Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Podezření na RootKit.Agent

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Podezření na RootKit.Agent

#1 Příspěvek od Majirka »

Ten problém je asi takový: Provider mu odstavil SMTP kvůly Spamu, Tak jsem začal hledat. V PC nainstalovaný NOD32 - nic nenašel, SpyBoot, také nic, přeinstaloval jsem na AVG9 IS - také nic, až Malwarebytes našel:

Malwarebytes' Anti-Malware 1.44
Verze databáze: 3526
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

9.1.2010 22:53:32
mbam-log-2010-01-09 (22-53-32).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 98677
Uplynulý čas: 5 minute(s), 52 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
C:\Windows\system32\Drivers\voxcom.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

Ještě jsem zkoušel ComboFix:

ComboFix 10-01-04.01 - Forejtar 09.01.2010 21:59:58.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1912.1001 [GMT 1:00]
Spuštěný z: c:\users\Forejtar\Desktop\ComboFix1.exe
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-09 do 2010-01-09 )))))))))))))))))))))))))))))))
.

2010-01-09 21:06 . 2010-01-09 21:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-09 20:48 . 2010-01-09 20:48 -------- d-----w- C:\ComboFix1
2010-01-09 17:05 . 2010-01-09 16:51 3776280 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-01-09 17:05 . 2010-01-09 16:51 4043032 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-01-09 17:05 . 2010-01-09 16:51 2033432 ----a-w- c:\programdata\avg9\update\backup\avgtray.exe
2010-01-09 17:05 . 2010-01-09 16:51 2352920 ----a-w- c:\programdata\avg9\update\backup\avgresf.dll
2010-01-09 17:05 . 2010-01-09 16:50 916248 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-01-09 17:05 . 2010-01-09 16:51 3967256 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-01-09 16:51 . 2010-01-09 16:51 -------- d-----w- C:\$AVG
2010-01-09 16:51 . 2010-01-09 16:51 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-09 16:51 . 2010-01-09 16:51 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-09 16:51 . 2010-01-09 16:51 25608 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-01-09 16:51 . 2010-01-09 16:51 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-01-09 16:51 . 2010-01-09 16:51 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-09 16:51 . 2010-01-09 16:51 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-09 16:51 . 2010-01-09 16:51 -------- d-----w- c:\windows\system32\drivers\Avg
2010-01-09 16:50 . 2010-01-09 16:50 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-01-09 16:50 . 2010-01-09 16:50 -------- d-----w- c:\program files\AVG
2010-01-09 16:50 . 2010-01-09 16:50 -------- d-----w- c:\programdata\avg9
2010-01-09 12:39 . 2010-01-09 12:39 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-09 12:38 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 12:38 . 2010-01-09 12:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 12:38 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 21:35 . 2010-01-07 21:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-31 12:35 . 2009-12-31 12:35 -------- d-----w- c:\program files\Common Files\Apple
2009-12-31 12:34 . 2009-12-31 12:35 -------- d-----w- c:\program files\QuickTime
2009-12-31 12:34 . 2009-12-31 12:34 -------- d-----w- c:\programdata\Apple Computer
2009-12-31 12:28 . 2009-12-31 12:28 -------- d-----w- c:\program files\Apple Software Update
2009-12-31 12:28 . 2009-12-31 12:28 -------- d-----w- c:\programdata\Apple
2009-12-30 16:54 . 2009-12-30 17:20 -------- d-----w- c:\users\Forejtar\AppData\Local\Deployment
2009-12-30 16:54 . 2009-12-30 16:54 -------- d-----w- c:\users\Forejtar\AppData\Local\Apps
2009-12-30 14:43 . 2009-12-30 14:43 -------- d-----w- c:\users\Forejtar\AppData\Local\ESET
2009-12-21 16:35 . 2009-12-21 16:35 -------- d-----w- c:\users\Forejtar\{f4281064-fd68-4607-b852-7b6aa4733770}
2009-12-21 16:35 . 2009-12-21 16:35 -------- d-----w- c:\windows\system32\nn-NO
2009-12-21 16:35 . 2009-04-17 15:59 397312 ----a-w- c:\windows\system32\athihvs.dll
2009-12-21 16:35 . 2008-07-28 14:53 919552 ----a-w- c:\windows\system32\drivers\athr.sys
2009-12-21 16:35 . 2008-07-28 13:31 516096 ----a-w- c:\windows\system32\S64CPA.exe
2009-12-21 16:35 . 2008-07-28 13:31 53248 ----a-w- c:\windows\system32\athihvui.dll
2009-12-21 16:35 . 2009-12-21 16:36 -------- d-----w- c:\program files\Atheros
2009-12-21 12:25 . 2009-12-21 12:25 -------- d-----w- c:\users\Forejtar\AppData\Roaming\Malwarebytes
2009-12-21 12:25 . 2009-12-21 12:25 -------- d-----w- c:\programdata\Malwarebytes
2009-12-21 12:00 . 2009-12-21 12:00 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-12 07:46 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-12 07:46 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-12 07:46 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 21:03 . 2008-01-21 06:46 598832 ----a-w- c:\windows\system32\perfh005.dat
2010-01-09 21:03 . 2008-01-21 06:46 114992 ----a-w- c:\windows\system32\perfc005.dat
2010-01-07 21:35 . 2008-07-22 10:08 -------- d-----w- c:\program files\Java
2009-12-21 16:35 . 2008-07-22 10:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-21 16:32 . 2009-05-22 19:11 -------- d-----w- c:\programdata\Atheros
2009-12-17 13:39 . 2009-05-26 05:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 07:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-11 06:37 . 2008-07-22 11:10 -------- d-----w- c:\programdata\Microsoft Help
2009-12-05 15:21 . 2009-12-05 15:21 -------- d-----w- c:\programdata\WindowsSearch
2009-11-21 06:40 . 2009-12-10 06:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 06:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-10 06:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-10 06:33 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 06:53 . 2009-11-18 06:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 06:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 06:53 . 2009-11-18 06:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 06:53 . 2009-11-18 06:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 15:47 . 2009-11-15 15:47 -------- d-----w- c:\programdata\Panasonic
2009-11-02 19:42 . 2009-10-03 06:24 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-26 06:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-17 13:48 . 2009-10-05 13:26 2380538 ----a-w- c:\programdata\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe
.

------- Sigcheck -------

[-] 2009-04-11 . E647EDC0D734DBFE6076EF80E8BF6CBC . 627712 . . [6.0.6001.18000] . . c:\windows\System32\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-05-15 95536]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2008-01-11 574864]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-07 149280]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"HDMICtrlMan"="c:\program files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [2008-04-26 716800]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-10-31 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-24 509816]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-11-17 726328]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2008-05-15 54576]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-09 2033432]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-4-14 2979144]
PHOTOfunSTUDIO HD Edition.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe [2009-10-3 44176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b6,96,a8,39,19,1b,ca,01

R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\drivers\AVGIDSvx.sys [9.1.2010 17:51 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [9.1.2010 17:51 161800]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [9.1.2010 17:50 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [9.1.2010 17:51 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [9.1.2010 17:51 360584]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [22.5.2009 20:13 20352]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [9.1.2010 17:50 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [9.1.2010 17:51 2303680]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [9.1.2010 17:50 5832712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [16.4.2008 23:19 40960]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\Toshiba\SMARTLogService\TosIPCSrv.exe [15.7.2008 15:16 106496]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [9.1.2010 17:50 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [9.1.2010 17:50 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [9.1.2010 17:50 27800]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [13.8.2008 10:28 112128]
R3 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [15.4.2008 9:13 51160]
R3 QIOMem;Generic IO & Memory Access;c:\windows\System32\drivers\QIOMem.sys [9.4.2007 16:13 8192]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [24.4.2008 17:35 73728]
S3 FontCache;Mezipaměť písem Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21.1.2008 3:23 21504]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [22.5.2009 20:13 937984]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - voxcom

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'

2010-01-09 c:\windows\Tasks\User_Feed_Synchronization-{728EF048-443D-43E8-8754-6686EDF04B99}.job
- c:\windows\system32\msfeedssync.exe [2009-12-10 04:59]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home
FF - ProfilePath - c:\users\Forejtar\AppData\Roaming\Mozilla\Firefox\Profiles\rj6320j0.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
AddRemove-HDMI - c:\windows\system32\igxpun.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-09 22:25
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\voxcom]

.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-01-09 22:27:10
ComboFix-quarantined-files.txt 2010-01-09 21:27

Před spuštěním: Volných bajtů: 61 406 957 568
Po spuštění: Volných bajtů: 66 234 826 752

- - End Of File - - 9EE3A9A2FFCE8D186FF51CE144744B77

Děkuji za rychlou pomoc.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#2 Příspěvek od motji »

Hezké odpoledne :)

nemá cenu kvůli nějakému problému hned vyměnovat antivir, spíš je lepší použít jednorázové skenery, nebo přijít k nám :) . Zbytečně cpete do pc další drivery a pokud ten starý antivir špatně odinstalujete, mhou spolu kolidovat :roll: .

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

KillAll::
Collect::
C:\Windows\system32\Drivers\voxcom.sys
Driver::
voxcom


-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci


:arrow: Start - ovládací panely - možnosti složky - zobrazení - odkrýt skryté a systémové soubory

:arrow: Dejte soubor otestovat na http://www.virustotal.com

c:\windows\System32\user32.dll

Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Re: Podezření na RootKit.Agent

#3 Příspěvek od Majirka »

LOG:
ComboFix 10-01-04.01 - Forejtar 10.01.2010 15:09:37.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1912.840 [GMT 1:00]
Spuštěný z: c:\users\Forejtar\Desktop\ComboFix1.exe
Použité ovládací přepínače :: c:\users\Forejtar\Desktop\CFScript.txt
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Drivers\voxcom.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_VOXCOM
-------\Service_voxcom


((((((((((((((((((((((((( Soubory vytvořené od 2009-12-10 do 2010-01-10 )))))))))))))))))))))))))))))))
.

2010-01-10 14:20 . 2010-01-10 14:35 -------- d-----w- c:\users\Forejtar\AppData\Local\temp
2010-01-10 14:20 . 2010-01-10 14:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-10 14:20 . 2010-01-10 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-10 13:22 . 2010-01-10 13:22 -------- d-----w- c:\users\Forejtar\AppData\Local\Threat Expert
2010-01-10 13:22 . 2010-01-10 13:22 -------- d-----w- c:\program files\Enigma Software Group
2010-01-10 13:21 . 2009-11-10 09:28 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-01-10 13:21 . 2009-11-10 09:28 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-01-10 13:21 . 2009-11-10 09:28 1640400 ----a-w- c:\windows\PCTBDCore.dll
2010-01-10 13:21 . 2009-11-10 09:26 767952 ----a-w- c:\windows\BDTSupport.dll
2010-01-10 13:21 . 2009-10-28 00:36 1152444 ----a-w- c:\windows\UDB.zip
2010-01-10 13:21 . 2008-11-26 11:08 131 ----a-w- c:\windows\IDB.zip
2010-01-10 13:20 . 2009-10-30 10:09 98600 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2010-01-10 07:47 . 2009-10-30 10:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-10 07:46 . 2009-11-09 10:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-10 07:46 . 2009-10-06 15:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-10 07:46 . 2010-01-10 07:47 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-10 07:46 . 2009-09-03 08:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-10 07:46 . 2010-01-10 14:35 -------- d-----w- c:\program files\Spyware Doctor
2010-01-10 07:46 . 2010-01-10 07:46 -------- d-----w- c:\users\Forejtar\AppData\Roaming\PC Tools
2010-01-10 07:46 . 2010-01-10 07:46 -------- d-----w- c:\programdata\PC Tools
2010-01-09 20:58 . 2010-01-09 21:27 -------- d-----w- C:\ComboFix12264C
2010-01-09 20:48 . 2010-01-09 20:48 -------- d-----w- C:\ComboFix1
2010-01-09 17:05 . 2010-01-09 16:51 3776280 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-01-09 17:05 . 2010-01-09 16:51 4043032 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-01-09 17:05 . 2010-01-09 16:51 2033432 ----a-w- c:\programdata\avg9\update\backup\avgtray.exe
2010-01-09 17:05 . 2010-01-09 16:51 2352920 ----a-w- c:\programdata\avg9\update\backup\avgresf.dll
2010-01-09 17:05 . 2010-01-09 16:50 916248 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-01-09 17:05 . 2010-01-09 16:51 3967256 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-01-09 16:51 . 2010-01-09 16:51 -------- d-----w- C:\$AVG
2010-01-09 16:51 . 2010-01-09 16:51 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-09 16:51 . 2010-01-09 16:51 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-09 16:51 . 2010-01-09 16:51 25608 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-01-09 16:51 . 2010-01-09 16:51 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-01-09 16:51 . 2010-01-09 16:51 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-09 16:51 . 2010-01-09 16:51 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-09 16:51 . 2010-01-10 13:58 -------- d-----w- c:\windows\system32\drivers\Avg
2010-01-09 16:50 . 2010-01-09 16:50 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-01-09 16:50 . 2010-01-09 16:50 -------- d-----w- c:\program files\AVG
2010-01-09 16:50 . 2010-01-09 16:50 -------- d-----w- c:\programdata\avg9
2010-01-09 12:39 . 2010-01-09 12:39 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-09 12:38 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 12:38 . 2010-01-09 12:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 12:38 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 21:35 . 2010-01-07 21:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-31 12:35 . 2009-12-31 12:35 -------- d-----w- c:\program files\Common Files\Apple
2009-12-31 12:34 . 2009-12-31 12:35 -------- d-----w- c:\program files\QuickTime
2009-12-31 12:34 . 2009-12-31 12:34 -------- d-----w- c:\programdata\Apple Computer
2009-12-31 12:28 . 2009-12-31 12:28 -------- d-----w- c:\program files\Apple Software Update
2009-12-31 12:28 . 2009-12-31 12:28 -------- d-----w- c:\programdata\Apple
2009-12-30 16:54 . 2009-12-30 17:20 -------- d-----w- c:\users\Forejtar\AppData\Local\Deployment
2009-12-30 16:54 . 2009-12-30 16:54 -------- d-----w- c:\users\Forejtar\AppData\Local\Apps
2009-12-30 14:43 . 2009-12-30 14:43 -------- d-----w- c:\users\Forejtar\AppData\Local\ESET
2009-12-21 16:35 . 2009-12-21 16:35 -------- d-----w- c:\users\Forejtar\{f4281064-fd68-4607-b852-7b6aa4733770}
2009-12-21 16:35 . 2009-12-21 16:35 -------- d-----w- c:\windows\system32\nn-NO
2009-12-21 16:35 . 2009-04-17 15:59 397312 ----a-w- c:\windows\system32\athihvs.dll
2009-12-21 16:35 . 2008-07-28 14:53 919552 ----a-w- c:\windows\system32\drivers\athr.sys
2009-12-21 16:35 . 2008-07-28 13:31 516096 ----a-w- c:\windows\system32\S64CPA.exe
2009-12-21 16:35 . 2008-07-28 13:31 53248 ----a-w- c:\windows\system32\athihvui.dll
2009-12-21 16:35 . 2009-12-21 16:36 -------- d-----w- c:\program files\Atheros
2009-12-21 12:25 . 2009-12-21 12:25 -------- d-----w- c:\users\Forejtar\AppData\Roaming\Malwarebytes
2009-12-21 12:25 . 2009-12-21 12:25 -------- d-----w- c:\programdata\Malwarebytes
2009-12-21 12:00 . 2009-12-21 12:00 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-12 07:46 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-12 07:46 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-12 07:46 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 13:58 . 2008-01-21 06:46 598832 ----a-w- c:\windows\system32\perfh005.dat
2010-01-10 13:58 . 2008-01-21 06:46 114992 ----a-w- c:\windows\system32\perfc005.dat
2010-01-07 21:35 . 2008-07-22 10:08 -------- d-----w- c:\program files\Java
2009-12-21 16:35 . 2008-07-22 10:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-21 16:32 . 2009-05-22 19:11 -------- d-----w- c:\programdata\Atheros
2009-12-17 13:39 . 2009-05-26 05:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 07:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-11 06:37 . 2008-07-22 11:10 -------- d-----w- c:\programdata\Microsoft Help
2009-12-05 15:21 . 2009-12-05 15:21 -------- d-----w- c:\programdata\WindowsSearch
2009-11-21 06:40 . 2009-12-10 06:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 06:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-10 06:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-10 06:33 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 06:53 . 2009-11-18 06:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 06:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 06:53 . 2009-11-18 06:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 06:53 . 2009-11-18 06:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 15:47 . 2009-11-15 15:47 -------- d-----w- c:\programdata\Panasonic
2009-11-02 19:42 . 2009-10-03 06:24 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-26 06:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-17 13:48 . 2009-10-05 13:26 2380538 ----a-w- c:\programdata\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-05-15 95536]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2008-01-11 574864]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-07 149280]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"HDMICtrlMan"="c:\program files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [2008-04-26 716800]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-10-31 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-24 509816]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-11-17 726328]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2008-05-15 54576]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-09 2033432]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-4-14 2979144]
PHOTOfunSTUDIO HD Edition.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe [2009-10-3 44176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b6,96,a8,39,19,1b,ca,01

R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\drivers\AVGIDSvx.sys [9.1.2010 17:51 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [9.1.2010 17:51 161800]
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [10.1.2010 8:46 207792]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [9.1.2010 17:50 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [9.1.2010 17:51 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [9.1.2010 17:51 360584]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [22.5.2009 20:13 20352]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [9.1.2010 17:50 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [9.1.2010 17:51 2303680]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [9.1.2010 17:50 5832712]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [10.1.2010 14:21 112592]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [16.4.2008 23:19 40960]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10.1.2010 8:46 359624]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\Toshiba\SMARTLogService\TosIPCSrv.exe [15.7.2008 15:16 106496]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [9.1.2010 17:50 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [9.1.2010 17:50 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [9.1.2010 17:50 27800]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [13.8.2008 10:28 112128]
R3 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [15.4.2008 9:13 51160]
R3 QIOMem;Generic IO & Memory Access;c:\windows\System32\drivers\QIOMem.sys [9.4.2007 16:13 8192]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [24.4.2008 17:35 73728]
S3 FontCache;Mezipaměť písem Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21.1.2008 3:23 21504]
S3 GUFAE;GUFAE;c:\users\Forejtar\AppData\Local\Temp\GUFAE.exe --> c:\users\Forejtar\AppData\Local\Temp\GUFAE.exe [?]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [22.5.2009 20:13 937984]
S3 N;N;c:\users\Forejtar\AppData\Local\Temp\N.exe --> c:\users\Forejtar\AppData\Local\Temp\N.exe [?]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - mchInjDrv
*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'

2010-01-10 c:\windows\Tasks\User_Feed_Synchronization-{728EF048-443D-43E8-8754-6686EDF04B99}.job
- c:\windows\system32\msfeedssync.exe [2009-12-10 04:59]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home
FF - ProfilePath - c:\users\Forejtar\AppData\Roaming\Mozilla\Firefox\Profiles\rj6320j0.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 15:35
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(4788)
c:\program files\Spyware Doctor\pctgmhk.dll
c:\windows\system32\OneX.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\System32\bgsvcgen.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2010-01-10 15:42:03 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-10 14:41
ComboFix2.txt 2010-01-09 21:27

Před spuštěním: Volných bajtů: 65 015 709 696
Po spuštění: Volných bajtů: 64 741 990 400

- - End Of File - - C1FEAE62CCF2D62B528934499E55F801

a odkaz:
http://www.virustotal.com/cs/analisis/d ... 1259429256

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#4 Příspěvek od motji »

Fajn, měl by být pryč :) . Jak to vypadá s počítačem?

:arrow: Odinstalujte combofix přes
Start >> Spustit zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.



:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir


:arrow: Stahněte TFC a použijte
TFC (http://oldtimer.geekstogo.com/TFC.exe)


:arrow: Stáhněte Ccleaner,viz můj podpis
-nainstalujte a vyčištěte dočasné soubory, i registry

:arrow: Vložte nový log ze RSIT a řekněte co počítač,jak se chová,už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Re: Podezření na RootKit.Agent

#5 Příspěvek od Majirka »

Tak jsem se dostal k note. Provedl jsem vše podle Vašich pokynů. Notebook se po "scriptu" restartoval a Visty zuřivě opravovali systém, ale běží v pořádku. Po dalším čištění je zatím vše OK. Přikládám Log.:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Forejtar at 2010-01-12 00:07:06
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 64 GB (53%) free of 120 GB
Total RAM: 1912 MB (52% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{728EF048-443D-43E8-8754-6686EDF04B99}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-07 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [2008-01-11 574864]
"topi"=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [2007-07-10 581632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-07 149280]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-06-25 145944]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2007-09-28 75136]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-06-25 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-06-25 170520]
"HDMICtrlMan"=C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [2008-04-26 716800]
"Google EULA Launcher"=c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe [2008-05-28 20480]
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2008-04-29 417792]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-12-15 184320]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2007-10-31 54608]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2008-06-24 509816]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2008-11-17 726328]
"OM2_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe [2008-05-15 54576]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-10-10 203264]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"OM2_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2008-05-15 95536]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PHOTOfunSTUDIO HD Edition.lnk - C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-06-12 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-01-12 00:07:06 ----D---- C:\rsit
2010-01-12 00:07:06 ----D---- C:\Program Files\trend micro
2010-01-12 00:04:03 ----D---- C:\Program Files\CCleaner
2010-01-10 22:39:24 ----D---- C:\Program Files\ESET
2010-01-10 15:42:08 ----D---- C:\Windows\temp
2010-01-10 15:35:00 ----D---- C:\$RECYCLE.BIN
2010-01-10 14:22:29 ----D---- C:\Program Files\Enigma Software Group
2010-01-10 08:46:49 ----AD---- C:\ProgramData\TEMP
2010-01-09 21:58:41 ----D---- C:\ComboFix12264C
2010-01-09 21:48:31 ----D---- C:\Windows\ERDNT
2010-01-09 21:48:31 ----D---- C:\ComboFix1
2010-01-09 21:17:42 ----A---- C:\Windows\ntbtlog.txt
2010-01-09 17:50:12 ----D---- C:\Program Files\AVG
2010-01-09 13:38:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-07 22:35:39 ----A---- C:\Windows\system32\javaws.exe
2010-01-07 22:35:39 ----A---- C:\Windows\system32\deploytk.dll
2010-01-07 22:35:38 ----A---- C:\Windows\system32\javaw.exe
2010-01-07 22:35:38 ----A---- C:\Windows\system32\java.exe
2010-01-02 11:31:18 ----D---- C:\Windows\Minidump
2009-12-31 13:35:32 ----D---- C:\Program Files\Common Files\Apple
2009-12-31 13:34:47 ----D---- C:\ProgramData\Apple Computer
2009-12-31 13:34:47 ----D---- C:\Program Files\QuickTime
2009-12-31 13:28:19 ----D---- C:\ProgramData\Apple
2009-12-31 13:28:19 ----D---- C:\Program Files\Apple Software Update
2009-12-21 17:35:32 ----D---- C:\Windows\system32\nn-NO
2009-12-21 17:35:32 ----A---- C:\Windows\system32\S64CPA.exe
2009-12-21 17:35:32 ----A---- C:\Windows\system32\athihvui.dll
2009-12-21 17:35:32 ----A---- C:\Windows\system32\athihvs.dll
2009-12-21 17:35:13 ----D---- C:\Program Files\Atheros
2009-12-21 13:25:35 ----D---- C:\Users\Forejtar\AppData\Roaming\Malwarebytes
2009-12-21 13:25:29 ----D---- C:\ProgramData\Malwarebytes
2009-12-17 14:39:01 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 months======

2010-01-12 00:07:06 ----RD---- C:\Program Files
2010-01-12 00:01:38 ----D---- C:\Windows
2010-01-11 23:58:28 ----AD---- C:\Windows\System32
2010-01-11 23:58:27 ----D---- C:\Windows\inf
2010-01-11 23:58:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-11 23:49:31 ----D---- C:\Windows\system32\drivers
2010-01-10 22:39:56 ----SHD---- C:\Windows\Installer
2010-01-10 22:38:25 ----SHD---- C:\System Volume Information
2010-01-10 22:33:23 ----D---- C:\ProgramData
2010-01-10 22:32:09 ----D---- C:\Windows\system32\catroot
2010-01-10 15:46:38 ----D---- C:\Program Files\Common Files
2010-01-10 15:35:27 ----A---- C:\Windows\system.ini
2010-01-10 15:20:35 ----D---- C:\Windows\system32\config
2010-01-10 15:20:35 ----D---- C:\Boot
2010-01-10 15:15:19 ----D---- C:\Windows\AppPatch
2010-01-10 14:22:38 ----D---- C:\Windows\system32\Tasks
2010-01-10 14:21:08 ----D---- C:\Windows\Prefetch
2010-01-10 14:19:27 ----D---- C:\Windows\winsxs
2010-01-09 23:00:37 ----D---- C:\Windows\system
2010-01-09 17:49:37 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-09 17:24:58 ----D---- C:\Windows\IME
2010-01-09 14:37:13 ----D---- C:\Windows\tapi
2010-01-07 22:37:03 ----D---- C:\Program Files\Mozilla Firefox
2010-01-07 22:35:17 ----D---- C:\Program Files\Java
2010-01-07 21:23:08 ----SD---- C:\Windows\Downloaded Program Files
2010-01-05 20:31:46 ----D---- C:\Windows\system32\catroot2
2009-12-30 15:50:42 ----D---- C:\Windows\rescache
2009-12-30 10:07:36 ----D---- C:\Windows\system32\cs-CZ
2009-12-21 17:35:32 ----D---- C:\Windows\system32\zh-TW
2009-12-21 17:35:32 ----D---- C:\Windows\system32\zh-CN
2009-12-21 17:35:32 ----D---- C:\Windows\system32\tr-TR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\sv-SE
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ru-RU
2009-12-21 17:35:32 ----D---- C:\Windows\system32\pt-PT
2009-12-21 17:35:32 ----D---- C:\Windows\system32\pl-PL
2009-12-21 17:35:32 ----D---- C:\Windows\system32\nl-NL
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ko-KR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ja-JP
2009-12-21 17:35:32 ----D---- C:\Windows\system32\it-IT
2009-12-21 17:35:32 ----D---- C:\Windows\system32\hu-HU
2009-12-21 17:35:32 ----D---- C:\Windows\system32\fr-FR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\fi-FI
2009-12-21 17:35:32 ----D---- C:\Windows\system32\es-ES
2009-12-21 17:35:32 ----D---- C:\Windows\system32\en-US
2009-12-21 17:35:32 ----D---- C:\Windows\system32\el-GR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\de-DE
2009-12-21 17:35:32 ----D---- C:\Windows\system32\da-DK
2009-12-21 17:35:10 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-21 17:32:26 ----D---- C:\ProgramData\Atheros
2009-12-21 14:52:00 ----SD---- C:\ProgramData\Microsoft
2009-12-20 06:06:17 ----D---- C:\Windows\Tasks
2009-12-20 06:06:17 ----D---- C:\Windows\system32\spool
2009-12-20 06:06:17 ----D---- C:\Windows\system32\Msdtc
2009-12-20 06:06:16 ----D---- C:\Windows\system32\wbem
2009-12-20 06:06:16 ----D---- C:\Windows\registration
2009-12-20 06:02:33 ----D---- C:\Windows\system32\LogFiles
2009-12-17 15:09:12 ----D---- C:\ProgramData\Adobe
2009-12-17 14:39:08 ----D---- C:\Program Files\Common Files\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 cdrbsdrv;cdrbsdrv; C:\Windows\system32\drivers\cdrbsdrv.sys [2006-02-20 33408]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 jswpslwf;JumpStart Wireless Filter Driver; C:\Windows\system32\DRIVERS\jswpslwf.sys [2007-08-31 20352]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 95896]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-17 8704]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-11-27 164400]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-07-28 919552]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-03-04 188416]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-03-25 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-03-25 207872]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-06-12 2381312]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-06-20 112128]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2008-04-15 51160]
R3 QIOMem;Generic IO & Memory Access; C:\Windows\system32\DRIVERS\QIOMem.sys [2007-04-09 8192]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2008-03-25 41472]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
R3 usbvideo;Chicony USB 2.0 Camera; C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 UVCFTR;UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [2007-12-17 18432]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-03-25 661504]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-04-04 310272]
S3 catchme;catchme; \??\C:\Users\Forejtar\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 esihdrv;esihdrv; \??\C:\Users\Forejtar\AppData\Local\Temp\esihdrv.sys []
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 Inspect;Comodo Firewall Network Driver; C:\Windows\system32\DRIVERS\inspect.sys []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-04-23 131712]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2008-03-19 74112]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2008-01-22 54144]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 bgsvcgen;B's Recorder GOLD Library General Service; C:\Windows\System32\bgsvcgen.exe [2007-06-15 145504]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-16 40960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 o2flash;O2Micro Flash Memory Card Service; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [2007-02-12 65536]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
R2 TNaviSrv;TOSHIBA Navi Support Service; C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [2008-07-18 83312]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2007-11-21 129632]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2008-04-11 124264]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-07-15 106496]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-17 386560]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [2008-04-24 73728]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 GUFAE;GUFAE; C:\Users\Forejtar\AppData\Local\Temp\GUFAE.exe []
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-22 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 jswpsapi;Jumpstart Wifi Protected Setup; C:\Program Files\Jumpstart\jswpsapi.exe [2007-10-29 937984]
S3 N;N; C:\Users\Forejtar\AppData\Local\Temp\N.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#6 Příspěvek od motji »

:shock: A nevíte co tak zuřivě opravovaly? :o , smazali jsme pouze jednoho rootkita, nic víc :) .

:arrow: Prosím stahněte ještě odtud Hijackthis a vložte zde log :)
http://www.slunecnice.cz/sw/hijackthis/stahnout/

:arrow: smažte
C:\ComboFix12264C
C:\ComboFix1

:arrow: Tuto složku znáte?
C:\Windows\system32\nn-NO

:arrow: start - spustit
napsat - cmd -ok
-do černého okénka napište
sc delete catchme
ok
sc delete esihdrv

ok
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Re: Podezření na RootKit.Agent

#7 Příspěvek od Majirka »

nevím, ale vypisovaly opravené bloky.

Log:
Logfile of HijackThis v1.99.1
Scan saved at 9:20:52, on 13.1.2010
Platform: Unknown Windows (WinNT 6.00.1906 SP2)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
C:\Users\Forejtar\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO HD Edition.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\System32\bgsvcgen.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GUFAE - Unknown owner - C:\Users\Forejtar\AppData\Local\Temp\GUFAE.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: N - Unknown owner - C:\Users\Forejtar\AppData\Local\Temp\N.exe (file missing)
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#8 Příspěvek od motji »

Chybné bloky? :o

:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript

Kód: Vybrat vše

:processes
explorer.exe
 
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Users\Forejtar\AppData\Local\Temp\*.exe /s
:reg

:Services
GUFAE
N
gpsvc
seclogon

:commands
[emptytemp]
[clearallrestorepoints]
[Reboot]
-klikněte na červené tlačítko Moveit!
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem

:arrow: Pak poprosím o nový log ze Rsitu :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Re: Podezření na RootKit.Agent

#9 Příspěvek od Majirka »

Log OTM:
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5C42.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E0.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC715.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp folder moved successfully.
C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Temp\RACE436.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\308a824ca78ce3bce06ec2198d074849\BIT5D5B.tmp moved successfully.
File/Folder C:\Users\Forejtar\AppData\Local\Temp\*.exe not found.
========== REGISTRY ==========
========== SERVICES/DRIVERS ==========
Service GUFAE stopped successfully!
Service GUFAE deleted successfully!
Service N stopped successfully!
Service N deleted successfully!
Error: No service named gpsvc was found to stop!
Unable to stop service gpsvc!
Error: Unable to stop service seclogon!
Service seclogon deleted successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Forejtar
->Temp folder emptied: 0 bytes

A Log Rsit:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Forejtar at 2010-01-13 09:56:10
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 66 GB (54%) free of 120 GB
Total RAM: 1912 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:28, on 13.1.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\notepad.exe
C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Apoint2K\HidFind.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
G:\RSIT.exe
C:\Program Files\trend micro\Forejtar.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PHOTOfunSTUDIO HD Edition.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\System32\bgsvcgen.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7934 bytes

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{728EF048-443D-43E8-8754-6686EDF04B99}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-07 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [2008-01-11 574864]
"topi"=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [2007-07-10 581632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-07 149280]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-06-25 145944]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2007-09-28 75136]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-06-25 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-06-25 170520]
"HDMICtrlMan"=C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [2008-04-26 716800]
"Google EULA Launcher"=c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe [2008-05-28 20480]
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2008-04-29 417792]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-12-15 184320]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2007-10-31 54608]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2008-06-24 509816]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2008-11-17 726328]
"OM2_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe [2008-05-15 54576]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-10-10 203264]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"OM2_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2008-05-15 95536]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PHOTOfunSTUDIO HD Edition.lnk - C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-06-12 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-01-13 09:47:47 ----D---- C:\_OTM
2010-01-13 09:11:25 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 09:11:24 ----A---- C:\Windows\system32\fontsub.dll
2010-01-12 00:07:06 ----D---- C:\rsit
2010-01-12 00:07:06 ----D---- C:\Program Files\trend micro
2010-01-12 00:04:03 ----D---- C:\Program Files\CCleaner
2010-01-10 22:39:24 ----D---- C:\Program Files\ESET
2010-01-10 15:42:08 ----D---- C:\Windows\temp
2010-01-10 15:35:00 ----D---- C:\$RECYCLE.BIN
2010-01-10 14:22:29 ----D---- C:\Program Files\Enigma Software Group
2010-01-10 08:46:49 ----AD---- C:\ProgramData\TEMP
2010-01-09 21:48:31 ----D---- C:\Windows\ERDNT
2010-01-09 17:50:12 ----D---- C:\Program Files\AVG
2010-01-09 13:38:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-07 22:35:39 ----A---- C:\Windows\system32\javaws.exe
2010-01-07 22:35:39 ----A---- C:\Windows\system32\deploytk.dll
2010-01-07 22:35:38 ----A---- C:\Windows\system32\javaw.exe
2010-01-07 22:35:38 ----A---- C:\Windows\system32\java.exe
2010-01-02 11:31:18 ----D---- C:\Windows\Minidump
2009-12-31 13:35:32 ----D---- C:\Program Files\Common Files\Apple
2009-12-31 13:34:47 ----D---- C:\ProgramData\Apple Computer
2009-12-31 13:34:47 ----D---- C:\Program Files\QuickTime
2009-12-31 13:28:19 ----D---- C:\ProgramData\Apple
2009-12-31 13:28:19 ----D---- C:\Program Files\Apple Software Update
2009-12-21 17:35:32 ----A---- C:\Windows\system32\S64CPA.exe
2009-12-21 17:35:32 ----A---- C:\Windows\system32\athihvui.dll
2009-12-21 17:35:32 ----A---- C:\Windows\system32\athihvs.dll
2009-12-21 17:35:13 ----D---- C:\Program Files\Atheros
2009-12-21 13:25:35 ----D---- C:\Users\Forejtar\AppData\Roaming\Malwarebytes
2009-12-21 13:25:29 ----D---- C:\ProgramData\Malwarebytes
2009-12-17 14:39:01 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 months======

2010-01-13 09:49:01 ----D---- C:\Windows\winsxs
2010-01-13 09:45:39 ----AD---- C:\Windows\System32
2010-01-13 09:45:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-13 09:45:38 ----D---- C:\Windows\inf
2010-01-13 09:34:30 ----SHD---- C:\System Volume Information
2010-01-13 09:27:37 ----SHD---- C:\Windows\Installer
2010-01-13 09:27:31 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 09:27:09 ----D---- C:\Windows\system32\catroot
2010-01-13 09:27:05 ----D---- C:\Program Files\Windows Mail
2010-01-13 09:25:46 ----D---- C:\Windows\Debug
2010-01-13 09:09:00 ----D---- C:\Windows\system32\catroot2
2010-01-13 09:07:06 ----D---- C:\Windows
2010-01-12 00:18:02 ----D---- C:\Windows\system32\drivers
2010-01-12 00:07:06 ----RD---- C:\Program Files
2010-01-10 22:33:23 ----D---- C:\ProgramData
2010-01-10 15:46:38 ----D---- C:\Program Files\Common Files
2010-01-10 15:35:27 ----A---- C:\Windows\system.ini
2010-01-10 15:20:35 ----D---- C:\Windows\system32\config
2010-01-10 15:20:35 ----D---- C:\Boot
2010-01-10 15:15:19 ----D---- C:\Windows\AppPatch
2010-01-10 14:22:38 ----D---- C:\Windows\system32\Tasks
2010-01-10 14:21:08 ----D---- C:\Windows\Prefetch
2010-01-09 23:00:37 ----D---- C:\Windows\system
2010-01-09 17:49:37 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-09 17:24:58 ----D---- C:\Windows\IME
2010-01-09 14:37:13 ----D---- C:\Windows\tapi
2010-01-07 22:37:03 ----D---- C:\Program Files\Mozilla Firefox
2010-01-07 22:35:17 ----D---- C:\Program Files\Java
2010-01-07 21:23:08 ----SD---- C:\Windows\Downloaded Program Files
2010-01-05 01:17:46 ----A---- C:\Windows\system32\mrt.exe
2009-12-30 15:50:42 ----D---- C:\Windows\rescache
2009-12-30 10:07:36 ----D---- C:\Windows\system32\cs-CZ
2009-12-21 17:35:32 ----D---- C:\Windows\system32\zh-TW
2009-12-21 17:35:32 ----D---- C:\Windows\system32\zh-CN
2009-12-21 17:35:32 ----D---- C:\Windows\system32\tr-TR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\sv-SE
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ru-RU
2009-12-21 17:35:32 ----D---- C:\Windows\system32\pt-PT
2009-12-21 17:35:32 ----D---- C:\Windows\system32\pl-PL
2009-12-21 17:35:32 ----D---- C:\Windows\system32\nl-NL
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ko-KR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\ja-JP
2009-12-21 17:35:32 ----D---- C:\Windows\system32\it-IT
2009-12-21 17:35:32 ----D---- C:\Windows\system32\hu-HU
2009-12-21 17:35:32 ----D---- C:\Windows\system32\fr-FR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\fi-FI
2009-12-21 17:35:32 ----D---- C:\Windows\system32\es-ES
2009-12-21 17:35:32 ----D---- C:\Windows\system32\en-US
2009-12-21 17:35:32 ----D---- C:\Windows\system32\el-GR
2009-12-21 17:35:32 ----D---- C:\Windows\system32\de-DE
2009-12-21 17:35:32 ----D---- C:\Windows\system32\da-DK
2009-12-21 17:35:10 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-21 17:32:26 ----D---- C:\ProgramData\Atheros
2009-12-21 14:52:00 ----SD---- C:\ProgramData\Microsoft
2009-12-20 06:06:17 ----D---- C:\Windows\Tasks
2009-12-20 06:06:17 ----D---- C:\Windows\system32\spool
2009-12-20 06:06:17 ----D---- C:\Windows\system32\Msdtc
2009-12-20 06:06:16 ----D---- C:\Windows\system32\wbem
2009-12-20 06:06:16 ----D---- C:\Windows\registration
2009-12-20 06:02:33 ----D---- C:\Windows\system32\LogFiles
2009-12-17 15:09:12 ----D---- C:\ProgramData\Adobe
2009-12-17 14:39:08 ----D---- C:\Program Files\Common Files\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 cdrbsdrv;cdrbsdrv; C:\Windows\system32\drivers\cdrbsdrv.sys [2006-02-20 33408]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 jswpslwf;JumpStart Wireless Filter Driver; C:\Windows\system32\DRIVERS\jswpslwf.sys [2007-08-31 20352]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 95896]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-17 8704]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-11-27 164400]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-07-28 919552]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-03-04 188416]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-03-25 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-03-25 207872]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-06-12 2381312]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-06-20 112128]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2008-04-15 51160]
R3 QIOMem;Generic IO & Memory Access; C:\Windows\system32\DRIVERS\QIOMem.sys [2007-04-09 8192]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2008-03-25 41472]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
R3 usbvideo;Chicony USB 2.0 Camera; C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 UVCFTR;UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [2007-12-17 18432]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-03-25 661504]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-04-04 310272]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 Inspect;Comodo Firewall Network Driver; C:\Windows\system32\DRIVERS\inspect.sys []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-04-23 131712]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2008-03-19 74112]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2008-01-22 54144]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 bgsvcgen;B's Recorder GOLD Library General Service; C:\Windows\System32\bgsvcgen.exe [2007-06-15 145504]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-16 40960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 o2flash;O2Micro Flash Memory Card Service; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [2007-02-12 65536]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
R2 TNaviSrv;TOSHIBA Navi Support Service; C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [2008-07-18 83312]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2007-11-21 129632]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2008-04-11 124264]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-07-15 106496]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-17 386560]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [2008-04-24 73728]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-22 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 jswpsapi;Jumpstart Wifi Protected Setup; C:\Program Files\Jumpstart\jswpsapi.exe [2007-10-29 937984]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#10 Příspěvek od motji »

:arrow: Otevřete si Poznámkový blok a zkopírujte do něj text

Kód: Vybrat vše

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-


 
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.

:arrow:Otevřete znovu Otm a klikněte na tlačítko CleanUp,potvrďte ok


Jak to vypadá ted s počítačem?

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Majirka
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 10 čer 2009 09:47

Re: Podezření na RootKit.Agent

#11 Příspěvek od Majirka »

Děkuji za odpovědi (PC2 a PC3). PC které je na kabelu tak je spojení OK, ale Notebook přes WiFi se taky seká. Včera jsem dělal hlubší kontrolu jeho sítě a asi se nahromadilo víc věcí najednou: Viry, problém s routerem( nefunkční Scan volného WiFi kanálu ), a to podtrřeno Vistou :(( . Jěště provedu vámi poslané opravy. Děkuji

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Podezření na RootKit.Agent

#12 Příspěvek od motji »

Dobře, uvidíme co z toho vyleze :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět