AdminHPR?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
jiri25
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 Črc 2010 07:04

Re: AdminHPR?

#16 Příspěvek od jiri25 »

nechal jsem to proběhnout a byly tam same 0/0/0 0/0/0 bez infekce mam tedy nechat udělat ještě nový log z combofixu?

Avatar uživatele
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 Říj 2004 07:00
Místo/Bydliště: České Budějovice
Kontaktovat uživatele:

Re: AdminHPR?

#17 Příspěvek od riffman »

ano :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

jiri25
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 Črc 2010 07:04

Re: AdminHPR?

#18 Příspěvek od jiri25 »

vkládám log

ComboFix 10-07-15.03 - jiri25 19.07.2010 7:01.3.2 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1428 [GMT 2:00]
Spuštěný z: c:\documents and settings\jiri25\Plocha\comfic.exe
AV: AVG Anti-Virus Network Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-06-19 do 2010-07-19 )))))))))))))))))))))))))))))))
.

2010-07-19 04:52 . 2010-06-30 15:25 1013584 ----a-w- c:\windows\system32\drivers\TDSSKiller.exe
2010-07-17 15:25 . 2010-07-17 15:25 -------- d-----w- C:\comfic
2010-07-16 05:06 . 2010-07-16 05:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-16 05:02 . 2010-07-16 05:02 -------- d-----w- c:\windows\system32\drivers\NSS
2010-07-16 05:02 . 2010-07-16 05:02 -------- d-----w- c:\program files\Norton Security Scan
2010-07-16 05:02 . 2010-07-16 05:02 -------- d-----w- c:\program files\NortonInstaller
2010-07-15 10:48 . 2010-07-15 10:48 -------- d-----w- C:\putty
2010-07-14 03:52 . 2010-07-14 03:52 -------- d-----w- c:\program files\Microsoft.NET
2010-07-14 03:47 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-12 07:15 . 2010-07-12 07:15 -------- d-----w- c:\program files\VMware
2010-07-12 05:04 . 2010-07-12 05:04 -------- d-----w- c:\program files\MSBuild
2010-07-12 05:02 . 2010-07-12 05:02 -------- d-----w- c:\windows\system32\XPSViewer
2010-07-12 05:02 . 2010-07-12 05:02 -------- d-----w- c:\program files\Reference Assemblies
2010-07-12 05:02 . 2006-10-14 14:43 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-07-12 05:01 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-07-08 07:44 . 2010-07-08 07:44 -------- d-----w- c:\program files\Western Digital Corporation
2010-07-02 07:18 . 2010-07-02 07:18 -------- d-----w- c:\documents and settings\All Users\Data aplikac
2010-06-29 06:38 . 2010-06-29 06:38 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-28 10:10 . 2010-05-12 15:02 22856 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-06-28 10:10 . 2010-05-12 15:02 19784 ----a-w- c:\windows\system32\dopdfmi7.dll
2010-06-28 10:10 . 2010-06-28 10:10 -------- d-----w- c:\program files\Softland
2010-06-21 08:39 . 2010-06-21 08:39 -------- d-----w- c:\program files\Maxthon

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 01:50 . 2009-08-18 04:06 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-12 05:04 . 1979-12-31 22:00 94942 ----a-w- c:\windows\system32\perfc005.dat
2010-07-12 05:04 . 1979-12-31 22:00 477792 ----a-w- c:\windows\system32\perfh005.dat
2010-06-29 06:38 . 2009-05-18 07:05 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-29 06:38 . 2009-05-18 07:05 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-18 08:05 . 2010-06-18 08:05 -------- d-----w- c:\program files\ICQ7.2
2010-06-14 14:31 . 2007-11-29 09:00 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
2010-06-01 06:19 . 2007-12-05 05:03 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-26 04:59 . 2010-05-26 04:59 -------- d-----w- c:\program files\BlueVoda Website Builder
2010-05-26 04:59 . 2007-12-07 10:01 737280 ----a-w- c:\windows\iun6002.exe
2010-05-06 10:35 . 1979-12-31 22:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-05 04:20 . 2010-05-05 04:20 75776 ----a-w- c:\windows\cadkasdeinst01e.exe
2010-05-02 08:09 . 1979-12-31 23:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:32 . 1979-12-31 22:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2008-04-17 07:01 . 2008-01-09 05:02 72 --sh--w- c:\windows\SA6AF492B.tmp
.

((((((((((((((((((((((((((((( SnapShot@2010-07-16_07.17.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-19 05:00 . 2010-07-19 05:00 16384 c:\windows\Temp\Perflib_Perfdata_644.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TransClock"="c:\documents and settings\jiri25\Dokumenty\TransClock.exe" [2002-01-23 248320]
"Yodm3D"="c:\documents and settings\jiri25\Plocha\3d plocha\Yodm3D.exe" [2007-06-26 2058752]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2010-06-18 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-03 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"SkyTel"="SkyTel.EXE" [2007-10-11 1826816]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-07-12 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 49152]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-11 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-01-07 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Status Monitor CLJ1500"="c:\program files\Hewlett-Packard\CLJ1500\\Toolbox\HPPOUMUI.exe" [2003-06-05 692224]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-29 2065760]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\jiri25\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Mozilla Thunderbird.lnk - c:\program files\Mozilla Thunderbird\thunderbird.exe [2007-12-11 8319560]
Psi.lnk - c:\program files\Psi\Psi.exe [2009-12-3 8456704]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFileUrl"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-29 06:38 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Psi\\psi.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\diskg\\Sybase\\SQL Anywhere 9\\win32\\dbisqlg.exe"=
"c:\\diskg\\Sybase\\SQL Anywhere 9\\win32\\dbeng9.exe"=
"c:\\diskg\\Sybase\\Shared\\Sybase Central 4.3\\win32\\scjview.exe"=
"c:\\Xitami\\xigui32.exe"=
"c:\\MERCURY\\mercury.exe"=
"c:\\DISKG\\Sybase\\SQL Anywhere 9\\WIN32\\dbsrv9.exe"=
"c:\\Xitami\\xidos32.exe"=
"c:\\Program Files\\Mozilla Firefox3\\FIREFOX.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"\\\\Vgserver\\Video Guard 32\\VGClient32.exe"=
"c:\\Program Files\\Video Guard 32\\VGClient.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13364:UDP"= 13364:UDP:Print Server Utility
"13621:UDP"= 13621:UDP:MFP Bot Utility
"13107:UDP"= 13107:UDP:Print Server Utility
"69:UDP"= 69:UDP:Print Server Utility
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc
"5910:TCP"= 5910:TCP:vnc5910

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [18.5.2009 9:05 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18.5.2009 9:05 216400]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18.5.2009 9:05 243024]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [29.6.2010 8:38 921440]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [29.6.2010 8:38 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [29.6.2010 8:38 2331032]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [13.5.2009 11:00 246520]
R2 VshtD;VshtD;c:\windows\system32\drivers\Vshtd.sys [2.2.2000 13:33 19020]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [27.11.2009 5:37 30104]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys --> c:\windows\system32\DRIVERS\pssnap.sys [?]
S3 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [14.1.2010 10:37 29416]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [27.11.2009 5:37 30104]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [1.10.2006 13:05 26624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe --> c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.12.2007 13:06 685816]
.
Obsah adresáře 'Naplánované úlohy'

2010-07-19 c:\windows\Tasks\Norton Security Scan for jiri25.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-07-16 22:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - c:\program files\ICQ7.2\ICQ.exe
Trusted Zone: ica.cz\b
TCP: {A0034368-23E0-402F-AC3C-11033CEB4F70}
.

**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"

[HKEY_LOCAL_MACHINE\software\Xanthic\{290A6A8A-0F70-FC9A-A343-BE3AB91B8116}*_]
"fr"="078C407F5A545A"
"lr"="078C7B5D5E5441"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1404)
c:\windows\system32\CLBCATQ.DLL

- - - - - - - > 'explorer.exe'(3692)
c:\documents and settings\jiri25\Plocha\3d plocha\Yodm3D.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-07-19 07:07:03
ComboFix-quarantined-files.txt 2010-07-19 05:07
ComboFix2.txt 2010-07-17 15:39
ComboFix3.txt 2010-07-16 07:31

Před spuštěním: 7 525 457 920
Po spuštění: 7 506 542 592

- - End Of File - - FD80E729340002443B066E8DD7E35E76

Avatar uživatele
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 Říj 2004 07:00
Místo/Bydliště: České Budějovice
Kontaktovat uživatele:

Re: AdminHPR?

#19 Příspěvek od riffman »

z me strany hotovo, jeste po mne uklidte...

http://sweb.cz/Marinus/T-Cleaner.exe

stahnout, spustit, v okne potvrdit klepnutim na klavesu A vykonani akce, nechat probehnout :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

jiri25
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 Črc 2010 07:04

Re: AdminHPR?

#20 Příspěvek od jiri25 »

klikl jsem na ten odkaz a avg mi vyhodilo hlášku že blokuje virus
Trojský kůň Generic 17.CCJF tak jsem dal raději zrušit a nepokračovat

jiri25
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 Črc 2010 07:04

Re: AdminHPR?

#21 Příspěvek od jiri25 »

zkousel jsem t-cleaner stahnout i odjinud ale pokazde mi to avg zablokuje a vyhodi ze naslo vyse uvedeny virus mam i presto tento program stahnout a pouzit?

Avatar uživatele
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 Říj 2004 07:00
Místo/Bydliště: České Budějovice
Kontaktovat uživatele:

Re: AdminHPR?

#22 Příspěvek od riffman »

ignorovat, nebrat v potaz a AVG mimochodem nahradit :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

jiri25
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 Črc 2010 07:04

Re: AdminHPR?

#23 Příspěvek od jiri25 »

OK provedeno uz jsem uvazoval o nahrade avg desne brzdi pc :( a dekuji za pomoc

Avatar uživatele
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 Říj 2004 07:00
Místo/Bydliště: České Budějovice
Kontaktovat uživatele:

Re: AdminHPR?

#24 Příspěvek od riffman »

nemate zac :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Odpovědět