Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s virem Security tool

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Davefin
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 01 říj 2010 18:14

Problém s virem Security tool

#1 Příspěvek od Davefin »

Nazdarte,

spolužákovi se podařilo dostat si do počítače vir Security tool - nechápu, nemá antivir, firewall, nic - ale to je offtopic.
Problém je, že v normálním módu neudělám vůbec nic - Security tool všechno zablokuje a řekne že je virus - a ted jsem v nouzovym režimu, ale RSIT nejde.
Stáhnul jsem CCleaner a Comodo (v nouzáku), CCleaner nainstalován, pročištěno, registry, startup divný věci smazaný - ale Comodo se nenainstaluje, v normálnim módu to Security tool blokne a v nouzáku to hází chybu že potřebuje normální mód.
Snažil jsem se vytvořit log z RSIT - ale na "Running HijackThis" se to vždycky sekne - jako by to Security tool blokoval.

Co mám dělat? Win7 starter, netbook, žádnej antivir atd...
Předem díky za každou pomoc.
//EDIT: JÁ BLBEC ZAPOMNĚL NA "SPUSTIT JAKO SPRÁVCE", NEJSEM ZVYKLEJ NA WIN7. TAKŽE TEĎ TO BĚŽÍ, JÁ JDU ZATÍM NA OBĚD, PAK SEM HODÍM LOG. DÍKY.

_______________log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Adam at 2010-11-03 12:24:38
Microsoft Windows 7 Starter
System drive C: has 80 GB (78%) free of 102 GB
Total RAM: 1014 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:25:03, on 3.11.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Safe mode with network support

Running processes:
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\explorer.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\explorer.exe
C:\Users\Adam\Downloads\RSIT.exe
C:\Program Files\trend micro\Adam.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe autorun
O4 - HKLM\..\Run: [LiveUpdate] AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [EeeSplendidAgent] C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe
O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [LivCam] "C:\Program Files\ASUS\LivCam\LivCam.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [ASUSPRP] C:\Program Files\ASUS\APRP\APRP.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files\ASUS\ASUS WebStorage\2.2.56.108\ASUSWSDashBoard.exe /S
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: x-owacid - {0215258F-F0A8-49DE-BF1B-0FF02EDA8807} - C:\Program Files\Microsoft\Outlook Web Access SMIME Client\mimectl.dll
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) - Unknown owner - C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe

--
End of file - 7675 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
MyWebSearch Search Assistant BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL [2010-10-11 54704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
mwsBar BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2010-10-11 775696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-05 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-06-10 1233288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-06-10 1233288]
{07B18EA9-A523-4961-B6BB-170DE4475CCA} - My Web Search - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2010-10-11 775696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-20 1545512]
"HotkeyMon"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe []
"HotkeyService"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe []
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-11-17 414384]
"LiveUpdate"=AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto []
"EeeSplendidAgent"=C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe [2009-12-30 104960]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-07-20 83240]
"ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2010-01-18 3058304]
"LivCam"=C:\Program Files\ASUS\LivCam\LivCam.exe [2009-11-19 284160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-09-29 7744032]
"ASUSPRP"=C:\Program Files\ASUS\APRP\APRP.EXE [2010-01-18 2018032]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2010-04-19 141848]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2010-04-19 173592]
"Persistence"=C:\windows\system32\igfxpers.exe [2010-04-19 150552]
"ASUSWebStorage"=C:\Program Files\ASUS\ASUS WebStorage\2.2.56.108\ASUSWSDashBoard.exe [2010-09-01 5096784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2010-04-19 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-11-03 11:39:20 ----D---- C:\ProgramData\Comodo
2010-11-03 11:39:04 ----D---- C:\ProgramData\Comodo Downloader
2010-11-03 11:37:55 ----D---- C:\rsit
2010-11-03 11:31:24 ----D---- C:\Program Files\CCleaner
2010-11-01 17:54:03 ----D---- C:\Users\Adam\AppData\Roaming\skypePM
2010-11-01 17:50:27 ----D---- C:\Users\Adam\AppData\Roaming\Skype
2010-10-27 07:50:57 ----A---- C:\windows\system32\CPFilters.dll
2010-10-27 07:50:51 ----A---- C:\windows\system32\drivers\Diskdump.sys
2010-10-24 21:12:29 ----A---- C:\Users\Adam\AppData\Roaming\Adam3SQLite3.dll
2010-10-24 21:11:42 ----A---- C:\windows\AutoKMS.exe
2010-10-22 19:03:16 ----D---- C:\windows\cs
2010-10-22 19:02:44 ----A---- C:\windows\system32\drivers\fssfltr.sys
2010-10-22 18:57:37 ----A---- C:\windows\system32\XAudio2_5.dll
2010-10-22 18:57:37 ----A---- C:\windows\system32\XAPOFX1_3.dll
2010-10-22 18:57:37 ----A---- C:\windows\system32\d3dx10_42.dll
2010-10-22 17:26:04 ----A---- C:\windows\system32\mfreadwrite.dll
2010-10-22 17:26:04 ----A---- C:\windows\system32\mf.dll
2010-10-22 17:26:02 ----A---- C:\windows\system32\WMVDECOD.DLL
2010-10-14 10:06:24 ----A---- C:\windows\system32\wmpmde.dll
2010-10-14 10:06:23 ----A---- C:\windows\system32\StructuredQuery.dll
2010-10-14 10:06:22 ----A---- C:\windows\system32\ole32.dll
2010-10-14 10:06:19 ----A---- C:\windows\system32\iertutil.dll
2010-10-14 10:06:18 ----A---- C:\windows\system32\mshtml.dll
2010-10-14 10:06:16 ----A---- C:\windows\system32\ieframe.dll
2010-10-14 10:06:15 ----A---- C:\windows\system32\wininet.dll
2010-10-14 10:06:15 ----A---- C:\windows\system32\urlmon.dll
2010-10-14 10:06:15 ----A---- C:\windows\system32\msfeeds.dll
2010-10-14 10:06:15 ----A---- C:\windows\system32\licmgr10.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\mstime.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\mshtmled.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\msfeedssync.exe
2010-10-14 10:06:14 ----A---- C:\windows\system32\msfeedsbs.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\jsproxy.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\ieui.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\iepeers.dll
2010-10-14 10:06:14 ----A---- C:\windows\system32\iedkcs32.dll
2010-10-14 10:06:03 ----A---- C:\windows\system32\t2embed.dll
2010-10-14 10:04:04 ----A---- C:\windows\system32\schannel.dll
2010-10-14 09:18:34 ----A---- C:\windows\system32\comctl32.dll
2010-10-14 09:18:28 ----A---- C:\windows\system32\mfc40u.dll
2010-10-14 09:18:28 ----A---- C:\windows\system32\mfc40.dll
2010-10-14 09:17:59 ----A---- C:\windows\system32\wmp.dll
2010-10-14 09:17:56 ----A---- C:\windows\system32\wmploc.DLL
2010-10-14 09:13:38 ----A---- C:\windows\system32\win32k.sys
2010-10-14 09:13:36 ----A---- C:\windows\system32\srvsvc.dll
2010-10-14 09:13:36 ----A---- C:\windows\system32\drivers\srvnet.sys
2010-10-14 09:13:36 ----A---- C:\windows\system32\drivers\srv2.sys
2010-10-14 09:13:36 ----A---- C:\windows\system32\drivers\srv.sys
2010-10-11 19:39:27 ----D---- C:\Program Files\Microsoft Silverlight
2010-10-11 19:38:11 ----D---- C:\windows\system32\x64
2010-10-11 19:28:15 ----A---- C:\windows\system32\drivers\sffp_sd.sys
2010-10-11 10:07:48 ----D---- C:\Program Files\FunWebProducts
2010-10-11 10:07:45 ----D---- C:\Program Files\MyWebSearch
2010-10-09 07:09:16 ----D---- C:\windows\system32\log
2010-10-08 22:14:20 ----A---- C:\windows\system32\MRT.exe
2010-10-07 12:24:27 ----D---- C:\windows\system32\Service
2010-10-06 20:40:43 ----D---- C:\Program Files\Ask.com
2010-10-06 20:39:06 ----D---- C:\Users\Adam\AppData\Roaming\uTorrent

======List of files/folders modified in the last 1 months======

2010-11-03 19:55:04 ----D---- C:\windows\Tasks
2010-11-03 19:55:04 ----D---- C:\windows\system32\wfp
2010-11-03 19:55:04 ----D---- C:\windows\system32\wbem
2010-11-03 19:55:04 ----D---- C:\windows\system32\DriverStore
2010-11-03 19:55:04 ----D---- C:\windows\system32\catroot2
2010-11-03 19:55:03 ----D---- C:\windows\system32\drivers
2010-11-03 19:55:03 ----D---- C:\windows\system32\CodeIntegrity
2010-11-03 19:55:01 ----D---- C:\windows\registration
2010-11-03 19:53:24 ----SHD---- C:\System Volume Information
2010-11-03 19:51:32 ----D---- C:\windows\system32\LogFiles
2010-11-03 12:25:04 ----D---- C:\windows\Temp
2010-11-03 12:25:03 ----D---- C:\Program Files\Trend Micro
2010-11-03 11:39:20 ----HD---- C:\ProgramData
2010-11-03 11:36:32 ----D---- C:\windows\debug
2010-11-03 11:36:32 ----D---- C:\Windows
2010-11-03 11:31:24 ----RD---- C:\Program Files
2010-11-03 11:21:26 ----D---- C:\windows\system32\config
2010-11-03 11:15:30 ----D---- C:\windows\System32
2010-11-03 11:15:30 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-11-03 11:15:29 ----D---- C:\windows\inf
2010-11-01 19:50:06 ----D---- C:\windows\system32\Tasks
2010-11-01 19:47:49 ----HD---- C:\usxxxxxxxx.exe
2010-10-31 20:40:58 ----SHD---- C:\windows\Installer
2010-10-30 11:21:44 ----D---- C:\windows\winsxs
2010-10-30 11:21:37 ----D---- C:\windows\AppPatch
2010-10-30 11:18:17 ----D---- C:\Program Files\Mozilla Firefox
2010-10-27 07:50:42 ----D---- C:\windows\system32\catroot
2010-10-23 19:31:58 ----D---- C:\Program Files\Microsoft
2010-10-23 11:50:38 ----D---- C:\windows\Microsoft.NET
2010-10-23 11:48:13 ----RSD---- C:\windows\assembly
2010-10-22 19:03:25 ----D---- C:\Program Files\Windows Live
2010-10-22 19:02:46 ----DC---- C:\windows\system32\DRVSTORE
2010-10-22 18:59:34 ----SD---- C:\ProgramData\Microsoft
2010-10-22 18:58:57 ----D---- C:\Program Files\Common Files\microsoft shared
2010-10-22 18:57:31 ----D---- C:\windows\Logs
2010-10-22 18:57:08 ----D---- C:\windows\SoftwareDistribution
2010-10-22 17:23:17 ----D---- C:\Users\Adam\AppData\Roaming\ASUS WebStorage
2010-10-22 17:09:21 ----D---- C:\windows\system32\migration
2010-10-22 17:09:21 ----D---- C:\Program Files\Internet Explorer
2010-10-22 17:09:20 ----D---- C:\Program Files\Windows Media Player
2010-10-22 16:56:50 ----D---- C:\ProgramData\Microsoft Help
2010-10-19 10:41:44 ----A---- C:\windows\system32\MpSigStub.exe
2010-10-14 17:59:05 ----D---- C:\windows\Prefetch
2010-10-11 20:36:56 ----SD---- C:\Users\Adam\AppData\Roaming\Microsoft
2010-10-11 19:36:57 ----D---- C:\windows\system32\cs-CZ
2010-10-11 19:29:50 ----D---- C:\windows\system32\en-US
2010-10-11 19:29:42 ----D---- C:\Program Files\Microsoft.NET
2010-10-11 09:01:56 ----D---- C:\windows\system32\NDF
2010-10-09 07:12:57 ----D---- C:\windows\rescache
2010-10-08 22:21:14 ----D---- C:\Program Files\Windows Sidebar
2010-10-08 22:21:13 ----D---- C:\Program Files\Windows Mail
2010-10-08 22:21:13 ----D---- C:\Program Files\DVD Maker
2010-10-08 22:21:12 ----D---- C:\windows\servicing
2010-10-08 22:21:12 ----D---- C:\Program Files\Windows Photo Viewer
2010-10-08 22:21:12 ----D---- C:\Program Files\Windows Defender
2010-10-08 22:21:12 ----D---- C:\Program Files\Common Files\System
2010-10-08 22:21:11 ----D---- C:\windows\system32\winrm
2010-10-08 22:21:11 ----D---- C:\windows\system32\sysprep
2010-10-08 22:21:11 ----D---- C:\windows\system32\slmgr
2010-10-08 22:21:11 ----D---- C:\windows\system32\sk-SK
2010-10-08 22:21:11 ----D---- C:\windows\system32\oobe
2010-10-08 22:21:11 ----D---- C:\windows\system32\migwiz
2010-10-08 22:21:11 ----D---- C:\windows\system32\en
2010-10-08 22:21:11 ----D---- C:\windows\system32\Boot
2010-10-08 22:21:11 ----D---- C:\windows\en-US
2010-10-08 22:21:03 ----D---- C:\windows\system32\drivers\en-US
2010-10-08 22:20:53 ----D---- C:\windows\system32\WCN
2010-10-08 22:20:53 ----D---- C:\windows\system32\Dism
2010-10-08 22:20:49 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-10-08 22:20:32 ----D---- C:\windows\IME
2010-10-08 22:20:31 ----D---- C:\windows\system32\XPSViewer
2010-10-08 22:20:31 ----D---- C:\windows\PolicyDefinitions
2010-10-08 22:20:30 ----D---- C:\windows\system32\MUI
2010-10-08 22:20:30 ----D---- C:\windows\system32\drivers\UMDF
2010-10-08 22:20:26 ----D---- C:\windows\system32\pl-PL
2010-10-08 22:20:06 ----D---- C:\windows\system32\com
2010-10-08 22:19:43 ----D---- C:\windows\system32\hu-HU
2010-10-08 22:18:54 ----D---- C:\windows\Speech
2010-10-04 08:36:43 ----D---- C:\windows\system32\wdi

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2009-07-20 213552]
S1 AsUpIO;AsUpIO; C:\windows\system32\drivers\AsUpIO.sys [2009-07-06 11448]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 43944]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-07-01 86056]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2009-07-01 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-07-01 18344]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-22 39272]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2010-04-19 4806144]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHDA.sys [2009-09-29 2776672]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 AsusService;Asus Launcher Service; C:\Windows\System32\AsusService.exe [2009-08-19 219136]
S2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-08-03 582944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
S2 MyWebSearchService;My Web Search Service; C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe [2010-10-11 28762]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
S2 OberonGameConsoleService;Oberon Media Game Console service; C:\Program Files\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [2009-09-15 44312]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
S2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15670
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Problém s virem Security tool

#2 Příspěvek od JaRon »

ahoj,
najprv odinstaluj smejdov:
Ask Toolbar
My Web Search
potom vycisti s MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Davefin
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 01 říj 2010 18:14

Re: Problém s virem Security tool

#3 Příspěvek od Davefin »

Ok, díky, mám to tim MBAM rovnou mazat, nebo sem hodit log a počkat na tvůj názor?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem Security tool

#4 Příspěvek od motji »

Dobrý večer, záskok za kolegu :) .
Vložte zde raději napřed log :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Davefin
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 01 říj 2010 18:14

Re: Problém s virem Security tool

#5 Příspěvek od Davefin »

Tak pc už vypadá čistě, nakonec na MBAM nedošlo, spolužák už je pryč a už na tom normálně funguje. Kdyby se něco ještě dělo, hodím sem do novýho threadu log, zatím lock a díky :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem Security tool

#6 Příspěvek od motji »

:)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět