Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Co to moze byt?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Michal100
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 02 úno 2010 11:13

Co to moze byt?

#1 Příspěvek od Michal100 »

Na Usb-čkach sa mi začal samovolne vytvarat tento Ex-áč

Kód: Vybrat vše

http://www.uloz.to/3849443/unnamed.rar 

(Je zbalený v rare)

Prikladám aj:
  • Logfile of random's system information tool 1.06 (written by random/random)
    Run by galko at 2010-02-02 11:34:19
    Systém Microsoft Windows XP Professional Service Pack 3
    System drive C: has 64 GB (59%) free of 109 GB
    Total RAM: 767 MB (52% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:34:29, on 2.2.2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16981)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\WINDOWS\system32\cmd.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    c:\Program Files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe
    c:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\mgabg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\RunDll32.exe
    c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    \hp\OCSINVENTORY$\OCSInventory.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\WINDOWS\system32\userinit.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\galko\My Documents\Preberanie\RSIT.exe
    C:\Program Files\trend micro\galko.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.111.0.65:3128
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Matrox PowerDesk SE] "c:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
    O4 - HKCU\..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
    O4 - Global Startup: Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
    O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3508291843
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = podnik.zvsholding.sk
    O17 - HKLM\Software\..\Telephony: DomainName = podnik.zvsholding.sk
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A2C127-0F4F-4FE9-BD94-585F5E2EED85}: NameServer = 10.111.1.2,10.111.0.65
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CB7BEAB8-8DA4-4EE3-A58A-E1A3AF3C9FEE}: NameServer = 10.111.1.2,10.111.0.65
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = podnik.zvsholding.sk
    O17 - HKLM\System\CS1\Services\Tcpip\..\{B1A2C127-0F4F-4FE9-BD94-585F5E2EED85}: NameServer = 10.111.1.2,10.111.0.65
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = podnik.zvsholding.sk
    O17 - HKLM\System\CS2\Services\Tcpip\..\{B1A2C127-0F4F-4FE9-BD94-585F5E2EED85}: NameServer = 10.111.1.2,10.111.0.65
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Norton 2009 Reset (.norton2009Reset) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Norton\Norton2009Reset.exe (file missing)
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: Matrox Centering Service - Matrox Graphics Inc. - c:\Program Files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe
    O23 - Service: Matrox.Pdesk.ServicesHost - Matrox Graphics Inc - c:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe
    O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\system32\mgabg.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 9154 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-02 41760]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-02 79648]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RaidTool"=C:\Program Files\VIA\RAID\raid_tool.exe [2005-06-20 1056768]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-09-17 13574144]
    "nwiz"=nwiz.exe /install []
    "Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
    "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-09-17 86016]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
    "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
    "LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2008-08-11 63048]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
    "Matrox PowerDesk SE"=c:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe [2009-02-06 4223232]
    "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2006-02-01 98304]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-04-01 486856]
    "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
    "NokiaOviSuite2"=C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray []
    "DLD.EXE"=C:\Program Files\Download Direct\DLD.exe []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Aktualizovat ESET licenci.lnk - C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
    C:\WINDOWS\system32\LMIinit.dll [2009-09-28 87352]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-07-12 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=36
    "NoDriveAutoRun"=FFFFFFFF

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=
    "NoDriveTypeAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "F:\setup\HPZNET01.EXE"="F:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe"
    "F:\setup\HPONICIFS01.EXE"="F:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
    "C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager"
    "C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio"
    "C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi"
    "C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
    "C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
    "C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
    "C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
    "C:\WINDOWS\system32\Sysinfo.exe"="C:\WINDOWS\system32\Sysinfo.exe:*:Enabled:sysupdate"
    "C:\Program Files\McAfee\Common Framework\FrameworkService.exe"="C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0321fbd7-b2ea-11de-8be5-0004769f78ad}]
    shell\AutoRun\command - E:\setupSNK.exe


    ======List of files/folders created in the last 1 months======

    2010-02-02 11:27:11 ----RASHD---- C:\autorun.inf
    2010-02-02 11:16:28 ----D---- C:\Program Files\trend micro
    2010-02-02 11:16:26 ----D---- C:\rsit
    2010-02-02 10:05:42 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
    2010-02-02 10:05:41 ----D---- C:\Program Files\Common Files\Java
    2010-02-02 10:05:19 ----A---- C:\WINDOWS\system32\javaws.exe
    2010-02-02 10:05:19 ----A---- C:\WINDOWS\system32\javaw.exe
    2010-02-02 10:05:19 ----A---- C:\WINDOWS\system32\java.exe
    2010-02-02 10:05:19 ----A---- C:\WINDOWS\system32\deploytk.dll
    2010-02-02 10:05:05 ----D---- C:\Program Files\Java
    2010-02-02 10:04:27 ----D---- C:\Documents and Settings\galko\Application Data\Sun
    2010-02-02 10:02:57 ----D---- C:\Documents and Settings\galko\Application Data\ESET
    2010-02-02 10:02:15 ----D---- C:\Program Files\ESET
    2010-02-02 10:02:15 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
    2010-02-02 09:54:00 ----SHD---- C:\Config.Msi
    2010-02-02 09:13:52 ----D---- C:\Documents and Settings\galko\Application Data\FRISK Software
    2010-02-02 09:07:36 ----D---- C:\Documents and Settings\All Users\Application Data\FRISK Software
    2010-02-02 07:03:08 ----D---- C:\Program Files\Common Files\Cisco Systems
    2010-02-02 07:03:03 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
    2010-02-02 07:02:58 ----D---- C:\Program Files\McAfee
    2010-02-02 06:38:38 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2010-02-02 06:38:38 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
    2010-02-02 06:38:31 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    2010-02-01 11:03:59 ----D---- C:\WINDOWS\system32\LogFiles
    2010-02-01 11:03:55 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
    2010-02-01 10:40:57 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
    2010-02-01 10:21:07 ----A---- C:\WINDOWS\system32\nethlp.dll
    2010-02-01 06:14:38 ----D---- C:\Program Files\SpeedFan
    2010-01-20 05:50:44 ----D---- C:\WINDOWS\Minidump
    2010-01-19 06:57:22 ----D---- C:\WINDOWS\pss
    2010-01-18 06:22:13 ----D---- C:\Program Files\PC Connectivity Solution
    2010-01-18 06:11:04 ----D---- C:\Documents and Settings\All Users\Application Data\OviInstallerCache
    2010-01-13 07:38:25 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
    2010-01-12 14:07:36 ----D---- C:\Program Files\Common Files\Skype
    2010-01-12 14:07:33 ----RD---- C:\Program Files\Skype
    2010-01-11 09:17:10 ----D---- C:\Documents and Settings\galko\Application Data\OpenOffice.org

    ======List of files/folders modified in the last 1 months======

    2010-02-02 11:34:17 ----D---- C:\Documents and Settings\galko\Application Data\Skype
    2010-02-02 11:34:05 ----D---- C:\Program Files\Mozilla Firefox
    2010-02-02 11:33:35 ----D---- C:\WINDOWS
    2010-02-02 11:32:22 ----A---- C:\WINDOWS\SchedLgU.Txt
    2010-02-02 11:31:41 ----HD---- C:\WINDOWS\inf
    2010-02-02 11:31:41 ----D---- C:\WINDOWS\system32\drivers
    2010-02-02 11:31:29 ----SHD---- C:\WINDOWS\Installer
    2010-02-02 11:27:28 ----D---- C:\WINDOWS\Temp
    2010-02-02 11:16:28 ----RD---- C:\Program Files
    2010-02-02 10:15:42 ----D---- C:\WINDOWS\system32
    2010-02-02 10:05:41 ----D---- C:\Program Files\Common Files
    2010-02-02 10:04:47 ----A---- C:\WINDOWS\NeroDigital.ini
    2010-02-02 10:02:34 ----D---- C:\WINDOWS\system32\CatRoot2
    2010-02-02 09:54:28 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2010-02-02 09:12:12 ----D---- C:\Documents and Settings\galko\Application Data\skypePM
    2010-02-02 09:11:07 ----SHD---- C:\System Volume Information
    2010-02-02 07:23:15 ----D---- C:\WINDOWS\Prefetch
    2010-02-02 07:20:33 ----D---- C:\Program Files\Common Files\Nokia
    2010-02-02 07:19:35 ----HD---- C:\Program Files\InstallShield Installation Information
    2010-02-02 07:12:26 ----SHD---- C:\WINDOWS\CSC
    2010-02-02 07:06:36 ----SD---- C:\WINDOWS\Tasks
    2010-02-02 05:56:14 ----D---- C:\Program Files\LogMeIn
    2010-02-01 17:50:20 ----D---- C:\WINDOWS\security
    2010-02-01 11:03:26 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
    2010-02-01 10:39:27 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
    2010-01-28 07:49:15 ----D---- C:\WINDOWS\Registration
    2010-01-25 07:33:29 ----D---- C:\Program Files\Look@LAN
    2010-01-22 05:51:53 ----A---- C:\WINDOWS\imsins.BAK
    2010-01-22 05:50:58 ----DC---- C:\WINDOWS\system32\dllcache
    2010-01-22 05:50:50 ----D---- C:\WINDOWS\system32\en-US
    2010-01-22 05:50:50 ----D---- C:\Program Files\Internet Explorer
    2010-01-22 05:50:31 ----D---- C:\WINDOWS\ie7updates
    2010-01-22 05:49:10 ----HD---- C:\WINDOWS\$hf_mig$
    2010-01-21 12:38:59 ----D---- C:\USD
    2010-01-19 05:58:28 ----D---- C:\Documents and Settings\galko\Application Data\Nokia
    2010-01-18 06:20:37 ----D---- C:\WINDOWS\WinSxS
    2010-01-13 13:21:44 ----A---- C:\WINDOWS\win.ini
    2010-01-12 14:07:33 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2010-01-11 09:15:58 ----RSD---- C:\WINDOWS\Fonts
    2010-01-05 15:30:28 ----A---- C:\WINDOWS\system32\mshtml.dll
    2010-01-05 14:30:29 ----A---- C:\WINDOWS\system32\wininet.dll
    2010-01-05 14:30:28 ----N---- C:\WINDOWS\system32\pngfilt.dll
    2010-01-05 14:30:28 ----N---- C:\WINDOWS\system32\occache.dll
    2010-01-05 14:30:28 ----N---- C:\WINDOWS\system32\mstime.dll
    2010-01-05 14:30:28 ----A---- C:\WINDOWS\system32\webcheck.dll
    2010-01-05 14:30:28 ----A---- C:\WINDOWS\system32\urlmon.dll
    2010-01-05 14:30:28 ----A---- C:\WINDOWS\system32\url.dll
    2010-01-05 14:30:27 ----N---- C:\WINDOWS\system32\msrating.dll
    2010-01-05 14:30:27 ----N---- C:\WINDOWS\system32\mshtmled.dll
    2010-01-05 14:30:25 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
    2010-01-05 14:30:24 ----N---- C:\WINDOWS\system32\jsproxy.dll
    2010-01-05 14:30:24 ----N---- C:\WINDOWS\system32\iernonce.dll
    2010-01-05 14:30:24 ----N---- C:\WINDOWS\system32\iepeers.dll
    2010-01-05 14:30:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
    2010-01-05 14:30:24 ----A---- C:\WINDOWS\system32\iertutil.dll
    2010-01-05 14:30:23 ----A---- C:\WINDOWS\system32\ieframe.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\ieencode.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\iedkcs32.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\ieaksie.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\ieakeng.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\extmgr.dll
    2010-01-05 14:30:21 ----N---- C:\WINDOWS\system32\dxtrans.dll
    2010-01-05 14:30:21 ----A---- C:\WINDOWS\system32\ieapfltr.dll
    2010-01-05 14:30:21 ----A---- C:\WINDOWS\system32\icardie.dll
    2010-01-05 14:30:20 ----N---- C:\WINDOWS\system32\dxtmsft.dll
    2010-01-05 14:30:20 ----N---- C:\WINDOWS\system32\corpol.dll
    2010-01-05 14:30:20 ----N---- C:\WINDOWS\system32\advpack.dll
    2010-01-05 04:47:46 ----A---- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
    R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
    R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
    R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2005-12-15 1368000]
    R3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
    R3 G400DH;G400DH; C:\WINDOWS\system32\DRIVERS\g400dhm.sys [2009-02-06 350592]
    R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-08-11 10144]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
    S3 ag2jesv6;ag2jesv6; C:\WINDOWS\system32\drivers\ag2jesv6.sys []
    S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
    S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2003-11-11 41984]
    S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2009-12-22 13224]
    S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2009-12-22 25512]
    S3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
    S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-07-12 12160]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys []
    S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys []
    S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
    S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-09-17 6132576]
    S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
    S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
    S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
    S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
    S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-07-12 38528]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
    S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
    S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73472]
    S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-02 153376]
    R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files\LogMeIn\x86\RaMaint.exe [2009-09-28 116032]
    R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2008-08-11 63040]
    R2 Matrox Centering Service;Matrox Centering Service; c:\Program Files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe [2009-02-06 1263872]
    R2 Matrox.Pdesk.ServicesHost;Matrox.Pdesk.ServicesHost; c:\Program Files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe [2009-02-06 344832]
    R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
    R2 MGABGEXE;MGABGEXE; C:\WINDOWS\system32\mgabg.exe [2007-04-04 87560]
    R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
    R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
    R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    S2 .norton2009Reset;Norton 2009 Reset; C:\Documents and Settings\All Users\Application Data\Norton\Norton2009Reset.exe []
    S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-17 163908]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
    S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
    S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

    -----------------EOF-----------------
Naposledy upravil(a) Michal100 dne 02 úno 2010 11:39, celkem upraveno 1 x.

Michal100
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 02 úno 2010 11:13

Re: Co to moze byt?

#2 Příspěvek od Michal100 »

Neviem preco sa vytvorili dve temy,ale mam problem s netom :(

Michal100
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 02 úno 2010 11:13

Re: Co to moze byt?

#3 Příspěvek od Michal100 »

  • Soubor idg2.exe přijatý 2010.02.02 05:24:49 (UTC)

    Antivirus
    Verze
    Poslední aktualizace
    Výsledek

    a-squared
    4.5.0.50
    2010.02.02
    -

    AhnLab-V3
    5.0.0.2
    2010.02.01
    -

    AntiVir
    7.9.1.156
    2010.02.01
    TR/Dldr.Delphi.Gen

    Antiy-AVL
    2.0.3.7
    2010.02.01
    -

    Authentium
    5.2.0.5
    2010.02.02
    W32/Banload.E.gen!Eldorado

    Avast
    4.8.1351.0
    2010.02.02
    -

    AVG
    9.0.0.730
    2010.02.01
    -

    BitDefender
    7.2
    2010.02.02
    -

    CAT-QuickHeal
    10.00
    2010.02.01
    -

    ClamAV
    0.96.0.0-git
    2010.02.01
    -

    Comodo
    3789
    2010.02.02
    -

    DrWeb
    5.0.1.12222
    2010.02.02
    DLOADER.IRC.Trojan

    eSafe
    7.0.17.0
    2010.02.01
    -

    eTrust-Vet
    35.2.7275
    2010.02.01
    -

    F-Prot
    4.5.1.85
    2010.02.01
    W32/Banload.E.gen!Eldorado

    F-Secure
    9.0.15370.0
    2010.02.02
    Suspicious:W32/Riskware!Online

    Fortinet
    4.0.14.0
    2010.02.02
    -

    GData
    19
    2010.02.02
    -

    Ikarus
    T3.1.1.80.0
    2010.02.02
    -

    Jiangmin
    13.0.900
    2010.01.28
    -

    K7AntiVirus
    7.10.962
    2010.02.01
    -

    Kaspersky
    7.0.0.125
    2010.02.02
    -

    McAfee
    5879
    2010.02.01
    New Malware.ai

    McAfee+Artemis
    5879
    2010.02.01
    Artemis!B46BDCAD1DFA

    McAfee-GW-Edition
    6.8.5
    2010.02.01
    Heuristic.LooksLike.Trojan.Dldr.FraudLo.C

    Microsoft
    1.5406
    2010.02.02
    -

    NOD32
    4825
    2010.02.01
    -

    Norman
    6.04.03
    2010.02.01
    W32/Obfuscated.FA

    nProtect
    2009.1.8.0
    2010.02.01
    -

    Panda
    10.0.2.2
    2010.02.01
    -

    PCTools
    7.0.3.5
    2010.02.02
    -

    Prevx
    3.0
    2010.02.02
    -

    Rising
    22.33.01.01
    2010.02.02
    Trojan.Win32.DownldrU.a

    Sophos
    4.50.0
    2010.02.02
    Mal/TinyDL-T

    Sunbelt
    3.2.1858.2
    2010.02.02
    -

    Symantec
    20091.2.0.41
    2010.02.02
    Suspicious.Insight

    TheHacker
    6.5.1.0.176
    2010.02.02
    -

    TrendMicro
    9.120.0.1004
    2010.02.02
    -

    VBA32
    3.12.12.1
    2010.02.01
    -

    ViRobot
    2010.2.2.2167
    2010.02.02
    -

    VirusBuster
    5.0.21.0
    2010.02.01
    -

Michal100
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 02 úno 2010 11:13

Re: Co to moze byt?

#4 Příspěvek od Michal100 »

  • ComboFix 10-02-01.02 - galko 02.02.2010 12:09:19.2.1 - x86
    Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.767.557 [GMT 4,5:30]
    Running from: c:\documents and settings\galko\My Documents\Preberanie\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\windows\system32\nethlp.dll
    c:\windows\system32\sysinfo.exe

    ----- BITS: Possible infected sites -----

    hxxp://hp
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_.norton2009Reset


    ((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
    .

    2010-02-02 06:46 . 2010-02-02 07:04 -------- d-----w- c:\program files\trend micro
    2010-02-02 06:46 . 2010-02-02 06:47 -------- d-----w- C:\rsit
    2010-02-02 05:46 . 2010-02-02 05:46 -------- d-----w- c:\documents and settings\galko\Local Settings\Application Data\ESET
    2010-02-02 05:35 . 2010-02-02 05:35 -------- d-----w- c:\program files\Common Files\Java
    2010-02-02 05:35 . 2010-02-02 05:35 503808 ----a-w- c:\documents and settings\galko\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-137853a2-n\msvcp71.dll
    2010-02-02 05:35 . 2010-02-02 05:35 499712 ----a-w- c:\documents and settings\galko\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-137853a2-n\jmc.dll
    2010-02-02 05:35 . 2010-02-02 05:35 348160 ----a-w- c:\documents and settings\galko\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-137853a2-n\msvcr71.dll
    2010-02-02 05:35 . 2010-02-02 05:35 61440 ----a-w- c:\documents and settings\galko\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-17c4833e-n\decora-sse.dll
    2010-02-02 05:35 . 2010-02-02 05:35 12800 ----a-w- c:\documents and settings\galko\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-17c4833e-n\decora-d3d.dll
    2010-02-02 05:35 . 2010-02-02 05:35 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-02 05:35 . 2010-02-02 05:35 -------- d-----w- c:\program files\Java
    2010-02-02 05:32 . 2010-02-02 05:32 -------- d-----w- c:\documents and settings\galko\Application Data\ESET
    2010-02-02 05:32 . 2010-02-02 07:01 -------- d-----w- c:\program files\ESET
    2010-02-02 05:32 . 2010-02-02 05:32 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
    2010-02-02 04:43 . 2010-02-02 04:43 -------- d-----w- c:\documents and settings\galko\Application Data\FRISK Software
    2010-02-02 04:37 . 2010-02-02 07:03 -------- d-----w- c:\documents and settings\All Users\Application Data\FRISK Software
    2010-02-02 02:37 . 2009-07-31 01:10 38022 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Common Framework\UpdateDir\mctool.exe
    2010-02-02 02:37 . 2009-07-31 01:10 3182712 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Common Framework\UpdateDir\mcscan32.dll
    2010-02-02 02:37 . 2009-07-31 01:10 213047 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Common Framework\UpdateDir\scan.exe
    2010-02-02 02:33 . 2010-02-02 02:33 -------- d-----w- c:\program files\Common Files\Cisco Systems
    2010-02-02 02:33 . 2010-02-02 02:48 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2010-02-02 02:32 . 2010-02-02 02:48 -------- d-----w- c:\program files\McAfee
    2010-02-02 02:08 . 2010-02-02 04:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
    2010-02-02 02:08 . 2010-02-02 04:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
    2010-02-02 02:08 . 2010-02-02 03:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
    2010-02-02 01:25 . 2010-01-21 12:39 52224 ----a-w- c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
    2010-02-02 01:25 . 2010-01-21 12:39 101376 ----a-w- c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
    2010-02-01 06:33 . 2010-02-01 06:33 -------- d-----w- c:\windows\system32\LogFiles
    2010-02-01 06:10 . 2010-02-01 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
    2010-02-01 06:10 . 2010-02-01 06:09 24570640 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\NokiaSoftwareUpdaterSetup_sk.exe
    2010-02-01 06:09 . 2010-02-01 06:09 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\msxml6Exec.exe
    2010-02-01 06:09 . 2010-02-01 06:09 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\Sleep.exe
    2010-02-01 06:09 . 2010-02-01 06:09 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\vcredistExec.exe
    2010-02-01 01:44 . 2010-02-02 04:09 -------- d-----w- c:\program files\SpeedFan
    2010-01-21 03:46 . 2010-01-21 03:46 -------- d-----w- c:\documents and settings\galko\Local Settings\Application Data\Temp
    2010-01-21 03:45 . 2010-01-25 07:46 -------- d-----w- c:\documents and settings\galko\Local Settings\Application Data\Google
    2010-01-19 01:28 . 2010-01-19 01:28 -------- d-----w- c:\documents and settings\galko\Local Settings\Application Data\Nokia
    2010-01-19 01:28 . 2010-01-19 01:28 -------- d-----w- c:\documents and settings\galko\Local Settings\Application Data\NokiaAccount
    2010-01-18 03:08 . 2010-01-22 03:30 768 ----a-w- c:\windows\system32\d3d8caps.dat
    2010-01-18 01:52 . 2008-08-26 04:56 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
    2010-01-18 01:52 . 2010-01-18 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
    2010-01-18 01:49 . 2010-01-18 01:49 12212040 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
    2010-01-18 01:49 . 2010-01-18 01:49 13930312 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
    2010-01-18 01:49 . 2010-01-18 01:49 77824 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
    2010-01-18 01:49 . 2010-01-18 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx86.exe
    2010-01-18 01:49 . 2010-01-18 01:49 58880 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx64.exe
    2010-01-18 01:49 . 2010-01-18 01:49 50000 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
    2010-01-18 01:41 . 2010-01-18 01:40 95992424 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Nokia_Ovi_Suite_PCS_Update.exe
    2010-01-18 01:41 . 2010-01-18 01:41 -------- d-----w- c:\documents and settings\All Users\Application Data\OviInstallerCache
    2010-01-12 09:37 . 2010-01-12 09:37 -------- d-----w- c:\program files\Common Files\Skype
    2010-01-12 09:37 . 2010-02-02 02:49 -------- d-----r- c:\program files\Skype
    2010-01-11 04:47 . 2010-01-11 04:47 1 ----a-w- c:\documents and settings\galko\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-01-11 04:47 . 2010-01-11 04:47 -------- d-----w- c:\documents and settings\galko\Application Data\OpenOffice.org

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-02 07:45 . 2009-09-21 03:50 -------- d-----w- c:\documents and settings\galko\Application Data\Skype
    2010-02-02 07:09 . 2009-10-27 01:36 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    2010-02-02 07:09 . 2009-10-27 01:36 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
    2010-02-02 05:45 . 2009-12-08 09:32 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-02-02 04:42 . 2009-09-21 03:52 -------- d-----w- c:\documents and settings\galko\Application Data\skypePM
    2010-02-02 02:50 . 2009-12-16 08:37 -------- d-----w- c:\program files\Common Files\Nokia
    2010-02-02 02:49 . 2009-09-23 14:54 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-02-02 01:26 . 2009-10-22 03:28 -------- d-----w- c:\program files\LogMeIn
    2010-02-01 06:34 . 2010-02-01 06:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
    2010-02-01 06:34 . 2010-02-01 06:34 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
    2010-02-01 06:33 . 2009-12-16 08:38 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
    2010-02-01 06:09 . 2009-12-16 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
    2010-01-25 03:43 . 2009-10-05 04:34 104976 ----a-w- c:\documents and settings\galko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-01-25 03:03 . 2009-09-28 02:16 -------- d-----w- c:\program files\Look@LAN
    2010-01-19 01:28 . 2009-12-16 08:38 -------- d-----w- c:\documents and settings\galko\Application Data\Nokia
    2010-01-12 09:37 . 2009-09-21 03:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
    2010-01-05 10:00 . 2008-04-23 00:16 832512 ----a-w- c:\windows\system32\wininet.dll
    2010-01-05 10:00 . 2008-07-12 19:10 78336 ------w- c:\windows\system32\ieencode.dll
    2010-01-05 10:00 . 2008-07-12 19:09 17408 ------w- c:\windows\system32\corpol.dll
    2009-12-22 04:55 . 2009-12-22 04:55 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
    2009-12-22 04:52 . 2009-12-22 04:52 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
    2009-12-22 04:52 . 2009-12-22 04:29 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
    2009-12-16 08:40 . 2009-12-16 08:38 -------- d-----w- c:\documents and settings\galko\Application Data\PC Suite
    2009-12-16 08:39 . 2009-12-16 08:39 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
    2009-12-16 08:39 . 2009-12-16 08:39 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
    2009-12-16 08:38 . 2009-12-16 08:37 -------- d-----w- c:\program files\DIFX
    2009-12-16 08:22 . 2009-12-16 08:22 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
    2009-12-16 08:22 . 2009-12-16 08:22 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
    2009-12-16 08:22 . 2009-12-16 08:22 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
    2009-12-16 08:22 . 2009-12-16 08:22 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
    2009-12-16 08:22 . 2009-12-16 08:23 33863976 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_slk_web.exe
    2009-12-10 05:05 . 2009-11-25 08:38 -------- d-----w- c:\program files\Pinnacle
    2009-12-10 04:51 . 2009-11-25 08:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
    2009-12-10 04:05 . 2009-12-10 04:05 -------- d-----w- c:\program files\Common Files\Nero
    2009-12-10 04:05 . 2009-09-21 03:57 -------- d-----w- c:\program files\Nero
    2009-12-10 04:05 . 2009-12-10 04:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
    2009-12-10 03:11 . 2009-12-07 03:05 -------- d-----w- c:\documents and settings\galko\Application Data\Any Video Converter
    2009-12-08 01:32 . 2009-12-08 01:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Matrox
    2009-12-08 01:32 . 2009-12-08 01:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Matrox Graphics Inc
    2009-12-08 01:32 . 2009-12-08 01:32 -------- d-----w- c:\program files\Matrox Graphics Inc
    2009-12-07 03:05 . 2009-12-07 03:05 -------- d-----w- c:\program files\Any Video Converter
    2009-12-07 01:36 . 2009-12-07 01:36 -------- d-----w- c:\program files\MSECache
    2009-12-04 08:57 . 2009-12-04 08:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
    2009-12-04 08:54 . 2009-12-04 08:54 -------- d-----w- c:\program files\Common Files\Pinnacle
    2009-12-04 08:53 . 2009-11-25 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate
    2009-12-01 06:23 . 2009-12-16 03:21 381304 ----a-w- c:\windows\system32\psexec.exe
    2009-12-01 06:22 . 2009-12-16 03:21 621944 ----a-w- c:\windows\system32\pskill.exe
    2009-11-21 15:51 . 2008-04-14 08:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    .

    ------- Sigcheck -------

    [-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-02-01 98304]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-06-20 1056768]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
    "nwiz"="nwiz.exe" [2008-09-17 1657376]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 35696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
    "Matrox PowerDesk SE"="c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe" [2009-02-06 4223232]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "nltide_2"="shell32" [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2009-09-28 15:04 87352 ------w- c:\windows\system32\LMIinit.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7.10.2009 7:02 717296]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [11.8.2008 12:41 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [22.10.2009 7:58 47640]
    R2 Matrox Centering Service;Matrox Centering Service;c:\program files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe [6.2.2009 14:09 1263872]
    R2 Matrox.Pdesk.ServicesHost;Matrox.Pdesk.ServicesHost;c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe [6.2.2009 14:08 344832]
    S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [22.12.2009 9:22 13224]
    S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [24.11.2008 22:31 29263712]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 12:30 14336]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    WINRM REG_MULTI_SZ WINRM
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Settings,ProxyServer = 10.111.0.65:3128
    uInternet Settings,ProxyOverride = <local>
    IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    TCP: {B1A2C127-0F4F-4FE9-BD94-585F5E2EED85} = 10.111.1.2,10.111.0.65
    TCP: {CB7BEAB8-8DA4-4EE3-A58A-E1A3AF3C9FEE} = 10.111.1.2,10.111.0.65
    FF - ProfilePath - c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\
    FF - prefs.js: network.proxy.ftp - 10.111.0.65
    FF - prefs.js: network.proxy.ftp_port - 3128
    FF - prefs.js: network.proxy.gopher - 10.111.0.65
    FF - prefs.js: network.proxy.gopher_port - 3128
    FF - prefs.js: network.proxy.http - 10.111.0.65
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.socks - 10.111.0.65
    FF - prefs.js: network.proxy.socks_port - 3128
    FF - prefs.js: network.proxy.ssl - 10.111.0.65
    FF - prefs.js: network.proxy.ssl_port - 3128
    FF - prefs.js: network.proxy.type - 1
    FF - component: c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
    FF - plugin: c:\documents and settings\galko\Application Data\Mozilla\Firefox\Profiles\8n31c744.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
    HKCU-Run-DLD.EXE - c:\program files\Download Direct\DLD.exe
    HKLM-Run-Cmaudio - cmicnfg.cpl
    HKLM-Run-Sysinfo.exe - c:\windows\System32\Sysinfo.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-02 12:15
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82F6E1F8]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\Disk -> CLASSPNP.SYS @ 0xf7583f28
    \Driver\ACPI -> ACPI.sys @ 0xf73cecb8
    \Driver\atapi -> atapi.sys @ 0xf7363b40
    IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
    ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
    \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
    ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
    NDIS: 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C -> SendCompleteHandler -> NDIS.sys @ 0xf725bb0a
    PacketIndicateHandler -> NDIS.sys @ 0xf7266a21
    SendHandler -> NDIS.sys @ 0xf725b949
    user & kernel MBR OK

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1292428093-926492609-1177238915-1515\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{12772B79-D269-1B66-E20E-14339EAFE6D4}*]
    "pagjjaheghlmdpaogfbieebnccnpgipc"=hex:61,61,00,00
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(568)
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll

    - - - - - - - > 'explorer.exe'(3516)
    c:\windows\system32\WININET.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\wpdshserviceobj.dll
    c:\windows\system32\portabledevicetypes.dll
    c:\windows\system32\portabledeviceapi.dll
    c:\windows\system32\LMIRfsClientNP.dll
    c:\program files\Microsoft Office\OFFICE11\msohev.dll
    c:\program files\Common Files\Ahead\lib\NeroDigitalExt.dll
    c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.SKY
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\LogMeIn\x86\RaMaint.exe
    c:\\hp\OCSINVENTORY$\OCSInventory.exe
    c:\program files\LogMeIn\x86\LogMeIn.exe
    c:\program files\LogMeIn\x86\LMIGuardian.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\mgabg.exe
    c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
    c:\windows\system32\locator.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\windows\system32\RunDll32.exe
    c:\program files\LogMeIn\x86\LMIGuardian.exe
    c:\program files\Skype\Plugin Manager\skypePM.exe
    .
    **************************************************************************
    .
    Completion time: 2010-02-02 12:18:35 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-02-02 07:48

    Pre-Run: 67 380 531 200 bytes free
    Post-Run: 11 adresárov, 69 913 227 264 voľných bajtov

    - - End Of File - - DA231D414F098DEA4BE826349C55489F

Michal100
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 02 úno 2010 11:13

Re: Co to moze byt?

#5 Příspěvek od Michal100 »

Problem vyrieseny,dokonca som nasiel aj command verziu :James008:

Odpovědět