Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Prosím o kontrolu logu

#1 Příspěvek od Richard 34 »

Pri kontrole sektora 1-62 na hd som zisťil že nie je prázdny.Kontaktoval som zákaznícku podporu ESET.Na ich doporučenie som spustil programy : mbrdump,gmer,autoruns.combofix,emebremover.
Po analíze došli k záveru citát :
Z logu co ste nam poslali, sme zistili pravdepodobnu infiltraciu mbr rootkita
Po dalšej analíze citát :
Podla popisu k tomuto PC vidno, ze vyrobca dodava HP Recovery Manager, cize je vysoky predpoklad, ze mate nestandardnu MBR, ktora dalej odkazuje na dalsie sektory - co je normalny stav

Logfile of random's system information tool 1.08 (written by random/random)
Run by kral at 2010-09-06 15:59:54
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 234 GB (77%) free of 305 GB
Total RAM: 3326 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:00:03, on 6. 9. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Users\kral\Programy\Process explorer\procexp.exe
C:\Users\kral\Programy\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\kral.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: JJZILK - Unknown owner - C:\Users\kral\AppData\Local\Temp\JJZILK.exe (file missing)
O23 - Service: NBDDYF - Unknown owner - C:\Users\kral\AppData\Local\Temp\NBDDYF.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: UDITC - Unknown owner - C:\Users\kral\AppData\Local\Temp\UDITC.exe (file missing)

--
End of file - 5009 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
"hpsysdrv"=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
"KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
"OsdMaestro"=C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [2007-02-15 118784]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-07-12 178712]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-06-26 13789728]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-09-03 16:10:42 ----D---- C:\Program Files\Common Files\Java
2010-09-03 16:10:07 ----A---- C:\Windows\system32\javaws.exe
2010-09-03 16:10:07 ----A---- C:\Windows\system32\javaw.exe
2010-09-03 16:10:07 ----A---- C:\Windows\system32\java.exe
2010-08-30 15:09:34 ----D---- C:\rsit
2010-08-30 10:28:27 ----D---- C:\Windows\temp
2010-08-19 14:15:01 ----D---- C:\ProgramData\ESET
2010-08-19 14:15:01 ----D---- C:\Program Files\ESET
2010-08-12 12:16:28 ----SHD---- C:\$RECYCLE.BIN
2010-08-12 11:45:02 ----A---- C:\Windows\system32\rtutils.dll
2010-08-12 11:45:01 ----A---- C:\Windows\system32\win32k.sys
2010-08-12 11:45:00 ----A---- C:\Windows\system32\iccvid.dll
2010-08-12 11:44:49 ----A---- C:\Windows\system32\iertutil.dll
2010-08-12 11:44:48 ----A---- C:\Windows\system32\mshtml.dll
2010-08-12 11:44:46 ----A---- C:\Windows\system32\ieframe.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\wininet.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\urlmon.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\mstime.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\occache.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\ieui.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iesetup.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iernonce.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iepeers.dll
2010-08-12 11:44:37 ----A---- C:\Windows\system32\schannel.dll
2010-08-12 11:44:29 ----A---- C:\Windows\system32\shell32.dll
2010-08-12 11:44:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-12 11:44:23 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-12 11:44:22 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-12 11:44:22 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-12 11:44:21 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-12 11:44:19 ----A---- C:\Windows\system32\msxml3.dll
2010-08-11 18:18:29 ----D---- C:\ProgramData\NOS

======List of files/folders modified in the last 1 months======

2010-09-06 16:00:02 ----D---- C:\Program Files\trend micro
2010-09-06 11:03:07 ----D---- C:\Windows\Prefetch
2010-09-03 16:58:00 ----AD---- C:\Windows
2010-09-03 16:58:00 ----A---- C:\Windows\Sandboxie.ini
2010-09-03 16:10:42 ----SHD---- C:\Windows\Installer
2010-09-03 16:10:42 ----D---- C:\Program Files\Common Files
2010-09-03 16:10:07 ----D---- C:\Windows\System32
2010-09-03 16:10:05 ----D---- C:\Program Files\Java
2010-09-03 16:09:44 ----SHD---- C:\System Volume Information
2010-09-03 15:07:46 ----D---- C:\Program Files\CCleaner
2010-09-03 10:53:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-03 10:53:45 ----D---- C:\Windows\inf
2010-09-03 10:50:15 ----D---- C:\Windows\system32\drivers
2010-09-03 10:48:01 ----D---- C:\ProgramData\NVIDIA
2010-09-03 10:47:53 ----D---- C:\Program Files\Microsoft Silverlight
2010-08-29 10:43:45 ----D---- C:\Users\kral\AppData\Roaming\uTorrent
2010-08-28 10:28:14 ----RD---- C:\Program Files
2010-08-28 10:27:29 ----D---- C:\ProgramData
2010-08-27 13:04:08 ----D---- C:\Users\kral\AppData\Roaming\Template
2010-08-26 17:52:01 ----SD---- C:\Windows\Downloaded Program Files
2010-08-26 17:45:07 ----D---- C:\Windows\Provisioning
2010-08-26 15:44:37 ----D---- C:\Windows\system32\Adobe
2010-08-25 16:29:36 ----D---- C:\Windows\ModemLogs
2010-08-25 16:29:01 ----D---- C:\Windows\system32\catroot2
2010-08-19 14:15:20 ----D---- C:\Windows\system32\catroot
2010-08-13 01:28:31 ----D---- C:\Program Files\Defraggler
2010-08-13 00:06:27 ----D---- C:\Windows\Debug
2010-08-12 16:55:14 ----D---- C:\Windows\Microsoft.NET
2010-08-12 16:54:58 ----RSD---- C:\Windows\assembly
2010-08-12 12:15:06 ----A---- C:\Windows\system.ini
2010-08-12 12:15:01 ----D---- C:\Windows\system32\drivers\etc
2010-08-12 12:13:28 ----D---- C:\Windows\AppPatch
2010-08-12 12:02:57 ----D---- C:\Windows\winsxs
2010-08-12 11:49:42 ----D---- C:\Windows\system32\migration
2010-08-12 11:49:42 ----D---- C:\Program Files\Internet Explorer
2010-08-12 11:49:41 ----D---- C:\Program Files\Movie Maker
2010-08-12 11:45:19 ----D---- C:\Program Files\Windows Mail
2010-08-12 11:37:49 ----D---- C:\Windows\system32\Msdtc
2010-08-12 11:37:48 ----D---- C:\Windows\system32\wbem
2010-08-12 11:36:46 ----D---- C:\Windows\system32\config
2010-08-12 11:36:19 ----D---- C:\Windows\Tasks
2010-08-12 11:36:19 ----D---- C:\Windows\system32\Tasks
2010-08-12 11:36:19 ----D---- C:\Windows\system32\spool
2010-08-12 11:36:19 ----D---- C:\Windows\system32\en-US
2010-08-12 11:36:13 ----D---- C:\Windows\registration
2010-08-11 21:37:35 ----D---- C:\Windows\system32\LogFiles

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 iaStor;Intel RAID Controller; C:\Windows\system32\drivers\iastor.sys [2008-12-04 328728]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-03 691696]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2008-03-19 1176064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-08-04 2744800]
R3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-06-26 9777376]
R3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2010-05-28 14896]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-10-03 99840]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-04-08 64000]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2010-07-04 119016]
S3 ARCSOFTVIRTUALCAPTURE;Magic-i Virtual Driver; C:\Windows\system32\DRIVERS\ArcSoftVirtualCapture.sys [2007-07-02 17664]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\Windows\system32\DRIVERS\pcdrndisuio.sys []
S3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:\Windows\system32\DRIVERS\w810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\w810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\w810mdm.sys [2006-02-20 94064]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-07-12 354840]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-06-26 211488]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2010-07-04 75496]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 fsssvc;Služba Bezpečnosť rodiny v službe Windows Live; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 JJZILK;JJZILK; C:\Users\kral\AppData\Local\Temp\JJZILK.exe []
S3 NBDDYF;NBDDYF; C:\Users\kral\AppData\Local\Temp\NBDDYF.exe []
S3 UDITC;UDITC; C:\Users\kral\AppData\Local\Temp\UDITC.exe []
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#2 Příspěvek od Caroprd111 »

Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#3 Příspěvek od Richard 34 »

ComboFix 10-09-04.06 - kral . 09. 2010 17:39:00.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3326.2224 [GMT 2:00]
Running from: c:\users\kral\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-08-06 to 2010-09-06 )))))))))))))))))))))))))))))))
.

2010-09-06 15:43 . 2010-09-06 15:43 -------- d-----w- c:\users\kral\AppData\Local\temp
2010-09-06 15:43 . 2010-09-06 15:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-06 15:37 . 2010-09-06 15:38 -------- d-----w- C:\32788R22FWJFW
2010-09-05 16:50 . 2010-09-06 15:37 -------- d-----r- c:\users\Public\recorded tv
2010-09-03 14:10 . 2010-09-03 14:10 -------- d-----w- c:\program files\Common Files\Java
2010-08-30 13:09 . 2010-09-06 14:00 -------- d-----w- C:\rsit
2010-08-19 12:15 . 2010-08-28 08:07 -------- d-----w- c:\program files\ESET
2010-08-12 09:45 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-12 09:45 . 2010-06-21 13:37 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-08-12 09:45 . 2010-05-27 20:08 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-08-11 16:18 . 2010-08-11 16:21 -------- d-----w- c:\programdata\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-06 15:42 . 2008-10-12 10:45 37490 ----a-w- c:\windows\system32\perfh01B.dat
2010-09-06 15:42 . 2008-10-12 10:45 10544 ----a-w- c:\windows\system32\perfc01B.dat
2010-09-06 15:35 . 2008-04-25 15:16 -------- d-----w- c:\programdata\NVIDIA
2010-09-06 14:00 . 2010-05-16 14:06 -------- d-----w- c:\program files\trend micro
2010-09-03 14:10 . 2008-04-25 15:23 -------- d-----w- c:\program files\Java
2010-09-03 13:07 . 2010-04-28 01:00 -------- d-----w- c:\program files\CCleaner
2010-09-03 08:47 . 2009-02-26 11:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-29 08:43 . 2008-10-05 23:04 -------- d-----w- c:\users\kral\AppData\Roaming\uTorrent
2010-08-29 08:42 . 2009-11-26 08:30 328568 ----a-w- c:\users\kral\AppData\Roaming\uTorrent\utorrent.exe
2010-08-28 15:34 . 2008-09-17 11:29 826 ----a-w- c:\users\kral\AppData\Roaming\wklnhst.dat
2010-08-27 11:04 . 2008-09-17 11:29 -------- d-----w- c:\users\kral\AppData\Roaming\Template
2010-08-26 11:57 . 2008-09-16 09:35 68104 ----a-w- c:\users\kral\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-12 23:28 . 2009-08-15 15:34 -------- d-----w- c:\program files\Defraggler
2010-08-12 09:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-07 22:35 . 2008-09-16 15:31 1356 ----a-w- c:\users\kral\AppData\Local\d3d9caps.dat
2010-08-05 06:29 . 2010-08-05 06:29 -------- d-----w- c:\program files\Common Files\Java(525)
2010-07-29 11:31 . 2010-07-29 11:31 41336 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2010-07-29 11:31 . 2010-07-29 11:31 32608 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2010-07-29 11:31 . 2010-07-29 11:31 136632 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-07-29 11:31 . 2010-07-29 11:31 134512 ----a-w- c:\windows\system32\drivers\epfw.sys
2010-07-29 11:31 . 2010-07-29 11:31 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-07-18 14:50 . 2009-02-09 04:29 -------- d-----w- c:\users\kral\AppData\Roaming\Skype
2010-07-17 03:00 . 2010-05-06 20:55 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:05 . 2010-08-12 09:44 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-12 09:44 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-12 09:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-12 09:44 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-21 21:33 . 2010-03-03 12:35 32061 ----a-w- c:\programdata\nvModes.dat
2010-06-18 15:04 . 2010-08-12 09:44 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-12 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-12 09:44 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-12 09:44 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-12 09:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-06-08 17:35 . 2010-08-12 09:44 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-08 17:35 . 2010-08-12 09:44 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
1999-04-23 22:22 . 1999-04-23 22:22 12 --sha-w- c:\windows\system\WININETICMP32.drv
2008-04-26 00:46 . 2008-04-26 00:21 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 13789728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):33,02,79,9a,49,fa,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3117225600-2553165260-2502525814-1000]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 JJZILK;JJZILK;c:\users\kral\AppData\Local\Temp\JJZILK.exe [x]
R3 NBDDYF;NBDDYF;c:\users\kral\AppData\Local\Temp\NBDDYF.exe [x]
R3 UDITC;UDITC;c:\users\kral\AppData\Local\Temp\UDITC.exe [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-03 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2008-03-19 1176064]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-05-28 14896]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/ig
FF - ProfilePath - c:\users\kral\AppData\Roaming\Mozilla\Firefox\Profiles\fbg5mb75.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/ig
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-06 17:43
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

[0] 0x202C646E

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,39,92,48,2c,6e,80,4e,af,1f,88,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,39,92,48,2c,6e,80,4e,af,1f,88,\

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-06 17:44:23
ComboFix-quarantined-files.txt 2010-09-06 15:44

Pre-Run: 245 498 810 368 bytes free
Post-Run: 245 449 097 216 bytes free

- - End Of File - - 86C740B755B9FD478F2F4F15F6DDE76F

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#4 Příspěvek od Caroprd111 »

Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\desktop\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#5 Příspěvek od Richard 34 »

Pri SPTD bola možnosť Uninstall neaktívna.
--------------------------------------------
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 19:03 on 06/09/2010 (kral)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...
----------------------------------------------------------------------------------
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
kernel: error reading MBR
-------------------------------------------------
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-09-06 19:12:16
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\kral\AppData\Local\Temp\uwldypog.sys


---- System - GMER 1.0.15 ----

Code 8CF90BFC ZwTraceEvent
Code 8CF90BFB NtTraceEvent

---- EOF - GMER 1.0.15 ----

Spustil som gmer ako správca v normálnom aj núdzovom režime,skúsil som aj premenovať vždy sa zasekne na rovnakom mieste :
\Device\HarddiskVolumeShadowCopy1

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#6 Příspěvek od Caroprd111 »

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe
  • Klikněte pravým tl. myši na ikonu MBR a zvolte vlastnosti. Zaškrtněte okénko "Spustit tento program jako správce" a potvrďte kliknutím na tlačítko "OK".
  • Start > Spustit (nebo použijte klávesovou zkratku Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\desktop\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#7 Příspěvek od Richard 34 »

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
kernel: MBR read successfully
user & kernel MBR OK

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#8 Příspěvek od Caroprd111 »

Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

Driver::
JJZILK
NBDDYF
UDITC

Folder::
c:\users\kral\AppData\Local\Temp\NBDDYF.exe

RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
  • Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

    Obrázek
  • Po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#9 Příspěvek od Richard 34 »

Zdravím všetkých.

ComboFix 10-09-04.06 - kral . 09. 2010 16:12:59.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3326.2393 [GMT 2:00]
Running from: c:\users\kral\Desktop\ComboFix.exe
Command switches used :: c:\users\kral\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_JJZILK
-------\Service_NBDDYF
-------\Service_UDITC


((((((((((((((((((((((((( Files Created from 2010-08-07 to 2010-09-07 )))))))))))))))))))))))))))))))
.

2010-09-07 14:16 . 2010-09-07 14:18 -------- d-----w- c:\users\kral\AppData\Local\temp
2010-09-07 14:16 . 2010-09-07 14:16 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-07 14:16 . 2010-09-07 14:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-03 14:10 . 2010-09-03 14:10 -------- d-----w- c:\program files\Common Files\Java
2010-08-30 13:09 . 2010-09-06 14:00 -------- d-----w- C:\rsit
2010-08-19 12:15 . 2010-08-28 08:07 -------- d-----w- c:\program files\ESET
2010-08-12 09:45 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-12 09:45 . 2010-06-21 13:37 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-08-12 09:45 . 2010-05-27 20:08 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-08-11 16:18 . 2010-08-11 16:21 -------- d-----w- c:\programdata\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-07 14:18 . 2008-04-25 15:16 -------- d-----w- c:\programdata\NVIDIA
2010-09-07 14:16 . 2008-10-12 10:45 37490 ----a-w- c:\windows\system32\perfh01B.dat
2010-09-07 14:16 . 2008-10-12 10:45 10544 ----a-w- c:\windows\system32\perfc01B.dat
2010-09-06 21:17 . 2008-09-16 15:31 1356 ----a-w- c:\users\kral\AppData\Local\d3d9caps.dat
2010-09-06 14:00 . 2010-05-16 14:06 -------- d-----w- c:\program files\trend micro
2010-09-03 14:10 . 2008-04-25 15:23 -------- d-----w- c:\program files\Java
2010-09-03 13:07 . 2010-04-28 01:00 -------- d-----w- c:\program files\CCleaner
2010-09-03 08:47 . 2009-02-26 11:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-29 08:43 . 2008-10-05 23:04 -------- d-----w- c:\users\kral\AppData\Roaming\uTorrent
2010-08-29 08:42 . 2009-11-26 08:30 328568 ----a-w- c:\users\kral\AppData\Roaming\uTorrent\utorrent.exe
2010-08-28 15:34 . 2008-09-17 11:29 826 ----a-w- c:\users\kral\AppData\Roaming\wklnhst.dat
2010-08-27 11:04 . 2008-09-17 11:29 -------- d-----w- c:\users\kral\AppData\Roaming\Template
2010-08-26 11:57 . 2008-09-16 09:35 68104 ----a-w- c:\users\kral\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-12 23:28 . 2009-08-15 15:34 -------- d-----w- c:\program files\Defraggler
2010-08-12 09:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-05 06:29 . 2010-08-05 06:29 -------- d-----w- c:\program files\Common Files\Java(525)
2010-07-29 11:31 . 2010-07-29 11:31 41336 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2010-07-29 11:31 . 2010-07-29 11:31 32608 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2010-07-29 11:31 . 2010-07-29 11:31 136632 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-07-29 11:31 . 2010-07-29 11:31 134512 ----a-w- c:\windows\system32\drivers\epfw.sys
2010-07-29 11:31 . 2010-07-29 11:31 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-07-18 14:50 . 2009-02-09 04:29 -------- d-----w- c:\users\kral\AppData\Roaming\Skype
2010-07-17 03:00 . 2010-05-06 20:55 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:05 . 2010-08-12 09:44 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-12 09:44 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-12 09:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-12 09:44 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-21 21:33 . 2010-03-03 12:35 32061 ----a-w- c:\programdata\nvModes.dat
2010-06-18 15:04 . 2010-08-12 09:44 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-12 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-12 09:44 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-12 09:44 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-12 09:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
1999-04-23 22:22 . 1999-04-23 22:22 12 --sha-w- c:\windows\system\WININETICMP32.drv
2008-04-26 00:46 . 2008-04-26 00:21 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 13789728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):33,02,79,9a,49,fa,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3117225600-2553165260-2502525814-1000]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-05-28 14896]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-03 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2008-03-19 1176064]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/ig
FF - ProfilePath - c:\users\kral\AppData\Roaming\Mozilla\Firefox\Profiles\fbg5mb75.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/ig
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-07 16:18
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\Secunia\PSI\psi.exe
c:\windows\ehome\ehsched.exe
c:\hp\kbd\kbd.exe
c:\windows\ehome\ehRecvr.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-09-07 16:22:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-07 14:22
ComboFix2.txt 2010-09-06 15:44

Pre-Run: 244 076 204 032 bytes free
Post-Run: 243 769 151 488 bytes free

- - End Of File - - A1BC7DBB92D64B9AF20FDD583F7269DB

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#10 Příspěvek od Caroprd111 »

Jsou s PC nějaké problémy :???:
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#11 Příspěvek od Richard 34 »

PC sa chová normálne.

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#12 Příspěvek od Caroprd111 »

Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter



Obrázek Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Obrázek Dejte nový log z RSIT.
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#13 Příspěvek od Richard 34 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by kral at 2010-09-07 16:53:50
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 233 GB (76%) free of 305 GB
Total RAM: 3326 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:54:00, on 7. 9. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\hp\kbd\kbd.exe
C:\Users\kral\Programy\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\kral.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 4628 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
"hpsysdrv"=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
"KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
"OsdMaestro"=C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [2007-02-15 118784]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-07-12 178712]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-06-26 13789728]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-09-07 16:53:50 ----D---- C:\rsit
2010-09-07 16:22:27 ----D---- C:\Windows\temp
2010-09-07 16:18:22 ----D---- C:\$RECYCLE.BIN
2010-09-03 16:10:42 ----D---- C:\Program Files\Common Files\Java
2010-09-03 16:10:07 ----A---- C:\Windows\system32\javaws.exe
2010-09-03 16:10:07 ----A---- C:\Windows\system32\javaw.exe
2010-09-03 16:10:07 ----A---- C:\Windows\system32\java.exe
2010-08-19 14:15:01 ----D---- C:\ProgramData\ESET
2010-08-19 14:15:01 ----D---- C:\Program Files\ESET
2010-08-12 11:45:02 ----A---- C:\Windows\system32\rtutils.dll
2010-08-12 11:45:01 ----A---- C:\Windows\system32\win32k.sys
2010-08-12 11:45:00 ----A---- C:\Windows\system32\iccvid.dll
2010-08-12 11:44:49 ----A---- C:\Windows\system32\iertutil.dll
2010-08-12 11:44:48 ----A---- C:\Windows\system32\mshtml.dll
2010-08-12 11:44:46 ----A---- C:\Windows\system32\ieframe.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\wininet.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\urlmon.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\mstime.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-12 11:44:45 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\occache.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-12 11:44:44 ----A---- C:\Windows\system32\ieui.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iesetup.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iernonce.dll
2010-08-12 11:44:44 ----A---- C:\Windows\system32\iepeers.dll
2010-08-12 11:44:37 ----A---- C:\Windows\system32\schannel.dll
2010-08-12 11:44:29 ----A---- C:\Windows\system32\shell32.dll
2010-08-12 11:44:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-12 11:44:23 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-12 11:44:22 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-12 11:44:22 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-12 11:44:21 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-12 11:44:19 ----A---- C:\Windows\system32\msxml3.dll
2010-08-11 18:18:29 ----D---- C:\ProgramData\NOS

======List of files/folders modified in the last 1 months======

2010-09-07 16:54:00 ----D---- C:\Windows\Prefetch
2010-09-07 16:54:00 ----D---- C:\Program Files\trend micro
2010-09-07 16:52:48 ----AD---- C:\Windows
2010-09-07 16:50:29 ----D---- C:\ProgramData\NVIDIA
2010-09-07 16:45:31 ----D---- C:\Windows\System32
2010-09-07 16:25:07 ----D---- C:\Windows\inf
2010-09-07 16:25:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-07 16:22:27 ----D---- C:\Windows\system32\drivers
2010-09-07 16:18:25 ----A---- C:\Windows\system.ini
2010-09-07 16:18:20 ----D---- C:\Windows\system32\drivers\etc
2010-09-07 16:17:03 ----D---- C:\Windows\system32\config
2010-09-07 16:17:03 ----D---- C:\Boot
2010-09-07 16:15:12 ----D---- C:\Windows\AppPatch
2010-09-07 16:15:11 ----D---- C:\Program Files\Common Files
2010-09-07 15:46:59 ----SHD---- C:\System Volume Information
2010-09-03 16:58:00 ----A---- C:\Windows\Sandboxie.ini
2010-09-03 16:10:42 ----SHD---- C:\Windows\Installer
2010-09-03 16:10:05 ----D---- C:\Program Files\Java
2010-09-03 15:07:46 ----D---- C:\Program Files\CCleaner
2010-09-03 10:47:53 ----D---- C:\Program Files\Microsoft Silverlight
2010-08-29 10:43:45 ----D---- C:\Users\kral\AppData\Roaming\uTorrent
2010-08-28 10:28:14 ----RD---- C:\Program Files
2010-08-28 10:27:29 ----D---- C:\ProgramData
2010-08-27 13:04:08 ----D---- C:\Users\kral\AppData\Roaming\Template
2010-08-26 17:52:01 ----SD---- C:\Windows\Downloaded Program Files
2010-08-26 17:45:07 ----D---- C:\Windows\Provisioning
2010-08-26 15:44:37 ----D---- C:\Windows\system32\Adobe
2010-08-25 16:29:36 ----D---- C:\Windows\ModemLogs
2010-08-25 16:29:01 ----D---- C:\Windows\system32\catroot2
2010-08-19 14:15:20 ----D---- C:\Windows\system32\catroot
2010-08-13 01:28:31 ----D---- C:\Program Files\Defraggler
2010-08-13 00:06:27 ----D---- C:\Windows\Debug
2010-08-12 16:55:14 ----D---- C:\Windows\Microsoft.NET
2010-08-12 16:54:58 ----RSD---- C:\Windows\assembly
2010-08-12 12:02:57 ----D---- C:\Windows\winsxs
2010-08-12 11:49:42 ----D---- C:\Windows\system32\migration
2010-08-12 11:49:42 ----D---- C:\Program Files\Internet Explorer
2010-08-12 11:49:41 ----D---- C:\Program Files\Movie Maker
2010-08-12 11:45:19 ----D---- C:\Program Files\Windows Mail
2010-08-12 11:37:49 ----D---- C:\Windows\system32\Msdtc
2010-08-12 11:37:48 ----D---- C:\Windows\system32\wbem
2010-08-12 11:36:19 ----D---- C:\Windows\Tasks
2010-08-12 11:36:19 ----D---- C:\Windows\system32\Tasks
2010-08-12 11:36:19 ----D---- C:\Windows\system32\spool
2010-08-12 11:36:19 ----D---- C:\Windows\system32\en-US
2010-08-12 11:36:13 ----D---- C:\Windows\registration
2010-08-11 21:37:35 ----D---- C:\Windows\system32\LogFiles

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 iaStor;Intel RAID Controller; C:\Windows\system32\drivers\iastor.sys [2008-12-04 328728]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-03 691696]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2008-03-19 1176064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-08-04 2744800]
R3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-06-26 9777376]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-10-03 99840]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-04-08 64000]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2010-07-04 119016]
S3 ARCSOFTVIRTUALCAPTURE;Magic-i Virtual Driver; C:\Windows\system32\DRIVERS\ArcSoftVirtualCapture.sys [2007-07-02 17664]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\Windows\system32\DRIVERS\pcdrndisuio.sys []
S3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2010-05-28 14896]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:\Windows\system32\DRIVERS\w810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\w810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\w810mdm.sys [2006-02-20 94064]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-07-12 354840]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-06-26 211488]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2010-07-04 75496]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 fsssvc;Služba Bezpečnosť rodiny v službe Windows Live; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Avatar uživatele
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 Bře 2009 20:48
Místo/Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#14 Příspěvek od Caroprd111 »

Log je v pořádku. :)
Obrázek

Avatar uživatele
Richard 34
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 08 Dub 2010 14:26

Re: Prosím o kontrolu logu

#15 Příspěvek od Richard 34 »

Ďakujem za kontrolu ahoj. :)

Odpovědět