Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka ( male problemy s ntb)

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Preventivka ( male problemy s ntb)

#1 Příspěvek od maximix »

Dobry den, chtel bych nechat zkontrolovat PC (ntb) moji pritelkyne... posledni dobou se ji sam vypina monitor po chvilce se ovsem zase zapne, ale stava se i ze se nezapne a musi pc tvrde vypnout... taky ma posledni dobou problemy s BSOD a se zamrzanim mysi (USB), kde i bylo (technikem) receno ze se podelal nejakej senzor v pc a proto mys zamrza...

zde je log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2010-10-11 05:43:27
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 164 GB (69%) free of 238 GB
Total RAM: 1023 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:46:37, on 11.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
C:\Program Files\QIP 2010\qip.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cobian Backup 10\cbVSCService.exe
C:\Program Files\Cobian Backup 10\cbService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\Documents and Settings\Uživatel\Plocha\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=14597&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Uživatel\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Uživatel\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cobian Backup 10 Volume Shadow Copy service (cbVSCService) - CobianSoft, Luis Cobian - C:\Program Files\Cobian Backup 10\cbVSCService.exe
O23 - Service: Cobian Backup 10 (CobianBackup10) - Luis Cobian, CobianSoft - C:\Program Files\Cobian Backup 10\cbService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - Unknown owner - E:\TuneUpPortable\App\TuneUp\TuneUpDefragService.exe (file missing)

--
End of file - 9044 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\AWC AutoSweep.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Uživatel\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-08-12 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-03 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-01-30 13594624]
"nwiz"=nwiz.exe /install []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2006-01-25 53248]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-04-07 2145000]
"VMonitorVMUVC"=C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe [2008-08-29 143360]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-09-28 2183680]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-03-17 421888]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-09-02 13351304]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2010-08-12 5829584]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoResolveTrack"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Documents and Settings\Uživatel\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Uživatel\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-10-11 05:43:28 ----D---- C:\Program Files\trend micro
2010-10-11 05:43:27 ----D---- C:\rsit
2010-10-11 03:33:42 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-10-11 03:33:32 ----D---- C:\WINDOWS\system32\temp
2010-10-11 03:33:32 ----D---- C:\WINDOWS\Logs
2010-10-11 03:33:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\PassMark
2010-10-11 03:33:26 ----D---- C:\Program Files\BurnInTest
2010-10-09 18:08:49 ----D---- C:\Program Files\Garmin
2010-10-09 18:08:31 ----D---- C:\MapSource
2010-10-09 17:57:28 ----D---- C:\garmin
2010-10-09 17:42:05 ----D---- C:\Program Files\Img2gps
2010-10-09 17:31:42 ----A---- C:\WINDOWS\gmt.exe
2010-10-09 17:31:28 ----D---- C:\Program Files\GmapTool
2010-10-09 17:28:41 ----D---- C:\Program Files\cGPSmapper
2010-10-09 17:07:54 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\GARMIN
2010-10-09 17:07:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\GARMIN
2010-10-09 16:35:27 ----A---- C:\WINDOWS\system32\drivers\grmnusb.sys
2010-10-09 16:35:27 ----A---- C:\WINDOWS\system32\drivers\grmngen.sys
2010-10-08 21:15:04 ----D---- C:\zaloha
2010-10-08 21:11:41 ----D---- C:\Program Files\Cobian Backup 10
2010-10-08 01:09:11 ----D---- C:\Program Files\Innovative Solutions
2010-10-07 01:31:53 ----D---- C:\WINDOWS\system32\AGEIA
2010-10-07 01:31:52 ----D---- C:\Program Files\AGEIA Technologies
2010-10-07 01:31:24 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-10-07 01:27:56 ----D---- C:\NVIDIA
2010-10-06 19:54:04 ----SHD---- C:\RECYCLER
2010-09-30 03:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-30 02:53:27 ----D---- C:\Program Files\Zeallsoft
2010-09-28 08:53:42 ----D---- C:\Program Files\Spyware Terminator
2010-09-25 17:21:45 ----D---- C:\Program Files\Speccy
2010-09-25 17:01:32 ----D---- C:\WINDOWS\pss
2010-09-24 17:23:53 ----D---- C:\Program Files\Common Files\Skype
2010-09-24 17:23:47 ----RD---- C:\Program Files\Skype
2010-09-23 21:42:57 ----D---- C:\Program Files\Ask.com
2010-09-23 21:41:15 ----D---- C:\Program Files\FreeTime
2010-09-23 21:05:50 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Jpeg Resampler
2010-09-23 21:05:48 ----D---- C:\Program Files\JPEG Resampler
2010-09-20 17:57:02 ----D---- C:\SuperWebcamRecorder
2010-09-18 17:02:08 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\ooVoo Details
2010-09-18 17:01:38 ----D---- C:\Program Files\ooVoo
2010-09-17 16:27:44 ----D---- C:\WINDOWS\VMUVC
2010-09-17 16:27:23 ----A---- C:\WINDOWS\system32\VvFtCtrl.dll
2010-09-17 16:27:23 ----A---- C:\WINDOWS\system32\VMUVC.dll
2010-09-17 16:27:23 ----A---- C:\WINDOWS\system32\drivers\vvftUVC.sys
2010-09-17 16:27:23 ----A---- C:\WINDOWS\system32\drivers\VMUVC.sys
2010-09-17 16:27:13 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys
2010-09-17 16:27:08 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys
2010-09-17 16:27:05 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys
2010-09-17 16:27:04 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys
2010-09-17 16:27:01 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2010-09-17 16:26:58 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys
2010-09-17 16:26:52 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys
2010-09-17 16:26:49 ----D---- C:\Program Files\Vimicro Corporation
2010-09-17 16:26:38 ----A---- C:\WINDOWS\system32\drivers\USBAUDIO.sys
2010-09-17 16:26:30 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-09-17 16:26:30 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys
2010-09-17 16:26:25 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2010-09-16 03:03:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-16 03:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-16 03:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-16 03:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-16 03:03:09 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-16 03:03:01 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-16 03:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-09-14 22:58:22 ----A---- C:\FONTLOG.TXT

======List of files/folders modified in the last 1 months======

2010-10-11 05:43:35 ----D---- C:\WINDOWS\Prefetch
2010-10-11 05:43:33 ----D---- C:\WINDOWS\Temp
2010-10-11 05:43:28 ----RD---- C:\Program Files
2010-10-11 04:05:27 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Skype
2010-10-11 04:03:44 ----D---- C:\WINDOWS
2010-10-11 04:02:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-11 03:33:46 ----D---- C:\WINDOWS\system32\DirectX
2010-10-11 03:33:46 ----D---- C:\WINDOWS\system32
2010-10-11 03:33:45 ----HD---- C:\WINDOWS\inf
2010-10-11 03:33:45 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-11 03:08:00 ----SHD---- C:\System Volume Information
2010-10-11 03:06:49 ----D---- C:\WINDOWS\Minidump
2010-10-11 02:15:43 ----D---- C:\WINDOWS\system32\Restore
2010-10-11 01:30:03 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\skypePM
2010-10-10 23:00:05 ----A---- C:\WINDOWS\NeroDigital.ini
2010-10-10 16:43:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-09 22:14:18 ----D---- C:\WINDOWS\repair
2010-10-09 18:24:22 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Temp
2010-10-09 18:11:44 ----D---- C:\WINDOWS\system32\drivers
2010-10-09 18:08:56 ----SHD---- C:\WINDOWS\Installer
2010-10-09 18:08:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-10-09 13:36:58 ----D---- C:\WINDOWS\Registration
2010-10-08 22:21:00 ----D---- C:\WINDOWS\Microsoft.NET
2010-10-08 22:20:49 ----RSD---- C:\WINDOWS\assembly
2010-10-08 18:07:25 ----A---- C:\WINDOWS\win.ini
2010-10-07 02:18:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-07 02:17:48 ----D---- C:\WINDOWS\WinSxS
2010-10-07 01:38:55 ----D---- C:\WINDOWS\nview
2010-10-07 01:31:24 ----D---- C:\Program Files\Common Files
2010-10-07 01:31:00 ----D---- C:\WINDOWS\Help
2010-10-06 19:53:57 ----SD---- C:\Documents and Settings\Uživatel\Data aplikací\Microsoft
2010-10-06 19:50:05 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Spyware Terminator
2010-10-06 19:38:34 ----A---- C:\WINDOWS\system.ini
2010-10-06 19:38:27 ----D---- C:\WINDOWS\system32\drivers\etc
2010-10-06 19:36:38 ----D---- C:\WINDOWS\AppPatch
2010-10-03 07:14:30 ----D---- C:\Program Files\CCleaner
2010-09-30 16:45:11 ----D---- C:\Documents and Settings
2010-09-30 03:00:53 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\WinRAR
2010-09-30 03:00:50 ----D---- C:\Program Files\WinRAR
2010-09-30 02:42:24 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\IObit
2010-09-28 10:18:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-09-24 17:23:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-09-23 21:43:05 ----SD---- C:\WINDOWS\Tasks
2010-09-19 19:05:49 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\TeamViewer
2010-09-19 17:31:24 ----D---- C:\Program Files\TeamViewer
2010-09-19 12:11:03 ----D---- C:\Program Files\Mozilla Firefox
2010-09-17 16:27:44 ----D---- C:\WINDOWS\twain_32
2010-09-17 16:27:36 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-09-17 16:26:49 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-16 18:32:12 ----D---- C:\WINDOWS\Debug
2010-09-16 03:03:38 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-16 03:01:03 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-04-07 55232]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-04-07 139192]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-04-07 134488]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2009-12-21 1570240]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-29 60800]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-04-07 32584]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys [2006-02-07 935424]
R3 HSXHWAZL;HSXHWAZL; C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys [2006-02-07 196608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-29 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-01-30 6250848]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-05-09 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-05-09 13184]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-07 11136]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2010-03-11 25088]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 VMUVC;Vimicro Camera Service VMUVC; C:\WINDOWS\System32\Drivers\VMUVC.sys [2009-01-09 251904]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC; C:\WINDOWS\system32\drivers\vvftUVC.sys [2008-07-01 398720]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys [2006-02-07 672256]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 grmnusb;Garmin USB Driver; C:\WINDOWS\system32\drivers\grmnusb.sys [2009-04-17 9344]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service; C:\Program Files\Cobian Backup 10\cbVSCService.exe [2010-09-23 67584]
R2 CobianBackup10;Cobian Backup 10; C:\Program Files\Cobian Backup 10\cbService.exe [2010-09-23 1125376]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-04-07 810120]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-02-18 877864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-01-30 168004]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-11-25 247152]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-09-28 488960]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-01 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-04-07 33560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-23 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; E:\TuneUpPortable\App\TuneUp\TuneUpDefragService.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#2 Příspěvek od maximix »

Omlouvam se ze pripisuju ale cetl sem tu prispevek se zpomalenym pc a jelikoz se moji partnerce seka pc tak jsem zkusil radu vaseho radce bootkit remover a co jsem nezjistil asi je v tom nejakej hajzl pac mi to hazi stejnou chybu jako onemu uzivateli..

log zde

Kód: Vybrat vše

Bootkit Remover
(c) 2009 eSage Lab
http://www.esagelab.com

Program version: 1.2.0.0
OS Version: Microsoft Windows XP Professional Service Pack 3 (build 2600)

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00007e00
Boot sector MD5 is: ee7fe9f24bc949ea3a78cf7064fbe50b

     Size  Device Name          MBR Status
 --------------------------------------------
   232 GB  \\.\PhysicalDrive0   Unknown boot code

Unknown boot code has been found on some of your physical disks.
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>


Done;
Press any key to quit...

EDIT: konkretne sem to nasel v tomto tematu http://www.viry.cz/forum/viewtopic.php?f=28&t=102770 znamena to tedy ze mi pomuze take jen oprava systemu?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#3 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Zkouset jen tak co najdete je nebezpecne - skoro kazda infekce je unikat a potrebuje individualni pristup

:arrow: Pouzivate Grub nebo nejaky jiny bootloader - vecicka, ktera Vam dava na vyber, pri startu PC, ktery system chcete spustit (napr. jestli Win ci Linux)

:arrow: Pokud je chyba v senzoru mysi = jde o HW zavadu, tak tu tezko vyresime :o Muzete zkusit pripojit mys pres PS2 konektor

:arrow: Na pricinu BSOD muzeme asi i prijit - OS vytvari zpravu tesne pred padem - ve slozce C:\Windows\Minidump by mely byt soubory s priponou dmp - zabalte je a poslete mi je na vyosek@forum.viry.cz - poprosim kolegu at se na ne podiva
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#4 Příspěvek od maximix »

Dobry den, dekuji za rychlou odpoved:)

Grub nepouzivam proto me ten remover.exe zarazi... me prijde divny jak muze senzor v pocitaci zasekavat mys pripojenou pres USB to prece jen ten senzor v te mysi ne? nevim proto se radsi ptam tu:D... jinak ty BSOD mam vyfocene od pritelkyne pres mobil.. ve slozce C:\Windows\Minidump sem zadny log ani jednou nenasel (zkousel sem pouzit i bluescreenview ale ten take zadny log nenasel), pritelkyne pouziva CCleaner tak jestli neni mozne ze on ty logy maze.... jinak pokud vam postaci fotka tu muzu dodat:)

EDIT: tak sem posledni minidump nasel...
EDIT2: Precetl sem si to znova a a doslo mi ze minidump mam odeslat.. tak to je na mailu, pardon

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#5 Příspěvek od vyosek »

:arrow: Poslete mi na mail prosim i ty fotky BSOD

:arrow: Je poskozeny senzor v mysi = buh vi co jeste je v ny poskozeno, jinou mys jste zkouseli :???: Ovladani prs touchpad se taky seka :???:

:arrow: Ohlednet toho monitoru - kabelaz jste kontroloval - jestli je spravne zapojena :???:

:arrow: Presunte bootkit remover na plochu, jestli jej tam jeste nemate

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\plocha\remover.exe" fix \\.\PhysicalDrive0
  • Kliknete na OK
  • Restartujte PC
  • Zopakujte sken s bootkit removerem, log opet sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#6 Příspěvek od maximix »

Fotky odeslany.... jinou mys sem nezkousel reknu at vyzkousi pouze touchpad... kabelaz nemyslite ze bych mel rozebrat ntb a mrknout se jestli neco nevyskocilo, na to se totiz necejtim... pri zadani prikazu "%userprofile%\plocha\remover.exe" fix \\.\PhysicalDrive0 mi vyskocila chyba ze remover.exe nebyl na plose nalezen...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#7 Příspěvek od vyosek »

:arrow: S kabelazi se omlouvam, jde vlastne o ntb

:arrow: A byl na plose presunuty, jak jsem psal :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#8 Příspěvek od maximix »

jojo v pohode:)... jo na plose je chyba se ukazuje porad...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#9 Příspěvek od vyosek »

:arrow: Aha, oni jej prejmenovali a ja mam v navodu stary nazev - zkontrolujte prosim zda se moje jmeno removeru (bootkit_remover.exe) shoduje s vasim jmenem removeru (pripadne jmeno meho upravte) - ale melo by to byt v poradku uz - ted jsem jej natahnul znovu...

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\plocha\bootkit_remover.exe" fix \\.\PhysicalDrive0
  • Kliknete na OK
  • Restartujte PC
  • Zopakujte sken s bootkit removerem, log opet sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#10 Příspěvek od maximix »

uspesne provedeno nejspise s uspesnym vysledkem
neslo mi to zkopirovat tak sme udelal screen
Obrázek

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#11 Příspěvek od vyosek »

:arrow: Screen je OK

:arrow: Odinstalujte Spyware Terminatora - mate tam balicek all-in-one od ESETu, takhle se Vam tam perou dva rez. stity (vice o kolizi je zde http://www.viry.cz/forum/viewtopic.php?f=29&t=2780 - sice to nejsou dva antiviry, ale oba maji rezidentni stit)

:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\Uživatel.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko

  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=14597&l=dis
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    services.msc
  • Kliknete na OK
  • Najdete sluzby nize
  • Služba Google Update
    Java Quick Starter
    Nero BackItUp Scheduler 3
  • U kazde provedte toto
    • Klik na ni pravym mysidlem a zvolit Vlastnosti
    • Nyní klik na Zastavit
    • Typ spousteni nastavit na Zakazano
    • Potvrdte kliknutim na OK
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#12 Příspěvek od maximix »

vse provedeno bez problemu:)

log z combofixu

ComboFix 10-10-10.03 - Uživatel 11.10.2010 17:58:43.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.474 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\ComboFix.exe
AV: ESET Smart Security 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Temp
c:\windows\system32\Temp\KSKD87SFDS

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-11 do 2010-10-11 )))))))))))))))))))))))))))))))
.

2010-10-11 03:43 . 2010-10-11 15:41 -------- d-----w- c:\program files\trend micro
2010-10-11 03:43 . 2010-10-11 03:46 -------- d-----w- C:\rsit
2010-10-11 01:33 . 2009-03-09 13:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2010-10-11 01:33 . 2010-10-11 01:33 -------- d-----w- c:\windows\Logs
2010-10-11 01:33 . 2010-10-11 01:33 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PassMark
2010-10-11 01:33 . 2010-10-11 01:33 -------- d-----w- c:\program files\BurnInTest
2010-10-09 16:08 . 2010-10-09 16:08 -------- d-----w- c:\program files\Garmin
2010-10-09 16:08 . 2010-10-09 16:08 -------- d-----w- C:\MapSource
2010-10-09 15:57 . 2010-10-09 16:17 -------- d-----w- C:\garmin
2010-10-09 15:42 . 2004-03-08 22:00 260880 ----a-w- c:\windows\system32\MSFLXGRD.OCX
2010-10-09 15:42 . 2010-10-09 15:42 -------- d-----w- c:\program files\Img2gps
2010-10-09 15:31 . 2010-10-04 21:08 74240 ----a-w- c:\windows\gmt.exe
2010-10-09 15:31 . 2010-10-09 15:31 -------- d-----w- c:\program files\GmapTool
2010-10-09 15:28 . 2010-10-09 15:28 -------- d-----w- c:\program files\cGPSmapper
2010-10-09 15:07 . 2010-10-09 15:08 -------- d-----w- c:\documents and settings\Uživatel\Data aplikací\GARMIN
2010-10-09 15:07 . 2010-10-09 15:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GARMIN
2010-10-09 14:35 . 2009-04-17 13:48 9344 ----a-w- c:\windows\system32\drivers\grmnusb.sys
2010-10-09 14:35 . 2009-04-17 13:48 18304 ----a-w- c:\windows\system32\drivers\grmngen.sys
2010-10-09 12:42 . 2001-08-17 17:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2010-10-09 12:41 . 2001-08-17 16:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys
2010-10-09 12:40 . 2001-10-24 08:24 252032 -c--a-w- c:\windows\system32\dllcache\sis300iv.dll
2010-10-09 12:39 . 2008-04-13 20:11 17664 -c--a-w- c:\windows\system32\dllcache\ppa3.sys
2010-10-09 12:38 . 2001-10-24 08:24 19968 -c--a-w- c:\windows\system32\dllcache\mxicfg.dll
2010-10-09 12:37 . 2001-08-17 17:28 797500 -c--a-w- c:\windows\system32\dllcache\ltsmt.sys
2010-10-09 12:36 . 2008-04-14 07:51 81920 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2010-10-09 12:35 . 2001-10-24 07:58 907456 -c--a-w- c:\windows\system32\dllcache\hcf_msft.sys
2010-10-09 12:34 . 2001-08-17 16:12 19594 -c--a-w- c:\windows\system32\dllcache\e100isa4.sys
2010-10-09 12:33 . 2008-04-13 18:06 48640 -c--a-w- c:\windows\system32\dllcache\cwrwdm.sys
2010-10-09 12:32 . 2001-10-24 07:49 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-10-09 12:31 . 2008-04-13 20:06 44928 -c--a-w- c:\windows\system32\dllcache\agpcpq.sys
2010-10-08 19:15 . 2010-10-09 20:14 -------- d-----w- C:\zaloha
2010-10-08 19:12 . 2010-10-08 19:12 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Safe mirror
2010-10-08 19:11 . 2010-10-08 19:12 -------- d-----w- c:\program files\Cobian Backup 10
2010-10-07 23:09 . 2010-10-07 23:09 -------- d-----w- c:\documents and settings\Uživatel\Local Settings\Data aplikací\Innovative Solutions
2010-10-07 23:09 . 2010-10-07 23:09 -------- d-----w- c:\program files\Innovative Solutions
2010-10-06 23:31 . 2010-10-06 23:31 -------- d-----w- c:\windows\system32\AGEIA
2010-10-06 23:31 . 2010-10-06 23:31 -------- d-----w- c:\program files\AGEIA Technologies
2010-10-06 23:31 . 2010-10-06 23:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-10-06 23:27 . 2010-10-06 23:27 -------- d-----w- C:\NVIDIA
2010-09-30 14:45 . 2010-09-30 14:46 -------- d-sh--w- c:\documents and settings\Uzivatel
2010-09-30 00:53 . 2010-09-30 00:53 -------- d-----w- c:\program files\Zeallsoft
2010-09-25 15:21 . 2010-09-25 15:21 -------- d-----w- c:\program files\Speccy
2010-09-24 15:23 . 2010-09-24 15:23 -------- d-----w- c:\program files\Common Files\Skype
2010-09-24 15:23 . 2010-09-24 15:23 -------- d-----r- c:\program files\Skype
2010-09-23 21:58 . 2010-10-10 22:02 -------- d-----w- c:\documents and settings\Uživatel\Local Settings\Data aplikací\AskToolbar
2010-09-23 19:42 . 2010-09-23 19:43 -------- d-----w- c:\program files\Ask.com
2010-09-23 19:41 . 2010-09-23 19:41 -------- d-----w- c:\program files\FreeTime
2010-09-23 19:05 . 2010-09-23 19:12 -------- d-----w- c:\documents and settings\Uživatel\Data aplikací\Jpeg Resampler
2010-09-23 19:05 . 2010-09-23 19:05 -------- d-----w- c:\program files\JPEG Resampler
2010-09-20 15:57 . 2010-10-11 02:24 -------- d-----w- C:\SuperWebcamRecorder
2010-09-18 15:02 . 2010-09-18 15:05 -------- d-----w- c:\documents and settings\Uživatel\Data aplikací\ooVoo Details
2010-09-18 15:01 . 2010-09-18 15:01 -------- d-----w- c:\program files\ooVoo
2010-09-17 14:26 . 2008-04-13 20:16 85248 -c--a-w- c:\windows\system32\dllcache\nabtsfec.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

------- Sigcheck -------

[-] 2008-04-29 . B054BB152547F33685D19F3343F444D0 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files\QIP 2010\qip.exe" [2010-08-12 5829584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 53248]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-08-29 143360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Uživatel\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [7.4.2010 21:07 114984]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [15.5.2008 13:07 61424]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [8.10.2010 21:12 67584]
R2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [8.10.2010 21:12 1125376]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [7.4.2010 21:07 810120]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16.11.2009 18:33 50704]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [6.7.2010 17:03 173352]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [11.3.2010 11:17 25088]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [17.9.2010 16:27 251904]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [17.9.2010 16:27 398720]
R4 sp_rsdrv2;Spyware Terminator Driver 2;\??\c:\windows\system32\drivers\sp_rsdrv2.sys --> c:\windows\system32\drivers\sp_rsdrv2.sys [?]
S4 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1.2.2010 18:47 135664]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - sp_rssrv
.
Obsah adresáře 'Naplánované úlohy'

2010-10-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2010-10-11 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-08-23 12:11]

2010-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 16:47]

2010-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 16:47]

2010-10-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 13:23]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=14597&l=dis
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=FF&o=14594&locale=en_EU&apn_uid=FACA4BBF-0CA6-4B14-9F96-DFCAC64D8A53&apn_ptnrs=FV&apn_sauid=6BB29463-E74E-4B34-997F-F48515CB1C97&apn_dtid=YYYYYYYYCZ&q=
FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-602162358-2139871995-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9E447679-0EE1-0509-60C3-895A89BE369C}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaonjggpcgdjjfibpkblihgofajhkm"=hex:61,69,69,64,68,70,6d,70,70,6f,65,65,62,6c,
6a,68,69,6b,6f,69,68,68,6c,70,70,68,66,6c,70,6b,6b,62,6b,63,6a,69,64,6a,70,\
"iajofaenkfifolblje"=hex:6a,61,66,64,64,64,6c,66,68,63,70,6f,62,6c,65,6c,6c,68,
6d,61,00,00
"hadolpjfclohfddf"=hex:6a,61,67,64,63,61,69,68,6b,69,62,70,65,6e,68,6e,70,6c,
6f,69,00,00
.
Celkový čas: 2010-10-11 18:04:39
ComboFix-quarantined-files.txt 2010-10-11 16:04

Před spuštěním: Volných bajtů: 171 239 759 872
Po spuštění: Volných bajtů: 171 216 789 504

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - D883CBC0AD8814DD76D407AC5B664BE7

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#13 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Driver::
    sp_rssrv
    
    File::
    C:\Documents and Settings\Uživatel\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
    c:\windows\Tasks\AppleSoftwareUpdate.job
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    
    Folder::
    c:\program files\Ask.com\
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"=-
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=14597&l=dis
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?clien ... YYYYYCZ&q=
    FF - component: c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\qje8yiac.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
    
    RegLock::
    [HKEY_USERS\S-1-5-21-602162358-2139871995-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9E447679-0EE1-0509-60C3-895A89BE369C}*]
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

maximix
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 201
Registrován: 15 zář 2006 17:22
Kontaktovat uživatele:

Re: Preventivka ( male problemy s ntb)

#14 Příspěvek od maximix »

ok provedu, jen se chci zeptat je v tom pc nejakej smejd co muze za vypinani obrazovky popr ty BSOD a zpomalene pc?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivka ( male problemy s ntb)

#15 Příspěvek od vyosek »

:arrow: za zpomaleni muze treba i ten Spyware Terminator - jelikoz se pere s ESETem

:arrow: Smejd je tam v podobe Ask.com

:arrow: Veci ohledne BSOD jsem poslal kolegovi, ktery se tim zabyva - byva vsak online spise az v noci, tak na to koukne...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět