facebook-pic000934519.exe IRC/Sdbot trojan

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
xyx
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 31 Led 2011 22:39

facebook-pic000934519.exe IRC/Sdbot trojan

#1 Příspěvek od xyx »

Prajem príjemný deň-noc.
ESET mi našiel a ,,odstránil" 2trojany facebook-pic000934519.exe IRC/Sdbot trojan a c:\users\public\nvcvc32.exe IRC/SdBot trojan.Dodávam, že účet public nepoužívam,a pravdepodobne treba PC prebehnúť aj CCCleaner-om.Ak treba aj log z Combofixu,spravím a prilepím zajtra.
Vopred v

  • Logfile of random's system information tool 1.08 (written by random/random)
    Run by Marek at 2011-01-31 22:53:02
    Microsoft Windows 7 Ultimate
    System drive C: has 33 GB (47%) free of 72 GB
    Total RAM: 3582 MB (68% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 22:53:04, on 31. 1. 2011
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16700)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe
    C:\Windows\DAODx.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
    C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
    C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\trend micro\Marek.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
    R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [NVIDIA driver monitor] c:\users\public\nvsvc32.exe
    O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - Unknown owner - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 8447 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    wininit.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    winlogon.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    atieclxx
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
    "taskhost.exe"
    "C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
    "C:\Windows\system32\Dwm.exe"
    "C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
    C:\Windows\Explorer.EXE
    taskeng.exe {BD2EF4DD-0746-4DCD-A7B9-A6112FC8A6E8}
    "C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe"
    C:\Windows\DAODx.exe
    "C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
    C:\Windows\system32\svchost.exe -k imgsvc
    "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
    "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
    "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
    "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    "C:\Program Files (x86)\Real\realplayer\Update\realsched.exe" -osboot
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\SearchIndexer.exe /Embedding
    "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
    "C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
    C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
    "C:\Users\Marek\Desktop\RSITx64.exe"

    ======Scheduled tasks folder======

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll [2010-10-31 317496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
    RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-11-13 382720]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
    Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-31 843832]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    aTube Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    {D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-01-29 10038304]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-07-02 2903688]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-10-31 39408]
    "DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
    "NVIDIA driver monitor"=c:\users\public\nvsvc32.exe []

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 98304]
    "BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-26 375000]
    "NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
    "JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]
    "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
    "TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2010-11-13 274608]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=5
    "ConsentPromptBehaviorUser"=3
    "EnableUIADesktopToggle"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    ======List of files/folders created in the last 1 months======

    2011-01-31 22:48:50 ----D---- C:\Program Files\trend micro
    2011-01-31 22:48:49 ----D---- C:\rsit
    2011-01-30 21:09:04 ----A---- C:\ekrn.exe
    2011-01-30 20:32:48 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
    2011-01-28 23:09:57 ----D---- C:\Program Files\CCleaner
    2011-01-27 00:47:46 ----D---- C:\Users\Marek\AppData\Roaming\vlc
    2011-01-14 01:50:43 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
    2011-01-14 01:50:43 ----A---- C:\Windows\system32\d3d10warp.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\DWrite.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\d2d1.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\XpsPrint.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\WMVDECOD.DLL
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\mf.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\FntCache.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\DWrite.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\d2d1.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\mf.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\d3d10_1core.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\XpsRasterService.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfreadwrite.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfps.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\d3d10_1.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\cdd.dll
    2011-01-14 01:50:34 ----A---- C:\Windows\SYSWOW64\odbc32.dll
    2011-01-14 01:50:34 ----A---- C:\Windows\system32\odbc32.dll
    2011-01-14 01:04:23 ----D---- C:\Program Files (x86)\ESET
    2011-01-14 00:55:38 ----D---- C:\Program Files (x86)\TNod User & Password Finder
    2011-01-09 17:25:39 ----D---- C:\Users\Marek\AppData\Roaming\dvdcss
    2011-01-09 01:15:25 ----D---- C:\Users\Marek\AppData\Roaming\Malwarebytes
    2011-01-09 01:15:14 ----D---- C:\ProgramData\Malwarebytes
    2011-01-09 01:15:14 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
    2011-01-09 01:15:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2011-01-09 01:15:11 ----A---- C:\Windows\system32\drivers\mbam.sys
    2011-01-05 00:34:30 ----SHD---- C:\$RECYCLE.BIN
    2011-01-05 00:29:30 ----D---- C:\Windows\temp
    2011-01-05 00:29:29 ----A---- C:\ComboFix.txt
    2011-01-05 00:23:28 ----A---- C:\Windows\zip.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\SWSC.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\SWREG.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\sed.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\PEV.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\NIRCMD.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\MBR.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\grep.exe
    2011-01-05 00:23:25 ----D---- C:\Windows\ERDNT
    2011-01-05 00:23:15 ----D---- C:\Qoobox
    2011-01-05 00:23:00 ----A---- C:\Windows\SWXCACLS.exe

    ======List of files/folders modified in the last 1 months======

    2011-01-31 22:48:58 ----D---- C:\Windows\Prefetch
    2011-01-31 22:48:50 ----RD---- C:\Program Files
    2011-01-31 22:40:49 ----D---- C:\Users\Marek\AppData\Roaming\Skype
    2011-01-31 22:29:26 ----D---- C:\Windows\system32\config
    2011-01-31 22:25:17 ----D---- C:\Windows\System32
    2011-01-31 22:25:17 ----D---- C:\Windows\inf
    2011-01-31 22:25:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2011-01-31 20:03:44 ----D---- C:\Users\Marek\AppData\Roaming\skypePM
    2011-01-30 20:54:33 ----D---- C:\Windows\system32\Tasks
    2011-01-30 20:32:48 ----D---- C:\ProgramData
    2011-01-30 13:31:43 ----D---- C:\Windows\system32\catroot2
    2011-01-30 01:48:27 ----SHD---- C:\System Volume Information
    2011-01-30 01:43:43 ----RD---- C:\Program Files (x86)
    2011-01-16 20:35:29 ----SHD---- C:\Windows\Installer
    2011-01-14 02:07:25 ----D---- C:\Windows\SysWOW64
    2011-01-14 02:07:22 ----D---- C:\Windows\winsxs
    2011-01-14 01:56:10 ----D---- C:\Windows\system32\drivers
    2011-01-14 01:51:39 ----A---- C:\Windows\system32\MRT.exe
    2011-01-14 01:50:29 ----D---- C:\Windows\system32\catroot
    2011-01-14 00:53:24 ----D---- C:\Windows
    2011-01-11 13:32:39 ----SD---- C:\Users\Marek\AppData\Roaming\Microsoft
    2011-01-10 17:50:33 ----D---- C:\Users\Marek\AppData\Roaming\XnView
    2011-01-09 01:15:14 ----D---- C:\Windows\SYSWOW64\drivers
    2011-01-05 22:53:03 ----D---- C:\Program Files (x86)\TC UP 5 2
    2011-01-05 00:28:50 ----D---- C:\Windows\Tasks
    2011-01-05 00:27:12 ----A---- C:\Windows\system.ini
    2011-01-05 00:25:49 ----D---- C:\Windows\AppPatch
    2011-01-05 00:25:49 ----D---- C:\Program Files\Common Files
    2011-01-05 00:25:49 ----D---- C:\Program Files (x86)\Common Files

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
    R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-11 115824]
    R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
    R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-02 834544]
    R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
    R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
    R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 139704]
    R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 166984]
    R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-28 169592]
    R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 50600]
    R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-10 6368256]
    R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-10 188416]
    R3 AODDriver;AODDriver; \??\C:\Program Files (x86)\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
    R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
    R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-28 33608]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-01-29 2260256]
    R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
    R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-05-31 333928]
    R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
    S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2009-10-25 23552]
    S3 ayroassp;ayroassp; C:\Windows\system32\drivers\ayroassp.sys []
    S3 cpuz130;cpuz130; \??\C:\Users\Marek\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
    S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
    S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
    S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
    S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
    S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-10 202752]
    R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-26 223464]
    R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
    R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-07-02 810144]
    R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
    R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-31 136176]
    S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe []
    S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
    S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-07-02 42360]
    S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-10-31 182768]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
    S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
    S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

    -----------------EOF-----------------

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#2 Příspěvek od JaRon »

O4 - HKCU\..\Run: [NVIDIA driver monitor] c:\users\public\nvsvc32.exe
FIXni v HijackThis - restart a dalsi log RSIT
:idea: ak ho zasa vlozis v tej svetlomodrej farbe, tak si ho asi budes luskat sam ,,,
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

xyx
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 31 Led 2011 22:39

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#3 Příspěvek od xyx »

fixol som to,a už ho(nvsvc32.exe)nevidim.Všimol som si ešte v logu S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe [].Mal som s tým v decembri problémy,a teraz ho vidím znovu.Akurat mi nejde dohlavy že som ho musel najsť v logu ja sam.A ESET ho ma v ... ?.A vo vynimkach nie je určite.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Marek at 2011-02-01 21:18:32
Microsoft Windows 7 Ultimate
System drive C: has 35 GB (49%) free of 72 GB
Total RAM: 3582 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:18:35, on 1. 2. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe
C:\Windows\DAODx.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
C:\Program Files\trend micro\Marek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - Unknown owner - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8318 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
taskeng.exe {011A0633-77A3-4D10-B21E-AD37E58F6FE5}
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"taskhost.exe"
taskeng.exe {A5B328D3-0AAE-46D3-ADA5-D6B707F7FBE8}
taskeng.exe {EA433F32-77F7-4E58-9EAD-78ACE6B4B1D7}
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe"
C:\Windows\DAODx.exe
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Real\realplayer\Update\realsched.exe" -osboot
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Marek\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll [2010-10-31 317496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-11-13 382720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-31 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-01-29 10038304]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-07-02 2903688]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-10-31 39408]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 98304]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-26 375000]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2010-11-13 274608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-01-31 22:48:50 ----D---- C:\Program Files\trend micro
2011-01-31 22:48:49 ----D---- C:\rsit
2011-01-30 21:09:04 ----A---- C:\ekrn.exe
2011-01-30 20:32:48 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2011-01-28 23:09:57 ----D---- C:\Program Files\CCleaner
2011-01-27 00:47:46 ----D---- C:\Users\Marek\AppData\Roaming\vlc
2011-01-14 01:50:43 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-14 01:50:43 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-01-14 01:50:42 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-14 01:50:42 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-14 01:50:42 ----A---- C:\Windows\system32\mf.dll
2011-01-14 01:50:42 ----A---- C:\Windows\system32\FntCache.dll
2011-01-14 01:50:42 ----A---- C:\Windows\system32\DWrite.dll
2011-01-14 01:50:42 ----A---- C:\Windows\system32\d2d1.dll
2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-01-14 01:50:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-14 01:50:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-14 01:50:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-14 01:50:41 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-14 01:50:40 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfps.dll
2011-01-14 01:50:40 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-14 01:50:40 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-14 01:50:40 ----A---- C:\Windows\system32\cdd.dll
2011-01-14 01:50:34 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-14 01:50:34 ----A---- C:\Windows\system32\odbc32.dll
2011-01-14 01:04:23 ----D---- C:\Program Files (x86)\ESET
2011-01-14 00:55:38 ----D---- C:\Program Files (x86)\TNod User & Password Finder
2011-01-09 17:25:39 ----D---- C:\Users\Marek\AppData\Roaming\dvdcss
2011-01-09 01:15:25 ----D---- C:\Users\Marek\AppData\Roaming\Malwarebytes
2011-01-09 01:15:14 ----D---- C:\ProgramData\Malwarebytes
2011-01-09 01:15:14 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-01-09 01:15:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-01-09 01:15:11 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-01-05 00:34:30 ----SHD---- C:\$RECYCLE.BIN
2011-01-05 00:29:30 ----D---- C:\Windows\temp
2011-01-05 00:29:29 ----A---- C:\ComboFix.txt
2011-01-05 00:23:28 ----A---- C:\Windows\zip.exe
2011-01-05 00:23:28 ----A---- C:\Windows\SWSC.exe
2011-01-05 00:23:28 ----A---- C:\Windows\SWREG.exe
2011-01-05 00:23:28 ----A---- C:\Windows\sed.exe
2011-01-05 00:23:28 ----A---- C:\Windows\PEV.exe
2011-01-05 00:23:28 ----A---- C:\Windows\NIRCMD.exe
2011-01-05 00:23:28 ----A---- C:\Windows\MBR.exe
2011-01-05 00:23:28 ----A---- C:\Windows\grep.exe
2011-01-05 00:23:25 ----D---- C:\Windows\ERDNT
2011-01-05 00:23:15 ----D---- C:\Qoobox
2011-01-05 00:23:00 ----A---- C:\Windows\SWXCACLS.exe

======List of files/folders modified in the last 1 months======

2011-02-01 21:18:09 ----D---- C:\Windows\system32\config
2011-02-01 21:04:33 ----D---- C:\Windows\Prefetch
2011-02-01 20:41:40 ----D---- C:\Users\Marek\AppData\Roaming\Skype
2011-02-01 20:28:26 ----D---- C:\Users\Marek\AppData\Roaming\skypePM
2011-02-01 15:54:45 ----D---- C:\Windows\System32
2011-02-01 15:54:44 ----D---- C:\Windows\inf
2011-02-01 15:54:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-01 10:06:56 ----SHD---- C:\System Volume Information
2011-01-31 22:48:50 ----RD---- C:\Program Files
2011-01-30 20:54:33 ----D---- C:\Windows\system32\Tasks
2011-01-30 20:32:48 ----D---- C:\ProgramData
2011-01-30 13:31:43 ----D---- C:\Windows\system32\catroot2
2011-01-30 01:43:43 ----RD---- C:\Program Files (x86)
2011-01-16 20:35:29 ----SHD---- C:\Windows\Installer
2011-01-14 02:07:25 ----D---- C:\Windows\SysWOW64
2011-01-14 02:07:22 ----D---- C:\Windows\winsxs
2011-01-14 01:56:10 ----D---- C:\Windows\system32\drivers
2011-01-14 01:51:39 ----A---- C:\Windows\system32\MRT.exe
2011-01-14 01:50:29 ----D---- C:\Windows\system32\catroot
2011-01-14 00:53:24 ----D---- C:\Windows
2011-01-11 13:32:39 ----SD---- C:\Users\Marek\AppData\Roaming\Microsoft
2011-01-10 17:50:33 ----D---- C:\Users\Marek\AppData\Roaming\XnView
2011-01-09 01:15:14 ----D---- C:\Windows\SYSWOW64\drivers
2011-01-05 22:53:03 ----D---- C:\Program Files (x86)\TC UP 5 2
2011-01-05 00:28:50 ----D---- C:\Windows\Tasks
2011-01-05 00:27:12 ----A---- C:\Windows\system.ini
2011-01-05 00:25:49 ----D---- C:\Windows\AppPatch
2011-01-05 00:25:49 ----D---- C:\Program Files\Common Files
2011-01-05 00:25:49 ----D---- C:\Program Files (x86)\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-11 115824]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-02 834544]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 139704]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 166984]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-28 169592]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 50600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-10 6368256]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-10 188416]
R3 AODDriver;AODDriver; \??\C:\Program Files (x86)\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-28 33608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-01-29 2260256]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-05-31 333928]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2009-10-25 23552]
S3 a171z7xl;a171z7xl; C:\Windows\system32\drivers\a171z7xl.sys []
S3 cpuz130;cpuz130; \??\C:\Users\Marek\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-10 202752]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-26 223464]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-07-02 810144]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-31 136176]
S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-07-02 42360]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-10-31 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

xyx
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 31 Led 2011 22:39

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#4 Příspěvek od xyx »

Ospravedlňujem sa,ale to farebne zvýrazňovanie mi nejak nejde.Asi s tym zvýrazňovaním prestanem.
P.S.:Riešite na tomto fóre aj BLUESCREENy?.Mal som 4x,všetky 0x00...116-tky.A asi by to mala byť nová téma.Stručný výpis z bluescren view:

111610-15631-01.dmp 16. 11. 2010 2:46:38 0x00000116 fffffa80`0360d4e0 fffff880`03e75fcc ffffffff`c0000001 00000000`00000003 dxgkrnl.sys dxgkrnl.sys+5cef8 x64 C:\Windows\minidump\111610-15631-01.dmp 4 15 7600
111610-15834-01.dmp 16. 11. 2010 2:12:56 0x00000116 fffffa80`035c70d0 fffff880`03fb2fcc ffffffff`c0000001 00000000`00000003 dxgkrnl.sys dxgkrnl.sys+5cef8 x64 C:\Windows\minidump\111610-15834-01.dmp 4 15 7600
120210-15880-01.dmp 2. 12. 2010 1:39:27 0x00000116 fffffa80`0448a4e0 fffff880`03e75fcc ffffffff`c0000001 00000000`00000003 dxgkrnl.sys dxgkrnl.sys+5cef8 x64 C:\Windows\minidump\120210-15880-01.dmp 4 15 7600

Takmer rovnake výpisy sú hodnotené ako chyba grafiky alebo nekompatibilita grafiky s hardwarom.Grafika je však vstavaná,a PC ma iba 4mesiace.

A tá zaujímavá vec,kt. bud súvisí s týmto fórom-stránkou,alebo je to extrémna náhoda,alebo znamenie zhora:
Pri všetkých 4xbluscrenoch som vykonával rovnakú činnosť: vlc.exe,plugin adobe flash player,Mozilla Firefox, a hlavne otvorené 3rovnaké web stránky.
Stránky sú 18+ a s menšou dôveryhodnosťou.URL zatiaľ nedávam.Odvtedy na tie url nechodim a nové bluscreeny niesu.

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#5 Příspěvek od JaRon »

R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
FIXni v HijackThis
+
prescanuj PC s MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

xyx
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 31 Led 2011 22:39

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#6 Příspěvek od xyx »

Log mbab je uplne čisty tak ho nedavam.Subor-proces-bordel: O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - Unknown owner - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe (file missing) je tu ešte stále.
Poprosím aj o názor na Bluescreen,alebo radu na koho(kde) sa obratiť.
  • Logfile of random's system information tool 1.08 (written by random/random)
    Run by Marek at 2011-02-02 15:20:40
    Microsoft Windows 7 Ultimate
    System drive C: has 35 GB (49%) free of 72 GB
    Total RAM: 3582 MB (54% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 15:20:44, on 2. 2. 2011
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16700)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
    C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe
    C:\Windows\DAODx.exe
    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
    C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
    C:\Program Files\trend micro\Marek.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - Unknown owner - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 7888 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    wininit.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    winlogon.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    atieclxx
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
    "C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
    "C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
    "C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
    "C:\Windows\system32\Dwm.exe"
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe -k imgsvc
    "taskhost.exe"
    "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
    "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    taskeng.exe {F06BE058-A349-42A5-BA5E-C60A5E4602FC}
    "C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe"
    C:\Windows\DAODx.exe
    "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
    "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
    "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    "C:\Program Files (x86)\Real\realplayer\Update\realsched.exe" -osboot
    C:\Windows\system32\SearchIndexer.exe /Embedding
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    "C:\Windows\System32\taskmgr.exe"
    "C:\Users\Marek\Desktop\RSITx64.exe"

    ======Scheduled tasks folder======

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll [2010-10-31 317496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
    RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-11-13 382720]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
    Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-31 843832]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-05 399536]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-05 297648]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-01-29 10038304]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-07-02 2903688]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-10-31 39408]
    "DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 98304]
    "BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-26 375000]
    "NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
    "JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]
    "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
    "TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2010-11-13 274608]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=5
    "ConsentPromptBehaviorUser"=3
    "EnableUIADesktopToggle"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    ======List of files/folders created in the last 1 months======

    2011-02-02 14:43:50 ----D---- C:\Program Files (x86)\Trend Micro
    2011-01-31 22:48:50 ----D---- C:\Program Files\trend micro
    2011-01-31 22:48:49 ----D---- C:\rsit
    2011-01-30 21:09:04 ----A---- C:\ekrn.exe
    2011-01-30 20:32:48 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
    2011-01-28 23:09:57 ----D---- C:\Program Files\CCleaner
    2011-01-27 00:47:46 ----D---- C:\Users\Marek\AppData\Roaming\vlc
    2011-01-14 01:50:43 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
    2011-01-14 01:50:43 ----A---- C:\Windows\system32\d3d10warp.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\DWrite.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\SYSWOW64\d2d1.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\XpsPrint.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\WMVDECOD.DLL
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\mf.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\FntCache.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\DWrite.dll
    2011-01-14 01:50:42 ----A---- C:\Windows\system32\d2d1.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
    2011-01-14 01:50:41 ----A---- C:\Windows\SYSWOW64\mf.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
    2011-01-14 01:50:41 ----A---- C:\Windows\system32\d3d10_1core.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\XpsRasterService.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfreadwrite.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\mfps.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\d3d10_1.dll
    2011-01-14 01:50:40 ----A---- C:\Windows\system32\cdd.dll
    2011-01-14 01:50:34 ----A---- C:\Windows\SYSWOW64\odbc32.dll
    2011-01-14 01:50:34 ----A---- C:\Windows\system32\odbc32.dll
    2011-01-14 01:04:23 ----D---- C:\Program Files (x86)\ESET
    2011-01-14 00:55:38 ----D---- C:\Program Files (x86)\TNod User & Password Finder
    2011-01-09 17:25:39 ----D---- C:\Users\Marek\AppData\Roaming\dvdcss
    2011-01-09 01:15:25 ----D---- C:\Users\Marek\AppData\Roaming\Malwarebytes
    2011-01-09 01:15:14 ----D---- C:\ProgramData\Malwarebytes
    2011-01-09 01:15:14 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
    2011-01-09 01:15:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2011-01-09 01:15:11 ----A---- C:\Windows\system32\drivers\mbam.sys
    2011-01-05 00:34:30 ----SHD---- C:\$RECYCLE.BIN
    2011-01-05 00:29:30 ----D---- C:\Windows\temp
    2011-01-05 00:29:29 ----A---- C:\ComboFix.txt
    2011-01-05 00:23:28 ----A---- C:\Windows\zip.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\SWSC.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\SWREG.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\sed.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\PEV.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\NIRCMD.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\MBR.exe
    2011-01-05 00:23:28 ----A---- C:\Windows\grep.exe
    2011-01-05 00:23:25 ----D---- C:\Windows\ERDNT
    2011-01-05 00:23:15 ----D---- C:\Qoobox
    2011-01-05 00:23:00 ----A---- C:\Windows\SWXCACLS.exe

    ======List of files/folders modified in the last 1 months======

    2011-02-02 15:10:41 ----D---- C:\Windows\Prefetch
    2011-02-02 14:56:20 ----D---- C:\Windows\System32
    2011-02-02 14:56:20 ----D---- C:\Windows\inf
    2011-02-02 14:56:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2011-02-02 14:52:23 ----D---- C:\Windows\system32\config
    2011-02-02 14:43:51 ----SHD---- C:\Windows\Installer
    2011-02-02 14:43:50 ----RD---- C:\Program Files (x86)
    2011-02-02 14:43:42 ----SHD---- C:\System Volume Information
    2011-02-01 20:41:40 ----D---- C:\Users\Marek\AppData\Roaming\Skype
    2011-02-01 20:28:26 ----D---- C:\Users\Marek\AppData\Roaming\skypePM
    2011-01-31 22:48:50 ----RD---- C:\Program Files
    2011-01-30 20:54:33 ----D---- C:\Windows\system32\Tasks
    2011-01-30 20:32:48 ----D---- C:\ProgramData
    2011-01-30 13:31:43 ----D---- C:\Windows\system32\catroot2
    2011-01-14 02:07:25 ----D---- C:\Windows\SysWOW64
    2011-01-14 02:07:22 ----D---- C:\Windows\winsxs
    2011-01-14 01:56:10 ----D---- C:\Windows\system32\drivers
    2011-01-14 01:51:39 ----A---- C:\Windows\system32\MRT.exe
    2011-01-14 01:50:29 ----D---- C:\Windows\system32\catroot
    2011-01-14 00:53:24 ----D---- C:\Windows
    2011-01-11 13:32:39 ----SD---- C:\Users\Marek\AppData\Roaming\Microsoft
    2011-01-10 17:50:33 ----D---- C:\Users\Marek\AppData\Roaming\XnView
    2011-01-09 01:15:14 ----D---- C:\Windows\SYSWOW64\drivers
    2011-01-05 22:53:03 ----D---- C:\Program Files (x86)\TC UP 5 2
    2011-01-05 00:28:50 ----D---- C:\Windows\Tasks
    2011-01-05 00:27:12 ----A---- C:\Windows\system.ini
    2011-01-05 00:25:49 ----D---- C:\Windows\AppPatch
    2011-01-05 00:25:49 ----D---- C:\Program Files\Common Files
    2011-01-05 00:25:49 ----D---- C:\Program Files (x86)\Common Files

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
    R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-11 115824]
    R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
    R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-02 834544]
    R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
    R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
    R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 139704]
    R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 166984]
    R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-28 169592]
    R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 50600]
    R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-10 6368256]
    R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-10 188416]
    R3 AODDriver;AODDriver; \??\C:\Program Files (x86)\ASUS\GPU Boost Driver\amd64\AODDriver.sys [2010-03-12 52280]
    R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
    R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-28 33608]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-01-29 2260256]
    R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
    R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-05-31 333928]
    R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
    S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2009-10-25 23552]
    S3 a9a92h4p;a9a92h4p; C:\Windows\system32\drivers\a9a92h4p.sys []
    S3 cpuz130;cpuz130; \??\C:\Users\Marek\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
    S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
    S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
    S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
    S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
    S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-10 202752]
    R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-26 223464]
    R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
    R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-07-02 810144]
    R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
    R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-31 136176]
    S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe []
    S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
    S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-07-02 42360]
    S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-10-31 182768]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
    S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
    S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

    -----------------EOF-----------------

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: facebook-pic000934519.exe IRC/Sdbot trojan

#7 Příspěvek od JaRon »

spusti s prikazoveho riadku services.msc
tam najdi sluzbu a nastav ju na zakazanu:
SmileyCentral_1vService
+
co sa tyka bluscreen skus preinstalovat ovladace GK
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět