Stránka 2 z 3

Re: neautorizovaná změna systému

Napsal: 30 dub 2011 22:45
od motji
Já ten log prohlédnu zítra ještě jendou, ted už na to moc nevidím, ale zdá se, že je vše v pořádku. Zjistěte, jak je na tom pc :) . Zítra tu budu večer.

Re: neautorizovaná změna systému

Napsal: 01 kvě 2011 08:51
od makinecka
Dobře, zatím děkuji za pomoc :) . Budu dnes PC intenzitvně "testovat" :)

Re: neautorizovaná změna systému

Napsal: 01 kvě 2011 08:57
od motji
Dobře, pak napište, jak to vypadá :)

Re: neautorizovaná změna systému

Napsal: 01 kvě 2011 18:46
od makinecka
Dnes jsem celý den vypínala a zase zapínala počítač ... "závada" se znovu neobjevila :!:

Re: neautorizovaná změna systému

Napsal: 01 kvě 2011 21:18
od motji
:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Dirlook::
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

File::
C:\ProgramData\ezsidmv.dat

FixCSet::

DDS::
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com

Firefox::
FF - ProfilePath - c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2463487&q=
F - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci



:arrow: Otestujte na www.virustotal.com

C:\Windows\System32\bcmwlrmt.dll
C:\Windows\System32\vbscript.dll


-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 13:30
od makinecka
ComboFix 11-04-29.04 - Makyna 02.05.2011 14:07:30.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2037.1161 [GMT 2:00]
Spuštěný z: c:\users\Makyna\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Makyna\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\ezsidmv.dat"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ezsidmv.dat
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\engineSettings.json
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\fbAlert.js
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\DualPackage\install.rdf
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\chrome.manifest
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\install.rdf
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\lib\xpcom.js
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\META-INF\manifest.mf
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\searchplugin\conduit.src
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\extensions\engine@conduit.com\version.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-02 do 2011-05-02 )))))))))))))))))))))))))))))))
.
.
2011-05-02 12:18 . 2011-05-02 12:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-30 15:45 . 2011-04-30 15:52 -------- d-----w- c:\program files\trend micro
2011-04-30 15:45 . 2011-04-30 15:46 -------- d-----w- C:\rsit
2011-04-30 08:28 . 2011-04-30 08:28 -------- d-----w- c:\users\Makyna\AppData\Roaming\Malwarebytes
2011-04-30 08:28 . 2011-04-30 08:28 -------- d-----w- c:\programdata\Malwarebytes
2011-04-30 08:28 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-30 08:28 . 2011-04-30 17:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-30 08:28 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-29 14:15 . 2011-04-29 14:15 -------- d-----w- c:\program files\ESET
2011-04-29 06:57 . 2011-04-11 07:04 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8173E8E0-A28A-4E1B-AC87-7222CB5AC539}\mpengine.dll
2011-04-28 07:03 . 2011-03-03 14:56 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-28 07:03 . 2011-03-03 13:01 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-18 17:25 . 2010-07-28 06:03 40112 ----a-w- c:\windows\avastSS.scr
2011-04-18 17:25 . 2010-07-28 06:03 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-18 17:17 . 2011-03-16 12:57 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-18 17:17 . 2010-07-28 06:04 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-18 17:16 . 2010-07-28 06:04 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-18 17:13 . 2010-07-28 06:04 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-18 17:13 . 2010-07-28 06:04 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-18 17:12 . 2010-07-28 06:04 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-13 17:32 . 2010-10-14 08:53 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2011-03-03 14:56 . 2011-04-28 07:03 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 14:56 . 2011-04-28 07:03 459776 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 14:56 . 2011-04-28 07:03 2153984 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 14:56 . 2011-04-28 07:03 541696 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-02-02 16:11 . 2010-07-28 11:17 222080 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 ----
.
.
---- Directory of c:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 ----
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"Device Detection"="c:\program files\FUJIFILM\MyFinePix Studio\dd.exe" [2010-12-01 401592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 133656]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 174616]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-08-15 149280]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2010-08-30 111928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-15 717296]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-04-18 53592]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2007-06-06 111616]
.
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz
Trusted Zone: mojebanka.cz
FF - ProfilePath - c:\users\Makyna\AppData\Roaming\Mozilla\Firefox\Profiles\xmnkxqrs.default\
FF - prefs.js: browser.search.selectedEngine - Brothersoft Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Seznam lištička: {ea614400-e918-4741-9a97-7a972ff7c30b} - c:\program files\Mozilla Firefox\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
FF - Ext: Brothersoft Community Toolbar: {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - %profile%\extensions\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-02 14:22
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2011-05-02 14:28:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-02 12:28
ComboFix2.txt 2011-04-30 17:26
.
Před spuštěním: Volných bajtů: 58 687 238 144
Po spuštění: Volných bajtů: 58 551 169 024
.
- - End Of File - - EABBDF5E2E15B2940F4B51EA20AED635

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 13:40
od makinecka

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 14:19
od motji
Fajn, vypadá to dobře. Ještě odinstalujte Swetim toolbar.


:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 20:31
od makinecka
Přeji dobrý večer - počítač se "tváří" v pořádku.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Makyna at 2011-05-02 21:20:56
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 56 GB (55%) free of 101 GB
Total RAM: 2037 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:21:21, on 2.5.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18602)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\OEM02Mon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\FUJIFILM\MyFinePix Studio\dd.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\ICQ7.2\ICQ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Makyna\Downloads\RSIT.exe
C:\Program Files\trend micro\Makyna.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: YouTubeUploaderLib.YouTubeUploaderLib - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Device Detection] C:\Program Files\FUJIFILM\MyFinePix Studio\dd.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6978 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-06-21 1018680]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-15 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-15 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-15 133656]
"Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2007-12-08 3444736]
"OEM02Mon.exe"=C:\Windows\OEM02Mon.exe [2007-05-10 36864]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-07-24 174616]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-08-15 149280]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1603152]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
"Device Detection"=C:\Program Files\FUJIFILM\MyFinePix Studio\dd.exe [2010-12-01 401592]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-01-02 200704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2011-05-02 21:20:56 ----D---- C:\rsit
2011-05-02 16:00:07 ----D---- C:\Program Files\CCleaner
2011-05-02 15:55:24 ----D---- C:\Users\Makyna\AppData\Roaming\Reviversoft
2011-05-02 15:55:05 ----A---- C:\Windows\system32\roboot.exe
2011-05-02 15:45:26 ----SHD---- C:\Config.Msi
2011-05-02 14:28:12 ----D---- C:\Windows\temp
2011-05-02 14:22:02 ----SHD---- C:\$RECYCLE.BIN
2011-04-30 19:03:37 ----D---- C:\Windows\ERDNT
2011-04-30 17:45:48 ----D---- C:\Program Files\trend micro
2011-04-30 10:28:25 ----D---- C:\Users\Makyna\AppData\Roaming\Malwarebytes
2011-04-30 10:28:09 ----D---- C:\ProgramData\Malwarebytes
2011-04-29 16:15:48 ----D---- C:\Program Files\ESET
2011-04-28 09:03:23 ----A---- C:\Windows\system32\Apphlpdm.dll
2011-04-28 09:03:21 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2011-04-14 08:40:22 ----A---- C:\Windows\system32\atmfd.dll
2011-04-14 08:40:21 ----A---- C:\Windows\system32\atmlib.dll
2011-04-14 08:40:19 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-14 08:40:19 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-14 08:40:19 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-14 08:40:19 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-14 08:40:15 ----A---- C:\Windows\system32\mfc42.dll
2011-04-14 08:40:14 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-14 08:40:12 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-14 08:40:12 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-14 08:40:12 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-14 08:40:10 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-14 08:40:10 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-14 08:40:10 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-14 08:40:05 ----A---- C:\Windows\system32\mshtml.dll
2011-04-14 08:40:04 ----A---- C:\Windows\system32\urlmon.dll
2011-04-14 08:40:04 ----A---- C:\Windows\system32\ieapfltr.dll
2011-04-14 08:40:02 ----A---- C:\Windows\system32\mshtmled.dll
2011-04-14 08:40:01 ----A---- C:\Windows\system32\ieframe.dll
2011-04-14 08:40:00 ----A---- C:\Windows\system32\wininet.dll
2011-04-14 08:40:00 ----A---- C:\Windows\system32\mstime.dll
2011-04-14 08:40:00 ----A---- C:\Windows\system32\ieaksie.dll
2011-04-14 08:39:59 ----A---- C:\Windows\system32\iepeers.dll
2011-04-14 08:39:59 ----A---- C:\Windows\system32\iedkcs32.dll
2011-04-14 08:39:58 ----A---- C:\Windows\system32\occache.dll
2011-04-14 08:39:58 ----A---- C:\Windows\system32\msfeeds.dll
2011-04-14 08:39:58 ----A---- C:\Windows\system32\iertutil.dll
2011-04-14 08:39:57 ----A---- C:\Windows\system32\jsproxy.dll
2011-04-14 08:39:57 ----A---- C:\Windows\system32\ieencode.dll
2011-04-14 08:39:55 ----A---- C:\Windows\system32\win32k.sys
2011-04-14 08:39:53 ----A---- C:\Windows\system32\vbscript.dll
2011-04-14 08:39:53 ----A---- C:\Windows\system32\jscript.dll
2011-04-14 08:39:51 ----A---- C:\Windows\system32\inetcomm.dll

======List of files/folders modified in the last 1 months======

2011-05-02 21:21:16 ----D---- C:\Windows\Prefetch
2011-05-02 16:22:32 ----D---- C:\Windows\System32
2011-05-02 16:22:32 ----D---- C:\Windows\inf
2011-05-02 16:22:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-02 16:04:30 ----RD---- C:\Program Files
2011-05-02 16:04:29 ----D---- C:\Windows\system32\drivers
2011-05-02 16:01:53 ----D---- C:\Windows\Minidump
2011-05-02 16:01:53 ----D---- C:\Windows\Debug
2011-05-02 16:01:53 ----D---- C:\Windows
2011-05-02 16:01:18 ----SHD---- C:\System Volume Information
2011-05-02 15:55:31 ----D---- C:\Windows\system32\Tasks
2011-05-02 15:46:53 ----SHD---- C:\Windows\Installer
2011-05-02 15:46:52 ----D---- C:\ProgramData
2011-05-02 14:51:03 ----D---- C:\Users\Makyna\AppData\Roaming\ICQ
2011-05-02 14:22:08 ----A---- C:\Windows\system.ini
2011-05-02 14:21:50 ----D---- C:\Windows\system32\drivers\etc
2011-05-02 14:13:39 ----D---- C:\Windows\AppPatch
2011-05-02 14:13:36 ----D---- C:\Program Files\Common Files
2011-04-30 19:34:13 ----D---- C:\Program Files\Mozilla Firefox
2011-04-30 11:49:48 ----SD---- C:\ProgramData\Microsoft
2011-04-29 08:55:36 ----D---- C:\Windows\winsxs
2011-04-28 08:40:51 ----D---- C:\Windows\system32\catroot2
2011-04-28 08:40:51 ----D---- C:\Windows\system32\catroot
2011-04-21 21:26:08 ----SD---- C:\Users\Makyna\AppData\Roaming\Microsoft
2011-04-18 19:25:10 ----A---- C:\Windows\system32\aswBoot.exe
2011-04-17 22:09:44 ----D---- C:\Windows\Microsoft.NET
2011-04-17 22:08:33 ----RSD---- C:\Windows\assembly
2011-04-15 12:14:38 ----D---- C:\Program Files\Internet Explorer
2011-04-15 08:51:22 ----D---- C:\Program Files\Windows Mail

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-04-25 277784]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-15 717296]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-04-18 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-04-18 441176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-04-18 307288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-04-18 49240]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-04-18 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-04-18 53592]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 8192]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-12-06 1044984]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-11-02 986624]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-11-02 206848]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 2016256]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 111616]
R3 OEM02Dev;Creative Camera OEM002 Driver; C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-11 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver; C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 7424]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-09-13 330240]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-11-02 659968]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 278528]
S3 ajamkygo;ajamkygo; C:\Windows\system32\drivers\ajamkygo.sys []
S3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Windows\system32\aestsrv.exe [2007-09-20 73728]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-04-18 42184]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-07-24 354840]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 STacSV;SigmaTel Audio Service; C:\Windows\system32\STacSV.exe [2007-09-13 102400]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2007-12-08 24064]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-04 386560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 20:35
od motji
:arrow: Otestujte na www.virustotal.com
C:\Windows\system32\roboot.exe

Re: neautorizovaná změna systému

Napsal: 02 kvě 2011 21:30
od makinecka

Re: neautorizovaná změna systému

Napsal: 03 kvě 2011 08:15
od motji
:arrow: Otevřete si Poznámkový blok a zkopírujte do něj text

Kód: Vybrat vše

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"CanonSolutionMenu"=-
"CanonMyPrinter"=-
"SSBkgdUpdate"=-
Adobe Reader Speed Launcher"=-
"Adobe ARM"=-


 
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.


Pokud nejsou problémy, je to vše :)

Re: neautorizovaná změna systému

Napsal: 03 kvě 2011 20:02
od makinecka
Vypadá to, že je počítač v pořádku. Moc Vám děkuji za pomoc :) :worship:

Re: neautorizovaná změna systému

Napsal: 03 kvě 2011 20:06
od motji
Není zač :)

Re: neautorizovaná změna systému

Napsal: 07 kvě 2011 11:15
od makinecka
Tak mi ta radost dlouho nevydržela - dnes po spuštění stejná písnička. Pomohlo vyndání baterie ...