Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
coconut
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 12 led 2010 16:26

Prosím o kontrolu logu

#1 Příspěvek od coconut »

Nejdou spustit některé internetové stránky

Logfile of random's system information tool 1.06 (written by random/random)
Run by uzivatel at 2010-01-12 16:19:56
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 74 GB (65%) free of 114 GB
Total RAM: 1023 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:20:03, on 12.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\uzivatel\Plocha\RSIT.exe
C:\Program Files\trend micro\uzivatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\TRANSLAT\WEBIE.DLL
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C43 Series" /O5 "LPT1:" /M "Stylus C43"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0032367468
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: winmm.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/uzivatel/LOCALS~1/Temp/msohtml1/01/clip_image001.gif

--
End of file - 8786 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5E269E6B-FDD2-437B-9D72-8252E87D258B}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2009-12-15 1218000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\TRANSLAT\WEBIE.DLL [2006-11-08 360448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-01-04 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-11-10 2133056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\TRANSLAT\WEBIE.DLL [2006-11-08 360448]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-11-10 2133056]
Locked
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2009-12-15 1218000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-24 90112]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-07-20 7110656]
"nwiz"=nwiz.exe /install []
"SW20"=C:\WINDOWS\system32\sw20.exe [2005-06-30 200704]
"SW24"=C:\WINDOWS\system32\sw24.exe [2005-07-04 69632]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-07-20 86016]
"EPSON Stylus C43 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2002-12-10 75776]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-14 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-14 81920]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-01-04 2033432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-12 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-01-04 12464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.scr - open - "C:\WINDOWS\system32\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-01-12 16:18:02 ----D---- C:\rsit
2010-01-12 15:58:25 ----D---- C:\Program Files\Trend Micro
2010-01-12 15:34:59 ----D---- C:\Program Files\Crawler
2010-01-12 15:34:55 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Spyware Terminator
2010-01-12 15:34:51 ----D---- C:\Program Files\Spyware Terminator
2010-01-12 15:34:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-01-12 15:16:26 ----A---- C:\WINDOWS\resetlog.txt
2010-01-05 18:13:51 ----D---- C:\AVGTemp
2010-01-04 19:56:26 ----HD---- C:\$AVG
2010-01-04 19:56:16 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-01-04 19:56:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2010-01-04 19:55:43 ----D---- C:\Program Files\AVG
2010-01-04 19:55:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\avg9
2010-01-04 19:39:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Martau
2010-01-04 19:39:13 ----D---- C:\Program Files\Total Uninstall 5
2010-01-04 17:51:57 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Mozilla
2010-01-04 17:51:47 ----D---- C:\Program Files\Mozilla Firefox
2010-01-02 14:58:38 ----D---- C:\WINDOWS\Minidump
2009-12-30 18:51:45 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-12-30 18:51:26 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-12-30 18:51:09 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-12-30 18:50:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-12-28 11:21:41 ----A---- C:\WINDOWS\system32\MFC71.dll
2009-12-28 11:21:38 ----D---- C:\Program Files\Alwil Software
2009-12-28 11:18:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avg7
2009-12-28 10:56:14 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-12-28 10:56:09 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-12-28 10:55:51 ----D---- C:\Program Files\Windows Media Connect 2
2009-12-28 10:55:40 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-12-28 10:54:06 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-12-28 10:53:23 ----D---- C:\WINDOWS\system32\LogFiles
2009-12-28 10:53:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-12-28 10:40:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2009-12-28 10:40:30 ----D---- C:\Program Files\Common Files\Adobe
2009-12-27 11:12:04 ----D---- C:\=Jazyky=
2009-12-24 10:17:31 ----D---- C:\Program Files\ViaVoiceTTS
2009-12-24 10:17:31 ----A---- C:\WINDOWS\system32\rotest.txt
2009-12-24 10:16:12 ----D---- C:\WINDOWS\Lhsp
2009-12-24 10:15:59 ----D---- C:\WINDOWS\speech
2009-12-24 10:15:44 ----D---- C:\Program Files\TZ one
2009-12-21 19:04:41 ----A---- C:\WINDOWS\system32\tsccvid.dll

======List of files/folders modified in the last 1 months======

2010-01-12 16:18:10 ----D---- C:\WINDOWS\Prefetch
2010-01-12 15:58:25 ----RD---- C:\Program Files
2010-01-12 15:34:57 ----D---- C:\WINDOWS\system32\drivers
2010-01-12 15:26:41 ----D---- C:\WINDOWS\Temp
2010-01-12 15:25:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-12 15:23:11 ----D---- C:\WINDOWS
2010-01-12 15:21:37 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-12 15:21:31 ----D---- C:\WINDOWS\system32
2010-01-12 15:21:31 ----D---- C:\Program Files\RTSStavitel
2010-01-12 15:21:26 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-12 15:06:13 ----HD---- C:\WINDOWS\inf
2010-01-12 12:36:55 ----D---- C:\=Adast=
2010-01-07 14:40:08 ----D---- C:\WINDOWS\network diagnostic
2010-01-06 21:21:04 ----SD---- C:\WINDOWS\Tasks
2010-01-06 15:55:52 ----D---- C:\Program Files\MS Agent a české SAPI od GT Soft
2010-01-04 19:55:29 ----SHD---- C:\WINDOWS\Installer
2010-01-04 19:01:17 ----D---- C:\WINDOWS\WinSxS
2010-01-04 19:01:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-04 18:24:22 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-04 18:03:32 ----A---- C:\WINDOWS\TRNCOM.INI
2010-01-04 17:26:04 ----D---- C:\= Fotky =
2009-12-30 18:51:48 ----A---- C:\WINDOWS\imsins.BAK
2009-12-29 09:06:48 ----D---- C:\= Soudy =
2009-12-28 14:54:53 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-28 14:15:26 ----D---- C:\WINDOWS\system32\config
2009-12-28 11:18:02 ----D---- C:\WINDOWS\system
2009-12-28 11:06:52 ----D---- C:\Program Files\Build Power
2009-12-28 10:57:45 ----D---- C:\Program Files\Windows Media Player
2009-12-28 10:56:03 ----A---- C:\WINDOWS\win.ini
2009-12-28 10:55:47 ----D---- C:\WINDOWS\Help
2009-12-28 10:52:42 ----D---- C:\= Filmy =
2009-12-28 10:40:30 ----D---- C:\Program Files\Common Files
2009-12-28 10:40:30 ----D---- C:\Program Files\Adobe
2009-12-27 11:55:01 ----A---- C:\WINDOWS\winzip32.ini
2009-12-24 10:28:57 ----RSD---- C:\WINDOWS\Fonts
2009-12-24 10:26:16 ----D---- C:\= Dokumenty =
2009-12-24 10:18:02 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-24 10:15:53 ----D---- C:\WINDOWS\msagent
2009-12-17 17:34:48 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Adobe
2009-12-14 13:47:35 ----D---- C:\=Zákony a předpisy=
2009-12-13 19:23:38 ----D---- C:\WINDOWS\system32\wbem
2009-12-13 19:23:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-01-04 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-01-04 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-01-04 360584]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-26 3786944]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-07-20 3198368]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Winacpci;Winacpci; C:\WINDOWS\system32\DRIVERS\winacpci.sys [1999-11-03 900528]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-10-21 223128]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-01-04 285392]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2002-07-17 94208]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-07-20 127043]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-01-12 488960]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-11-24 603904]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-11-24 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-11-24 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119495
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#2 Příspěvek od Rudy »

Nic nebezpečného nevidím. Dejte log z MBAM: http://www.malwarebytes.org/mbam.php . Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

coconut
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 12 led 2010 16:26

Re: Prosím o kontrolu logu

#3 Příspěvek od coconut »

Při testování MBAM vytuhne.Projel jsem to Spyware Terminátorem , a našlo to nějaký WinSys.
tady je log z terminatora.
Logfile of Spyware Terminator v2.6.5.111 (db:4.001.012.000)
Scan Time: 12.1.2010 15:41:57 length: 155 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Fast_Spyware_Scan
Scanned Objects: 38456 (Critical:1)
Filter: No System items, No Safe items, No Invalid items

Running Processes
SAgent2.exe [SEIKO EPSON CORPORATION] : C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
nvsvc32.exe [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exe
TUProgSt.exe [TuneUp Software] : C:\WINDOWS\system32\TUProgSt.exe

Internet Settings
R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://www.google.com/ie
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://www.google.com/ie
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - : C:\TRANSLAT\WEBIE.DLL
02 - BHO: ToolBarButton Class - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - : C:\TRANSLAT\WEBIE.DLL
02 - BHO: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - : C:\TRANSLAT\WEBIE.DLL
02 - BHO: MenuItem3 Class - {CC963627-B1DC-40E0-B52A-CF21EE748450} - : C:\TRANSLAT\WEBIE.DLL
02 - BHO: MenuItem2 Class - {CC963627-B1DC-40E0-B52A-CF21EE748451} - : C:\TRANSLAT\WEBIE.DLL
02 - BHO: MenuItem1 Class - {CC963627-B1DC-40E0-B52A-CF21EE748452} - : C:\TRANSLAT\WEBIE.DLL

Toolbars
03 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - : C:\TRANSLAT\WEBIE.DLL

StartUps
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SW20 : : C:\WINDOWS\system32\sw20.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SW24 : : C:\WINDOWS\system32\sw24.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, EPSON Stylus C43 Series : [SEIKO EPSON CORPORATION] : C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\E_S10IC2.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe ARM : [Adobe Systems Incorporated] : C:\Program Files\Common Files\ADOBE\ARM\1.0\ADOBEARM.EXE

Shell Extensions
Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
- {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
nView Desktop Context Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A48} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
ACTHUMBNAIL - {AC1DB655-4F9A-4c39-8AD2-A65324A4C446} - [Autodesk, Inc.] : C:\Program Files\Common Files\Autodesk Shared\Thumbnail\AcThumbnail16.dll
AcSignIcon - {36A21736-36C2-4C11-8ACB-D4136F2B57BD} - [Autodesk, Inc.] : C:\WINDOWS\system32\AcSignIcon.dll
WinZip - {e0d79300-84be-11ce-9641-444553540000} - [Nico Mak Computing, Inc.] : C:\Program Files\WINZIP\WZSHLEXT.DLL
AcColumnHandler - {8A0BC933-7552-42E2-A228-3BE055777227} - [Autodesk] : C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
AcInfoTipHandler - {5800AD5B-72C1-477B-9A08-CA112DF06D97} - [Autodesk] : C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
AcDgnImageExtractor - {ADC46291-D8A1-4486-A24C-86FFB392AEFA} - [Autodesk] : C:\Program Files\Common Files\Autodesk Shared\AcDgnCOM17.dll
TuneUp Theme Extension - {44440D00-FF19-4AFC-B765-9A0970567D97} - [TuneUp Software] : C:\WINDOWS\system32\uxtuneup.dll
TuneUp Shredder Shell Extension - {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} - [TuneUp Software] : C:\Program Files\TuneUp Utilities 2009\SDShelEx-win32.dll
TuneUp Disk Space Explorer Shell Extension - {4838CD50-7E5D-4811-9B17-C47A85539F28} - [TuneUp Software] : C:\Program Files\TuneUp Utilities 2009\DseShExt-x86.dll

Protocol Handler
Data Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
Data Page Plugable Protocal mso-offdap11 Handler - {32505114-5902-49B2-880A-1F7738E5A384} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL

Services
23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\ALCXWDM.SYS
23 - [SEIKO EPSON CORPORATION] : C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
23 - [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exe
23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
23 - : C:\WINDOWS\system32\Drivers\sptd.sys
23 - [TuneUp Software] : C:\WINDOWS\system32\TUProgSt.exe
23 - [Conexant] : C:\WINDOWS\system32\DRIVERS\winacpci.sys
23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys

Threat Files
<WSys> : C:\WINDOWS\system32\WinSys.exe

Advanced Files Report
%SYSDIR%\uxtuneup.dll [TuneUp Software] [TuneUp Utilities 2009] MD5=4360D5653E885479FED75C378E9FAAB3 SIZE=27904
%SYSDIR%\EBPMON2.DLL [SEIKO EPSON CORPORATION] [EPSON Bidirectional Printer] MD5=6A21323BD6705D5FE9F44731C9C3154E SIZE=73676
%SYSDIR%\pdfcmnnt.dll MD5=1574DD9D409F2DC45CF82C22B99164A4 SIZE=116224
%SYSDIR%\AcSignIcon.dll [Autodesk, Inc.] [AutoCAD] MD5=F28ADCF2E9B3574F25089A69B03DC756 SIZE=44648
%PROGRAMFILES%\Zoner\Callisto 4\Program\fshex40.dll [ZONER software, Ltd.] [Zoner Shell Extensions] MD5=E9E4E4191B6144E988297F112A77ED09 SIZE=45056
%PROGRAMFILES%\Zoner\Callisto 4\Program\FShEx40Res.CZ [ZONER software, Ltd.] [Zoner File ShellEx] MD5=FA042983776E82B1E3D32DFBE146074C SIZE=32768
%COMMONFILES%\Autodesk Shared\AcShellEx\AcShellExtension.dll [Autodesk] [AutoCAD] MD5=9F06182191C4D861EADAA5B9726F53D8 SIZE=103016
%SYSDIR%\NVRSCS.DLL [NVIDIA Corporation] [NVIDIA Compatible Windows 2000 Display driver, Version 77.77] MD5=1F44FC0B07F5604FF26BC51E00D6056E SIZE=233472
%COMMONFILES%\EPSON\EBAPI\SAgent2.exe [SEIKO EPSON CORPORATION] [EPSON Bidirectional Printer] MD5=12CDB5DC7774298223099D6E41ED5CE7 SIZE=94208
%SYSDIR%\EBAPI2.DLL [SEIKO EPSON CORPORATION] [EPSON Bidirectional Printer] MD5=B40DA4318B477B07D635565E3014513D SIZE=139264
%COMMONFILES%\EPSON\EBAPI\EBPLPT.DLL [SEIKO EPSON CORPORATION] [EPSON Bidirectional Printer] MD5=BCE1C54740086D375721E8BBFE41D8F2 SIZE=230912
%SYSDIR%\nvsvc32.exe [NVIDIA Corporation] [NVIDIA Driver Helper Service, Version 77.77] MD5=0BD326515E07602C311FCE4D087F448F SIZE=127043
%SYSDIR%\TUProgSt.exe [TuneUp Software] [TuneUp Utilities 2009] MD5=02E5F68A55CD413C5BFB9F2DF677DD01 SIZE=603904
%SYSDIR%\Macromed\Flash\Flash10d.ocx [Adobe Systems, Inc.] [Shockwave Flash] MD5=C5AA69ED6CE6F2962A79F03039A87084 SIZE=3982240
deskpan.dll
%SYSDIR%\nvshell.dll [NVIDIA Corporation] [NVIDIA Desktop Explorer, Version 105.31] MD5=60ABAF9518D6E184C71B2D9FE3A98F8E SIZE=466944
%COMMONFILES%\Autodesk Shared\Thumbnail\AcThumbnail16.dll [Autodesk, Inc.] [AutoCAD] MD5=8037A66AC428DF35662BF18F85859CFC SIZE=20072
%PROGRAMFILES%\WINZIP\WZSHLEXT.DLL [Nico Mak Computing, Inc.] [WinZip] MD5=5D4EE905DACCB9BCDFBCBD8F20B86471 SIZE=14336
%COMMONFILES%\Autodesk Shared\AcDgnCOM17.dll [Autodesk] [AcDgnCOM Module] MD5=64140741D0295ABE833D6E72A64C2274 SIZE=19560
%PROGRAMFILES%\TuneUp Utilities 2009\SDShelEx-win32.dll [TuneUp Software] [TuneUp Utilities 2009] MD5=D74613A548B310661D3C2E8EE1D2E6D5 SIZE=27392
%PROGRAMFILES%\TuneUp Utilities 2009\DseShExt-x86.dll [TuneUp Software] [TuneUp Utilities 2009] MD5=D0931C71B6204817B54E56089A484CB9 SIZE=25856
%SYSDIR%\drivers\ALCXWDM.SYS [Realtek Semiconductor Corp.] [Windows (R) WDM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab)] MD5=C881453898EEC64027274EBB3C8CBC0F SIZE=3786944
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\svchost.exe -k HTTPFilter
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\svchost -k rpcss
%SYSDIR%\DRIVERS\Rtlnicxp.sys [Realtek Semiconductor Corporation] [Realtek 10/100/1000 NIC Family all in one NDIS Driver] MD5=7F0413BDD7D53EB4C7A371E7F6F84DF1 SIZE=74496
%SYSDIR%\Drivers\sptd.sys SIZE=664064
%SYSDIR%\DRIVERS\winacpci.sys [Conexant] [Modem] MD5=AEAEBE191D30EA837D6241CED16866BB SIZE=900528
%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [Spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592
%COMMONFILES%\Microsoft Shared\Web Components\10\OWC10.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=CD87D4396557AA897952B0ED890DF91E SIZE=7255872
%COMMONFILES%\Microsoft Shared\Web Components\11\OWC11.DLL [Microsoft Corporation] [Microsoft Office 2003] MD5=6038EB24E4B56F42E92072C5A306ECA8 SIZE=8058192

End of Report

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119495
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#4 Příspěvek od Rudy »

OK. Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět