Prosím o kontrolu logu RSIT

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Prosím o kontrolu logu RSIT

#16 Příspěvek od motji »

Jakou máte grafickou kartu? Nemůžete ji odzkoušet v jiném pc, třeba je chyba v ní :o


:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

gazebo
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 Kvě 2007 07:00

Re: Prosím o kontrolu logu RSIT

#17 Příspěvek od gazebo »

Spatna by teoreticky byt nemela ... mam ji tusim 2 roky a jedna se o Gigabyte Radeon 9250.
A taky ono vse zacalo az po nove instalaci systemu. Odesel mi HDD, koupil jsem tedy novy
a instaloval system a vsechny drivery i ke GK a presto to nekdy zazlobi. Na starem HDD bylo
vse ok.
gaz

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Prosím o kontrolu logu RSIT

#18 Příspěvek od motji »

Udělejte ten combofix a uvidíme.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

gazebo
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 Kvě 2007 07:00

Re: Prosím o kontrolu logu RSIT

#19 Příspěvek od gazebo »

ComboFix 10-08-07.02 - Petr 08.08.2010 21:57:00.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1017 [GMT 2:00]
Spuštěný z: c:\staženo\ComboFix.exe
AV: Panda Cloud Antivirus *On-access scanning enabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Data

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-08 do 2010-08-08 )))))))))))))))))))))))))))))))
.

2010-08-08 19:05 . 2010-08-08 19:05 -------- d-----w- c:\program files\FLVPlayer
2010-08-07 18:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-07 18:06 . 2010-08-07 18:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 18:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 12:09 . 2010-07-30 12:34 -------- d-----w- C:\ubuntu
2010-07-30 11:10 . 2010-07-30 11:10 -------- d-----w- c:\program files\trend micro
2010-07-30 08:55 . 2010-07-30 08:55 -------- d-----w- c:\windows\Sun
2010-07-29 15:19 . 2010-07-29 15:19 55300 ---ha-w- c:\windows\system32\mlfcache.dat
2010-07-29 10:57 . 2010-07-29 10:57 -------- d-----w- c:\program files\QIP 2010
2010-07-29 10:45 . 2010-07-29 10:45 -------- d-----w- c:\program files\Safari
2010-07-29 10:45 . 2010-07-29 10:45 -------- d-----w- c:\program files\Bonjour
2010-07-29 10:44 . 2010-07-29 10:44 -------- d-----w- c:\program files\Common Files\Apple
2010-07-29 10:44 . 2010-07-29 10:44 -------- d-----w- c:\program files\Apple Software Update
2010-07-29 08:40 . 2010-07-29 08:40 -------- d-----w- c:\program files\Free WMA to MP3 Converter
2010-07-28 22:18 . 2010-07-28 22:18 -------- d-----w- c:\program files\Yamicsoft
2010-07-28 14:01 . 2010-07-28 22:13 -------- d-----w- c:\program files\COMODO
2010-07-28 13:51 . 2010-07-28 13:51 264 ----a-w- c:\windows\system32\PSUNCpl.dat
2010-07-28 13:50 . 2010-07-28 13:50 -------- d-----w- c:\program files\Panda Security
2010-07-28 09:19 . 2010-07-28 09:23 -------- d-----w- c:\program files\Cyklotrasy
2010-07-28 05:53 . 2010-07-28 13:29 -------- d-----w- c:\program files\Nexus Radio
2010-07-28 05:53 . 2010-07-28 05:53 -------- d-----w- C:\My Plugins
2010-07-28 05:53 . 2010-07-28 05:53 -------- d-----w- C:\My Saved Files
2010-07-28 05:53 . 2010-07-28 05:53 -------- d-----w- C:\My Recorded Files
2010-07-28 05:47 . 2010-07-28 05:47 -------- d-----w- c:\program files\RarmaRadio
2010-07-27 14:33 . 2010-07-27 14:33 -------- d-----w- c:\program files\GuerillaSoft
2010-07-27 14:25 . 2010-07-27 14:25 -------- d--h--w- c:\program files\InstallJammer Registry
2010-07-27 14:24 . 2010-07-27 14:24 -------- d-----w- c:\program files\Esmska
2010-07-27 06:33 . 2010-07-27 06:33 -------- d-----w- c:\program files\365dni
2010-07-27 06:18 . 2010-07-27 06:20 -------- d-----w- c:\program files\Readon Technology
2010-07-27 05:29 . 2010-07-27 05:29 -------- d-----w- c:\program files\Ashampoo
2010-07-27 05:20 . 2010-07-27 05:20 -------- d-----w- c:\program files\FLAC
2010-07-26 13:42 . 2010-07-26 13:50 -------- d-----w- c:\program files\Folder Marker
2010-07-26 07:44 . 2010-07-26 07:44 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-07-25 23:15 . 2010-07-25 23:18 -------- d-----w- c:\program files\Translator
2010-07-25 22:17 . 2010-07-25 22:17 -------- d-----w- c:\documents and settings\Petr\Data aplikac?
2010-07-25 18:41 . 2010-07-25 18:41 -------- d-----w- c:\program files\DVD Shrink
2010-07-25 00:25 . 2010-07-25 00:25 -------- d-----w- c:\program files\QuickTime
2010-07-24 23:10 . 2010-07-24 23:10 -------- d-----w- c:\windows\system32\URTTEMP
2010-07-24 23:09 . 2006-04-28 20:05 127614 ----a-w- c:\windows\system32\atiicdxx.dat
2010-07-24 22:32 . 2010-08-08 06:26 -------- d-----w- c:\program files\IDOS
2010-07-24 22:04 . 2009-02-13 10:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
2010-07-24 22:03 . 2010-07-24 22:03 -------- d-----w- c:\program files\Western Digital
2010-07-24 21:45 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-07-24 21:38 . 2010-07-24 21:44 -------- d-----w- c:\windows\system32\XPSViewer
2010-07-24 21:37 . 2010-07-24 21:37 -------- d-----w- c:\program files\Reference Assemblies
2010-07-24 21:37 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-07-24 21:36 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-07-24 21:36 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-07-24 21:36 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-07-24 21:36 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-07-24 21:36 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-07-24 21:36 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-07-24 21:36 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-07-24 21:36 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-07-24 21:36 . 2010-07-24 21:37 -------- d-----w- C:\970dfc9078ce5a25c33f5cd05ed52d65
2010-07-24 21:28 . 2010-07-24 21:28 -------- d-----w- C:\ATI
2010-07-24 21:11 . 2010-07-24 21:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\DCoder Image Source
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\7-Zip
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\FFMPEG Core Files
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\SHOUTcast Source
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\MONOGRAM AMR SplitterDecoder
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\CD Audio Reader Filter
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\OpenSource AVI Splitter
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\Gabest MPEG Splitter
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\OpenSource DTSAC3DD+ Source Filter
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\RealMedia
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\DScaler5
2010-07-24 20:52 . 2010-07-24 20:52 -------- d-----w- c:\program files\AC3Filter
2010-07-24 20:51 . 2010-07-24 20:51 -------- d-----w- c:\program files\OpenSource Flash Video Splitter
2010-07-24 20:51 . 2010-07-24 20:51 -------- d-----w- c:\program files\DirectVobSub
2010-07-24 20:51 . 2010-07-24 20:51 -------- d-----w- c:\program files\Bass Audio Decoder
2010-07-24 20:51 . 2010-07-24 20:51 -------- d-----w- c:\program files\ffdshow
2010-07-24 20:51 . 2010-07-24 20:53 -------- d-----w- c:\program files\Zoom Player
2010-07-24 20:42 . 2010-07-24 20:42 -------- d-----w- c:\program files\Microsoft.NET
2010-07-24 20:27 . 2010-07-24 22:04 -------- dc----w- c:\windows\system32\DRVSTORE
2010-07-24 08:21 . 2010-07-24 08:22 -------- d-----w- c:\program files\Kodek CZ
2010-07-24 08:15 . 2010-07-24 08:15 737280 ----a-w- c:\windows\iun6002.exe
2010-07-24 08:15 . 2010-07-24 08:15 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-07-24 07:47 . 1999-10-11 01:00 41984 ------w- c:\windows\Ctregrun.exe
2010-07-24 07:30 . 2006-05-03 09:57 520192 ------w- c:\windows\system32\ati2sgag.exe
2010-07-24 07:30 . 2006-05-03 16:54 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-07-24 07:25 . 2010-07-26 09:01 -------- d-----w- c:\program files\ATI Technologies
2010-07-24 07:24 . 2004-05-02 08:47 23040 ----a-r- c:\windows\system32\drivers\GVCplDrv.sys
2010-07-24 07:23 . 2010-07-24 07:23 -------- d-----w- c:\program files\MediaKey
2010-07-24 07:21 . 2010-07-24 07:21 -------- d-----w- c:\program files\HD Tune
2010-07-24 07:06 . 2010-07-29 10:56 -------- d-----w- c:\program files\QIP Infium
2010-07-24 07:00 . 2010-07-24 07:00 -------- d-----w- c:\program files\Common Files\Java
2010-07-24 06:59 . 2010-07-24 06:59 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-24 06:59 . 2010-07-24 06:59 -------- d-----w- c:\program files\Java
2010-07-24 06:57 . 2010-07-25 23:21 -------- d-----w- C:\BOX
2010-07-24 06:50 . 2010-07-24 06:50 -------- d--h--w- c:\windows\Icons
2010-07-24 06:47 . 2010-07-24 06:47 2331776 ----a-w- c:\windows\system32\TUKernel.exe
2010-07-24 06:35 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-07-24 06:35 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-07-24 06:35 . 2010-07-24 06:35 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-07-24 06:33 . 2010-08-07 23:05 -------- d-----w- c:\program files\CCleaner
2010-07-24 06:29 . 2010-07-24 06:29 -------- d-----w- c:\program files\VideoLAN
2010-07-24 06:27 . 2010-07-24 06:27 -------- d-----w- c:\program files\uTorrent
2010-07-24 06:15 . 2010-07-24 06:20 -------- d-----w- c:\program files\Photo Art Studio
2010-07-24 06:13 . 2010-07-24 06:13 -------- d-sh--w- c:\documents and settings\Petr\PrivacIE
2010-07-24 06:12 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-07-24 06:12 . 2010-06-08 16:10 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-07-24 06:12 . 2010-06-08 16:10 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-07-24 06:12 . 2010-03-10 19:29 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-07-24 06:12 . 2009-11-03 17:34 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-07-24 06:12 . 2010-07-24 09:11 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-07-24 06:08 . 2010-07-24 06:08 -------- d-----w- c:\program files\Free Desktop Clock
2010-07-24 06:05 . 2010-07-24 06:05 -------- d-----w- c:\program files\Kalendar
2010-07-24 05:54 . 2010-07-24 05:54 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-07-24 05:53 . 2010-07-24 05:53 -------- d-----w- c:\program files\Common Files\Skype
2010-07-24 05:53 . 2010-07-24 05:53 -------- d-----r- c:\program files\Skype
2010-07-24 05:45 . 2010-07-24 05:51 -------- d-----w- c:\program files\ICQ6.5
2010-07-24 05:34 . 2010-07-24 05:34 -------- d-----w- c:\program files\Zoner
2010-07-24 05:09 . 2010-07-24 05:09 -------- d-----w- c:\program files\Webteh
2010-07-24 05:02 . 2010-07-25 23:12 -------- d-----w- c:\program files\Unlocker
2010-07-24 04:56 . 2010-07-24 04:56 -------- d-----w- c:\program files\Elaborate Bytes
2010-07-24 04:51 . 2010-07-25 00:21 -------- d-----w- c:\program files\Common Files\COWON
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\UC.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\RAR.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKZIP.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\LHA.PIF
2010-07-24 04:39 . 2010-07-07 05:55 545 ----a-w- c:\windows\ARJ.PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-28 13:47 . 2010-07-24 00:46 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-07-27 13:51 . 2010-07-24 00:57 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-27 13:51 . 2010-07-24 00:57 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-07-27 13:50 . 2010-07-24 00:58 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-07-25 20:02 . 2001-10-25 12:00 92422 ----a-w- c:\windows\system32\perfc005.dat
2010-07-25 20:02 . 2001-10-25 12:00 476468 ----a-w- c:\windows\system32\perfh005.dat
2010-07-25 00:35 . 2010-07-24 00:51 -------- d-----w- c:\program files\DU Meter
2010-07-24 00:59 . 2010-07-24 00:59 -------- d-----w- c:\program files\microsoft frontpage
2010-07-24 00:55 . 2010-07-24 00:55 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-07-24 00:55 . 2010-07-24 00:54 -------- d-----w- c:\program files\Windows Media Connect 2
2010-07-24 00:37 . 2010-07-24 00:37 -------- d-----w- c:\program files\Seznam.cz
2010-07-24 00:27 . 2010-07-24 00:27 -------- d-----w- c:\program files\Microsoft Works
2010-07-24 00:27 . 2010-07-24 00:27 -------- d-----w- c:\program files\MSBuild
2010-07-24 00:10 . 2010-07-24 00:10 0 ----a-w- c:\windows\nsreg.dat
2010-06-14 14:31 . 2010-07-24 00:56 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-04 09:55 . 2010-06-04 09:55 229312 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-06-01 17:00 . 2010-06-01 17:00 278288 ----a-w- c:\windows\system32\guard32.dll
2010-06-01 17:00 . 2010-06-01 17:00 87824 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-06-01 17:00 . 2010-06-01 17:00 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-06-01 17:00 . 2010-06-01 17:00 15464 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-05-27 16:39 . 2010-05-27 16:39 141384 ----a-w- c:\windows\system32\drivers\PSINAflt.sys
2010-05-12 08:58 . 2010-05-12 08:58 110920 ----a-w- c:\windows\system32\drivers\PSINProt.sys
.

------- Sigcheck -------

[-] 2008-08-08 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Malware Icon]
@="{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}"
[HKEY_CLASSES_ROOT\CLSID\{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}]
2010-05-14 13:04 320832 ----a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Suspect Icon]
@="{9AE343CB-BA45-4618-AF6A-0230EE6FC793}"
[HKEY_CLASSES_ROOT\CLSID\{9AE343CB-BA45-4618-AF6A-0230EE6FC793}]
2010-05-14 13:04 320832 ----a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-05-19 462104]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-07-24 2645528]
"Kalendar"="c:\program files\Kalendar\kalendar.exe" [2005-11-09 580608]
"SkinClock"="c:\program files\Free Desktop Clock\DesktopClock.exe" [2006-10-01 334848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"CTSysVol"="c:\program files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MediaKey"="c:\progra~1\MediaKey\MMKeybd.EXE" [2003-01-17 172032]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2010-05-14 406848]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-5-10 4456448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"UpdReg"=c:\windows\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [4.6.2010 11:55 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [1.6.2010 19:00 25240]
R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [4.5.2010 8:36 129928]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [24.7.2010 2:51 1386008]
R2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [30.4.2010 13:47 136448]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [27.5.2010 18:39 141384]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [30.4.2010 13:46 97032]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [30.4.2010 13:46 111624]
R2 PSINProt;PSINProt;c:\windows\system32\drivers\PSINProt.sys [12.5.2010 10:58 110920]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [10.5.2010 11:33 110592]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [10.5.2010 11:32 1858048]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [10.5.2010 11:32 482304]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [25.7.2010 0:04 11520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [10.3.2010 8:18 24216]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-07-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\4vubzabv.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.6&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
FF - user.js: network.http.max-connections-per-server - 8
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-08 22:04
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll

- - - - - - - > 'lsass.exe'(876)
c:\windows\system32\guard32.dll
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll

- - - - - - - > 'explorer.exe'(3512)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.DLL
c:\program files\Panda Security\Panda Cloud Antivirus\PSNCGP.dll
c:\program files\Panda Security\Panda Cloud Antivirus\PSNCIPC.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\Unlocker\UnlockerCOM.dll
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
c:\program files\JetAudio\JetFlExt.dll
c:\program files\JetAudio\JetFlExt.CSY
c:\program files\WinRAR\rarext.dll
c:\program files\WinRAR\rarlng.dll
c:\program files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
c:\program files\TuneUp Utilities 2010\SDShelEx-win32.dll
c:\program files\COMODO\COMODO Internet Security\cavshell.dll
c:\program files\7-Zip\7-zip.dll
c:\windows\system32\xpsp1res.dll

- - - - - - - > 'explorer.exe'(160)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.DLL
c:\program files\Panda Security\Panda Cloud Antivirus\PSNCGP.dll
c:\program files\Panda Security\Panda Cloud Antivirus\PSNCIPC.dll
c:\program files\Microsoft Office\Office12\1029\GrooveIntlResource.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Celkový čas: 2010-08-08 22:23:53
ComboFix-quarantined-files.txt 2010-08-08 20:23

Před spuštěním: Volných bajtů: 87 480 889 344
Po spuštění: Volných bajtů: 87 452 721 152

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=P21ES3
C:\wubildr.mbr = "Ubuntu"

- - End Of File - - 3C36031BE9D00C8C2994CE4C51737479
gaz

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Prosím o kontrolu logu RSIT

#20 Příspěvek od motji »

Změnilo se něco?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

gazebo
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 08 Kvě 2007 07:00

Re: Prosím o kontrolu logu RSIT

#21 Příspěvek od gazebo »

No tak problemy zatim nepozoruju...dame tomu nejakej cas a pak se zase ozvu ano ?
Zatim dekuji za Vas cas a pomoc. :)
gaz

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Prosím o kontrolu logu RSIT

#22 Příspěvek od motji »

Dobře, za pár dní se ozvěte, ještě uklidíme :D .
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět