
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Neotvára mi niektoré stránky na nete
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Neotvára mi niektoré stránky na nete
Tu asi dochádza k tej mojej závade.
Ten odkaz na combofix mi nevie načítať.
Ten odkaz na combofix mi nevie načítať.
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
To musis este kliknut na download, tu:
http://www.bleepingcomputer.com/downloa ... fix/dl/12/
a pockaj chvilku.
http://www.bleepingcomputer.com/downloa ... fix/dl/12/
a pockaj chvilku.
Re: Neotvára mi niektoré stránky na nete
ComboFix 13-02-18.01 - admin 18.02.2013 17:18:45.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1407.676 [GMT 1:00]
Spuštěný z: c:\documents and settings\admin\Plocha\ComboFix.exe
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\FreeRapid
c:\program files\FreeRapid\copyright
c:\program files\FreeRapid\doc\changes.txt
c:\program files\FreeRapid\doc\readme.cz.txt
c:\program files\FreeRapid\doc\readme.esp(LA).txt
c:\program files\FreeRapid\doc\readme.esp.txt
c:\program files\FreeRapid\doc\readme.fr.txt
c:\program files\FreeRapid\doc\readme.hr.txt
c:\program files\FreeRapid\doc\readme.ru.txt
c:\program files\FreeRapid\doc\readme.txt
c:\program files\FreeRapid\frd.exe
c:\program files\FreeRapid\frd.ico
c:\program files\FreeRapid\frd.jar
c:\program files\FreeRapid\frd.png
c:\program files\FreeRapid\frd.sh
c:\program files\FreeRapid\lib\appframework.jar
c:\program files\FreeRapid\lib\buttonpanel.jar
c:\program files\FreeRapid\lib\commons-cli-2.0-SNAPSHOT.jar
c:\program files\FreeRapid\lib\commons-codec-1.3.jar
c:\program files\FreeRapid\lib\commons-httpclient-3.1.jar
c:\program files\FreeRapid\lib\commons-logging-1.1.jar
c:\program files\FreeRapid\lib\forms.jar
c:\program files\FreeRapid\lib\jai_codec.jar
c:\program files\FreeRapid\lib\jgoodiesbinding.jar
c:\program files\FreeRapid\lib\jpf.jar
c:\program files\FreeRapid\lib\l2fprod-common-buttonbar.jar
c:\program files\FreeRapid\lib\l2fprod-common-directorychooser.jar
c:\program files\FreeRapid\lib\languages.jar
c:\program files\FreeRapid\lib\swingx.jar
c:\program files\FreeRapid\License
c:\program files\FreeRapid\lookandfeel\JTattoo.jar
c:\program files\FreeRapid\lookandfeel\kunststoff.jar
c:\program files\FreeRapid\lookandfeel\PgsLookAndFeel.jar
c:\program files\FreeRapid\lookandfeel\squareness.jar
c:\program files\FreeRapid\lookandfeel\substance-lite.jar
c:\program files\FreeRapid\lookandfeel\substance-swingx.jar
c:\program files\FreeRapid\plugins\dailymotion.frp
c:\program files\FreeRapid\plugins\dataup.frp
c:\program files\FreeRapid\plugins\disperseit.frp
c:\program files\FreeRapid\plugins\edisk.frp
c:\program files\FreeRapid\plugins\egoshare.frp
c:\program files\FreeRapid\plugins\enterupload.frp
c:\program files\FreeRapid\plugins\file2box.frp
c:\program files\FreeRapid\plugins\filebaseto.frp
c:\program files\FreeRapid\plugins\filebox.frp
c:\program files\FreeRapid\plugins\filefactory.frp
c:\program files\FreeRapid\plugins\leteckaposta.frp
c:\program files\FreeRapid\plugins\ulozto.frp
c:\program files\FreeRapid\readme.txt
c:\program files\FreeRapid\startup.properties
c:\program files\FreeRapid\syscmd.properties
c:\program files\FreeRapid\tools\gocr\gocr.exe
c:\program files\FreeRapid\tools\nircmd\nircmd.exe
c:\program files\FreeRapid\tools\nircmd\NirCmd.chm
c:\program files\FreeRapid\tools\socks\setupproxy.sh
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-18 do 2013-02-18 )))))))))))))))))))))))))))))))
.
.
