Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o preventivni kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Squerak
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 07 črc 2010 07:51

Prosim o preventivni kontrolu

#1 Příspěvek od Squerak »

Dobry den, prosim o preventivni kontrolu

RSIT zde:


Logfile of random's system information tool 1.07 (written by random/random)
Run by Martin at 2010-07-07 08:49:23
Microsoft Windows XP Home Edition Service Pack 3
System drive D: has 33 GB (23%) free of 141 GB
Total RAM: 1023 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:49:32, on 7.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\ALCMTR.EXE
D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
D:\Program Files\IObit\IObit Security 360\IS360tray.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Stardock\CursorFX\CursorFX.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
D:\Program Files\IObit\IObit Security 360\IS360srv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\IoctlSvc.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\system32\PnkBstrB.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\alg.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
D:\Program Files\IObit\IObit Security 360\is360.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Martin\Dokumenty\Downloads\RSIT.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://verysafesearch.com/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verysafesearch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://verysafesearch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://verysafesearch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://verysafesearch.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2475029
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://verysafesearch.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://verysafesearch.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=fbpage&s= ... Terms}&f=4
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - D:\Program Files\MyAshampoo\tbMyAs.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - D:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoods.dll
O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - D:\Program Files\MyAshampoo\tbMyAs.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - D:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoodsTlbr.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - D:\Program Files\MyAshampoo\tbMyAs.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IObit Security 360] "D:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorFX] "D:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SmartRAM] "D:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
O4 - HKCU\..\Run: [Advanced SystemCare 3] "D:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 7662749750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7663261625
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CSIScanner - Unknown owner - D:\Program Files\Prevx\prevx.exe (file missing)
O23 - Service: Služba Google Update (gupdate1ca7b4c969b41ee) (gupdate1ca7b4c969b41ee) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: IS360service - IObit - D:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - D:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - D:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - D:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)

--
End of file - 10379 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
D:\WINDOWS\tasks\AWC AutoSweep.job
D:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1247290395.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-1303643608-1177238915-1004Core.job
D:\WINDOWS\tasks\SmartDefrag.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
CescrtHlpr Object - D:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoods.dll [2010-05-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
MyAshampoo Toolbar - D:\Program Files\MyAshampoo\tbMyAs.dll [2009-12-31 2349080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-07-03 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - facemoods Toolbar - D:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoodsTlbr.dll [2010-05-14 163840]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - MyAshampoo Toolbar - D:\Program Files\MyAshampoo\tbMyAs.dll [2009-12-31 2349080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-04-26 14370816]
"Alcmtr"=D:\WINDOWS\ALCMTR.EXE [2005-04-11 65536]
"ISUSPM Startup"=D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"NeroFilterCheck"=D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-02-28 570664]
"NBKeyScan"=D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-02-18 2221352]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-09-25 98304]
"Kernel and Hardware Abstraction Layer"=D:\WINDOWS\KHALMNPR.EXE [2007-09-21 55824]
"IObit Security 360"=D:\Program Files\IObit\IObit Security 360\IS360tray.exe [2010-06-11 1280344]
"SunJavaUpdateSched"=D:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"CursorFX"=D:\Program Files\Stardock\CursorFX\CursorFX.exe [2008-02-05 417528]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
"SmartRAM"=D:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe [2010-07-02 198864]
"Advanced SystemCare 3"=D:\Program Files\IObit\Advanced SystemCare 3\AWC.exe [2010-07-02 2347216]
"Google Update"=D:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-06-14 136176]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
hp psc 1000 series.lnk - D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
hpoddt01.exe.lnk - D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
Logitech SetPoint.lnk - D:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2009-09-24 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2007-11-15 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoResolveSearch"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\WINDOWS\system32\PnkBstrA.exe"="D:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"D:\WINDOWS\system32\PnkBstrB.exe"="D:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Program Files\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe"="D:\Program Files\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-07-07 08:49:23 ----D---- D:\rsit
2010-07-03 17:46:42 ----RA---- D:\WINDOWS\system32\tmp163.tmp
2010-07-03 17:46:42 ----RA---- D:\WINDOWS\system32\tmp162.tmp
2010-07-03 17:45:45 ----D---- D:\Documents and Settings\All Users\Data aplikací\Sun
2010-07-03 17:45:42 ----D---- D:\Program Files\Common Files\Java
2010-07-03 17:45:09 ----A---- D:\WINDOWS\system32\javaws.exe
2010-07-03 17:45:09 ----A---- D:\WINDOWS\system32\javaw.exe
2010-07-03 17:45:09 ----A---- D:\WINDOWS\system32\java.exe
2010-07-03 17:45:09 ----A---- D:\WINDOWS\system32\deployJava1.dll
2010-07-02 16:53:30 ----D---- D:\Documents and Settings\Martin\Data aplikací\Mount&Blade
2010-07-01 17:18:17 ----D---- D:\Program Files\Puzzle Quest Galactrix
2010-06-30 17:03:19 ----D---- D:\Documents and Settings\All Users\Data aplikací\NovaTech Network
2010-06-15 17:13:27 ----D---- D:\Documents and Settings\Martin\Data aplikací\Ashampoo
2010-06-15 17:12:34 ----D---- D:\Program Files\MyAshampoo
2010-06-15 17:12:26 ----D---- D:\Documents and Settings\All Users\Data aplikací\ashampoo
2010-06-15 17:11:53 ----D---- D:\Program Files\Ashampoo
2010-06-15 09:01:33 ----HDC---- D:\WINDOWS\$NtUninstallKB980218$
2010-06-15 07:54:08 ----HDC---- D:\WINDOWS\$NtUninstallKB980195$
2010-06-15 07:52:50 ----HDC---- D:\WINDOWS\$NtUninstallKB979559$
2010-06-15 07:50:34 ----HDC---- D:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-15 07:50:31 ----HDC---- D:\WINDOWS\$NtUninstallKB979482$
2010-06-15 07:50:26 ----HDC---- D:\WINDOWS\$NtUninstallKB975562$
2010-06-13 19:18:41 ----A---- D:\Documents and Settings\Martin\Data aplikací\PnkBstrB.exe
2010-06-13 09:16:55 ----D---- D:\Program Files\RegCleaner
2010-06-11 16:17:48 ----D---- D:\WINDOWS\system32\NtmsData
2010-06-10 20:11:21 ----D---- D:\Program Files\Mozilla Firefox
2010-06-10 20:11:20 ----D---- D:\Program Files\facemoods.com

======List of files/folders modified in the last 1 months======

2010-07-07 08:49:32 ----D---- D:\Program Files\Trend Micro
2010-07-07 08:49:21 ----D---- D:\WINDOWS\Prefetch
2010-07-07 08:40:06 ----D---- D:\WINDOWS\Temp
2010-07-07 08:40:06 ----D---- D:\WINDOWS
2010-07-07 07:25:18 ----D---- D:\Program Files\WoW Wotlk
2010-07-07 07:20:33 ----D---- D:\WINDOWS\system32\Lang
2010-07-06 21:08:42 ----A---- D:\WINDOWS\system32\PnkBstrB.exe
2010-07-06 19:25:30 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-07-03 17:46:42 ----D---- D:\WINDOWS\system32
2010-07-03 17:46:42 ----A---- D:\WINDOWS\system32\wrap_oal.dll
2010-07-03 17:46:42 ----A---- D:\WINDOWS\system32\OpenAL32.dll
2010-07-03 17:46:36 ----HD---- D:\WINDOWS\inf
2010-07-03 17:46:07 ----RSD---- D:\WINDOWS\assembly
2010-07-03 17:45:43 ----SHD---- D:\Config.Msi
2010-07-03 17:45:42 ----SHD---- D:\WINDOWS\Installer
2010-07-03 17:45:42 ----D---- D:\Program Files\Common Files
2010-07-03 17:45:36 ----D---- D:\WINDOWS\system32\CatRoot2
2010-07-03 17:44:41 ----D---- D:\WINDOWS\system32\DirectX
2010-07-03 17:42:09 ----HD---- D:\Program Files\InstallShield Installation Information
2010-07-03 17:42:09 ----D---- D:\Program Files\Paradox Interactive
2010-07-03 17:37:27 ----D---- D:\Program Files
2010-06-30 17:46:36 ----A---- D:\WINDOWS\AviSplitter.INI
2010-06-28 15:13:36 ----D---- D:\WINDOWS\Microsoft.NET
2010-06-27 10:50:29 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-06-27 10:50:11 ----D---- D:\WINDOWS\WinSxS
2010-06-24 15:23:02 ----D---- D:\Program Files\ICQ6.5
2010-06-24 15:22:29 ----D---- D:\Documents and Settings\Martin\Data aplikací\ICQ
2010-06-24 14:46:13 ----A---- D:\WINDOWS\NeroDigital.ini
2010-06-23 12:11:35 ----D---- D:\Program Files\Mozilla Firefox 3.6 Beta 1
2010-06-19 20:18:35 ----D---- D:\Documents and Settings\Martin\Data aplikací\Nero
2010-06-19 20:07:13 ----D---- D:\Program Files\Common Files\Nero
2010-06-19 20:06:52 ----D---- D:\Program Files\Nero
2010-06-19 20:06:29 ----D---- D:\Documents and Settings\All Users\Data aplikací\Nero
2010-06-15 09:01:35 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-06-15 07:54:13 ----A---- D:\WINDOWS\imsins.BAK
2010-06-15 07:54:07 ----HD---- D:\WINDOWS\$hf_mig$
2010-06-15 07:50:15 ----D---- D:\WINDOWS\system32\cs-cz
2010-06-15 07:50:15 ----D---- D:\Program Files\Internet Explorer
2010-06-14 16:09:20 ----SD---- D:\WINDOWS\Tasks
2010-06-13 19:02:00 ----D---- D:\Program Files\GamePark
2010-06-13 08:56:29 ----D---- D:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-06-13 08:55:52 ----D---- D:\WINDOWS\system32\drivers
2010-06-13 08:48:39 ----D---- D:\WINDOWS\system32\CatRoot
2010-06-13 08:48:25 ----D---- D:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2010-06-12 09:14:38 ----D---- D:\WINDOWS\ie7updates
2010-06-11 17:26:34 ----D---- D:\Program Files\Hry
2010-06-11 17:26:05 ----D---- D:\Program Files\Hry k vypaleni ;)
2010-06-11 17:10:31 ----D---- D:\WINDOWS\system32\config

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; D:\WINDOWS\system32\drivers\AFS2K.sys [2009-07-11 82380]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 prodrv06;StarForce Protection Environment Driver v6; D:\WINDOWS\System32\drivers\prodrv06.sys [2004-11-25 54368]
R2 atksgt;atksgt; D:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-04-09 278984]
R2 lirsgt;lirsgt; D:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-04-09 25416]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-09-24 4481024]
R3 hamachi;Hamachi Network Interface; D:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-04-27 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-04-25 2937344]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; D:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-09-21 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; D:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-09-21 35088]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; D:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-09-21 36240]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; D:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2007-09-21 28432]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; D:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2010-02-15 304928]
S3 a1qudaw1;a1qudaw1; D:\WINDOWS\system32\drivers\a1qudaw1.sys []
S3 axneh7vw;axneh7vw; D:\WINDOWS\system32\drivers\axneh7vw.sys []
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 cpuz132;cpuz132; \??\D:\DOCUME~1\Martin\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\Program Files\MediaCoder\SysInfo.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; D:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; D:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; D:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 lgusbsmodem;LGE Mobile USB Modem; D:\WINDOWS\system32\DRIVERS\lgusbsmodem.sys [2007-07-09 23680]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Ovladač programu Sledování sítě; D:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 PnkBstrK;PnkBstrK; \??\D:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2009-09-24 602112]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; D:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 IS360service;IS360service; D:\Program Files\IObit\IObit Security 360\IS360srv.exe [2010-06-11 312152]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2010-07-03 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-02-18 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; D:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; D:\WINDOWS\system32\PnkBstrA.exe [2009-10-30 75064]
R2 PnkBstrB;PnkBstrB; D:\WINDOWS\system32\PnkBstrB.exe [2010-07-06 214520]
R3 NMIndexingService;NMIndexingService; D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2009-09-25 593920]
S2 CSIScanner;CSIScanner; D:\Program Files\Prevx\prevx.exe /service []
S2 gupdate1ca7b4c969b41ee;Služba Google Update (gupdate1ca7b4c969b41ee); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-12 133104]
S2 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe []
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; D:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2007-11-15 121360]
S3 Pml Driver HPZ12;Pml Driver HPZ12; D:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119409
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o preventivni kontrolu

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Squerak
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 07 črc 2010 07:51

Re: Prosim o preventivni kontrolu

#3 Příspěvek od Squerak »

ComboFix 10-07-07.01 - Martin 08.07.2010 9:09.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.641 [GMT 2:00]
Spuštěný z: d:\documents and settings\Martin\Dokumenty\Downloads\ComboFix.exe
.
Tyto soubory byly během aplikování deaktivovány:
d:\program files\IObit\IObit Security 360\IS360mon.dll


((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\program files\FlashGet Network
d:\program files\FlashGet Network\FlashGet universal\fgoption.ini
d:\program files\FlashGet Network\FlashGet universal\P2PCfg.ini
d:\program files\FlashGet Network\FlashGet universal\p2spmgr.ini
d:\program files\FlashGet Network\FlashGet universal\p4spmgr.ini
d:\program files\FlashGet Network\FlashGet universal\Profiles\config.dat
d:\program files\FlashGet Network\FlashGet universal\Profiles\tasks.dat
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\components\FFHst.dll
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\components\FFHst.xpt
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\facemoods.css
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\facemoods.png
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\facemoods.xul
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\fcmdDef.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\facemoods.png
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\fb.gif
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\help_16.gif
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\home.gif
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\logo.png
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\moodsIcon.png
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\pref.jpg
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\privecy_16_hot.gif
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\stripicons.png
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\tellafriend.gif
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\Thumbs.db
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images\vssver.scc
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\instlgc.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\Loader.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\mtrprt.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\newTabLgc.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences\preferences.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences\preferences.xul
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences\vssver.scc
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\prefman.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\script-compiler.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\Thumbs.db
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\utils.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\vssver.scc
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\xmlhttprequester.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\xpiInstallLgc.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\defaults\preferences\instlPref.js
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\defaults\preferences\vssver.scc
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\chrome.manifest
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\install.rdf
d:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\vssver.scc
d:\windows\system32\tmp3.tmp

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-08 do 2010-07-08 )))))))))))))))))))))))))))))))
.

2010-07-07 06:49 . 2010-07-07 06:49 -------- d-----w- D:\rsit
2010-07-03 15:45 . 2010-07-03 15:45 -------- d-----w- d:\program files\Common Files\Java
2010-07-03 15:45 . 2010-07-03 15:44 411368 ----a-w- d:\windows\system32\deployJava1.dll
2010-07-01 15:18 . 2010-07-01 15:18 -------- d-----w- d:\program files\Puzzle Quest Galactrix
2010-06-15 15:12 . 2010-06-15 15:12 -------- d-----w- d:\program files\MyAshampoo
2010-06-15 15:11 . 2010-06-15 15:11 -------- d-----w- d:\program files\Ashampoo
2010-06-13 07:16 . 2010-06-13 07:24 -------- d-----w- d:\program files\RegCleaner
2010-06-11 14:17 . 2010-06-11 14:18 -------- d-----w- d:\windows\system32\NtmsData

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-07 17:28 . 2009-08-02 14:25 137464 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2010-07-07 17:28 . 2009-08-02 14:25 214520 ----a-w- d:\windows\system32\PnkBstrB.exe
2010-07-07 16:32 . 2010-04-17 07:34 -------- d-----w- d:\program files\Hry
2010-07-07 14:18 . 2009-07-15 13:46 -------- d-----w- d:\program files\WoW Wotlk
2010-07-07 06:49 . 2009-10-24 05:00 -------- d-----w- d:\program files\Trend Micro
2010-07-03 15:46 . 2009-07-11 08:07 444952 ----a-w- d:\windows\system32\wrap_oal.dll
2010-07-03 15:46 . 2009-07-11 08:07 109080 ----a-w- d:\windows\system32\OpenAL32.dll
2010-07-03 15:42 . 2009-09-18 09:58 -------- d-----w- d:\program files\Paradox Interactive
2010-07-03 15:42 . 2009-07-07 13:44 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-06-27 08:50 . 2008-04-14 12:00 82642 ----a-w- d:\windows\system32\perfc005.dat
2010-06-27 08:50 . 2008-04-14 12:00 437336 ----a-w- d:\windows\system32\perfh005.dat
2010-06-24 13:23 . 2009-07-15 12:59 -------- d-----w- d:\program files\ICQ6.5
2010-06-23 10:11 . 2010-02-20 17:54 -------- d-----w- d:\program files\Mozilla Firefox 3.6 Beta 1
2010-06-19 18:07 . 2009-08-24 13:57 -------- d-----w- d:\program files\Common Files\Nero
2010-06-19 18:06 . 2009-08-24 13:57 -------- d-----w- d:\program files\Nero
2010-06-13 17:02 . 2009-08-02 13:57 -------- d-----w- d:\program files\GamePark
2010-06-11 15:26 . 2009-10-30 06:07 -------- d-----w- d:\program files\Hry k vypaleni ;)
2010-06-05 07:50 . 2010-06-05 07:50 -------- d-----w- d:\program files\DIFX
2010-06-05 07:50 . 2009-07-11 15:18 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2010-06-05 07:50 . 2009-11-01 10:02 -------- d-----w- d:\program files\AGEIA Technologies
2010-06-05 07:26 . 2009-10-29 15:26 -------- d-----w- d:\program files\2K Games
2010-06-03 13:46 . 2010-06-03 13:35 -------- d-----w- d:\program files\Fox
2010-06-03 13:45 . 2009-08-05 11:13 21840 ----atw- d:\windows\system32\SIntfNT.dll
2010-06-03 13:45 . 2009-08-05 11:13 17212 ----atw- d:\windows\system32\SIntf32.dll
2010-06-03 13:45 . 2009-08-05 11:13 12067 ----atw- d:\windows\system32\SIntf16.dll
2010-05-31 16:19 . 2010-05-31 16:19 -------- d-----w- d:\program files\Playlogic
2010-05-30 07:34 . 2009-11-29 16:21 -------- d-----w- d:\program files\IObit
2010-05-24 16:34 . 2010-02-28 13:13 -------- d-----w- d:\program files\Warcraft III
2010-05-22 17:36 . 2010-05-22 17:36 -------- d-----w- d:\program files\Cenega Czech
2010-05-22 17:02 . 2010-05-22 16:50 -------- d-----w- d:\program files\Black Isle
2010-05-19 12:05 . 2009-10-20 14:41 -------- d-----w- d:\program files\WMV9_VCM
2010-05-18 13:33 . 2010-02-28 13:18 210167 ----a-w- d:\windows\War3Unin.dat
2010-05-16 16:41 . 2010-05-16 16:41 -------- d-----w- d:\program files\KYE
2010-05-16 16:41 . 2010-05-16 16:41 -------- d-----w- d:\program files\Common Files\snpstd
2010-05-16 16:28 . 2010-05-16 16:28 -------- d-----w- d:\program files\Driver-Soft
2010-05-16 16:15 . 2010-05-16 16:15 -------- d-----w- d:\program files\PC Drivers HeadQuarters
2010-05-15 18:07 . 2009-08-02 11:14 -------- d-----w- d:\program files\Opera
2010-05-12 12:16 . 2010-05-12 12:04 -------- d-----w- d:\program files\Valve
2010-05-04 17:18 . 2008-04-14 12:00 832512 ----a-w- d:\windows\system32\wininet.dll
2010-05-04 17:18 . 2008-04-14 12:00 78336 ----a-w- d:\windows\system32\ieencode.dll
2010-05-04 17:18 . 2008-04-14 12:00 17408 ----a-w- d:\windows\system32\corpol.dll
2010-05-02 08:09 . 2008-04-14 12:00 1851264 ----a-w- d:\windows\system32\win32k.sys
2010-04-27 14:53 . 2010-04-02 05:36 25280 ----a-w- d:\windows\system32\drivers\hamachi.sys
2010-04-20 05:32 . 2008-04-14 12:00 285696 ----a-w- d:\windows\system32\atmfd.dll
2010-04-09 16:28 . 2010-04-09 16:28 278984 ----a-w- d:\windows\system32\drivers\atksgt.sys
2010-04-09 16:28 . 2010-04-09 16:28 25416 ----a-w- d:\windows\system32\drivers\lirsgt.sys
2008-10-10 03:22 . 2008-10-10 03:22 193552 ----a-w- d:\program files\text.xml.bin
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "d:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]

[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2009-12-31 09:53 2349080 ----a-w- d:\program files\MyAshampoo\tbMyAs.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "d:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]

[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "d:\program files\IObitCom\tbIOb1.dll" [2010-02-25 2349080]

[HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorFX"="d:\program files\Stardock\CursorFX\CursorFX.exe" [2008-02-05 417528]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"SmartRAM"="d:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" [2010-07-02 198864]
"Advanced SystemCare 3"="d:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]
"Google Update"="d:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-06-14 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-26 14370816]
"ISUSPM Startup"="d:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="d:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"IObit Security 360"="d:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

d:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp psc 1000 series.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Logitech SetPoint.lnk - d:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-25 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 09:10 72208 ----a-w- d:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"d:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"d:\\Program Files\\ICQ6.5\\ICQ.exe"=

R0 pxscan;pxscan;d:\windows\system32\drivers\pxscan.sys [25.10.2009 17:09 22024]
R0 pxsec;pxsec;d:\windows\system32\drivers\pxsec.sys [25.10.2009 17:09 27656]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 11:16 1107336]
R2 IS360service;IS360service;d:\program files\IObit\IObit Security 360\is360srv.exe [22.6.2010 11:38 312152]
S2 CSIScanner;CSIScanner;"d:\program files\Prevx\prevx.exe" /service --> d:\program files\Prevx\prevx.exe [?]
S2 gupdate1ca7b4c969b41ee;Služba Google Update (gupdate1ca7b4c969b41ee);d:\program files\Google\Update\GoogleUpdate.exe [12.12.2009 19:00 133104]
S3 lgusbsmodem;LGE Mobile USB Modem;d:\windows\system32\drivers\lgusbsmodem.sys [30.12.2009 14:41 23680]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [29.10.2009 11:36 691696]
.
Obsah adresáře 'Naplánované úlohy'

2010-07-08 d:\windows\Tasks\AWC AutoSweep.job
- d:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-04-10 12:11]

2009-10-24 d:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8247290395.job
- d:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]

2010-07-08 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-12-12 16:59]

2010-07-07 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-12-12 16:59]

2010-05-09 d:\windows\Tasks\SmartDefrag.job
- d:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-05-09 14:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uDefault_Search_URL = hxxp://verysafesearch.com/
uSearchAssistant = hxxp://verysafesearch.com/
uCustomizeSearch = hxxp://verysafesearch.com/
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - (no file)
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-08 09:15
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-507921405-1303643608-1177238915-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:10,25,b2,02,80,8b,8a,83,50,e6,89,4f,8d,7d,75,31,6c,e6,02,57,1b,06,51,
6f,a4,99,1b,6d,2a,6c,8b,06,9b,eb,6b,b7,00,9f,78,13,ff,56,c1,9c,01,af,f9,d9,\
"??"=hex:cb,3d,37,89,42,b8,6a,49,3e,58,0d,13,00,eb,09,42
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(840)
d:\windows\system32\Ati2evxx.dll
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Celkový čas: 2010-07-08 09:18:14
ComboFix-quarantined-files.txt 2010-07-08 07:17

Před spuštěním: Volných bajtů: 36 602 318 848
Po spuštění: Volných bajtů: 36 646 817 792

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - CB14AD2FF214B0192589190BEB1D29E3

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119409
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o preventivni kontrolu

#4 Příspěvek od Rudy »

Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
D:\WINDOWS\system32\tmp163.tmp
D:\WINDOWS\system32\tmp162.tmp
Uložte na plochu jako CFScript.txt. pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Squerak
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 07 črc 2010 07:51

Re: Prosim o preventivni kontrolu

#5 Příspěvek od Squerak »

ComboFix 10-07-07.02 - Martin 09.07.2010 9:14.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.643 [GMT 2:00]
Spuštěný z: d:\documents and settings\Martin\Plocha\ComboFix.exe
Použité ovládací přepínače :: d:\documents and settings\Martin\Plocha\CFScript.txt
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-06-09 do 2010-07-09 )))))))))))))))))))))))))))))))
.

2010-07-07 06:49 . 2010-07-07 06:49 -------- d-----w- D:\rsit
2010-07-03 15:45 . 2010-07-03 15:45 -------- d-----w- d:\program files\Common Files\Java
2010-07-03 15:45 . 2010-07-03 15:44 411368 ----a-w- d:\windows\system32\deployJava1.dll
2010-07-01 15:18 . 2010-07-01 15:18 -------- d-----w- d:\program files\Puzzle Quest Galactrix
2010-06-15 15:12 . 2010-06-15 15:12 -------- d-----w- d:\program files\MyAshampoo
2010-06-15 15:11 . 2010-06-15 15:11 -------- d-----w- d:\program files\Ashampoo
2010-06-13 07:16 . 2010-06-13 07:24 -------- d-----w- d:\program files\RegCleaner
2010-06-11 14:17 . 2010-06-11 14:18 -------- d-----w- d:\windows\system32\NtmsData

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-08 17:08 . 2009-08-02 14:25 137464 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2010-07-08 17:08 . 2009-08-02 14:25 214520 ----a-w- d:\windows\system32\PnkBstrB.exe
2010-07-07 16:32 . 2010-04-17 07:34 -------- d-----w- d:\program files\Hry
2010-07-07 14:18 . 2009-07-15 13:46 -------- d-----w- d:\program files\WoW Wotlk
2010-07-07 06:49 . 2009-10-24 05:00 -------- d-----w- d:\program files\Trend Micro
2010-07-03 15:46 . 2009-07-11 08:07 444952 ----a-w- d:\windows\system32\wrap_oal.dll
2010-07-03 15:46 . 2009-07-11 08:07 109080 ----a-w- d:\windows\system32\OpenAL32.dll
2010-07-03 15:42 . 2009-09-18 09:58 -------- d-----w- d:\program files\Paradox Interactive
2010-07-03 15:42 . 2009-07-07 13:44 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-06-27 08:50 . 2008-04-14 12:00 82642 ----a-w- d:\windows\system32\perfc005.dat
2010-06-27 08:50 . 2008-04-14 12:00 437336 ----a-w- d:\windows\system32\perfh005.dat
2010-06-24 13:23 . 2009-07-15 12:59 -------- d-----w- d:\program files\ICQ6.5
2010-06-23 10:11 . 2010-02-20 17:54 -------- d-----w- d:\program files\Mozilla Firefox 3.6 Beta 1
2010-06-19 18:07 . 2009-08-24 13:57 -------- d-----w- d:\program files\Common Files\Nero
2010-06-19 18:06 . 2009-08-24 13:57 -------- d-----w- d:\program files\Nero
2010-06-13 17:02 . 2009-08-02 13:57 -------- d-----w- d:\program files\GamePark
2010-06-11 15:26 . 2009-10-30 06:07 -------- d-----w- d:\program files\Hry k vypaleni ;)
2010-06-05 07:50 . 2010-06-05 07:50 -------- d-----w- d:\program files\DIFX
2010-06-05 07:50 . 2009-07-11 15:18 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2010-06-05 07:50 . 2009-11-01 10:02 -------- d-----w- d:\program files\AGEIA Technologies
2010-06-05 07:26 . 2009-10-29 15:26 -------- d-----w- d:\program files\2K Games
2010-06-03 13:46 . 2010-06-03 13:35 -------- d-----w- d:\program files\Fox
2010-06-03 13:45 . 2009-08-05 11:13 21840 ----atw- d:\windows\system32\SIntfNT.dll
2010-06-03 13:45 . 2009-08-05 11:13 17212 ----atw- d:\windows\system32\SIntf32.dll
2010-06-03 13:45 . 2009-08-05 11:13 12067 ----atw- d:\windows\system32\SIntf16.dll
2010-05-31 16:19 . 2010-05-31 16:19 -------- d-----w- d:\program files\Playlogic
2010-05-30 07:34 . 2009-11-29 16:21 -------- d-----w- d:\program files\IObit
2010-05-24 16:34 . 2010-02-28 13:13 -------- d-----w- d:\program files\Warcraft III
2010-05-22 17:36 . 2010-05-22 17:36 -------- d-----w- d:\program files\Cenega Czech
2010-05-22 17:02 . 2010-05-22 16:50 -------- d-----w- d:\program files\Black Isle
2010-05-19 12:05 . 2009-10-20 14:41 -------- d-----w- d:\program files\WMV9_VCM
2010-05-18 13:33 . 2010-02-28 13:18 210167 ----a-w- d:\windows\War3Unin.dat
2010-05-16 16:41 . 2010-05-16 16:41 -------- d-----w- d:\program files\KYE
2010-05-16 16:41 . 2010-05-16 16:41 -------- d-----w- d:\program files\Common Files\snpstd
2010-05-16 16:28 . 2010-05-16 16:28 -------- d-----w- d:\program files\Driver-Soft
2010-05-16 16:15 . 2010-05-16 16:15 -------- d-----w- d:\program files\PC Drivers HeadQuarters
2010-05-15 18:07 . 2009-08-02 11:14 -------- d-----w- d:\program files\Opera
2010-05-12 12:16 . 2010-05-12 12:04 -------- d-----w- d:\program files\Valve
2010-05-04 17:18 . 2008-04-14 12:00 832512 ----a-w- d:\windows\system32\wininet.dll
2010-05-04 17:18 . 2008-04-14 12:00 78336 ----a-w- d:\windows\system32\ieencode.dll
2010-05-04 17:18 . 2008-04-14 12:00 17408 ----a-w- d:\windows\system32\corpol.dll
2010-05-02 08:09 . 2008-04-14 12:00 1851264 ----a-w- d:\windows\system32\win32k.sys
2010-04-27 14:53 . 2010-04-02 05:36 25280 ----a-w- d:\windows\system32\drivers\hamachi.sys
2010-04-20 05:32 . 2008-04-14 12:00 285696 ----a-w- d:\windows\system32\atmfd.dll
2008-10-10 03:22 . 2008-10-10 03:22 193552 ----a-w- d:\program files\text.xml.bin
.

((((((((((((((((((((((((((((( SnapShot@2010-07-08_07.15.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-09 06:59 . 2010-07-09 06:59 16384 d:\windows\Temp\Perflib_Perfdata_6a4.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "d:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]

[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2009-12-31 09:53 2349080 ----a-w- d:\program files\MyAshampoo\tbMyAs.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "d:\program files\MyAshampoo\tbMyAs.dll" [2009-12-31 2349080]

[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "d:\program files\IObitCom\tbIOb1.dll" [2010-02-25 2349080]

[HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorFX"="d:\program files\Stardock\CursorFX\CursorFX.exe" [2008-02-05 417528]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"SmartRAM"="d:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" [2010-07-02 198864]
"Advanced SystemCare 3"="d:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-07-02 2347216]
"Google Update"="d:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-06-14 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-26 14370816]
"ISUSPM Startup"="d:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="d:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"IObit Security 360"="d:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

d:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp psc 1000 series.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Logitech SetPoint.lnk - d:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-25 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 09:10 72208 ----a-w- d:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"d:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"d:\\Program Files\\ICQ6.5\\ICQ.exe"=

R0 pxscan;pxscan;d:\windows\system32\drivers\pxscan.sys [25.10.2009 17:09 22024]
R0 pxsec;pxsec;d:\windows\system32\drivers\pxsec.sys [25.10.2009 17:09 27656]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 11:16 1107336]
R2 IS360service;IS360service;d:\program files\IObit\IObit Security 360\is360srv.exe [22.6.2010 11:38 312152]
S2 CSIScanner;CSIScanner;"d:\program files\Prevx\prevx.exe" /service --> d:\program files\Prevx\prevx.exe [?]
S2 gupdate1ca7b4c969b41ee;Služba Google Update (gupdate1ca7b4c969b41ee);d:\program files\Google\Update\GoogleUpdate.exe [12.12.2009 19:00 133104]
S3 lgusbsmodem;LGE Mobile USB Modem;d:\windows\system32\drivers\lgusbsmodem.sys [30.12.2009 14:41 23680]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [29.10.2009 11:36 691696]
.
Obsah adresáře 'Naplánované úlohy'

2010-07-09 d:\windows\Tasks\AWC AutoSweep.job
- d:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-04-10 12:11]

2009-10-24 d:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8247290395.job
- d:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]

2010-07-09 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-12-12 16:59]

2010-07-08 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-12-12 16:59]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uDefault_Search_URL = hxxp://verysafesearch.com/
uSearchAssistant = hxxp://verysafesearch.com/
uCustomizeSearch = hxxp://verysafesearch.com/
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-09 09:22
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-507921405-1303643608-1177238915-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:10,25,b2,02,80,8b,8a,83,50,e6,89,4f,8d,7d,75,31,6c,e6,02,57,1b,06,51,
6f,a4,99,1b,6d,2a,6c,8b,06,9b,eb,6b,b7,00,9f,78,13,ff,56,c1,9c,01,af,f9,d9,\
"??"=hex:cb,3d,37,89,42,b8,6a,49,3e,58,0d,13,00,eb,09,42
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(840)
d:\windows\system32\Ati2evxx.dll
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

- - - - - - - > 'explorer.exe'(488)
d:\program files\Logitech\SetPoint\GameHook.dll
d:\program files\Logitech\SetPoint\lgscroll.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-07-09 09:24:03
ComboFix-quarantined-files.txt 2010-07-09 07:24
ComboFix2.txt 2010-07-08 07:18

Před spuštěním: Volných bajtů: 36 366 024 704
Po spuštění: Volných bajtů: 36 352 733 184

- - End Of File - - 9E200BDD1606A32EEA885EA46038E72C

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119409
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o preventivni kontrolu

#6 Příspěvek od Rudy »

Log již vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Squerak
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 07 črc 2010 07:51

Re: Prosim o preventivni kontrolu

#7 Příspěvek od Squerak »

dekuji

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119409
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o preventivni kontrolu

#8 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět