Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

svchost nakažen trojanem backdoor.generic12.BOEN

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

svchost nakažen trojanem backdoor.generic12.BOEN

#1 Příspěvek od jilda »

pár měsíců mám tento problém-když stahuji cokoli z internetu a odejdu třeba na 7 hodin od PC (do školy :D ) a vrátím se, tak mi vždy AVG (9 free) vyjede tento virus, zabráněný rezidentním štítem nebo automatickým testem.Virus nakazil proces svchost.exe, tím pádem jak to avgčko přesune do trezoru, vždy se mi zasekne stahování :( . Taky mám poklesy fps ve hrách každých 10 sekund třeba ze 70fps na 9 fps .Je to hlavně u multiplayer her na Windows XP pro ... (mám dual-boot, na druhém oddílu win7pro,a tam se fps nesnižuje ani avast nehlásí nakažený svchost)
virus se pořád dokola a dokola objevuje ..... jinak na xp mám avg 9 free a na 7-mách avast 5
Obrázek
Naposledy upravil(a) jilda dne 04 čer 2010 17:32, celkem upraveno 2 x.

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#2 Příspěvek od jilda »

dds




DDS (Ver_10-03-17.01) - NTFSx86
Run by Jˇleźkovi at 18:36:08,67 on p  04.06.2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_20
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1178 [GMT 2:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\winsys2.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\WINDOWS\HKExt3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Jílečkovi\Local Settings\Data aplikací\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\WINDOWS\MHotkey.exe
E:\FRAPS\FRAPS.EXE
C:\WINDOWS\ChiFuncExt.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\Jílečkovi\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jílečkovi\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jílečkovi\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Jílečkovi\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Downloads\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - c:\windows\system32\gigagetbho_v10.dll
BHO: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\jílečkovi\local settings\data aplikací\google\update\GoogleUpdate.exe" /c
uRun: [ManicTime] c:\program files\manictime\ManicTime.exe /minimized /name:
uRun: [ViGlance] c:\program files\viglance\ViGlance.exe
uRun: [Fraps] e:\fraps\FRAPS.EXE
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SW20] c:\windows\system32\sw20.exe
mRun: [SW24] c:\windows\system32\sw24.exe
mRun: [WinSys2] c:\windows\system32\winsys2.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [LchDrvKey] LchDrvKey.exe
mRun: [HKExt3] HKExt3.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: &Download All by Gigaget - e:\program files\giganology\gigaget\getallurl.htm
IE: &Download by Gigaget - e:\program files\giganology\gigaget\geturl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - e:\program files\icq\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/s ... ab_nvd.cab
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jlekov~1\dataap~1\mozilla\firefox\profiles\osi2ma1n.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\jílečkovi\data aplikací\mozilla\firefox\profiles\osi2ma1n.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\jă­leäťkovi\data aplikacă­\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\jă­leäťkovi\local settings\data aplikacă­\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: e:\program files\adobe\reader 9.0\reader\browser\nppdf32.dll
FF - plugin: e:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: e:\program files\opera\program\plugins\npdsplay.dll
FF - plugin: e:\program files\opera\program\plugins\NPSWF32.dll
FF - plugin: e:\program files\opera\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
e:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
e:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
e:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
e:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
e:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.jit.chrome", true);
e:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
e:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
e:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
e:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
e:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
e:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
e:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
e:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
e:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
e:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
e:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
e:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
e:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
e:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
e:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
e:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
e:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
e:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-11-14 52872]
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2010-3-26 38448]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-14 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-14 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-14 242896]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-12 916760]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-12 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1169232]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
S0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-4 64288]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-11-13 1684736]
S3 DfSdkS;Defragmentation-Service;e:\program files\ashampoo\ashampoo winoptimizer 2010 advanced\DfSdkS.exe [2009-12-28 406016]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-4-5 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-4-5 8456]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 WFIOCTL;WFIOCTL;c:\program files\winfast\wfdtv\WFIOCTL.sys [2009-11-14 9446]

=============== Created Last 30 ================

2010-06-04 16:35:59 0 d--h--w- c:\windows\PIF
2010-06-04 16:02:00 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-04 16:00:08 0 dc-h--w- c:\docume~1\alluse~1\dataap~1\{42E04EE4-AB57-407A-9691-3FFA8B8FEBBE}
2010-06-04 15:59:44 0 d-----w- c:\program files\Lavasoft
2010-06-04 15:40:04 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-06-04 15:40:04 0 d-----w- c:\docume~1\alluse~1\dataap~1\Spybot - Search & Destroy
2010-06-04 15:32:59 0 dc-h--w- c:\docume~1\alluse~1\dataap~1\~0
2010-06-04 14:45:28 0 d-----w- c:\docume~1\jlekov~1\dataap~1\Soldat
2010-06-04 14:44:12 0 d-----w- c:\docume~1\alluse~1\dataap~1\vsosdk
2010-06-04 13:57:12 87608 ----a-w- c:\docume~1\jlekov~1\dataap~1\inst.exe
2010-06-04 13:57:12 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-06-04 13:57:12 47360 ----a-w- c:\docume~1\jlekov~1\dataap~1\pcouffin.sys
2010-06-04 13:57:03 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-06-04 13:57:03 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-06-04 13:57:03 217127 ----a-w- c:\windows\system32\drv43260.dll
2010-06-04 13:57:03 208935 ----a-w- c:\windows\system32\drv33260.dll
2010-06-04 13:57:03 176165 ----a-w- c:\windows\system32\drv23260.dll
2010-06-04 13:57:03 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-06-04 13:57:03 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-06-04 13:57:01 0 d-----w- c:\program files\VSO
2010-06-03 16:18:54 0 ----a-r- C:\logwmemory.bin
2010-05-25 19:15:39 0 d--h--r- c:\documents and settings\jílečkovi\Recent
2010-05-24 18:35:01 0 d-----w- c:\docume~1\jlekov~1\dataap~1\ViGlance
2010-05-24 18:34:59 0 d-----w- c:\program files\ViGlance
2010-05-24 18:11:24 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-24 16:31:46 62 ----a-w- c:\windows\Wininit.ini
2010-05-24 13:33:06 0 d-----w- c:\docume~1\jlekov~1\dataap~1\ConMet
2010-05-24 13:33:06 0 d-----w- c:\docume~1\alluse~1\dataap~1\ConMet
2010-05-24 12:59:03 0 d-----w- c:\program files\ManicTime
2010-05-07 19:52:46 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-05-07 15:58:18 38 ----a-w- c:\windows\AviSplitter.INI
2010-05-06 11:53:51 11746 ----a-w- c:\windows\mhotkey_reg.ini
2010-05-06 11:53:50 580096 ----a-w- c:\windows\mHotkey.exe
2010-05-06 11:53:50 24576 ----a-w- c:\windows\HKNTDLL.dll
2010-05-06 11:53:50 0 d-----w- c:\program files\KYE
2010-05-06 11:53:49 57344 ----a-w- c:\windows\ChiFuncExt.exe
2010-05-06 11:53:49 313856 ----a-w- c:\windows\HKExt3.exe
2010-05-06 11:53:49 294912 ----a-w- c:\windows\PIC.dll
2010-05-06 11:53:48 36864 ----a-w- c:\windows\LchDrvKey.exe

==================== Find3M ====================

2010-06-04 15:02:11 2828 --sha-w- c:\docume~1\alluse~1\dataap~1\KGyGaAvL.sys
2010-06-03 05:27:32 13893632 ----a-w- c:\documents and settings\jílečkovi\NTUSER.DAT
2010-06-03 05:16:27 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-31 15:34:26 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-05-31 15:34:19 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-24 18:10:32 87952 ----a-w- c:\windows\system32\perfc005.dat
2010-05-24 18:10:32 454492 ----a-w- c:\windows\system32\perfh005.dat
2010-03-12 08:40:44 12464 ----a-w- c:\windows\system32\avgrsstx.dll

============= FINISH: 18:36:25,29 ===============


attach




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Systém Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 13.11.2009 15:19:25
System Uptime: 6.4.2010 15:49:27 (1419 hours ago)

Motherboard: MSI | | MS-7390
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2210/200mhz
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2210/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 29 GiB total, 3,936 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 184 GiB total, 57,164 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is CDROM ()
L: is CDROM ()
W: is FIXED (NTFS) - 19 GiB total, 1,441 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP218: 22.4.2010 9:35:01 - Avg Update
RP219: 22.4.2010 9:37:42 - Avg Update
RP220: 23.4.2010 6:15:35 - Avg Update
RP221: 24.4.2010 18:21:05 - Revo Uninstaller's restore point - ABBYY FineReader 9.0 Professional Edition
RP222: 24.4.2010 22:50:36 - Revo Uninstaller's restore point - Assassin's Creed II
RP223: 24.4.2010 22:50:55 - Odstraněno Assassin's Creed II
RP224: 24.4.2010 22:51:47 - Revo Uninstaller's restore point - Batman: Arkham Asylum
RP225: 24.4.2010 22:52:06 - Removed Batman: Arkham Asylum
RP226: 26.4.2010 6:36:27 - Kontrolní bod systému
RP227: 28.4.2010 7:47:00 - Kontrolní bod systému
RP228: 29.4.2010 8:43:11 - Kontrolní bod systému
RP229: 3.5.2010 7:45:12 - Kontrolní bod systému
RP230: 4.5.2010 8:15:12 - Kontrolní bod systému
RP231: 6.5.2010 6:54:09 - Avg Update
RP232: 6.5.2010 13:53:48 - Installed SlimStar 320
RP233: 7.5.2010 19:49:38 - Kontrolní bod systému
RP234: 12.5.2010 8:01:28 - Kontrolní bod systému
RP235: 13.5.2010 8:14:53 - Kontrolní bod systému
RP236: 13.5.2010 15:19:11 - Revo Uninstaller's restore point - Command & Conquer™ 4 Tiberian Twilight
RP237: 13.5.2010 15:29:09 - Removed Command & Conquer™ 4 Tiberian Twilight
RP238: 13.5.2010 15:31:45 - Revo Uninstaller's restore point - Posel Smrti 2
RP239: 13.5.2010 15:32:31 - Revo Uninstaller's restore point - DiRT2
RP240: 13.5.2010 15:32:52 - Revo Uninstaller's restore point - Google Desktop
RP241: 24.5.2010 7:58:31 - Kontrolní bod systému
RP242: 24.5.2010 14:59:01 - Installed ManicTime
RP243: 24.5.2010 20:07:01 - Installed ManicTime
RP244: 24.5.2010 20:10:26 - Installed Java(TM) 6 Update 20
RP245: 25.5.2010 21:13:17 - Revo Uninstaller's restore point - DiRT2
RP246: 25.5.2010 21:13:39 - Removed DiRT2
RP247: 27.5.2010 8:08:01 - Kontrolní bod systému
RP248: 28.5.2010 8:11:28 - Kontrolní bod systému
RP249: 29.5.2010 13:33:05 - Nainstalováno ProductName from default.wxl
RP250: 3.6.2010 7:16:38 - Avg Update
RP251: 4.6.2010 17:55:39 - Revo Uninstaller's restore point - Ad-Aware Game Edition
RP252: 4.6.2010 18:01:45 - Revo Uninstaller's restore point - FortKnox Personal Firewall

==== Installed Programs ======================


7-Zip 4.65
Active@ Hard Disk Monitor
Ad-Aware
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Photoshop CS4
Adobe Reader 9.3.1 - Czech
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
AMR to MP3 Converter 1.4
Any Video Converter 3.0.3
Apple Application Support
Apple Software Update
Ashampoo Burning Studio 2010
Ashampoo WinOptimizer 2010 Advanced
Asterisk Key 9.3
µTorrent
Audacity 1.2.6
AVG 9.0
AVI ReComp 1.4.5
AviSynth 2.5
Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
BS.Player PRO
Call of Duty(R) 4 - Modern Warfare(TM)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Call of Duty: Modern Warfare 2
Call of Duty: Modern Warfare 2 - Multiplayer
CamStudio Lossless Codec
Canon MP210 series
CCleaner
CNC4 Offline Patch
Combined Community Codec Pack 2009-09-09
ConvertXtoDVD 4.0.12.327
Corel WinDVD 2010
DesetiPrsty5 5.2
DivX Plus Web Player
Dual-Core Optimizer
EA Download Manager
EASEUS Partition Master 4.1.1 Home Edition
Easy-Hide-IP 3.0
EasyBCD 1.7
ESET Online Scanner v3
EVEREST Ultimate Edition v5.02
Facebook Plug-In
Far Cry
FastStone Capture 6.5
Fraps (remove only)
Game Booster
Game Cam 2.54.0.47
Game Cam v1.4
GamePark
Gigaget
GOM Player
Google Chrome
Google SketchUp 6
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB954550-v5)
Cheat Engine 5.4
IBM ViaVoice TTS Runtime v6.405 - Deutsch
ICQ6.5
Jalbum
Java Auto Updater
Java(TM) 6 Update 20
K-Lite Codec Pack 5.1.0 (Basic)
LAME v3.98.2 for Audacity
Lernout & Hauspie TruVoice American English TTS Engine
linguatec Voice Reader
ManicTime
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office Access MUI (Czech) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Czech) 2007
Microsoft Office Groove MUI (Czech) 2007
Microsoft Office InfoPath MUI (Czech) 2007
Microsoft Office OneNote MUI (Czech) 2007
Microsoft Office Outlook MUI (Czech) 2007
Microsoft Office PowerPoint MUI (Czech) 2007
Microsoft Office Proof (Czech) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Slovak) 2007
Microsoft Office Proofing (Czech) 2007
Microsoft Office Publisher MUI (Czech) 2007
Microsoft Office Shared MUI (Czech) 2007
Microsoft Office Word MUI (Czech) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Software Update for Web Folders (Czech) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Virtual PC 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.6.3)
MSXML 6.0 Parser (KB927977)
Need for Speed™ SHIFT
Nero 6 Enterprise Edition
Nokia Wireless Presenter
Notepad++
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
OpenAL
OpenOffice.org 3.1
Oprava Hotfix systému Windows XP (KB942288-v3)
Ovladače videa společnosti Pinnacle
Paragon Partition Manager 8.5 Professional
PDF Settings
Pinnacle Studio 14
PIXMA Extended Survey Program
PowerDVD
PunkBuster Services
Rapture3D 2.3.22 Game
Realtek High Definition Audio Driver
Registrace uživatele zařízení Canon MP210 series
Replay AV 8
Replay Converter 3
Revo Uninstaller 1.83
Safari
Serious Sam HD: The First Encounter Demo
Skype™ 4.1
SlimStar 320
Spybot - Search & Destroy
Steam
Subtitle Workshop 2.51
System Requirements Lab
TagScanner 5.1 build 558
Total Commander (Remove or Repair)
Ubisoft Game Launcher
UltraISO Magazine Edition V8.66
VC80CRTRedist - 8.0.50727.4053
Vegas Pro 9.0
ViGlance
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VobSub 2.23
Vypínač na dobrou noc verze 2.0
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Media Format 11 runtime
Windows Presentation Foundation
Windows Search 4.0
WinFast PVR2
WinFast TV2000 Expert / WinFast DV2000 Driver
WinPcap 4.0.2
WinRAR
WM Converter 2.0
Xfire (remove only)
XML Paper Specification Shared Components Pack 1.0
Xvid 1.2.1
Zero Gear
Zoner Callisto 5
Zoner GIF Animator 5
Zoner Photo Studio 12

==== End Of File ===========================


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Systém Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 13.11.2009 15:19:25
System Uptime: 6.4.2010 15:49:27 (1419 hours ago)

Motherboard: MSI | | MS-7390
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2210/200mhz
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2210/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 29 GiB total, 3,936 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 184 GiB total, 57,164 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is CDROM ()
L: is CDROM ()
W: is FIXED (NTFS) - 19 GiB total, 1,441 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP218: 22.4.2010 9:35:01 - Avg Update
RP219: 22.4.2010 9:37:42 - Avg Update
RP220: 23.4.2010 6:15:35 - Avg Update
RP221: 24.4.2010 18:21:05 - Revo Uninstaller's restore point - ABBYY FineReader 9.0 Professional Edition
RP222: 24.4.2010 22:50:36 - Revo Uninstaller's restore point - Assassin's Creed II
RP223: 24.4.2010 22:50:55 - Odstraněno Assassin's Creed II
RP224: 24.4.2010 22:51:47 - Revo Uninstaller's restore point - Batman: Arkham Asylum
RP225: 24.4.2010 22:52:06 - Removed Batman: Arkham Asylum
RP226: 26.4.2010 6:36:27 - Kontrolní bod systému
RP227: 28.4.2010 7:47:00 - Kontrolní bod systému
RP228: 29.4.2010 8:43:11 - Kontrolní bod systému
RP229: 3.5.2010 7:45:12 - Kontrolní bod systému
RP230: 4.5.2010 8:15:12 - Kontrolní bod systému
RP231: 6.5.2010 6:54:09 - Avg Update
RP232: 6.5.2010 13:53:48 - Installed SlimStar 320
RP233: 7.5.2010 19:49:38 - Kontrolní bod systému
RP234: 12.5.2010 8:01:28 - Kontrolní bod systému
RP235: 13.5.2010 8:14:53 - Kontrolní bod systému
RP236: 13.5.2010 15:19:11 - Revo Uninstaller's restore point - Command & Conquer™ 4 Tiberian Twilight
RP237: 13.5.2010 15:29:09 - Removed Command & Conquer™ 4 Tiberian Twilight
RP238: 13.5.2010 15:31:45 - Revo Uninstaller's restore point - Posel Smrti 2
RP239: 13.5.2010 15:32:31 - Revo Uninstaller's restore point - DiRT2
RP240: 13.5.2010 15:32:52 - Revo Uninstaller's restore point - Google Desktop
RP241: 24.5.2010 7:58:31 - Kontrolní bod systému
RP242: 24.5.2010 14:59:01 - Installed ManicTime
RP243: 24.5.2010 20:07:01 - Installed ManicTime
RP244: 24.5.2010 20:10:26 - Installed Java(TM) 6 Update 20
RP245: 25.5.2010 21:13:17 - Revo Uninstaller's restore point - DiRT2
RP246: 25.5.2010 21:13:39 - Removed DiRT2
RP247: 27.5.2010 8:08:01 - Kontrolní bod systému
RP248: 28.5.2010 8:11:28 - Kontrolní bod systému
RP249: 29.5.2010 13:33:05 - Nainstalováno ProductName from default.wxl
RP250: 3.6.2010 7:16:38 - Avg Update
RP251: 4.6.2010 17:55:39 - Revo Uninstaller's restore point - Ad-Aware Game Edition
RP252: 4.6.2010 18:01:45 - Revo Uninstaller's restore point - FortKnox Personal Firewall

==== Installed Programs ======================


7-Zip 4.65
Active@ Hard Disk Monitor
Ad-Aware
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Photoshop CS4
Adobe Reader 9.3.1 - Czech
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
AMR to MP3 Converter 1.4
Any Video Converter 3.0.3
Apple Application Support
Apple Software Update
Ashampoo Burning Studio 2010
Ashampoo WinOptimizer 2010 Advanced
Asterisk Key 9.3
µTorrent
Audacity 1.2.6
AVG 9.0
AVI ReComp 1.4.5
AviSynth 2.5
Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
BS.Player PRO
Call of Duty(R) 4 - Modern Warfare(TM)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Call of Duty: Modern Warfare 2
Call of Duty: Modern Warfare 2 - Multiplayer
CamStudio Lossless Codec
Canon MP210 series
CCleaner
CNC4 Offline Patch
Combined Community Codec Pack 2009-09-09
ConvertXtoDVD 4.0.12.327
Corel WinDVD 2010
DesetiPrsty5 5.2
DivX Plus Web Player
Dual-Core Optimizer
EA Download Manager
EASEUS Partition Master 4.1.1 Home Edition
Easy-Hide-IP 3.0
EasyBCD 1.7
ESET Online Scanner v3
EVEREST Ultimate Edition v5.02
Facebook Plug-In
Far Cry
FastStone Capture 6.5
Fraps (remove only)
Game Booster
Game Cam 2.54.0.47
Game Cam v1.4
GamePark
Gigaget
GOM Player
Google Chrome
Google SketchUp 6
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB954550-v5)
Cheat Engine 5.4
IBM ViaVoice TTS Runtime v6.405 - Deutsch
ICQ6.5
Jalbum
Java Auto Updater
Java(TM) 6 Update 20
K-Lite Codec Pack 5.1.0 (Basic)
LAME v3.98.2 for Audacity
Lernout & Hauspie TruVoice American English TTS Engine
linguatec Voice Reader
ManicTime
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office Access MUI (Czech) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Czech) 2007
Microsoft Office Groove MUI (Czech) 2007
Microsoft Office InfoPath MUI (Czech) 2007
Microsoft Office OneNote MUI (Czech) 2007
Microsoft Office Outlook MUI (Czech) 2007
Microsoft Office PowerPoint MUI (Czech) 2007
Microsoft Office Proof (Czech) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Slovak) 2007
Microsoft Office Proofing (Czech) 2007
Microsoft Office Publisher MUI (Czech) 2007
Microsoft Office Shared MUI (Czech) 2007
Microsoft Office Word MUI (Czech) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Software Update for Web Folders (Czech) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Virtual PC 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.6.3)
MSXML 6.0 Parser (KB927977)
Need for Speed™ SHIFT
Nero 6 Enterprise Edition
Nokia Wireless Presenter
Notepad++
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
OpenAL
OpenOffice.org 3.1
Oprava Hotfix systému Windows XP (KB942288-v3)
Ovladače videa společnosti Pinnacle
Paragon Partition Manager 8.5 Professional
PDF Settings
Pinnacle Studio 14
PIXMA Extended Survey Program
PowerDVD
PunkBuster Services
Rapture3D 2.3.22 Game
Realtek High Definition Audio Driver
Registrace uživatele zařízení Canon MP210 series
Replay AV 8
Replay Converter 3
Revo Uninstaller 1.83
Safari
Serious Sam HD: The First Encounter Demo
Skype™ 4.1
SlimStar 320
Spybot - Search & Destroy
Steam
Subtitle Workshop 2.51
System Requirements Lab
TagScanner 5.1 build 558
Total Commander (Remove or Repair)
Ubisoft Game Launcher
UltraISO Magazine Edition V8.66
VC80CRTRedist - 8.0.50727.4053
Vegas Pro 9.0
ViGlance
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VobSub 2.23
Vypínač na dobrou noc verze 2.0
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Media Format 11 runtime
Windows Presentation Foundation
Windows Search 4.0
WinFast PVR2
WinFast TV2000 Expert / WinFast DV2000 Driver
WinPcap 4.0.2
WinRAR
WM Converter 2.0
Xfire (remove only)
XML Paper Specification Shared Components Pack 1.0
Xvid 1.2.1
Zero Gear
Zoner Callisto 5
Zoner GIF Animator 5
Zoner Photo Studio 12

==== End Of File ===========================

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#3 Příspěvek od jilda »

log dds z win7, xp dodám zítra



DDS (Ver_10-03-17.01) - NTFSx86
Run by Jilda at 23:29:08,67 on p  04.06.2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2047.1171 [GMT 2:00]


============== Running Processes ===============

W:\Windows\system32\wininit.exe
W:\Windows\system32\lsm.exe
W:\Windows\system32\svchost.exe -k DcomLaunch
W:\Windows\system32\nvvsvc.exe
W:\Windows\system32\svchost.exe -k RPCSS
W:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
W:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
W:\Windows\system32\svchost.exe -k netsvcs
W:\Windows\system32\svchost.exe -k LocalService
W:\Windows\system32\nvvsvc.exe
W:\Windows\system32\svchost.exe -k NetworkService
W:\Program Files\Alwil Software\Avast5\AvastSvc.exe
W:\Windows\system32\Dwm.exe
W:\Windows\Explorer.EXE
W:\Windows\System32\spoolsv.exe
W:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
W:\Windows\system32\taskhost.exe
W:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
W:\Program Files\ICQ6Toolbar\ICQ Service.exe
W:\Program Files\Common Files\Java\Java Update\jusched.exe
W:\Program Files\Alwil Software\Avast5\AvastUI.exe
E:\win7\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
W:\Windows\HKExt3.exe
W:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
W:\Windows\system32\taskeng.exe
W:\Windows\system32\svchost.exe -k imgsvc
W:\Program Files\Windows Sidebar\sidebar.exe
W:\Users\Jilda\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
W:\Windows\MHotKey.exe
W:\Program Files\DAEMON Tools Lite\DTLite.exe
E:\Program Files\Steam\steam.exe
W:\Windows\system32\svchost.exe -k bthsvcs
E:\win7\Program Files\ManicTime\ManicTime.exe
E:\win7\Program Files\Loonies\Actual Booster\ActlBstr.exe
W:\Windows\ChiFuncExt.exe
W:\Program Files\OpenOffice.org 3\program\soffice.exe
W:\Program Files\OpenOffice.org 3\program\soffice.bin
W:\Windows\system32\WUDFHost.exe
W:\Windows\system32\SearchIndexer.exe
W:\Program Files\Common Files\Steam\SteamService.exe
W:\Program Files\Windows Media Player\wmpnetwk.exe
W:\Windows\System32\svchost.exe -k LocalServicePeerNet
W:\Windows\System32\svchost.exe -k secsvcs
E:\win7\Program Files\Nokia\Nokia Wireless Presenter\Wireless Presenter.exe
E:\win7\Program Files\Microsoft Office\Office12\POWERPNT.EXE
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Users\Jilda\AppData\Local\Google\Chrome\Application\chrome.exe
W:\Windows\system32\DllHost.exe
W:\Windows\system32\DllHost.exe
W:\Windows\system32\DllHost.exe
E:\Downloads\dds.pif
W:\Windows\system32\conhost.exe
W:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - w:\program files\icq6toolbar\ICQToolBar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - w:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - w:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: H - No File
BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - w:\windows\system32\gigagetbho_v10.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - w:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: FG2CatchUrl: {1f364306-aa45-47b5-9f9d-39a8b94e7ef1} - w:\program files\flashget network\flashget universal\comdlls\bhoCATCH.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - e:\win7\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Pomocník pro přihlášení ke službě Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - w:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - w:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - w:\program files\java\jre6\bin\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - w:\program files\daemon tools toolbar\DTToolbar.dll
TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - w:\program files\icq6toolbar\ICQToolBar.dll
uRun: [Google Update] "w:\users\jilda\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Sidebar] w:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DAEMON Tools Lite] "w:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [Steam] "e:\program files\steam\steam.exe" -silent
uRun: [ManicTime] e:\win7\program files\manictime\ManicTime.exe /minimized /name:
uRun: [Actual Booster] e:\win7\program files\loonies\actual booster\ActlBstr.exe
mRun: [SunJavaUpdateSched] "w:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "w:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "w:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avast5] "w:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [GrooveMonitor] "e:\win7\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [LchDrvKey] LchDrvKey.exe
mRun: [HKExt3] HKExt3.exe
StartupFolder: w:\users\jilda\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - w:\program files\openoffice.org 3\program\quickstart.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Download All by FlashGet - w:\program files\flashget network\flashget universal\comdlls\Bhoall.htm
IE: &Download All by Gigaget - w:\program files\giganology\gigaget\getallurl.htm
IE: &Download by FlashGet - w:\program files\flashget network\flashget universal\comdlls\Bholink.htm
IE: &Download by Gigaget - w:\program files\giganology\gigaget\geturl.htm
IE: E&xportovat do aplikace Microsoft Excel - e:\win7\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: ????3?? - w:\users\jilda\appdata\roaming\flashgetbho\GetUrl.htm
IE: ????3?????? - w:\users\jilda\appdata\roaming\flashgetbho\GetAllUrl.htm
IE: {88EB38EF-4D2C-436D-ABD3-56B232674062} - w:\program files\icq7.0\ICQ.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - e:\win7\progra~1\micros~1\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - w:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\win7\progra~1\micros~1\office12\REFIEBAR.DLL
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: kuaiche.com\software
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - e:\win7\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - w:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - w:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - e:\win7\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - w:\users\jilda\appdata\roaming\mozilla\firefox\profiles\nmf0512l.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - component: w:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: w:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: w:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: w:\users\jilda\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: w:\users\jilda\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Java Console: No Registry Reference - w:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
w:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
w:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
w:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
w:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
w:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.jit.chrome", true);
w:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
w:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
w:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
w:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
w:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
w:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
w:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
w:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
w:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
w:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
w:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
w:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
w:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
w:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
w:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
w:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
w:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
w:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
w:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
w:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;w:\windows\system32\drivers\aswSP.sys [2010-4-21 164048]
R2 aswFsBlk;aswFsBlk;w:\windows\system32\drivers\aswFsBlk.sys [2010-4-21 19024]
R2 aswMonFlt;aswMonFlt;w:\windows\system32\drivers\aswMonFlt.sys [2010-4-21 51792]
R2 avast! Antivirus;avast! Antivirus;w:\program files\alwil software\avast5\AvastSvc.exe [2010-5-8 40384]
R2 ICQ Service;ICQ Service;w:\program files\icq6toolbar\ICQ Service.exe [2010-4-17 246520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;w:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-4-3 240232]
R3 avast! Mail Scanner;avast! Mail Scanner;w:\program files\alwil software\avast5\AvastSvc.exe [2010-5-8 40384]
R3 avast! Web Scanner;avast! Web Scanner;w:\program files\alwil software\avast5\AvastSvc.exe [2010-5-8 40384]
R3 BthAvrcp;Bluetooth AVRCP Profile;w:\windows\system32\drivers\BthAvrcp.sys [2009-8-13 22528]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;w:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 DrvAgent32;DrvAgent32;w:\windows\system32\drivers\DrvAgent32.sys [2010-5-2 23456]
S3 StorSvc;Služba úložiště;w:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]

=============== Created Last 30 ================

2010-06-04 11:51:00 679936 ----a-w- w:\windows\system32\D3DX81ab.dll
2010-06-04 11:51:00 1970176 ----a-w- w:\windows\system32\d3dx9.dll
2010-06-03 16:14:34 0 d-----w- w:\users\jilda\appdata\roaming\Soldat
2010-05-19 16:35:37 0 d-----w- w:\users\jilda\appdata\roaming\BitTorrent
2010-05-17 19:22:52 12 ----a-w- w:\users\jilda\appdata\roaming\qvjsge.dat
2010-05-17 13:08:59 0 d-----w- w:\users\jilda\appdata\roaming\Facebook
2010-05-16 11:43:52 0 d-----w- w:\users\jilda\appdata\roaming\NVIDIA
2010-05-15 18:37:23 0 d-----w- w:\users\jilda\appdata\roaming\Xfire
2010-05-15 18:37:22 0 d-----w- w:\programdata\Xfire
2010-05-13 17:58:09 0 d---a-w- w:\programdata\TEMP
2010-05-13 17:57:15 0 d-----w- w:\users\jilda\appdata\roaming\MotionDSP
2010-05-08 10:56:40 3084 ----a-w- w:\windows\mHotkey.xml
2010-05-08 10:56:40 11718 ----a-w- w:\windows\mhotkey_reg.ini
2010-05-08 10:56:39 580096 ----a-w- w:\windows\mHotkey.exe
2010-05-08 10:56:39 57344 ----a-w- w:\windows\ChiFuncExt.exe
2010-05-08 10:56:39 36864 ----a-w- w:\windows\LchDrvKey.exe
2010-05-08 10:56:39 313856 ----a-w- w:\windows\HKExt3.exe
2010-05-08 10:56:39 294912 ----a-w- w:\windows\PIC.dll
2010-05-08 10:56:39 24576 ----a-w- w:\windows\HKNTDLL.dll
2010-05-08 10:56:39 0 d-----w- w:\program files\KYE

==================== Find3M ====================

2010-06-04 18:43:00 622422 ----a-w- w:\windows\system32\perfh005.dat
2010-06-04 18:43:00 118604 ----a-w- w:\windows\system32\perfc005.dat
2010-05-06 20:34:10 51792 ----a-w- w:\windows\system32\drivers\aswMonFlt.sys
2010-05-02 17:20:01 23456 ----a-w- w:\windows\system32\drivers\DrvAgent32.sys
2010-04-30 15:51:07 56 ---ha-w- w:\programdata\ezsidmv.dat
2010-04-22 21:04:56 0 ---ha-w- w:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-04-17 11:47:14 411368 ----a-w- w:\windows\system32\deploytk.dll
2010-04-16 12:48:31 691696 ----a-w- w:\windows\system32\drivers\sptd.sys
2010-04-15 19:07:10 0 ---ha-w- w:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-04-03 16:27:00 985704 ----a-w- w:\windows\system32\nvsvc.dll
2010-04-03 16:27:00 13683816 ----a-w- w:\windows\system32\nvcpl.dll
2010-04-03 16:27:00 129640 ----a-w- w:\windows\system32\nvvsvc.exe
2010-04-03 16:27:00 110696 ----a-w- w:\windows\system32\nvmctray.dll
2010-03-28 13:22:26 86016 ----a-w- w:\windows\system32\frapsvid.dll
2010-03-24 18:24:34 31032 ----a-w- w:\windows\system32\ntaccess_64.sys
2010-03-24 18:24:28 25400 ----a-w- w:\windows\system32\Ntaccess.sys
2010-03-12 16:02:38 261632 ----a-w- w:\windows\PEV.exe
2010-03-08 21:33:56 427520 ----a-w- w:\windows\system32\vbscript.dll
2009-07-14 08:43:59 36232 ----a-w- w:\windows\inf\perflib\0405\perfd.dat
2009-07-14 08:43:59 36232 ----a-w- w:\windows\inf\perflib\0405\perfc.dat
2009-07-14 08:43:59 292004 ----a-w- w:\windows\inf\perflib\0405\perfi.dat
2009-07-14 08:43:59 292004 ----a-w- w:\windows\inf\perflib\0405\perfh.dat
2009-07-14 04:41:57 174 --sha-w- w:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- w:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- w:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- w:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- w:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- w:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- w:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 23:29:37,54 ===============

attach



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 16.4.2010 4:14:43
System Uptime: 6.4.2010 20:38:16 (1419 hours ago)

Motherboard: MSI | | MS-7390
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2210/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 29 GiB total, 3,942 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 184 GiB total, 57,118 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
K: is CDROM ()
L: is Removable
W: is FIXED (NTFS) - 19 GiB total, 1,415 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4d36e96c-e325-11ce-bfc1-08002be10318}
Description: Conexant 2388x Tuner (FM1216 MK3, 4 in 1)
Device ID: STREAM\CXTUNE.VEN_14F1.PHILIPS4IN1\5&1600807D&0&1
Manufacturer: Conexant
Name: Conexant 2388x Tuner (FM1216 MK3, 4 in 1)
PNP Device ID: STREAM\CXTUNE.VEN_14F1.PHILIPS4IN1\5&1600807D&0&1
Service: CXTUNE

Class GUID:
Description: Periferní zařízení Bluetooth
Device ID: BTHENUM\{00000002-0000-1000-8000-0002EE000002}_VID&00010001_PID&008C\7&106E264C&0&0025CFA2F567_C00000001
Manufacturer:
Name: Periferní zařízení Bluetooth
PNP Device ID: BTHENUM\{00000002-0000-1000-8000-0002EE000002}_VID&00010001_PID&008C\7&106E264C&0&0025CFA2F567_C00000001
Service:

Class GUID:
Description:
Device ID: STREAM\CX88XBAR.VEN_14F1.CNXT\5&1600807D&0&0
Manufacturer:
Name:
PNP Device ID: STREAM\CX88XBAR.VEN_14F1.CNXT\5&1600807D&0&0
Service:

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 2 (SP2)
3DMark Vantage
Actual Booster 3.1
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop CS4
Adobe Reader 9.3.2 - Czech
Asistent pro přihlášení ke službě Windows Live
avast! Free Antivirus
AVI ReComp 1.2.3
AviSynth 2.5
BitTorrent
Combined Community Codec Pack 2009-09-09
ConvertHelper 2.2
DAEMON Tools Toolbar
Driver Pro
DriverAgent by eSupport.com
EVEREST Ultimate Edition v5.50
Facebook Plug-In
Fraps (remove only)
Futuremark SystemInfo
Game Booster
Game Cam
GamePark
Gigaget
GOM Player
Google Chrome
Grand Theft Auto
Grand Theft Auto IV - Episodes From Liberty City
Grand Theft Auto: Episodes from Liberty City
HijackThis 2.0.2
Cheat Engine 5.6
I-Doser v4
ICQ Toolbar
ICQ7
Java Auto Updater
Java(TM) 6 Update 18
ManicTime
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Choice Guard
Microsoft Office Access MUI (Czech) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Czech) 2007
Microsoft Office Groove MUI (Czech) 2007
Microsoft Office InfoPath MUI (Czech) 2007
Microsoft Office OneNote MUI (Czech) 2007
Microsoft Office Outlook MUI (Czech) 2007
Microsoft Office PowerPoint MUI (Czech) 2007
Microsoft Office PowerPoint Viewer 2007 (Czech)
Microsoft Office Proof (Czech) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Slovak) 2007
Microsoft Office Proofing (Czech) 2007
Microsoft Office Publisher MUI (Czech) 2007
Microsoft Office Shared MUI (Czech) 2007
Microsoft Office Word MUI (Czech) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV TO AVI CONVERTER version 3.0
Mozilla Firefox (3.6.3)
MSVCRT
Next Video Converter 2.1.0
Nokia Wireless Presenter
Nástroj pro odesílání služby Windows Live
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OpenOffice.org 3.2
PVSonyDll
Skype Toolbars
Skype™ 4.2
SlimStar 320
Soldat 1.5.0
Steam
System Requirements Lab
The KMPlayer (remove only)
Total Commander (Remove or Repair)
Ubisoft Game Launcher
VobSub v2.23 (Remove Only)
vReveal
Vypínač na dobrou noc verze 2.0
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live Movie Maker
Windows Live Sync
Windows Movie Maker 2.6
WinRAR
Xvid 1.1.2 final uninstall
YouTube Downloader 2.5
Zoner Photo Studio 12

==== End Of File ===========================

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#4 Příspěvek od jilda »

tady je log z ckscanneru:


CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----


a ještě jsem zapomněl - avast na win7 mi před časem našel nějaký typ malwaru, myslím ve složce restore/system volume information/..čísla.. .Nemůžu najít printscreen nálezu a nechce se mi přepínat do sedmiček :) myslím že se jmenoval Win32/Malware , což mi zní dost nebezpečně..

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#5 Příspěvek od jilda »

zatím mám jen log z win7, z xp dodám dnes nebo zítra, jak mi to vyjde s časem...
taky jsem našel screen logu z avastu, je úplně dole.ten vir nešl smazat, tak jsem zapnul nouzový reřžim a tam se to povedlo.asi. :D

ComboFix 10-06-05.02 - Jilda 06.06.2010 12:58:40.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2047.1089 [GMT 2:00]
Spuštěný z: w:\users\Jilda\Desktop\ComboFix.exe
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-05-06 do 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-06 11:03 . 2010-06-06 11:03 -------- d-----w- w:\users\Jilda\AppData\Local\temp
2010-06-06 11:03 . 2010-06-06 11:03 -------- d-----w- w:\users\Public\AppData\Local\temp
2010-06-06 11:03 . 2010-06-06 11:03 -------- d-----w- w:\users\Default\AppData\Local\temp
2010-06-04 11:51 . 2009-11-03 12:07 679936 ----a-w- w:\windows\system32\D3DX81ab.dll
2010-06-04 11:51 . 2009-11-03 12:07 1970176 ----a-w- w:\windows\system32\d3dx9.dll
2010-06-03 16:16 . 2009-03-28 17:52 94208 ----a-w- w:\users\Jilda\AppData\Roaming\Soldat\Battleye\BEServer.dll
2010-06-03 16:16 . 2009-03-28 17:52 102400 ----a-w- w:\users\Jilda\AppData\Roaming\Soldat\Battleye\BEClient.dll
2010-06-03 16:14 . 2010-06-03 16:14 -------- d-----w- w:\users\Jilda\AppData\Roaming\Soldat
2010-05-27 18:38 . 2010-05-27 18:38 -------- d-----w- w:\users\Jilda\AppData\Local\Diagnostics
2010-05-19 16:35 . 2010-05-29 18:53 -------- d-----w- w:\users\Jilda\AppData\Roaming\BitTorrent
2010-05-17 13:09 . 2010-05-17 13:09 50354 ----a-w- w:\users\Jilda\AppData\Roaming\Facebook\uninstall.exe
2010-05-17 13:08 . 2010-05-17 13:09 -------- d-----w- w:\users\Jilda\AppData\Roaming\Facebook
2010-05-16 11:43 . 2010-05-16 11:43 -------- d-----w- w:\users\Jilda\AppData\Roaming\NVIDIA
2010-05-15 18:59 . 2010-05-15 18:59 -------- d-----w- w:\users\Jilda\AppData\Local\PunkBuster
2010-05-15 18:37 . 2010-05-15 18:59 -------- d-----w- w:\users\Jilda\AppData\Roaming\Xfire
2010-05-15 18:37 . 2010-05-15 18:39 -------- d-----w- w:\programdata\Xfire
2010-05-13 18:05 . 2010-04-03 22:55 56424 ----a-w- w:\windows\system32\OpenCL.dll
2010-05-13 18:05 . 2010-04-03 22:55 11573800 ----a-w- w:\windows\system32\drivers\nvlddmkm.sys
2010-05-13 18:05 . 2010-04-03 22:55 4029544 ----a-w- w:\windows\system32\nvcuda.dll
2010-05-13 18:05 . 2010-04-03 22:55 316008 ----a-w- w:\windows\system32\nvdecodemft.dll
2010-05-13 18:05 . 2010-04-03 22:55 2907752 ----a-w- w:\windows\system32\nvencodemft.dll
2010-05-13 18:05 . 2010-04-03 22:55 2646632 ----a-w- w:\windows\system32\nvcuvenc.dll
2010-05-13 18:05 . 2010-04-03 22:55 2009704 ----a-w- w:\windows\system32\nvcuvid.dll
2010-05-13 18:05 . 2010-04-03 22:55 15227496 ----a-w- w:\windows\system32\nvoglv32.dll
2010-05-13 18:05 . 2010-04-03 22:55 227944 ----a-w- w:\windows\system32\nvcod1914.dll
2010-05-13 18:05 . 2010-04-03 22:55 227944 ----a-w- w:\windows\system32\nvcod.dll
2010-05-13 18:05 . 2010-04-03 22:55 11647592 ----a-w- w:\windows\system32\nvcompiler.dll
2010-05-13 17:58 . 2010-05-13 17:58 -------- d-----w- w:\users\Jilda\AppData\Local\MotionDSP
2010-05-13 17:57 . 2010-05-13 17:57 -------- d-----w- w:\users\Jilda\AppData\Roaming\MotionDSP
2010-05-13 15:10 . 2010-05-13 15:10 -------- d-----w- w:\users\Jilda\AppData\Local\Finkit
2010-05-08 10:56 . 2010-05-08 10:56 -------- d-----w- w:\program files\KYE
2010-05-08 10:56 . 2009-02-06 19:57 57344 ----a-w- w:\windows\ChiFuncExt.exe
2010-05-08 10:56 . 2008-09-16 17:59 580096 ----a-w- w:\windows\mHotkey.exe
2010-05-08 10:56 . 2008-09-16 17:47 313856 ----a-w- w:\windows\HKExt3.exe
2010-05-08 10:56 . 2008-08-27 16:55 24576 ----a-w- w:\windows\HKNTDLL.dll
2010-05-08 10:56 . 2007-03-28 15:55 36864 ----a-w- w:\windows\LchDrvKey.exe
2010-05-08 10:56 . 2003-07-03 12:21 294912 ----a-w- w:\windows\PIC.dll
2010-05-08 10:56 . 2010-05-08 10:56 -------- d-----w- w:\users\Jilda\AppData\Roaming\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 11:02 . 2009-07-14 08:44 622422 ----a-w- w:\windows\system32\perfh005.dat
2010-06-06 11:02 . 2009-07-14 08:44 118604 ----a-w- w:\windows\system32\perfc005.dat
2010-06-06 10:57 . 2010-04-16 13:06 -------- d-----w- w:\programdata\NVIDIA
2010-05-27 18:05 . 2010-04-16 14:35 -------- d-----w- w:\program files\Common Files\Steam
2010-05-27 15:49 . 2010-04-16 14:35 -------- d-----w- w:\program files\Steam
2010-05-26 15:00 . 2010-04-17 11:49 -------- d--h--w- w:\program files\InstallShield Installation Information
2010-05-26 14:59 . 2010-05-04 15:20 -------- d-----w- w:\programdata\Ubisoft
2010-05-17 19:22 . 2010-05-17 19:22 12 ----a-w- w:\users\Jilda\AppData\Roaming\qvjsge.dat
2010-05-13 18:07 . 2010-04-16 13:05 -------- d-----w- w:\program files\NVIDIA Corporation
2010-05-09 11:15 . 2010-04-30 15:49 -------- d-----w- w:\users\Jilda\AppData\Roaming\Skype
2010-05-09 11:14 . 2010-04-30 15:51 -------- d-----w- w:\users\Jilda\AppData\Roaming\skypePM
2010-05-06 20:59 . 2010-04-21 19:11 165032 ----a-w- w:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-04-21 19:11 46672 ----a-w- w:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-04-21 19:11 164048 ----a-w- w:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-04-21 19:11 23376 ----a-w- w:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:34 . 2010-04-21 19:11 51792 ----a-w- w:\windows\system32\drivers\aswMonFlt.sys
2010-05-06 20:33 . 2010-04-21 19:11 19024 ----a-w- w:\windows\system32\drivers\aswFsBlk.sys
2010-05-05 17:32 . 2010-05-05 17:32 -------- d-----w- w:\program files\Microsoft Silverlight
2010-05-05 17:32 . 2010-05-05 17:32 -------- d-----w- w:\program files\Microsoft
2010-05-05 17:31 . 2010-05-05 17:31 -------- d-----w- w:\program files\Windows Live
2010-05-05 17:31 . 2010-05-05 17:31 -------- d-----w- w:\program files\Windows Live SkyDrive
2010-05-05 17:30 . 2010-05-05 17:30 -------- d-----w- w:\program files\Microsoft SQL Server Compact Edition
2010-05-05 17:25 . 2010-05-05 17:25 -------- d-----w- w:\program files\Common Files\Windows Live
2010-05-05 16:53 . 2010-05-05 16:53 -------- d-----w- w:\program files\Movie Maker 2.6
2010-05-04 15:17 . 2010-05-04 15:17 -------- d-----w- w:\program files\Ubisoft
2010-05-03 18:00 . 2010-05-03 18:00 -------- d-----w- w:\program files\Common Files\InstallShield
2010-05-02 17:27 . 2010-05-02 17:27 -------- d-----w- w:\program files\Setup Files
2010-05-02 17:20 . 2010-05-02 17:20 23456 ----a-w- w:\windows\system32\drivers\DrvAgent32.sys
2010-04-30 15:51 . 2010-04-30 15:51 56 ---ha-w- w:\programdata\ezsidmv.dat
2010-04-30 15:49 . 2010-04-30 15:49 -------- d-----r- w:\program files\Skype
2010-04-30 15:49 . 2010-04-30 15:49 -------- d-----w- w:\program files\Common Files\Skype
2010-04-30 15:49 . 2010-04-30 15:49 -------- d-----w- w:\programdata\Skype
2010-04-29 18:54 . 2010-04-29 18:54 -------- d-----w- w:\program files\Lavalys
2010-04-29 18:40 . 2010-04-29 18:40 -------- d-----w- w:\program files\IObit
2010-04-28 17:45 . 2010-04-16 04:13 114216 ----a-w- w:\users\Jilda\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-27 16:43 . 2010-04-27 16:34 -------- d-----w- w:\programdata\Microsoft Help
2010-04-27 16:41 . 2010-04-27 16:37 -------- d-----w- w:\program files\Microsoft Works
2010-04-27 16:37 . 2009-07-14 04:52 -------- d-----w- w:\program files\MSBuild
2010-04-27 16:36 . 2010-04-27 16:36 -------- d-----w- w:\program files\Microsoft.NET
2010-04-27 16:35 . 2010-04-27 16:35 -------- d-----w- w:\program files\Microsoft Visual Studio 8
2010-04-27 14:08 . 2010-04-27 14:08 0 ----a-w- w:\users\Jilda\AppData\Roaming\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2010-04-26 18:05 . 2010-04-19 12:17 1 ----a-w- w:\users\Jilda\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-04-26 16:54 . 2010-04-26 16:54 -------- d-----w- w:\users\Jilda\AppData\Roaming\DriverPro
2010-04-26 16:54 . 2010-04-26 16:54 -------- d-----w- w:\program files\Driver Pro
2010-04-25 16:04 . 2010-04-25 16:04 -------- d-----w- w:\program files\Next Video Converter
2010-04-25 11:14 . 2010-04-17 11:48 -------- d-----w- w:\program files\Common Files\Adobe
2010-04-24 12:33 . 2010-04-24 12:32 -------- d-----w- w:\users\Jilda\AppData\Roaming\GHISLER
2010-04-23 17:36 . 2010-04-23 17:35 -------- d-----w- w:\program files\AVI ReComp
2010-04-23 17:36 . 2010-04-23 17:36 -------- d-----w- w:\program files\Gabest
2010-04-23 17:36 . 2010-04-23 17:36 -------- d-----w- w:\program files\Xvid
2010-04-23 17:35 . 2010-04-23 17:35 -------- d-----w- w:\program files\AviSynth 2.5
2010-04-22 21:04 . 2010-04-22 21:04 0 ---ha-w- w:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-04-22 19:29 . 2010-04-22 19:29 -------- d-----w- w:\program files\ConvertHelper
2010-04-22 14:46 . 2010-04-22 14:46 -------- d-sh--w- w:\programdata\SecuROM
2010-04-22 14:44 . 2010-04-22 14:44 -------- d-----w- w:\program files\Microsoft Games for Windows - LIVE
2010-04-22 04:50 . 2010-04-22 04:50 -------- d-----w- w:\users\Jilda\AppData\Roaming\AnvSoft
2010-04-21 20:41 . 2010-04-21 20:41 -------- d-----w- w:\program files\FDRLab
2010-04-21 20:30 . 2010-04-21 20:30 -------- d-----w- w:\program files\MKVTOAVI
2010-04-21 19:12 . 2010-04-21 18:26 -------- d-----w- w:\program files\trend micro
2010-04-21 19:11 . 2010-04-21 19:11 -------- d-----w- w:\programdata\Alwil Software
2010-04-21 19:11 . 2010-04-21 19:11 -------- d-----w- w:\program files\Alwil Software
2010-04-21 15:10 . 2010-04-21 15:10 48648 ----a-w- w:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-04-21 15:10 . 2010-04-21 15:10 484160 ----a-w- w:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-04-20 17:28 . 2010-04-20 17:28 -------- d-----w- w:\program files\SystemRequirementsLab
2010-04-19 16:58 . 2010-04-19 16:58 -------- d--h--w- w:\programdata\CanonBJ
2010-04-19 12:17 . 2010-04-19 12:17 -------- d-----w- w:\users\Jilda\AppData\Roaming\OpenOffice.org
2010-04-19 12:15 . 2010-04-19 12:15 -------- d-----w- w:\program files\OpenOffice.org 3
2010-04-19 12:10 . 2010-04-19 12:09 -------- d-----w- w:\users\Jilda\AppData\Roaming\Zoner
2010-04-19 12:09 . 2010-04-19 12:09 -------- d-----w- w:\program files\Zoner
2010-04-19 11:47 . 2010-04-19 11:47 -------- d-----w- w:\program files\Giganology
2010-04-18 18:57 . 2010-04-18 18:57 -------- d-----w- w:\program files\Microsoft Games
2010-04-18 18:07 . 2010-04-17 12:36 -------- d-----w- w:\users\Jilda\AppData\Roaming\ICQ
2010-04-17 20:34 . 2010-04-17 20:34 598 ----a-w- w:\windows\system32\secushr.dat
2010-04-17 20:32 . 2010-04-17 20:32 -------- d-----w- w:\users\Jilda\AppData\Roaming\FlashGet
2010-04-17 16:46 . 2010-04-17 16:46 48648 ----a-w- w:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-04-17 16:46 . 2010-04-17 16:46 484160 ----a-w- w:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-04-17 12:39 . 2010-04-17 12:36 -------- d-----w- w:\program files\ICQ7.0
2010-04-17 12:37 . 2010-04-17 12:37 -------- d-----w- w:\program files\ICQ6Toolbar
2010-04-17 12:37 . 2010-04-17 12:37 -------- d-----w- w:\programdata\ICQ
2010-04-17 12:29 . 2010-04-17 11:50 -------- d-----w- w:\program files\Futuremark
2010-04-17 12:08 . 2010-04-17 11:50 -------- d-----w- w:\programdata\Futuremark
2010-04-17 11:51 . 2010-04-17 11:51 -------- d-----w- w:\program files\Common Files\Futuremark Shared
2010-04-17 11:47 . 2010-04-17 11:47 -------- d-----w- w:\program files\Common Files\Java
2010-04-17 11:47 . 2010-04-17 11:47 411368 ----a-w- w:\windows\system32\deploytk.dll
2010-04-17 11:47 . 2010-04-17 11:47 -------- d-----w- w:\program files\Java
2010-04-17 11:46 . 2010-04-17 11:46 -------- d-----w- w:\program files\MSECache
2010-04-17 11:44 . 2010-04-17 11:44 -------- d-----w- w:\program files\Combined Community Codec Pack
2010-04-17 11:42 . 2010-04-16 12:47 -------- d-----w- w:\users\Jilda\AppData\Roaming\DAEMON Tools Lite
2010-04-16 20:59 . 2010-04-16 20:59 -------- d-----w- w:\program files\Vypínač na dobrou noc
2010-04-16 19:26 . 2010-04-16 19:26 -------- d-----w- w:\users\Jilda\AppData\Roaming\GRETECH
2010-04-16 19:25 . 2010-04-16 19:25 -------- d-----w- w:\program files\GRETECH
2010-04-16 17:51 . 2010-04-16 17:50 -------- d-----w- w:\program files\The KMPlayer
2010-04-16 17:45 . 2010-04-16 17:45 -------- d-----w- w:\users\Jilda\AppData\Roaming\Media Player Classic
2010-04-16 12:48 . 2010-04-16 12:48 -------- d-----w- w:\program files\DAEMON Tools Toolbar
2010-04-16 12:48 . 2010-04-16 12:48 -------- d-----w- w:\program files\DAEMON Tools Lite
2010-04-16 12:48 . 2010-04-16 12:48 691696 ----a-w- w:\windows\system32\drivers\sptd.sys
2010-04-16 12:48 . 2010-04-16 12:47 -------- d-----w- w:\programdata\DAEMON Tools Lite
2010-04-16 02:14 . 2010-04-16 02:14 -------- d-sh--we w:\programdata\Plocha
2010-04-16 02:14 . 2010-04-16 02:14 -------- d-sh--we w:\programdata\Oblíbené položky
2010-04-16 02:14 . 2010-04-16 02:14 -------- d-sh--we w:\programdata\Šablony
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- w:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- w:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="w:\users\Jilda\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-04-16 136176]
"Sidebar"="w:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="w:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="e:\program files\steam\steam.exe" [2010-05-07 1238352]
"ManicTime"="e:\win7\Program Files\ManicTime\ManicTime.exe" [2010-05-19 582984]
"Actual Booster"="e:\win7\Program Files\Loonies\Actual Booster\ActlBstr.exe" [2005-12-10 12800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="w:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="w:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="w:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"avast5"="w:\program files\Alwil Software\Avast5\avastUI.exe" [2010-05-06 2815192]
"GrooveMonitor"="e:\win7\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LchDrvKey"="LchDrvKey.exe" [2007-03-28 36864]
"HKExt3"="HKExt3.exe" [2008-09-16 313856]

w:\users\Jilda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - w:\program files\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

R0 sptd;sptd;w:\windows\System32\Drivers\sptd.sys [2010-04-16 691696]
R2 eamonm;eamonm;w:\windows\system32\DRIVERS\eamonm.sys [x]
R3 cpuz130;cpuz130;w:\users\Jilda\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 DrvAgent32;DrvAgent32;w:\windows\system32\Drivers\DrvAgent32.sys [2010-05-02 23456]
R3 WEBNTACCESS;WEBNTACCESS;c:\progra~1\MSI\LIVEUP~1\NTACCESS.SYS [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;w:\windows\system32\drivers\aswMonFlt.sys [2010-05-06 51792]
S2 ICQ Service;ICQ Service;w:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;w:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S3 BthAvrcp;Bluetooth AVRCP Profile;w:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]

.
Obsah adresáře 'Naplánované úlohy'

2010-06-04 w:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2133549604-1030677499-4022257467-1000Core.job
- w:\users\Jilda\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-16 04:13]

2010-06-06 w:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2133549604-1030677499-4022257467-1000UA.job
- w:\users\Jilda\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-16 04:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://google.com/
IE: &Download All by FlashGet - w:\program files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
IE: &Download All by Gigaget - w:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by FlashGet - w:\program files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
IE: &Download by Gigaget - w:\program files\Giganology\Gigaget\geturl.htm
IE: E&xportovat do aplikace Microsoft Excel - e:\win7\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - w:\users\Jilda\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - w:\users\Jilda\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - w:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: kuaiche.com\software
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
FF - ProfilePath - w:\users\Jilda\AppData\Roaming\Mozilla\Firefox\Profiles\nmf0512l.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - component: w:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: w:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: w:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: w:\users\Jilda\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: w:\users\Jilda\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

---- NASTAVENÍ FIREFOXU ----
w:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
w:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
w:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
w:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
w:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
w:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
w:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
w:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
w:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
w:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
w:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-Grand Theft Auto - w:\program files\Rockstar Games\Grand Theft Auto\Uninst.isu


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-2133549604-1030677499-4022257467-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="w:\\Users\\Jilda\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022

[HKEY_USERS\S-1-5-21-2133549604-1030677499-4022257467-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="w:\\Users\\Jilda\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-06-06 13:05:26
ComboFix-quarantined-files.txt 2010-06-06 11:05
ComboFix2.txt 2010-04-25 18:15

Před spuštěním: 3 089 252 352
Po spuštění: 3 118 968 832

- - End Of File - - 35F90247EFB755164A2EEA02AD0DA3C0


Obrázek

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#6 Příspěvek od jilda »

log combofix z xpéček...

ComboFix 10-06-03.01 - Jílečkovi 06.06.2010 19:12:29.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1463 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jílečkovi\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000110_.tmp.dll
c:\windows\system32\BReWErS.dll
c:\windows\system32\Dvbpws.dll
c:\windows\system32\winsys.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-06 do 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-05 19:34 . 2010-06-05 19:34 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-06-05 18:52 . 2010-06-05 18:52 -------- d-----w- c:\windows\system32\AsBackup
2010-06-05 18:38 . 2010-06-05 18:38 -------- d-----w- c:\windows\DEA314C409294250BC9298E4C105F28D.TMP
2010-06-05 18:37 . 2010-04-03 22:55 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-05 18:37 . 2010-04-03 22:55 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-06-05 18:37 . 2010-04-03 22:55 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-06-05 18:37 . 2010-04-03 22:55 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-06-05 18:37 . 2010-04-03 22:55 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-06-05 18:37 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-06-05 18:37 . 2010-04-03 22:55 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-06-05 18:37 . 2010-04-03 22:55 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-05 18:33 . 2010-06-05 18:33 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-05 18:06 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-06-05 18:06 . 2010-04-03 22:55 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-06-05 14:29 . 2010-06-05 14:29 -------- d-----w- c:\windows\ServicePackFiles
2010-06-05 14:28 . 2008-04-14 06:52 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2010-06-04 16:35 . 2010-06-04 16:35 -------- d--h--w- c:\windows\PIF
2010-06-04 16:02 . 2010-06-05 18:25 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-04 15:59 . 2010-06-05 18:11 -------- d-----w- c:\program files\Lavasoft
2010-06-04 15:40 . 2010-06-04 15:47 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-04 13:57 . 2010-06-04 13:57 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-06-04 13:57 . 2010-02-09 14:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-06-04 13:57 . 2010-02-09 14:37 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-06-04 13:57 . 2010-02-09 14:37 217127 ----a-w- c:\windows\system32\drv43260.dll
2010-06-04 13:57 . 2010-02-09 14:37 208935 ----a-w- c:\windows\system32\drv33260.dll
2010-06-04 13:57 . 2010-02-09 14:37 176165 ----a-w- c:\windows\system32\drv23260.dll
2010-06-04 13:57 . 2010-02-09 14:37 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-06-04 13:57 . 2010-02-09 14:37 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-06-04 13:57 . 2010-06-04 13:57 -------- d-----w- c:\program files\VSO
2010-06-03 16:18 . 2010-06-03 16:18 0 ----a-r- C:\logwmemory.bin
2010-05-24 18:34 . 2010-05-25 04:06 -------- d-----w- c:\program files\ViGlance
2010-05-24 18:12 . 2010-05-24 18:12 -------- d-----w- c:\program files\Common Files\Java
2010-05-24 18:11 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-24 12:59 . 2010-05-24 18:07 -------- d-----w- c:\program files\ManicTime
2010-05-07 19:52 . 2010-05-07 19:52 41872 ----a-w- c:\windows\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 18:38 . 2009-11-15 09:11 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-05 18:33 . 2010-02-07 00:50 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-05 18:26 . 2009-11-14 10:11 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-05 17:46 . 2010-02-22 14:17 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-05 17:46 . 2010-02-22 14:16 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-06-05 14:35 . 2009-11-13 14:17 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-06-05 14:35 . 2009-11-13 14:17 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-06-03 05:16 . 2009-11-14 10:07 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-03 05:16 . 2009-11-14 10:07 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-25 19:14 . 2009-11-13 16:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-24 18:10 . 2009-11-14 14:19 -------- d-----w- c:\program files\Java
2010-05-24 18:10 . 2001-10-25 14:00 87952 ----a-w- c:\windows\system32\perfc005.dat
2010-05-24 18:10 . 2001-10-25 14:00 454492 ----a-w- c:\windows\system32\perfh005.dat
2010-05-14 04:06 . 2010-04-11 10:08 -------- d-----w- c:\program files\Google
2010-05-06 11:53 . 2010-05-06 11:53 -------- d-----w- c:\program files\KYE
2010-05-04 13:15 . 2010-05-04 13:15 -------- d-----w- c:\program files\Nokia
2010-04-27 19:26 . 2010-04-27 19:26 -------- d-----w- c:\program files\MSI
2010-04-11 19:18 . 2010-04-11 19:18 -------- d-----w- c:\program files\NeoSmart Technologies
2010-04-03 22:55 . 2009-11-13 16:53 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-04-03 22:55 . 2007-04-12 15:44 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2007-04-12 15:44 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-02 14:54 . 2009-11-13 16:07 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-03-27 20:24 . 2010-03-27 20:07 25 ----a-w- c:\windows\popcinfot.dat
2010-03-12 08:40 . 2010-03-12 08:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-12 08:39 . 2009-11-14 10:07 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-12 08:39 . 2009-11-14 10:07 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fraps"="e:\fraps\FRAPS.EXE" [2010-03-04 2353072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SW20"="c:\windows\system32\sw20.exe" [2006-12-15 208896]
"SW24"="c:\windows\system32\sw24.exe" [2006-12-15 69632]
"WinSys2"="c:\windows\system32\winsys2.exe" [2006-12-15 217088]
"RTHDCPL"="RTHDCPL.EXE" [2009-07-20 18670592]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"LchDrvKey"="LchDrvKey.exe" [2007-03-28 36864]
"HKExt3"="HKExt3.exe" [2008-09-16 313856]
"mspwr"="c:\windows\system32\PuXpMan2.exe" [2005-09-29 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\mamka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office 2007\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\mamka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office 2007\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\mamka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office 2007\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\mamka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office 2007\Office12\ONENOTEM.EXE [2006-10-26 98632]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-12 08:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Game Edition Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"e:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"e:\\Program Files\\ICQ\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office 2007\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office 2007\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office 2007\\Office12\\ONENOTE.EXE"=
"e:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\totalcmd\\TOTALCMD.EXE"=
"e:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"e:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"e:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"e:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\zero gear\\ZeroGear.bat"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Xfire\\Xfire.exe"=
"e:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\serious sam hd the first encounter\\Bin\\SamHD_Demo.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\serious sam hd the first encounter\\Bin\\SamHD.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"e:\\win7\\Soldat\\Soldat.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [14.11.2009 12:07 52872]
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [26.3.2010 20:52 38448]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.6.2010 18:02 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [14.11.2009 12:07 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [14.11.2009 12:07 242896]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12.3.2010 10:39 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12.3.2010 10:40 308064]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [17.4.2007 21:09 11032]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.11.2009 17:07 721904]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [13.11.2009 18:20 1684736]
S3 DfSdkS;Defragmentation-Service;e:\program files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\DfSdkS.exe [28.12.2009 13:59 406016]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [5.4.2010 16:50 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [5.4.2010 16:50 8456]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [4.2.2010 17:52 1352320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [6.11.2007 22:22 34064]
S3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [14.11.2009 11:50 9446]
.
Obsah adresáře 'Naplánované úlohy'

2010-06-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:25]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Download All by Gigaget - e:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - e:\program files\Giganology\Gigaget\geturl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jílečkovi\Data aplikací\Mozilla\Firefox\Profiles\osi2ma1n.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\Jílečkovi\Data aplikací\Mozilla\Firefox\Profiles\osi2ma1n.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: e:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: e:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npwachk.dll

---- NASTAVENÍ FIREFOXU ----
e:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
e:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-nwiz - nwiz.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-06 19:16
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
Celkový čas: 2010-06-06 19:17:52
ComboFix-quarantined-files.txt 2010-06-06 17:17
ComboFix2.txt 2010-04-25 18:15

Před spuštěním: 3 551 289 344
Po spuštění: 3 847 868 416

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /FASTDETECT

- - End Of File - - 08E2891CFF2C187FB95B3AC85F381CAB

jilda
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 říj 2008 13:02

Re: svchost nakažen trojanem backdoor.generic12.BOEN

#7 Příspěvek od jilda »

viry jsem zatím netestoval, tedy ne avgčkem a avastem, ale spybot mi našel nějaká cookies-smazal jsem je a ad-aware otestoval půlku počítače, pak jsem ho zastavil ale taky nic nenašel.....jinak ve hrách se pořád snižuje fps, což mi vadí, protože se to nedá hrát-na win 7 mám například v modern warfare 2 stabilně 70 fps po celou dobu, ale když hraju na win xp tak se mi to každých 10 sekund snižuje na 9 fps.a díky tomu mně v multiplayeru aspoň 50x dostali.což mně fakt štve.zkoušel jsem vypnout všechno, co nepotřebuji, aktualizoval jsem ovladače, defragmentoval všechny 3 oddíly Defragem 3 (Ash win opt 10)..ale pořád to stejné...díval sem se do task manageru, a nečinné procesy systému zabírají 98 CPU ... není to divné ? Jak říkám, na win 7 mi vše jde bez problému, až na to, že mi nenašly televizní kartu a když vložím DVD tak se počítač zasekne.To je jediný důvod, proč mám ještě XP, protože na nich vypaluji a našly televizní kartu.Hry se na nich ale sekají, takže musím každou chvíli resetovat kompa a měnit systém když chci zrovna vypalovat atd. Už mně ten můj komp štve.Vyhodil bych ho z okna.
Pardon, jen sem na vás vyhltil všechny svoje problémy a vztek. :shock: :P

Odpovědět