2013-02-18 15:14 . 2008-04-14 04:51 64256 ----a-w- c:\windows\system32\drivers\serial.sys
2013-02-18 13:35 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2013-02-18 13:35 . 2013-02-18 13:35 -------- d-----w- c:\program files\Ashampoo
2013-02-18 09:51 . 2013-02-18 09:51 -------- d-----w- c:\program files\MSXML 4.0
2013-02-18 09:25 . 2012-12-26 20:17 522240 ------w- c:\windows\system32\dllcache\jsdbgui.dll
2013-02-13 09:02 . 2013-02-13 09:06 -------- d-----w- c:\windows\system32\Adobe
2013-02-12 16:52 . 2013-02-12 16:52 -------- d-----w- c:\program files\Common Files\Java
2013-02-12 16:51 . 2013-02-12 16:51 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-12 16:51 . 2013-02-12 16:51 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-12 13:22 . 2013-02-13 09:44 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-01-23 11:34 . 2013-01-23 11:34 -------- d-----w- c:\documents and settings\admin\Data aplikací\Jablotron
2013-01-21 09:17 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 08:56 . 2012-06-01 14:04 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-13 08:56 . 2012-06-01 14:04 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-12 16:51 . 2012-05-16 15:57 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-02-12 16:51 . 2012-05-15 08:46 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55 . 2008-04-14 06:51 552448 ------w- c:\windows\system32\oleaut32.dll
2013-01-16 15:58 . 2013-01-16 15:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-01-16 15:58 . 2013-01-16 15:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
2013-01-07 07:24 . 2010-04-28 21:19 2071936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-07 07:24 . 2010-09-15 00:52 2195328 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 10:09 . 2010-09-15 00:53 1876224 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2010-09-15 00:51 1294848 ----a-w- c:\windows\system32\quartz.dll
2013-01-02 06:49 . 2008-04-14 06:52 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2012-12-26 20:18 . 2010-09-15 00:41 920064 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:17 . 2010-09-15 00:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:17 . 2010-09-15 00:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 07:03 . 2010-09-15 00:41 385024 ----a-w- c:\windows\system32\html.iec
2012-12-16 12:31 . 2010-09-15 00:52 290560 ----a-w- c:\windows\system32\atmfd.dll
2013-02-13 09:08 . 2013-02-13 09:07 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"nwiz"="nwiz.exe" [2009-04-14 1657376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13684736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-01-16 295072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2010-09-15 128512]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\admin\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.3.2012 7:40 120152]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [16.5.2012 17:56 14656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [7.3.2012 14:40 913144]
R2 LiveTunerPM;Ashampoo LiveTuner ProcessMonitor Driver;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerProcessMonitor32.sys [18.2.2013 14:35 12696]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [21.3.2011 10:17 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [21.3.2011 10:17 68928]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.10.2012 13:19 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.10.2012 13:19 676936]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\DfSdkS.exe [18.2.2013 14:35 406016]
S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [16.5.2012 17:57 29760]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\program files\MSI\Live Update 5\msibios32_100507.sys --> c:\program files\MSI\Live Update 5\msibios32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\program files\MSI\Live Update 5\NTIOLib.sys --> c:\program files\MSI\Live Update 5\NTIOLib.sys [?]
S3 usbcamcl;Driver for usbcamcl Device;c:\windows\system32\DRIVERS\usbcamcl.sys --> c:\windows\system32\DRIVERS\usbcamcl.sys [?]
S3 WO_LiveService;Ashampoo LiveTuner Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe [18.2.2013 14:35 884608]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 68560196
*NewlyCreated* - 97409400
*NewlyCreated* - LIVETUNERPM
*Deregistered* - 68560196
*Deregistered* - 97409400
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 08:56]
.
2012-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2013-02-15 c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\recordingmanager.exe [2012-11-29 19:33]
.
2013-02-18 c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2012-11-29 19:31]
.
2013-02-14 c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2012-11-29 19:31]
.
2013-02-18 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-18 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: Free YouTube Download - c:\documents and settings\admin\Data aplikací\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 2553797374656d526f6f74255c7765625c72656c617465642e68746d00
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\5x7zvfgw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3225826&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BitTorrentControl_v12 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxps://www.google.sk/
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-18 17:23
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1757981266-1123561945-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2b,5c,6f,cd,d3,c5,ee,42,b6,ae,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,1b,71,93,7d,d1,a2,48,b8,d2,31,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0d,f9,6a,e8,ce,4a,d6,4d,90,19,ca,\
.
Celkový čas: 2013-02-18 17:24:50
ComboFix-quarantined-files.txt 2013-02-18 16:24
.
Před spuštěním: 6 551 617 536
Po spuštění: 6 500 012 032
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
.
- - End Of File - - 81529B00621FE2485B6160AC787FF369
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1407.676 [GMT 1:00]
Spuštěný z: c:\documents and settings\admin\Plocha\ComboFix.exe
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\FreeRapid
c:\program files\FreeRapid\copyright
c:\program files\FreeRapid\doc\changes.txt
c:\program files\FreeRapid\doc\readme.cz.txt
c:\program files\FreeRapid\doc\readme.esp(LA).txt
c:\program files\FreeRapid\doc\readme.esp.txt
c:\program files\FreeRapid\doc\readme.fr.txt
c:\program files\FreeRapid\doc\readme.hr.txt
c:\program files\FreeRapid\doc\readme.ru.txt
c:\program files\FreeRapid\doc\readme.txt
c:\program files\FreeRapid\frd.exe
c:\program files\FreeRapid\frd.ico
c:\program files\FreeRapid\frd.jar
c:\program files\FreeRapid\frd.png
c:\program files\FreeRapid\frd.sh
c:\program files\FreeRapid\lib\appframework.jar
c:\program files\FreeRapid\lib\buttonpanel.jar
c:\program files\FreeRapid\lib\commons-cli-2.0-SNAPSHOT.jar
c:\program files\FreeRapid\lib\commons-codec-1.3.jar
c:\program files\FreeRapid\lib\commons-httpclient-3.1.jar
c:\program files\FreeRapid\lib\commons-logging-1.1.jar
c:\program files\FreeRapid\lib\forms.jar
c:\program files\FreeRapid\lib\jai_codec.jar
c:\program files\FreeRapid\lib\jgoodiesbinding.jar
c:\program files\FreeRapid\lib\jpf.jar
c:\program files\FreeRapid\lib\l2fprod-common-buttonbar.jar
c:\program files\FreeRapid\lib\l2fprod-common-directorychooser.jar
c:\program files\FreeRapid\lib\languages.jar
c:\program files\FreeRapid\lib\swingx.jar
c:\program files\FreeRapid\License
c:\program files\FreeRapid\lookandfeel\JTattoo.jar
c:\program files\FreeRapid\lookandfeel\kunststoff.jar
c:\program files\FreeRapid\lookandfeel\PgsLookAndFeel.jar
c:\program files\FreeRapid\lookandfeel\squareness.jar
c:\program files\FreeRapid\lookandfeel\substance-lite.jar
c:\program files\FreeRapid\lookandfeel\substance-swingx.jar
c:\program files\FreeRapid\plugins\dailymotion.frp
c:\program files\FreeRapid\plugins\dataup.frp
c:\program files\FreeRapid\plugins\disperseit.frp
c:\program files\FreeRapid\plugins\edisk.frp
c:\program files\FreeRapid\plugins\egoshare.frp
c:\program files\FreeRapid\plugins\enterupload.frp
c:\program files\FreeRapid\plugins\file2box.frp
c:\program files\FreeRapid\plugins\filebaseto.frp
c:\program files\FreeRapid\plugins\filebox.frp
c:\program files\FreeRapid\plugins\filefactory.frp
c:\program files\FreeRapid\plugins\leteckaposta.frp
c:\program files\FreeRapid\plugins\ulozto.frp
c:\program files\FreeRapid\readme.txt
c:\program files\FreeRapid\startup.properties
c:\program files\FreeRapid\syscmd.properties
c:\program files\FreeRapid\tools\gocr\gocr.exe
c:\program files\FreeRapid\tools\nircmd\nircmd.exe
c:\program files\FreeRapid\tools\nircmd\NirCmd.chm
c:\program files\FreeRapid\tools\socks\setupproxy.sh
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-18 do 2013-02-18 )))))))))))))))))))))))))))))))
.
.
2013-02-18 15:14 . 2008-04-14 04:51 64256 ----a-w- c:\windows\system32\drivers\serial.sys
2013-02-18 13:35 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2013-02-18 13:35 . 2013-02-18 13:35 -------- d-----w- c:\program files\Ashampoo
2013-02-18 09:51 . 2013-02-18 09:51 -------- d-----w- c:\program files\MSXML 4.0
2013-02-18 09:25 . 2012-12-26 20:17 522240 ------w- c:\windows\system32\dllcache\jsdbgui.dll
2013-02-13 09:02 . 2013-02-13 09:06 -------- d-----w- c:\windows\system32\Adobe
2013-02-12 16:52 . 2013-02-12 16:52 -------- d-----w- c:\program files\Common Files\Java
2013-02-12 16:51 . 2013-02-12 16:51 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-12 16:51 . 2013-02-12 16:51 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-12 13:22 . 2013-02-13 09:44 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-01-23 11:34 . 2013-01-23 11:34 -------- d-----w- c:\documents and settings\admin\Data aplikací\Jablotron
2013-01-21 09:17 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 08:56 . 2012-06-01 14:04 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-13 08:56 . 2012-06-01 14:04 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-12 16:51 . 2012-05-16 15:57 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-02-12 16:51 . 2012-05-15 08:46 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55 . 2008-04-14 06:51 552448 ------w- c:\windows\system32\oleaut32.dll
2013-01-16 15:58 . 2013-01-16 15:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-01-16 15:58 . 2013-01-16 15:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
2013-01-07 07:24 . 2010-04-28 21:19 2071936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-07 07:24 . 2010-09-15 00:52 2195328 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 10:09 . 2010-09-15 00:53 1876224 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2010-09-15 00:51 1294848 ----a-w- c:\windows\system32\quartz.dll
2013-01-02 06:49 . 2008-04-14 06:52 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2012-12-26 20:18 . 2010-09-15 00:41 920064 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:17 . 2010-09-15 00:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:17 . 2010-09-15 00:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 07:03 . 2010-09-15 00:41 385024 ----a-w- c:\windows\system32\html.iec
2012-12-16 12:31 . 2010-09-15 00:52 290560 ----a-w- c:\windows\system32\atmfd.dll
2013-02-13 09:08 . 2013-02-13 09:07 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"nwiz"="nwiz.exe" [2009-04-14 1657376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13684736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-01-16 295072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2010-09-15 128512]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\admin\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.3.2012 7:40 120152]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [16.5.2012 17:56 14656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [7.3.2012 14:40 913144]
R2 LiveTunerPM;Ashampoo LiveTuner ProcessMonitor Driver;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerProcessMonitor32.sys [18.2.2013 14:35 12696]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [21.3.2011 10:17 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [21.3.2011 10:17 68928]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.10.2012 13:19 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.10.2012 13:19 676936]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\DfSdkS.exe [18.2.2013 14:35 406016]
S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [16.5.2012 17:57 29760]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\program files\MSI\Live Update 5\msibios32_100507.sys --> c:\program files\MSI\Live Update 5\msibios32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\program files\MSI\Live Update 5\NTIOLib.sys --> c:\program files\MSI\Live Update 5\NTIOLib.sys [?]
S3 usbcamcl;Driver for usbcamcl Device;c:\windows\system32\DRIVERS\usbcamcl.sys --> c:\windows\system32\DRIVERS\usbcamcl.sys [?]
S3 WO_LiveService;Ashampoo LiveTuner Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe [18.2.2013 14:35 884608]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 68560196
*NewlyCreated* - 97409400
*NewlyCreated* - LIVETUNERPM
*Deregistered* - 68560196
*Deregistered* - 97409400
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 08:56]
.
2012-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2013-02-15 c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\recordingmanager.exe [2012-11-29 19:33]
.
2013-02-18 c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2012-11-29 19:31]
.
2013-02-14 c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\RealNetworks\RealDownloader\realupgrade.exe [2012-11-29 19:31]
.
2013-02-18 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-18 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-02-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: Free YouTube Download - c:\documents and settings\admin\Data aplikací\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 2553797374656d526f6f74255c7765625c72656c617465642e68746d00
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\5x7zvfgw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3225826&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BitTorrentControl_v12 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxps://www.google.sk/
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-18 17:23
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1757981266-1123561945-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2b,5c,6f,cd,d3,c5,ee,42,b6,ae,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,1b,71,93,7d,d1,a2,48,b8,d2,31,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0d,f9,6a,e8,ce,4a,d6,4d,90,19,ca,\
.
Celkový čas: 2013-02-18 17:24:50
ComboFix-quarantined-files.txt 2013-02-18 16:24
.
Před spuštěním: 6 551 617 536
Po spuštění: 6 500 012 032
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
.
- - End Of File - - 81529B00621FE2485B6160AC787FF369
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
Tento program, akoze Optimizer treba dat prec, odinstalovat
c:\program files\Ashampoo\Ashampoo WinOptimizer 9
Je proti logike aby dajaky OPTIMIZER, odcerpaval systemove prostriedky a natlacil kopec ovladacov do pamati.
Fuj...
Pri tejto akcii je nutné mať ComboFix na ploche.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log combofixxx.txt
c:\program files\Ashampoo\Ashampoo WinOptimizer 9
Je proti logike aby dajaky OPTIMIZER, odcerpaval systemove prostriedky a natlacil kopec ovladacov do pamati.
Fuj...
Pri tejto akcii je nutné mať ComboFix na ploche.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Kód: Vybrat vše
KILLALL::
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"QuickTime Task"=-
File::
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
DDS::
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 2553797374656d526f6f74255c7765625c72656c617465642e68746d00
Extra::
FireFox::
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\5x7zvfgw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BitTorrentControl_v12 Customized Web Search
RegLock::
[HKEY_USERS\S-1-5-21-1757981266-1123561945-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
ClearJavaCache::
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log combofixxx.txt
Re: Neotvára mi niektoré stránky na nete
Ok, ten winoptimizer potom odinštalujem. Aj to Anti-Malware môžem dať preč?
ComboFix 13-02-18.01 - admin 18.02.2013 18:21:42.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1407.926 [GMT 1:00]
Spuštěný z: c:\documents and settings\admin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\admin\Plocha\CFScript.txt
* Rezidentní štít AV je zapnutý
.
.
FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\AppleSoftwareUpdate.job"
"c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
.
ADS - WINDOWS: deleted 192 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-18 do 2013-02-18 )))))))))))))))))))))))))))))))
.
.
2013-02-18 16:54 . 2013-02-18 16:54 -------- d-----w- c:\windows\system32\wbem\snmp
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\system32\xircom
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\system32\oobe
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\srchasst
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\program files\microsoft frontpage
2013-02-18 15:14 . 2008-04-14 04:51 64256 ----a-w- c:\windows\system32\drivers\serial.sys
2013-02-18 13:35 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2013-02-18 13:35 . 2013-02-18 13:35 -------- d-----w- c:\program files\Ashampoo
2013-02-18 09:51 . 2013-02-18 09:51 -------- d-----w- c:\program files\MSXML 4.0
2013-02-18 09:25 . 2012-12-26 20:17 522240 ------w- c:\windows\system32\dllcache\jsdbgui.dll
2013-02-13 09:02 . 2013-02-13 09:06 -------- d-----w- c:\windows\system32\Adobe
2013-02-12 16:52 . 2013-02-12 16:52 -------- d-----w- c:\program files\Common Files\Java
2013-02-12 16:51 . 2013-02-12 16:51 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-12 16:51 . 2013-02-12 16:51 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-12 13:22 . 2013-02-13 09:44 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-01-23 11:34 . 2013-01-23 11:34 -------- d-----w- c:\documents and settings\admin\Data aplikací\Jablotron
2013-01-21 09:17 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 08:56 . 2012-06-01 14:04 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-13 08:56 . 2012-06-01 14:04 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-12 16:51 . 2012-05-16 15:57 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-02-12 16:51 . 2012-05-15 08:46 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55 . 2008-04-14 06:51 552448 ------w- c:\windows\system32\oleaut32.dll
2013-01-16 15:58 . 2013-01-16 15:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-01-16 15:58 . 2013-01-16 15:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
2013-01-07 07:24 . 2010-04-28 21:19 2071936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-07 07:24 . 2010-09-15 00:52 2195328 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 10:09 . 2010-09-15 00:53 1876224 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2010-09-15 00:51 1294848 ----a-w- c:\windows\system32\quartz.dll
2013-01-02 06:49 . 2008-04-14 06:52 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2012-12-26 20:18 . 2010-09-15 00:41 920064 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:17 . 2010-09-15 00:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:17 . 2010-09-15 00:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 07:03 . 2010-09-15 00:41 385024 ----a-w- c:\windows\system32\html.iec
2012-12-16 12:31 . 2010-09-15 00:52 290560 ----a-w- c:\windows\system32\atmfd.dll
2013-02-13 09:08 . 2013-02-13 09:07 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"nwiz"="nwiz.exe" [2009-04-14 1657376]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13684736]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-01-16 295072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2010-09-15 128512]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\admin\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.3.2012 7:40 120152]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [16.5.2012 17:56 14656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [7.3.2012 14:40 913144]
R2 LiveTunerPM;Ashampoo LiveTuner ProcessMonitor Driver;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerProcessMonitor32.sys [18.2.2013 14:35 12696]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [21.3.2011 10:17 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [21.3.2011 10:17 68928]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.10.2012 13:19 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.10.2012 13:19 676936]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\DfSdkS.exe [18.2.2013 14:35 406016]
S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [16.5.2012 17:57 29760]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\program files\MSI\Live Update 5\msibios32_100507.sys --> c:\program files\MSI\Live Update 5\msibios32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\program files\MSI\Live Update 5\NTIOLib.sys --> c:\program files\MSI\Live Update 5\NTIOLib.sys [?]
S3 usbcamcl;Driver for usbcamcl Device;c:\windows\system32\DRIVERS\usbcamcl.sys --> c:\windows\system32\DRIVERS\usbcamcl.sys [?]
S3 WO_LiveService;Ashampoo LiveTuner Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe [18.2.2013 14:35 884608]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: Free YouTube Download - c:\documents and settings\admin\Data aplikací\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 2553797374656d526f6f74255c7765625c72656c617465642e68746d00
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\5x7zvfgw.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.sk/
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-18 18:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1828)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\SearchIndexer.exe
.
**************************************************************************
.
Celkový čas: 2013-02-18 18:28:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-18 17:28
ComboFix2.txt 2013-02-18 17:15
ComboFix3.txt 2013-02-18 16:46
.
Před spuštěním: 6 499 614 720
Po spuštění: 6 496 047 104
.
- - End Of File - - 738B5D75FF8522C1A7DAA097B7BA3B8A
ComboFix 13-02-18.01 - admin 18.02.2013 18:21:42.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1407.926 [GMT 1:00]
Spuštěný z: c:\documents and settings\admin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\admin\Plocha\CFScript.txt
* Rezidentní štít AV je zapnutý
.
.
FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\AppleSoftwareUpdate.job"
"c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job"
.
ADS - WINDOWS: deleted 192 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1757981266-1123561945-1801674531-500.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-18 do 2013-02-18 )))))))))))))))))))))))))))))))
.
.
2013-02-18 16:54 . 2013-02-18 16:54 -------- d-----w- c:\windows\system32\wbem\snmp
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\system32\xircom
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\system32\oobe
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\windows\srchasst
2013-02-18 16:53 . 2013-02-18 16:53 -------- d-----w- c:\program files\microsoft frontpage
2013-02-18 15:14 . 2008-04-14 04:51 64256 ----a-w- c:\windows\system32\drivers\serial.sys
2013-02-18 13:35 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2013-02-18 13:35 . 2013-02-18 13:35 -------- d-----w- c:\program files\Ashampoo
2013-02-18 09:51 . 2013-02-18 09:51 -------- d-----w- c:\program files\MSXML 4.0
2013-02-18 09:25 . 2012-12-26 20:17 522240 ------w- c:\windows\system32\dllcache\jsdbgui.dll
2013-02-13 09:02 . 2013-02-13 09:06 -------- d-----w- c:\windows\system32\Adobe
2013-02-12 16:52 . 2013-02-12 16:52 -------- d-----w- c:\program files\Common Files\Java
2013-02-12 16:51 . 2013-02-12 16:51 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-12 16:51 . 2013-02-12 16:51 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-12 13:22 . 2013-02-13 09:44 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-01-23 11:34 . 2013-01-23 11:34 -------- d-----w- c:\documents and settings\admin\Data aplikací\Jablotron
2013-01-21 09:17 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 08:56 . 2012-06-01 14:04 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-13 08:56 . 2012-06-01 14:04 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-12 16:51 . 2012-05-16 15:57 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-02-12 16:51 . 2012-05-15 08:46 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55 . 2008-04-14 06:51 552448 ------w- c:\windows\system32\oleaut32.dll
2013-01-16 15:58 . 2013-01-16 15:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-01-16 15:58 . 2013-01-16 15:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
2013-01-07 07:24 . 2010-04-28 21:19 2071936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-07 07:24 . 2010-09-15 00:52 2195328 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 10:09 . 2010-09-15 00:53 1876224 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2010-09-15 00:51 1294848 ----a-w- c:\windows\system32\quartz.dll
2013-01-02 06:49 . 2008-04-14 06:52 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2012-12-26 20:18 . 2010-09-15 00:41 920064 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:17 . 2010-09-15 00:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:17 . 2010-09-15 00:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 07:03 . 2010-09-15 00:41 385024 ----a-w- c:\windows\system32\html.iec
2012-12-16 12:31 . 2010-09-15 00:52 290560 ----a-w- c:\windows\system32\atmfd.dll
2013-02-13 09:08 . 2013-02-13 09:07 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"nwiz"="nwiz.exe" [2009-04-14 1657376]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13684736]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-01-16 295072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2010-09-15 128512]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\admin\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.3.2012 7:40 120152]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [16.5.2012 17:56 14656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [7.3.2012 14:40 913144]
R2 LiveTunerPM;Ashampoo LiveTuner ProcessMonitor Driver;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerProcessMonitor32.sys [18.2.2013 14:35 12696]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [21.3.2011 10:17 196928]
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [21.3.2011 10:17 68928]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.10.2012 13:19 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.10.2012 13:19 676936]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\DfSdkS.exe [18.2.2013 14:35 406016]
S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [16.5.2012 17:57 29760]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\program files\MSI\Live Update 5\msibios32_100507.sys --> c:\program files\MSI\Live Update 5\msibios32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\program files\MSI\Live Update 5\NTIOLib.sys --> c:\program files\MSI\Live Update 5\NTIOLib.sys [?]
S3 usbcamcl;Driver for usbcamcl Device;c:\windows\system32\DRIVERS\usbcamcl.sys --> c:\windows\system32\DRIVERS\usbcamcl.sys [?]
S3 WO_LiveService;Ashampoo LiveTuner Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe [18.2.2013 14:35 884608]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: Free YouTube Download - c:\documents and settings\admin\Data aplikací\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 2553797374656d526f6f74255c7765625c72656c617465642e68746d00
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\5x7zvfgw.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.sk/
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-18 18:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1828)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\SearchIndexer.exe
.
**************************************************************************
.
Celkový čas: 2013-02-18 18:28:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-18 17:28
ComboFix2.txt 2013-02-18 17:15
ComboFix3.txt 2013-02-18 16:46
.
Před spuštěním: 6 499 614 720
Po spuštění: 6 496 047 104
.
- - End Of File - - 738B5D75FF8522C1A7DAA097B7BA3B8A
Re: Neotvára mi niektoré stránky na nete
Možno sa mi to tu pekne prečistilo, bohužiaľ problém s otváraním niektorých stránok zatiaľ pretrváva 

- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
No co uz...
c:\program files\Ashampoo\Ashampoo WinOptimizer 9\
Preco trvas na tomto programe?/
Mne je to-5, ja som ti to doporucil..
1:Premenuj ikonu combofixu na uninstall
a spust, klik ok,ok,ok, combofix sa odinstaluje z pc.
2:Stiahneme OTL exe na plochu a spustime.
http://oldtimer.geekstogo.com/OTL.exe
Nastavenie necháme tak ako je, dole do okna vložte tento skript.
a KLikni na gombik OPRAVIT,RunFix:
log vloz sem
Odskusaj pc, a napis ako funguje.
c:\program files\Ashampoo\Ashampoo WinOptimizer 9\
Preco trvas na tomto programe?/
Mne je to-5, ja som ti to doporucil..
1:Premenuj ikonu combofixu na uninstall
a spust, klik ok,ok,ok, combofix sa odinstaluje z pc.
2:Stiahneme OTL exe na plochu a spustime.
http://oldtimer.geekstogo.com/OTL.exe
Nastavenie necháme tak ako je, dole do okna vložte tento skript.
Kód: Vybrat vše
:Files
ipconfig /flushdns /c
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
log vloz sem
Odskusaj pc, a napis ako funguje.
Re: Neotvára mi niektoré stránky na nete
....tu som to napísal, že netrvám na tom optimizery, rád si dám poradiť. A čo ten anti-malware? oba som už odinštaloval, ok?Sinus píše:Ok, ten winoptimizer potom odinštalujem. Aj to Anti-Malware môžem dať preč?...........
Naposledy upravil(a) Sinus dne 18 úno 2013 19:16, celkem upraveno 1 x.
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
Ok, potom odinstaluj,..ten winoptimizer potom odinštalujem. Aj to Anti-Malware
Pockaj o chvilku dam ti program co odinstaluje combofix.
mozes spustit OTL, tak ako som ti napisal.
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
stiahni tento program na plochu a spust, ako spravca, to odinstaluje combofix, potom uz len zmaz ikonku combofixu.
http://leteckaposta.cz/567630548
a vloz sem log z OTL.EXE.
http://leteckaposta.cz/567630548
a vloz sem log z OTL.EXE.
Re: Neotvára mi niektoré stránky na nete
už ho mám odinštalovaný.... ja som omylom tú ikonu omylom premenoval na "uninstal" s jedným L 
tu je log z OTL :
All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Konfigurace protokolu IP systému Windows
Mezipaměť překládání DNS byla úspěšně vyprázdněna.
C:\Documents and Settings\admin\Plocha\cmd.bat deleted successfully.
C:\Documents and Settings\admin\Plocha\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Unable to stop System Restore Service. Error code 1717. Restore points not cleared.
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 327706 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 6124854 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 506 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 6,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 02182013_191911
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...

tu je log z OTL :
All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Konfigurace protokolu IP systému Windows
Mezipaměť překládání DNS byla úspěšně vyprázdněna.
C:\Documents and Settings\admin\Plocha\cmd.bat deleted successfully.
C:\Documents and Settings\admin\Plocha\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Unable to stop System Restore Service. Error code 1717. Restore points not cleared.
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 327706 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 6124854 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 506 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 6,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 02182013_191911
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
ok, restartuj pc, a odskusaj browser, ci uz otvara stranky.
Re: Neotvára mi niektoré stránky na nete
bohužiaľ, v tomto ohľade problém pretrváva. nechápem prečo. neotvorí napr. ani stránku www.mozilla.org , ale www.mozilla.sk otvorím
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Neotvára mi niektoré stránky na nete
Moze byt poskodeny profil, ale este nieco si overim.
1:Stiahni SecurityCheck
Ulož ho na plochu.
Dvakrát kliknite SecurityCheck.exe a postupujte podľa pokynov na obrazovke .
po skonceni skenu Notepad sa automaticky otvorí s názvom checkup.txt,obsah vloz sem.
2:Vytvorime súbor.bat.
1:Otvorte Notepad (Poznámkový blok) a skopíruj do neho text.
2:Potom klikneme na záložku Súbor v menu Uložiť ako..
3:Ako je Názov súboru, tak do toho riadku napíšeme:oprava.bat
4:Typ súboru tak tam vyberiete všetky súbory .
5:A uložíme ho na plochu.
6:2 x klikneme naň, alebo pravý klik a spustiť ako správca.
Log vloz sem
1:Stiahni SecurityCheck
Ulož ho na plochu.
Dvakrát kliknite SecurityCheck.exe a postupujte podľa pokynov na obrazovke .
po skonceni skenu Notepad sa automaticky otvorí s názvom checkup.txt,obsah vloz sem.
2:Vytvorime súbor.bat.
1:Otvorte Notepad (Poznámkový blok) a skopíruj do neho text.
2:Potom klikneme na záložku Súbor v menu Uložiť ako..
3:Ako je Názov súboru, tak do toho riadku napíšeme:oprava.bat
4:Typ súboru tak tam vyberiete všetky súbory .
5:A uložíme ho na plochu.
6:2 x klikneme naň, alebo pravý klik a spustiť ako správca.
Log vloz sem
Kód: Vybrat vše
@echo off
cd\
>face.txt (
ipconfig /all
nslookup www.mozilla.org
ping -n 3 www.mozilla.org
echo.
route print
)
start face.txt
del %0
Re: Neotvára mi niektoré stránky na nete
1. Obsah security check:
Results of screen317's Security Check version 0.99.58
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 13
Adobe Flash Player 11.5.502.149
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 12.0 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
------------------------------------------------------------------------------------------------------------
2. LOG z oprava.bat :
Konfigurace protokolu IP systému Windows
Název hostitele . . . . . . . . . : pokoj
Primární přípona DNS. . . . . . . :
Typ uzlu . . . . . . . . . . . . : neznámý
Povoleno směrování IP . . . . . . : Ne
WINS Proxy povoleno . . . . . . . : Ne
Adaptér sítě Ethernet Připojení k místní síti:
Přípona DNS podle připojení . . . :
Popis . . . . . . . . . . . . . . : NVIDIA nForce 10/100 Mbps Ethernet
Fyzická Adresa. . . . . . . . . . : 00-19-66-B9-FB-11
Protokol DHCP povolen . . . . . . : Ano
Automatická konfigurace povolena : Ano
Adresa IP . . . . . . . . . . . . : 192.168.1.2
Maska podsítě . . . . . . . . . . : 255.255.255.0
Výchozí brána . . . . . . . . . . : 192.168.1.1
Server DHCP . . . . . . . . . . . : 192.168.1.1
Servery DNS . . . . . . . . . . . : 192.168.1.1
Zapůjčeno . . . . . . . . . . . . : 18. února 2013 19:27:12
Zápůjčka vyprší . . . . . . . . . : 18. února 2013 20:27:12
Server: mygateway1.AR7RD
Address: 192.168.1.1
N˙zev: mozorg.dynect.mozilla.net
Address: 63.245.217.105
Aliases: www.mozilla.org
Pýˇkaz PING na www.mozilla.org [63.245.215.20] s d‚lkou 32 bajt…:
OdpovŘÔ od 63.245.215.20: bajty=32 źas=203ms TTL=45
OdpovŘÔ od 63.245.215.20: bajty=32 źas=204ms TTL=45
OdpovŘÔ od 63.245.215.20: bajty=32 źas=204ms TTL=45
Statistika ping pro 63.245.215.20:
Pakety: Odeslan‚ = 3, Pýijat‚ = 3, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n doba do pýijetˇ odezvy v milisekund ch:
Minimum = 203ms, Maximum = 204ms, Pr…mŘr = 203ms
===========================================================================
Seznam rozhranˇ
0x1 ........................... MS TCP Loopback interface
0x2 ...00 19 66 b9 fb 11 ...... NVIDIA nForce Networking Controller - Packet Scheduler Miniport
===========================================================================
===========================================================================
Aktivnˇ smŘrov nˇ:
Cˇl v sˇti Sˇśov maska Br na Rozhranˇ Metrika
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.2 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.2 192.168.1.2 20
192.168.1.2 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.2 192.168.1.2 20
224.0.0.0 240.0.0.0 192.168.1.2 192.168.1.2 20
255.255.255.255 255.255.255.255 192.168.1.2 192.168.1.2 1
Věchozˇ br na: 192.168.1.1
===========================================================================
Trval‚ trasy:
¦ dn‚
Results of screen317's Security Check version 0.99.58
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 13
Adobe Flash Player 11.5.502.149
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 12.0 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
------------------------------------------------------------------------------------------------------------
2. LOG z oprava.bat :
Konfigurace protokolu IP systému Windows
Název hostitele . . . . . . . . . : pokoj
Primární přípona DNS. . . . . . . :
Typ uzlu . . . . . . . . . . . . : neznámý
Povoleno směrování IP . . . . . . : Ne
WINS Proxy povoleno . . . . . . . : Ne
Adaptér sítě Ethernet Připojení k místní síti:
Přípona DNS podle připojení . . . :
Popis . . . . . . . . . . . . . . : NVIDIA nForce 10/100 Mbps Ethernet
Fyzická Adresa. . . . . . . . . . : 00-19-66-B9-FB-11
Protokol DHCP povolen . . . . . . : Ano
Automatická konfigurace povolena : Ano
Adresa IP . . . . . . . . . . . . : 192.168.1.2
Maska podsítě . . . . . . . . . . : 255.255.255.0
Výchozí brána . . . . . . . . . . : 192.168.1.1
Server DHCP . . . . . . . . . . . : 192.168.1.1
Servery DNS . . . . . . . . . . . : 192.168.1.1
Zapůjčeno . . . . . . . . . . . . : 18. února 2013 19:27:12
Zápůjčka vyprší . . . . . . . . . : 18. února 2013 20:27:12
Server: mygateway1.AR7RD
Address: 192.168.1.1
N˙zev: mozorg.dynect.mozilla.net
Address: 63.245.217.105
Aliases: www.mozilla.org
Pýˇkaz PING na www.mozilla.org [63.245.215.20] s d‚lkou 32 bajt…:
OdpovŘÔ od 63.245.215.20: bajty=32 źas=203ms TTL=45
OdpovŘÔ od 63.245.215.20: bajty=32 źas=204ms TTL=45
OdpovŘÔ od 63.245.215.20: bajty=32 źas=204ms TTL=45
Statistika ping pro 63.245.215.20:
Pakety: Odeslan‚ = 3, Pýijat‚ = 3, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n doba do pýijetˇ odezvy v milisekund ch:
Minimum = 203ms, Maximum = 204ms, Pr…mŘr = 203ms
===========================================================================
Seznam rozhranˇ
0x1 ........................... MS TCP Loopback interface
0x2 ...00 19 66 b9 fb 11 ...... NVIDIA nForce Networking Controller - Packet Scheduler Miniport
===========================================================================
===========================================================================
Aktivnˇ smŘrov nˇ:
Cˇl v sˇti Sˇśov maska Br na Rozhranˇ Metrika
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.2 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.2 192.168.1.2 20
192.168.1.2 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.2 192.168.1.2 20
224.0.0.0 240.0.0.0 192.168.1.2 192.168.1.2 20
255.255.255.255 255.255.255.255 192.168.1.2 192.168.1.2 1
Věchozˇ br na: 192.168.1.1
===========================================================================
Trval‚ trasy:
¦ dn‚