Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

trojan

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#16 Příspěvek od lklubo »

tu je 1-log



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-17 12:53:44
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\pc\LOCALS~1\Temp\pxtdapow.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)

---- EOF - GMER 1.0.15 ----

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#17 Příspěvek od lklubo »

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#18 Příspěvek od lklubo »

log č.2 v gmeri sa mi nepodarilo urobit (neodpovedá), skusal som to aj v safe mode a nic( raz som tu s vami riesil podobny problem na inom pc a takisto bol problem s 2-hym logom v gmeri)

co sa tyka tohto prikazu "%userprofile%\plocha\mbr" -t neda sa spustit, pise toto vid. priloha

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#19 Příspěvek od lklubo »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verzia databázy: 4108

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

17.5.2010 13:58:47
mbam-log-2010-05-17 (13-58-47).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 120702
Uplynulý čas: 3 min, 32 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 1
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 1

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\61883 (Rootkit.Agent) -> No action taken.

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
C:\WINDOWS\system32\drivers\61883.sys (Rootkit.Agent) -> No action taken.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#20 Příspěvek od lklubo »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verzia databázy: 4108

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

17.5.2010 14:02:24
mbam-log-2010-05-17 (14-02-24).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 120702
Uplynulý čas: 3 min, 32 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 1
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 1

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\61883 (Rootkit.Agent) -> Quarantined and deleted successfully.

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
C:\WINDOWS\system32\drivers\61883.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#21 Příspěvek od lklubo »

ospravedlnujem sa omylom som mazal :worship:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: trojan

#22 Příspěvek od motji »

Tak smazal jste vir, co Vám ho hlásil i antivir :D .
Mbr.exe zkuste z příkazového řádku spustit s tímto:
"%userprofile%\desktop\mbr" -t
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#23 Příspěvek od lklubo »

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
kernel: MBR read successfully
user & kernel MBR OK

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: trojan

#24 Příspěvek od motji »

Ještě jednou spustte combofix :) .
Jak se chová počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#25 Příspěvek od lklubo »

ComboFix 10-05-16.02 - pc 17.05.2010 15:25:50.2.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3070.2454 [GMT 2:00]
Running from: c:\documents and settings\pc\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\VB6KO.DLL
c:\windows\UA000106.DLL

.
((((((((((((((((((((((((( Files Created from 2010-04-17 to 2010-05-17 )))))))))))))))))))))))))))))))
.

2010-05-17 11:53 . 2010-05-17 11:53 -------- d-----w- c:\documents and settings\pc\Application Data\Malwarebytes
2010-05-17 11:53 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-17 11:53 . 2010-05-17 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-17 11:53 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-17 11:53 . 2010-05-17 12:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-17 10:18 . 2010-05-17 10:19 -------- d-----w- c:\documents and settings\pc\Application Data\Apple Computer
2010-05-17 09:52 . 2010-05-17 10:16 -------- d-----w- c:\program files\QuickTime
2010-05-17 09:52 . 2010-05-17 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-17 09:51 . 2010-05-17 09:51 -------- d-----w- c:\program files\Common Files\Apple
2010-05-17 09:51 . 2010-05-17 09:51 -------- d-----w- c:\documents and settings\pc\Local Settings\Application Data\Apple
2010-05-17 09:51 . 2010-05-17 09:51 -------- d-----w- c:\program files\Apple Software Update
2010-05-17 09:51 . 2010-05-17 09:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-05-17 09:51 . 2010-05-17 09:51 -------- d-----w- c:\documents and settings\pc\Local Settings\Application Data\Apple Computer
2010-05-14 09:28 . 2010-05-14 09:28 -------- d-----w- C:\rsit
2010-05-14 09:28 . 2010-05-14 09:28 -------- d-----w- c:\program files\trend micro
2010-05-14 09:12 . 2010-05-14 09:12 -------- d-----w- c:\program files\CCleaner
2010-05-03 17:59 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-03 17:59 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-03 11:37 . 2010-05-03 11:37 -------- d-----w- c:\program files\Microsoft Silverlight
2010-04-30 11:56 . 2001-08-17 20:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-04-30 11:56 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-30 11:56 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-30 11:56 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-04-20 07:58 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-20 07:51 . 2010-04-20 07:51 -------- d-----w- c:\documents and settings\pc\Application Data\ESET
2010-04-20 07:50 . 2010-04-20 07:50 -------- d-----w- c:\program files\ESET

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-17 13:29 . 2008-06-12 13:41 -------- d-----w- c:\documents and settings\pc\Application Data\Skype
2010-05-17 12:04 . 2008-06-10 12:35 -------- d-----w- c:\program files\lg_fwupdate
2010-05-17 10:44 . 2008-06-12 13:43 -------- d-----w- c:\documents and settings\pc\Application Data\skypePM
2010-05-14 09:22 . 2009-02-18 10:40 -------- d-----w- c:\program files\Total Commander
2010-05-14 09:21 . 2010-03-12 10:32 -------- d-----w- c:\program files\OpenOffice.org 3
2010-05-12 01:01 . 2008-06-12 13:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-04 07:35 . 2008-06-12 11:00 85168 ----a-w- c:\documents and settings\pc\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-04 06:27 . 2010-02-08 10:42 -------- d-----w- c:\program files\CAPCOM
2010-05-04 06:21 . 2010-01-28 13:27 -------- d-----w- c:\program files\FlashGet
2010-05-04 06:16 . 2008-06-10 12:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-04 01:02 . 2008-06-12 13:22 -------- d-----w- c:\program files\Microsoft Works
2010-04-20 07:50 . 2008-06-12 11:27 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-04-20 07:49 . 2009-09-30 07:19 -------- d-----w- c:\program files\TuneUp Utilities 2008
2010-04-20 07:32 . 2009-11-05 14:14 -------- d-----w- c:\program files\Full Tilt Poker
2010-04-16 12:28 . 2008-06-30 07:37 -------- d-----w- c:\program files\Java
2010-04-12 15:29 . 2010-04-16 12:28 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-12 06:02 . 2010-01-29 11:14 -------- d-----w- c:\documents and settings\pc\Application Data\vlc
2010-04-01 11:46 . 2008-06-12 14:21 -------- d-----w- c:\documents and settings\pc\Application Data\CyberLink
2010-04-01 11:46 . 2008-06-12 14:21 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2010-03-31 06:00 . 2008-06-30 07:36 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 06:00 . 2010-03-31 06:00 503808 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3d49a879-n\msvcp71.dll
2010-03-31 06:00 . 2010-03-31 06:00 499712 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3d49a879-n\jmc.dll
2010-03-31 06:00 . 2010-03-31 06:00 348160 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3d49a879-n\msvcr71.dll
2010-03-31 06:00 . 2010-03-31 06:00 61440 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-17fec0fa-n\decora-sse.dll
2010-03-31 06:00 . 2010-03-31 06:00 12800 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-17fec0fa-n\decora-d3d.dll
2010-03-24 18:33 . 2010-03-24 18:33 55232 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2010-03-24 18:33 . 2010-03-24 18:33 32584 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2010-03-24 18:33 . 2010-03-24 18:33 134488 ----a-w- c:\windows\system32\drivers\epfw.sys
2010-03-24 18:31 . 2010-03-24 18:31 114984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-03-24 18:23 . 2010-03-24 18:23 139192 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-03-12 10:34 . 2010-03-12 10:34 1 ----a-w- c:\documents and settings\pc\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-10 06:15 . 2008-06-10 06:42 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2008-06-10 06:42 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-06-12 12:09 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-06-12 12:09 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2008-07-25 08:31 . 2008-09-25 10:20 28672 ----a-w- c:\program files\mozilla firefox\components\flashgetXpi.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-05-14_10.00.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-17 12:04 . 2010-05-17 12:04 16384 c:\windows\Temp\Perflib_Perfdata_450.dat
+ 2007-07-27 12:00 . 2010-05-17 12:09 79094 c:\windows\system32\perfc009.dat
- 2007-07-27 12:00 . 2010-05-14 09:57 79094 c:\windows\system32\perfc009.dat
+ 2010-05-17 09:51 . 2010-05-17 09:51 27136 c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2009-07-11 23:12 . 2009-07-11 23:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-11 23:09 . 2009-07-11 23:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-11 23:08 . 2009-07-11 23:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2007-07-27 12:00 . 2010-05-17 12:09 465208 c:\windows\system32\perfh009.dat
- 2007-07-27 12:00 . 2010-05-14 09:57 465208 c:\windows\system32\perfh009.dat
+ 2010-05-17 09:51 . 2010-05-17 09:51 791552 c:\windows\Installer\f6c07e7.msi
+ 2010-05-17 09:52 . 2010-05-17 09:52 9472000 c:\windows\Installer\f6c07eb.msi
+ 2010-05-17 09:51 . 2010-05-17 09:51 1549312 c:\windows\Installer\f6c07e1.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2008-05-30 21718312]
"OEXPRESS"="c:\documents and settings\All Users\Application Data\LangSoft\OETRN.EXE" [2009-02-25 26624]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2008\MemOptimizer.exe" [2008-07-01 148480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2010-01-02 557056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 20480]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-03-24 2145000]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-1-20 113664]
iNetDVR Recorder.lnk - c:\program files\iNetDVR\iNetDVR Recorder\Dvr.exe [2008-9-24 372736]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AirLive MIMO-G Wireless Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AirLive MIMO-G Wireless Utility.lnk
backup=c:\windows\pss\AirLive MIMO-G Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\iNetDVR\\iNetDVR Recorder\\VidChat.exe"=
"c:\\Program Files\\iNetDVR\\iNetDVR Recorder\\Dvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [24.3.2010 20:31 114984]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [24.3.2010 20:31 810120]
R3 GVCAM;GVCAM;c:\windows\system32\drivers\GVCAM.sys [24.9.2008 13:38 195902]
R3 GVCV;GVCV;c:\windows\system32\drivers\GVCV.sys [24.9.2008 13:38 113657]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [10.6.2008 14:23 47624]
S3 OKI OPHD DCS Loader;OKI OPHD DCS Loader;c:\windows\system32\spool\drivers\w32x86\3\OPHDLDCS.EXE [11.12.2007 17:06 24576]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-05-17 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:09]

2010-05-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-05-17 c:\windows\Tasks\User_Feed_Synchronization-{5570AEF0-652E-4F8B-A63F-92296B00054B}.job
- c:\windows\system32\msfeedssync.exe [2009-12-18 03:31]

2010-05-17 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
TCP: {58B6ED7F-74E6-4E3A-96B3-F6E6C9104998} = 10.0.0.2
TCP: {7266F55B-7984-49DA-A647-362A510B2BDA} = 10.0.0.2
FF - ProfilePath - c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\rckvrr18.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-17 15:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-05-17 15:30:10
ComboFix-quarantined-files.txt 2010-05-17 13:30
ComboFix2.txt 2010-05-14 10:03

Pre-Run: 99 657 216 000 bytes free
Post-Run: 99 638 988 800 bytes free

- - End Of File - - E8A8594EEAF5175FA197A69F00AE51CF

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: trojan

#26 Příspěvek od motji »

Já se omlouvám :oops: , neuvědomila jsme si, že jste z karantény už vytahoval ty dva soubory
c:\windows\system32\VB6KO.DLL
c:\windows\UA000106.DLL

Máte je tam zase, můžete je prosím zase vytáhnout? j8 jsme nepočítala s tím, že combofix znovu použijeme, ale když nešel Gmer, chtěla jsme to zkontrolovat v combofixu :) .

:arrow: Až si ty soubory vytáhnete z qooboxu, pokračujte dále :)



:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#27 Příspěvek od lklubo »

Logfile of random's system information tool 1.07 (written by random/random)
Run by pc at 2010-05-17 16:01:42
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 98 GB (53%) free of 185 GB
Total RAM: 3070 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:01:49, on 17.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\All Users\Application Data\LangSoft\OETRN.EXE
C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe
C:\Program Files\iNetDVR\iNetDVR Recorder\Dvr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\OSK.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iNetDVR\iNetDVR Recorder\VidChat.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\iNetDVR\iNetDVR Recorder\DvrAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\pc\Desktop\RSIT.exe
C:\Program Files\trend micro\pc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Application Data\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: iNetDVR Recorder.lnk = C:\Program Files\iNetDVR\iNetDVR Recorder\Dvr.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{58B6ED7F-74E6-4E3A-96B3-F6E6C9104998}: NameServer = 10.0.0.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{7266F55B-7984-49DA-A647-362A510B2BDA}: NameServer = 10.0.0.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OKI OPHD DCS Loader - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHDLDCS.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 10086 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5570AEF0-652E-4F8B-A63F-92296B00054B}.job
C:\WINDOWS\tasks\Úklid 1 kliknutím.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll [2009-02-25 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll [2009-02-25 520192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-13 16857600]
"JMB36X IDE Setup"=C:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"36X Raid Configurer"=C:\WINDOWS\system32\xRaidSetup.exe [2007-08-29 1966080]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-03-28 13684736]
"nwiz"=nwiz.exe /install []
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2006-11-23 56928]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-12-05 54832]
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe [2010-01-02 557056]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2006-07-13 122880]
"AudioDrvEmulator"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2005-11-04 49152]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2006-12-12 19456]
"CTxfiHlp"=C:\WINDOWS\system32\CTXFIHLP.EXE [2006-12-12 20480]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-03-24 2145000]
"UVS12 Preload"=C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe [2008-06-09 397456]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-03-28 86016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2008-05-30 21718312]
"OEXPRESS"=C:\Documents and Settings\All Users\Application Data\LangSoft\OETRN.EXE [2009-02-25 26624]
"TuneUp MemOptimizer"=C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe [2008-07-01 148480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AirLive MIMO-G Wireless Utility.lnk]
C:\PROGRA~1\AIRLIV~1\Common\AIRLIV~1.EXE -s []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
iNetDVR Recorder.lnk - C:\Program Files\iNetDVR\iNetDVR Recorder\Dvr.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\iNetDVR\iNetDVR Recorder\VidChat.exe"="C:\Program Files\iNetDVR\iNetDVR Recorder\VidChat.exe:*:Enabled:VidChat"
"C:\Program Files\iNetDVR\iNetDVR Recorder\Dvr.exe"="C:\Program Files\iNetDVR\iNetDVR Recorder\Dvr.exe:*:Enabled:DVR Application"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-05-17 16:01:42 ----D---- C:\rsit
2010-05-17 15:47:22 ----A---- C:\WINDOWS\UA000106.DLL
2010-05-17 15:46:43 ----SHD---- C:\RECYCLER
2010-05-17 15:46:10 ----A---- C:\WINDOWS\system32\VB6KO.DLL
2010-05-17 13:53:39 ----D---- C:\Documents and Settings\pc\Application Data\Malwarebytes
2010-05-17 13:53:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-05-17 13:53:29 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-17 12:18:08 ----D---- C:\Documents and Settings\pc\Application Data\Apple Computer
2010-05-17 11:52:10 ----D---- C:\Program Files\QuickTime
2010-05-17 11:52:09 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2010-05-17 11:51:44 ----D---- C:\Program Files\Common Files\Apple
2010-05-17 11:51:26 ----D---- C:\Program Files\Apple Software Update
2010-05-17 11:51:26 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2010-05-14 11:54:57 ----A---- C:\Boot.bak
2010-05-14 11:54:51 ----RASHD---- C:\cmdcons
2010-05-14 11:28:18 ----D---- C:\Program Files\trend micro
2010-05-14 11:12:10 ----D---- C:\Program Files\CCleaner
2010-05-12 03:01:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-03 19:59:43 ----A---- C:\WINDOWS\system32\muweb.dll
2010-05-03 19:59:43 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2010-05-03 19:59:42 ----A---- C:\WINDOWS\system32\mucltui.dll
2010-05-03 13:37:08 ----D---- C:\Program Files\Microsoft Silverlight
2010-04-30 13:56:42 ----A---- C:\WINDOWS\system32\ptpusb.dll
2010-04-30 13:56:40 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-04-20 09:58:12 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-04-20 09:51:41 ----D---- C:\Documents and Settings\pc\Application Data\ESET
2010-04-20 09:50:56 ----D---- C:\Program Files\ESET

======List of files/folders modified in the last 1 months======

2010-05-17 16:00:45 ----D---- C:\WINDOWS\system32
2010-05-17 16:00:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-17 16:00:29 ----D---- C:\WINDOWS
2010-05-17 16:00:29 ----A---- C:\WINDOWS\MAILTRAN.INI
2010-05-17 15:57:27 ----D---- C:\Documents and Settings\pc\Application Data\Skype
2010-05-17 15:56:48 ----D---- C:\WINDOWS\Temp
2010-05-17 15:56:27 ----A---- C:\WINDOWS\lgfwup.ini
2010-05-17 15:56:25 ----D---- C:\Program Files\lg_fwupdate
2010-05-17 15:54:51 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-17 15:49:49 ----D---- C:\WINDOWS\Prefetch
2010-05-17 15:49:14 ----D---- C:\WINDOWS\system32\Restore
2010-05-17 15:29:14 ----A---- C:\WINDOWS\system.ini
2010-05-17 15:28:13 ----D---- C:\WINDOWS\system32\drivers
2010-05-17 15:28:13 ----D---- C:\WINDOWS\AppPatch
2010-05-17 15:28:12 ----D---- C:\Program Files\Common Files
2010-05-17 15:25:33 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-17 14:04:18 ----HDC---- C:\WINDOWS\$NtUninstallKB914388$
2010-05-17 14:02:35 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-17 13:53:29 ----RD---- C:\Program Files
2010-05-17 13:29:54 ----HD---- C:\WINDOWS\inf
2010-05-17 12:44:22 ----D---- C:\Documents and Settings\pc\Application Data\skypePM
2010-05-17 12:16:52 ----SHD---- C:\WINDOWS\Installer
2010-05-17 11:52:50 ----D---- C:\Program Files\Internet Explorer
2010-05-17 11:51:49 ----D---- C:\WINDOWS\WinSxS
2010-05-17 11:51:33 ----SD---- C:\WINDOWS\Tasks
2010-05-14 11:58:20 ----D---- C:\WINDOWS\system32\config
2010-05-14 11:54:57 ----RASH---- C:\boot.ini
2010-05-14 11:22:48 ----D---- C:\Program Files\Total Commander
2010-05-14 11:21:56 ----RSD---- C:\WINDOWS\assembly
2010-05-14 11:21:55 ----D---- C:\Program Files\OpenOffice.org 3
2010-05-14 11:14:15 ----D---- C:\WINDOWS\Minidump
2010-05-14 11:14:15 ----D---- C:\WINDOWS\Debug
2010-05-13 14:39:36 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-12 03:19:27 ----D---- C:\Program Files\Outlook Express
2010-05-12 03:01:31 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-05-12 01:54:09 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-04 08:27:49 ----D---- C:\Program Files\CAPCOM
2010-05-04 08:21:22 ----D---- C:\Program Files\FlashGet
2010-05-04 08:16:45 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-04 03:02:52 ----RSD---- C:\WINDOWS\Fonts
2010-05-04 03:02:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-04 03:02:23 ----D---- C:\Program Files\Microsoft Works
2010-05-04 03:01:28 ----A---- C:\WINDOWS\win.ini
2010-05-04 03:01:27 ----D---- C:\Program Files\Common Files\System
2010-04-30 20:51:06 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-20 09:50:56 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2010-04-20 09:49:24 ----D---- C:\Program Files\TuneUp Utilities 2008
2010-04-20 09:32:55 ----D---- C:\Program Files\Full Tilt Poker

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-03-24 114984]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-03-24 55232]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-08-23 278984]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-03-24 139192]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-03-24 134488]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-08-23 25416]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 BthEnum;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2006-12-19 511288]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2007-06-18 514560]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2006-12-19 14648]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2006-12-19 156984]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2006-12-19 90936]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-03-24 32584]
R3 GVCAM;GVCAM; C:\WINDOWS\system32\drivers\GVCAM.sys [2007-11-25 195902]
R3 GVCV;GVCV; C:\WINDOWS\system32\drivers\GVCV.sys [2007-11-25 113657]
R3 ha20x2k;Creative 20X HAL Driver; C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-12-19 1160504]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidBth;Microsoft Bluetooth HID Miniport; C:\WINDOWS\system32\DRIVERS\hidbth.sys [2008-04-13 25600]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-14 4676096]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-03-28 6280416]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2006-12-19 128312]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-11-22 105088]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys []
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\WINDOWS\system32\DRIVERS\avcstrm.sys [2008-04-13 13696]
S3 BTHMODEM;Bluetooth Modem Communications Driver; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2005-11-10 340704]
S3 ET5Drv;ET5Drv; \??\C:\WINDOWS\system32\Drivers\ET5Drv.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\WINDOWS\system32\DRIVERS\mstape.sys [2008-04-13 49024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RT61;AMIT RT61 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2006-01-19 363008]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-13 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-03-28 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-12-23 66872]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2008-06-09 53392]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-03-24 33560]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\GEST\GSvr.exe [2007-12-14 47624]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OKI OPHD DCS Loader;OKI OPHD DCS Loader; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHDLDCS.EXE [2005-10-01 24576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-09-30 355584]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: trojan

#28 Příspěvek od motji »

:arrow: Můžete omezit spouštění zbytečných programů po startu
- Stáhněte z mého podpisu program StartUpLite
- vypíše seznam zbytečně spouštěných programů po startu,
- vyberete které chcete zastavit,u nich zaškrtnete Disable a klikněte na Continue


:arrow: Jsou ještě nějaké problémy s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

lklubo
Návštěvník
Návštěvník
Příspěvky: 80
Registrován: 26 dub 2010 21:43

Re: trojan

#29 Příspěvek od lklubo »

zatial je vsetko ok.

velmi pekne dakujem lubo kosice :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: trojan

#30 Příspěvek od motji »

Není zač :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět