

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
problem se security tool
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
Re: problem se security tool
ten full sken MBAM jen na C: nebo i D: ?Naughty píše:Vse v MBAM vymaz. Tentokrat dobre odinstaluj CF. Pote radci ejse jednu probehni full sken MBAM a zaroven po dokonceni porosim o log z DDS.
-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
Re: problem se security tool
to si neber osobne
prislo mi to jen kratsi, nez abych musel vypisovat k cemu to patri... (a taky jsem to mel po ruce a nemusel listovat dolu strankou na "Odpovedet" 


-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
Re: problem se security tool
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3734
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
14.2.2010 10:41:53
mbam-log-2010-02-14 (10-40-46).txt
Typ kontroly: Kompletní kontrola (C:\|)
Zkontrolované objekty: 158839
Uplynulý čas: 35 minute(s), 16 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 2
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
C:\Program Files\Truck Dismount\msvcp60.dll (Malware.Packer.Gen) -> No action taken.
C:\Program Files\Truck Dismount\msvcrt.dll (Malware.Packer.Gen) -> No action taken.
Verze databáze: 3734
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
14.2.2010 10:41:53
mbam-log-2010-02-14 (10-40-46).txt
Typ kontroly: Kompletní kontrola (C:\|)
Zkontrolované objekty: 158839
Uplynulý čas: 35 minute(s), 16 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 2
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
C:\Program Files\Truck Dismount\msvcp60.dll (Malware.Packer.Gen) -> No action taken.
C:\Program Files\Truck Dismount\msvcrt.dll (Malware.Packer.Gen) -> No action taken.
-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
Re: problem se security tool
DDS (Ver_09-12-01.01) - NTFSx86
Run by Klaudie at 10:53:35,89 on ne 14.02.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.446.101 [GMT 1:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Documents and Settings\All Users\Data aplikací\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Documents and Settings\Klaudie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Klaudie\Plocha\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.centrum.cz/skinit/icq/
uURLSearchHooks: H - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe"
uRun: [ISUSPM] "c:\documents and settings\all users\data aplikací\macrovision\flexnet connect\6\ISUSPM.exe" -scheduler
uRun: [Google Update] "c:\documents and settings\klaudie\local settings\data aplikací\google\update\GoogleUpdate.exe" /c
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [HP Software Update] d:\program files\hp\hp software update\HPWuSchd2.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {3C772FCC-4252-4376-A966-589A92CFBFB4} = 194.228.2.1,212.83.68.130
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\klaudie\dataap~1\mozilla\firefox\profiles\lpgnnmdg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\klaudie\data aplikací\mozilla\firefox\profiles\lpgnnmdg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\klaudie\local settings\data aplikacă\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.jit.chrome", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-11-29 225792]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-13 38224]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2006-3-2 69120]
S2 gupdate1ca3a3067b7956a;Služba Google Update (gupdate1ca3a3067b7956a);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104]
S3 LTower;LEGO USB Tower Driver;c:\windows\system32\drivers\LTower.sys [2008-1-20 36981]
=============== Created Last 30 ================
2010-02-13 21:08:41 0 d-----w- c:\docume~1\klaudie\dataap~1\Malwarebytes
2010-02-13 21:08:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-13 21:08:27 0 d-----w- c:\docume~1\alluse~1\dataap~1\Malwarebytes
2010-02-13 21:08:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-13 21:08:25 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-13 19:54:01 0 d-sha-r- C:\cmdcons
2010-02-10 09:28:39 0 d-----w- c:\docume~1\klaudie\dataap~1\HpUpdate
2010-02-10 09:28:36 0 d-----w- c:\windows\Hewlett-Packard
2010-01-22 21:06:20 0 d-----w- c:\docume~1\alluse~1\dataap~1\WEBREG
2010-01-22 21:01:26 0 d-----w- c:\program files\common files\HP
2010-01-22 21:00:25 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-01-22 20:58:48 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-01-22 20:58:39 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-01-22 20:57:58 258048 ----a-r- c:\windows\system32\hpzids01.dll
2010-01-22 20:57:52 117760 ----a-w- c:\windows\system32\hpz3l4v2.dll
2010-01-22 20:57:18 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-01-22 20:56:38 892928 ----a-r- c:\windows\system32\hpotiop4.dll
2010-01-22 20:56:38 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-01-22 20:56:38 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-01-22 20:56:38 294912 ----a-r- c:\windows\system32\hpovst11.dll
2010-01-22 20:56:37 675840 ----a-r- c:\windows\system32\hpowiax4.dll
2010-01-22 20:56:36 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-22 20:56:36 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-22 20:51:09 0 d-----w- c:\program files\HP
2010-01-22 20:51:00 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-01-22 20:51:00 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-01-22 20:44:09 811 ------w- c:\windows\hpomdl13.dat
2010-01-22 20:44:09 145538 ----a-w- c:\windows\hpoins13.dat
==================== Find3M ====================
2010-01-14 10:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 12:26:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-21 19:08:42 916480 ------w- c:\windows\system32\wininet.dll
2009-12-18 22:45:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-17 07:42:35 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-12 13:39:23 79440 ----a-w- c:\windows\system32\perfc005.dat
2009-12-12 13:39:23 432516 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 10:11:07 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11:07 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2009-11-27 17:14:10 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14:09 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09:43 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09:43 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09:42 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:09:42 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09:42 11264 ----a-w- c:\windows\system32\msrle32.dll
============= FINISH: 10:54:13,25 ===============
Run by Klaudie at 10:53:35,89 on ne 14.02.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.446.101 [GMT 1:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Documents and Settings\All Users\Data aplikací\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Documents and Settings\Klaudie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Klaudie\Plocha\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.centrum.cz/skinit/icq/
uURLSearchHooks: H - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe"
uRun: [ISUSPM] "c:\documents and settings\all users\data aplikací\macrovision\flexnet connect\6\ISUSPM.exe" -scheduler
uRun: [Google Update] "c:\documents and settings\klaudie\local settings\data aplikací\google\update\GoogleUpdate.exe" /c
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [HP Software Update] d:\program files\hp\hp software update\HPWuSchd2.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {3C772FCC-4252-4376-A966-589A92CFBFB4} = 194.228.2.1,212.83.68.130
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\klaudie\dataap~1\mozilla\firefox\profiles\lpgnnmdg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\klaudie\data aplikací\mozilla\firefox\profiles\lpgnnmdg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\klaudie\local settings\data aplikacă\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.jit.chrome", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-11-29 225792]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-13 38224]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2006-3-2 69120]
S2 gupdate1ca3a3067b7956a;Služba Google Update (gupdate1ca3a3067b7956a);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104]
S3 LTower;LEGO USB Tower Driver;c:\windows\system32\drivers\LTower.sys [2008-1-20 36981]
=============== Created Last 30 ================
2010-02-13 21:08:41 0 d-----w- c:\docume~1\klaudie\dataap~1\Malwarebytes
2010-02-13 21:08:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-13 21:08:27 0 d-----w- c:\docume~1\alluse~1\dataap~1\Malwarebytes
2010-02-13 21:08:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-13 21:08:25 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-13 19:54:01 0 d-sha-r- C:\cmdcons
2010-02-10 09:28:39 0 d-----w- c:\docume~1\klaudie\dataap~1\HpUpdate
2010-02-10 09:28:36 0 d-----w- c:\windows\Hewlett-Packard
2010-01-22 21:06:20 0 d-----w- c:\docume~1\alluse~1\dataap~1\WEBREG
2010-01-22 21:01:26 0 d-----w- c:\program files\common files\HP
2010-01-22 21:00:25 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-01-22 20:58:48 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-01-22 20:58:39 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-01-22 20:57:58 258048 ----a-r- c:\windows\system32\hpzids01.dll
2010-01-22 20:57:52 117760 ----a-w- c:\windows\system32\hpz3l4v2.dll
2010-01-22 20:57:18 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-01-22 20:56:38 892928 ----a-r- c:\windows\system32\hpotiop4.dll
2010-01-22 20:56:38 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-01-22 20:56:38 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-01-22 20:56:38 294912 ----a-r- c:\windows\system32\hpovst11.dll
2010-01-22 20:56:37 675840 ----a-r- c:\windows\system32\hpowiax4.dll
2010-01-22 20:56:36 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-22 20:56:36 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-22 20:51:09 0 d-----w- c:\program files\HP
2010-01-22 20:51:00 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-01-22 20:51:00 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-01-22 20:44:09 811 ------w- c:\windows\hpomdl13.dat
2010-01-22 20:44:09 145538 ----a-w- c:\windows\hpoins13.dat
==================== Find3M ====================
2010-01-14 10:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 12:26:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-21 19:08:42 916480 ------w- c:\windows\system32\wininet.dll
2009-12-18 22:45:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-17 07:42:35 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-12 13:39:23 79440 ----a-w- c:\windows\system32\perfc005.dat
2009-12-12 13:39:23 432516 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 10:11:07 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11:07 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2009-11-27 17:14:10 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14:09 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09:43 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09:43 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09:42 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:09:42 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09:42 11264 ----a-w- c:\windows\system32\msrle32.dll
============= FINISH: 10:54:13,25 ===============
-
- Návštěvník
- Příspěvky: 36
- Registrován: 12 úno 2010 18:46
Re: problem se security tool
tak uz jsem nainstalovl fw - a moc dik - prosim Te, vas nekdo za tyhle sluzby plati...?