, zda když ho odpojím a pak zapojím nedostanu breberku zpátky.

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#19 Příspěvek od Domeek »

USB disky naformátovány, odpojeny. Provedl jsem reset PC, připojil disky. Zatím se na ně nic nezapsalo. Provádím vakcinaci subfixem.

Po spuštění PC se pokouší nějaký instalátor spustit instalaci PhotoGallery, nevím o co se jedná a jaký proces to vše spouští. Můžeme na to mrknout?

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#20 Příspěvek od Domeek »

Tady je požadovaný screen
Hunter_procesy.rar
(233.62 KiB) Staženo 27 x

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#21 Příspěvek od Domeek »

Potíž je v tom, že to chce disk, a já žádný nemám. Zatím to tedy nechám, domluvím se s majitelem na co to používá.
Budeme ještě čistit, nebo už je to všechno? :)

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#22 Příspěvek od Domeek »


Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#23 Příspěvek od Domeek »

Nový log RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by win-xp at 2013-02-10 16:31:04
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 55 GB (36%) free of 153 GB
Total RAM: 2046 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:31:08, on 10.2.2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\win-xp\Plocha\RSIT.exe
C:\Program Files\trend micro\win-xp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [LaunchList] D:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6391 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-09 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-09 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-11-07 8523776]
"nwiz"=nwiz.exe /install []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-11-07 81920]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-02-12 49152]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"NPSStartup"= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LaunchList"=D:\Program Files\Pinnacle\Studio 11\LaunchList2.exe [2007-03-21 145496]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-05 68856]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office\OSA9.EXE
Rychlé spuštění aplikace HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\59426988.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\59426988.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MJPG"=Pvmjpg30.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2013-02-10 15:32:15 ----RASHD---- C:\Autorun.inf
2013-02-10 14:09:33 ----A---- C:\TDSSKiller.2.8.15.0_10.02.2013_14.09.33_log.txt
2013-02-10 14:07:33 ----D---- C:\TDSSKiller_Quarantine
2013-02-10 14:05:50 ----A---- C:\TDSSKiller.2.8.15.0_10.02.2013_14.05.50_log.txt
2013-02-10 13:17:39 ----D---- C:\Documents and Settings\win-xp\Data aplikací\WinRAR
2013-02-10 13:17:34 ----D---- C:\Program Files\WinRAR
2013-02-10 10:41:16 ----A---- C:\UsbFix.txt
2013-02-10 10:41:14 ----D---- C:\UsbFix
2013-02-10 10:36:52 ----N---- C:\TDSSKiller.2.8.15.0_10.02.2013_10.36.52_log.txt
2013-02-10 10:17:12 ----D---- C:\_OTL
2013-02-10 10:14:59 ----D---- C:\WINDOWS\pss
2013-02-10 10:09:26 ----N---- C:\AdwCleaner[S1].txt
2013-02-10 10:08:49 ----N---- C:\AdwCleaner[R1].txt
2013-02-09 22:25:34 ----SHD---- C:\RECYCLER
2013-02-09 21:09:54 ----HD---- C:\WINDOWS\PIF
2013-02-09 20:27:35 ----D---- C:\WINDOWS\temp
2013-02-09 20:18:10 ----A---- C:\WINDOWS\zip.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWSC.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWREG.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\sed.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\PEV.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\NIRCMD.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\MBR.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\grep.exe
2013-02-09 20:18:06 ----D---- C:\zmizik.com
2013-02-09 20:16:34 ----D---- C:\Qoobox
2013-02-09 20:16:25 ----D---- C:\WINDOWS\erdnt
2013-02-09 20:13:56 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2013-02-09 20:13:29 ----D---- C:\WINDOWS\CSC
2013-02-09 19:16:19 ----N---- C:\PRIKAZ.TXT
2013-02-09 18:10:18 ----D---- C:\rsit
2013-02-09 18:10:18 ----D---- C:\Program Files\trend micro
2013-02-09 14:27:30 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2013-02-09 14:27:30 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2013-02-09 14:27:29 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2013-02-09 14:27:29 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2013-02-09 14:27:28 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2013-02-09 14:27:12 ----A---- C:\WINDOWS\system32\aswBoot.exe
2013-02-09 14:27:12 ----A---- C:\WINDOWS\avastSS.scr
2013-02-09 14:26:58 ----D---- C:\Program Files\AVAST Software
2013-02-09 14:26:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2013-02-09 13:52:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-02-09 12:33:47 ----D---- C:\lan
2013-02-09 12:09:21 ----D---- C:\Program Files\Defraggler
2013-02-09 12:06:58 ----A---- C:\WINDOWS\system32\drivers\HWiNFO32.SYS
2013-02-09 12:06:29 ----D---- C:\Program Files\HWiNFO32
2013-02-09 11:36:51 ----A---- C:\WINDOWS\system32\hidserv.dll
2013-02-09 11:36:48 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2013-02-07 20:33:08 ----D---- C:\WINDOWS\system32\CatRoot_bak
2013-02-07 20:02:17 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2013-02-07 17:49:44 ----D---- C:\WINDOWS\Performance
2013-02-07 17:49:14 ----D---- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2013-02-06 19:22:22 ----D---- C:\$WINDOWS.~BT
2013-02-06 18:32:53 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
2013-02-06 18:32:48 ----D---- C:\Documents and Settings\win-xp\Data aplikací\DAEMON Tools Lite
2013-02-06 18:32:44 ----D---- C:\Program Files\DAEMON Tools Lite
2013-02-06 18:31:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2013-02-05 16:20:17 ----D---- C:\Documents and Settings\win-xp\Data aplikací\searchresultstb
2013-02-04 14:25:39 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\535gege44f.txt
2013-02-02 14:56:39 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\88r8rrjejeue.txt
2013-02-01 18:52:29 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\87g8gg8g8g8g7g.txt
2013-01-22 17:22:03 ----D---- C:\Program Files\1C
2013-01-19 17:02:05 ----D---- C:\Program Files\Tetris

======List of files/folders modified in the last 1 month======

2013-02-10 16:29:42 ----SHD---- C:\WINDOWS\Installer
2013-02-10 16:29:33 ----D---- C:\Windows
2013-02-10 16:12:00 ----A---- C:\WINDOWS\wincmd.ini
2013-02-10 15:49:21 ----D---- C:\Config.Msi
2013-02-10 15:39:40 ----D---- C:\WINDOWS\system32
2013-02-10 15:39:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-02-10 15:25:03 ----D---- C:\WINDOWS\system32\CatRoot2
2013-02-10 14:09:58 ----D---- C:\WINDOWS\Prefetch
2013-02-10 14:09:34 ----D---- C:\WINDOWS\system32\drivers
2013-02-10 13:17:34 ----D---- C:\Program Files
2013-02-09 21:04:23 ----D---- C:\WINDOWS\system32\drivers\etc
2013-02-09 21:03:51 ----SD---- C:\WINDOWS\Tasks
2013-02-09 21:03:08 ----D---- C:\WINDOWS\SoftwareDistribution
2013-02-09 21:02:32 ----A---- C:\WINDOWS\system.ini
2013-02-09 21:00:50 ----D---- C:\WINDOWS\system32\config
2013-02-09 20:25:53 ----D---- C:\WINDOWS\AppPatch
2013-02-09 20:25:52 ----D---- C:\Program Files\Common Files
2013-02-09 14:27:23 ----D---- C:\WINDOWS\WinSxS
2013-02-09 14:27:22 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-02-09 14:00:32 ----A---- C:\WINDOWS\NeroDigital.ini
2013-02-09 13:31:27 ----D---- C:\WINDOWS\Minidump
2013-02-09 13:31:27 ----D---- C:\WINDOWS\Debug
2013-02-09 12:08:42 ----D---- C:\Program Files\CCleaner
2013-02-09 11:36:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-02-07 21:15:21 ----HD---- C:\WINDOWS\inf
2013-02-07 21:09:18 ----D---- C:\WINDOWS\system32\CatRoot
2013-02-07 19:33:47 ----D---- C:\install
2013-02-07 18:30:08 ----D---- C:\Program Files\Java
2013-02-07 18:30:08 ----D---- C:\Program Files\Internet Explorer
2013-02-07 18:30:08 ----D---- C:\Program Files\HP
2013-02-07 18:30:08 ----D---- C:\Program Files\Hewlett-Packard
2013-02-07 18:30:07 ----D---- C:\Program Files\Google
2013-02-07 18:30:07 ----D---- C:\Program Files\ESET
2013-02-07 18:30:07 ----D---- C:\Program Files\DIFX
2013-02-07 18:30:07 ----D---- C:\Program Files\CyberLink
2013-02-07 18:30:07 ----D---- C:\Program Files\ComPlus Applications
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\System
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Symantec Shared
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\SpeechEngines
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Skype
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Services
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\ODBC
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Nero
2013-02-07 18:30:06 ----D---- C:\Program Files\Realtek
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\MSSoap
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\Java
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\InstallShield
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\HP
2013-02-07 18:30:05 ----D---- C:\Program Files\proDAD
2013-02-07 18:30:05 ----D---- C:\Program Files\Pinnacle
2013-02-07 18:30:05 ----D---- C:\Program Files\PC Connectivity Solution
2013-02-07 18:30:05 ----D---- C:\Program Files\Outlook Express
2013-02-07 18:30:05 ----D---- C:\Program Files\Online Services
2013-02-07 18:30:05 ----D---- C:\Program Files\NOS
2013-02-07 18:30:05 ----D---- C:\Program Files\Norton Security Scan
2013-02-07 18:30:05 ----D---- C:\Program Files\NetMeeting
2013-02-07 18:30:05 ----D---- C:\Program Files\MSN Gaming Zone
2013-02-07 18:30:05 ----D---- C:\Program Files\Movie Maker
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Designer
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Ahead
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Adobe
2013-02-07 18:30:05 ----D---- C:\Program Files\CDex_150
2013-02-07 18:30:05 ----D---- C:\Program Files\BIAS
2013-02-07 18:30:05 ----D---- C:\Program Files\Ahead
2013-02-07 18:30:04 ----D---- C:\Program Files\microsoft frontpage
2013-02-07 18:30:04 ----D---- C:\Program Files\Messenger
2013-02-07 18:30:04 ----D---- C:\Program Files\MarkAny
2013-02-07 18:30:04 ----D---- C:\Program Files\Adobe
2013-02-07 18:30:03 ----D---- C:\Program Files\Yahoo!
2013-02-07 18:30:03 ----D---- C:\Program Files\xerox
2013-02-07 18:30:03 ----D---- C:\Program Files\Windows NT
2013-02-07 18:30:03 ----D---- C:\Program Files\Windows Media Player
2013-02-07 18:30:02 ----RD---- C:\Program Files\Skype
2013-02-07 18:30:02 ----D---- C:\Program Files\Video Converter Fox
2013-02-07 18:30:02 ----D---- C:\Program Files\Samsung
2013-02-07 17:58:46 ----RSD---- C:\WINDOWS\assembly
2013-02-07 17:47:33 ----D---- C:\WINDOWS\pchealth
2013-02-06 19:37:03 ----D---- C:\WINDOWS\Microsoft.NET
2013-02-05 16:06:06 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-02-01 19:05:38 ----A---- C:\WINDOWS\win.ini
2013-01-27 20:46:24 ----D---- C:\Documents and Settings\win-xp\Data aplikací\Skype
2013-01-26 09:52:34 ----HD---- C:\Program Files\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2013-02-06 466008]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2013-02-07 242240]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO32.SYS []
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-11-07 7429088]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 a9qmkbm3;a9qmkbm3; C:\WINDOWS\system32\drivers\a9qmkbm3.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\win-xp\LOCALS~1\Temp\catchme.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 RPHook;RPHook; \??\C:\DOCUME~1\win-xp\LOCALS~1\Temp\drv2 []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-10-09 161768]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-11-07 155716]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
S2 PCLEPCI;PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [2005-02-09 14165]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]

-----------------EOF-----------------

Domeek
Návštěvník
Návštěvník
Příspěvky: 44
Registrován: 18 pro 2009 18:22

Re: Zavirovaný PC, Autorun,inf

#24 Příspěvek od Domeek »

Děkuji Vám za pomoc, kdyby se ještě něco našlo, dám vědět. :worship: :)

Zamčeno