Stránka 1 z 3

Vypinani PC

Napsal: 09 kvě 2010 23:52
od ReQim
prosim o kontrolu logu.. nepravidelne se mi stava ze se mi sam vypina pc a kdyz ho zapnu tak bud hned nebo pozdeji se zase vypne :(


Logfile of random's system information tool 1.07 (written by random/random)
Run by Iveta at 2010-05-10 00:50:49
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 8 GB (52%) free of 16 GB
Total RAM: 502 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:51:20, on 10.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iveta\Plocha\RSIT.exe
C:\Program Files\trend micro\Iveta.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: VisualSalon - reindexace databází.lnk = C:\Program Files\VisualSalon\server\index_server.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: Google Update Service (gupdate1c98ca1f7ba834e) (gupdate1c98ca1f7ba834e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Unknown owner - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 6762 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-04-16 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-04-16 155648]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-04-16 131072]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-01-30 16116224]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2006-01-25 53248]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-05-19 774233]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-03-31 2145000]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2006-10-12 1282048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-10-09 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPWAUDAP]
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe [2006-09-06 54824]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
VisualSalon - reindexace databází.lnk - C:\Program Files\VisualSalon\server\index_server.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-04-16 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2006-12-14 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\EA SPORTS\FIFA 07\fifa07.exe"="C:\Program Files\EA SPORTS\FIFA 07\fifa07.exe:*:Enabled:fifa07"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Valve\hltv.exe"="C:\Program Files\Valve\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"D:\Program Files\Valve\hl.exe"="D:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42ea1c94-9930-11de-a87b-000fb0d3c20e}]
shell\AutoRun\command - G:\LaunchU3.exe -a


======List of files/folders created in the last 1 months======

2010-05-10 00:50:54 ----D---- C:\Program Files\trend micro
2010-05-10 00:50:49 ----D---- C:\rsit
2010-05-09 20:54:32 ----A---- C:\WINDOWS\system32\preflib.dll
2010-05-09 20:54:30 ----A---- C:\WINDOWS\system32\wltrynt.dll
2010-05-09 20:54:30 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2010-05-09 20:54:30 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2010-05-09 20:54:24 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2010-05-09 20:54:21 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2010-05-09 20:54:19 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2010-05-09 20:54:19 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2010-05-09 20:54:19 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2010-05-08 13:21:52 ----A---- C:\mbam-error.txt
2010-05-08 13:20:20 ----D---- C:\Documents and Settings\Iveta\Data aplikací\Malwarebytes
2010-05-08 13:20:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-05-08 13:20:04 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-08 02:37:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-05-08 02:33:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-08 02:30:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-08 02:26:30 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-08 02:22:25 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-08 02:18:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-08 02:04:38 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-08 02:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-05-08 01:59:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-08 01:56:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-08 01:54:22 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-08 01:50:40 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-08 01:45:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-08 01:40:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-08 01:36:07 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-05-08 01:33:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-08 01:29:07 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$
2010-05-08 01:27:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-08 01:25:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-05-08 01:23:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-08 01:20:29 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-08 01:18:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-08 01:15:28 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-08 01:12:37 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-05-08 01:04:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-05-08 00:37:10 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-05-08 00:13:28 ----D---- C:\Program Files\ESET
2010-05-08 00:13:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET

======List of files/folders modified in the last 1 months======

2010-05-10 00:51:20 ----D---- C:\WINDOWS\Temp
2010-05-10 00:50:57 ----D---- C:\WINDOWS\Prefetch
2010-05-10 00:50:54 ----RD---- C:\Program Files
2010-05-09 23:39:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-09 23:15:42 ----D---- C:\WINDOWS
2010-05-09 21:36:53 ----D---- C:\WINDOWS\system32
2010-05-09 20:55:04 ----D---- C:\WINDOWS\system32\drivers
2010-05-09 20:54:39 ----D---- C:\WINDOWS\Help
2010-05-09 19:55:39 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-09 19:44:03 ----HD---- C:\WINDOWS\inf
2010-05-09 18:04:38 ----SD---- C:\WINDOWS\Tasks
2010-05-09 18:03:49 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-09 17:56:38 ----SHD---- C:\WINDOWS\Installer
2010-05-09 17:43:14 ----D---- C:\Documents and Settings\Iveta\Data aplikací\ICQ
2010-05-08 21:04:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-08 14:54:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-08 14:45:52 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2010-05-08 13:37:44 ----D---- C:\Program Files\ICQ6.5
2010-05-08 12:02:55 ----D---- C:\WINDOWS\Debug
2010-05-08 10:06:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-08 10:04:27 ----D---- C:\WINDOWS\AppPatch
2010-05-08 02:36:02 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-08 01:46:12 ----D---- C:\Program Files\Movie Maker
2010-05-08 01:08:11 ----D---- C:\WINDOWS\WinSxS
2010-05-08 00:25:55 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-05-07 23:54:03 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-07 23:24:10 ----D---- C:\Program Files\DivX
2010-05-07 22:10:57 ----SD---- C:\Documents and Settings\Iveta\Data aplikací\Microsoft
2010-05-07 22:09:52 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-07 22:07:20 ----D---- C:\Program Files\Mozilla Firefox
2010-05-07 22:07:17 ----D---- C:\Documents and Settings\Iveta\Data aplikací\Mozilla
2010-05-07 22:05:08 ----D---- C:\Program Files\Google
2010-05-07 22:01:49 ----D---- C:\Documents and Settings\Iveta\Data aplikací\Vso
2010-05-07 22:01:49 ----A---- C:\Documents and Settings\Iveta\Data aplikací\inst.exe
2010-05-07 21:52:06 ----D---- C:\Program Files\Common Files
2010-05-07 18:16:04 ----D---- C:\Poznámky zákazníci
2010-04-30 15:05:40 ----AC---- C:\WINDOWS\WINCMD.INI
2010-04-14 16:31:33 ----A---- C:\WINDOWS\NeroDigital.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-03-31 114984]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-03-31 95872]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2007-06-14 21419]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-03-31 140216]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-08-02 12544]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-10-12 604928]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2008-12-20 223128]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-04-16 5760096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-01-30 4474368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-13 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-05-19 193088]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
S3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2007-06-20 25544]
S3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys []
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys []
S3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\drivers\LVPr2Mon.sys []
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-02-08 47360]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys []
S3 PID_08A0;Logitech QuickCam IM(PID_08A0); C:\WINDOWS\system32\DRIVERS\LV302AV.SYS []
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-11-24 5888]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-27 81408]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBCM;Scientific-Atlanta USB Cable Modem Driver; C:\WINDOWS\system32\DRIVERS\Sacm2A.sys [2004-06-10 15429]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-03-31 810120]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2006-08-02 434176]
R2 FNF5SVC;Fn+F5 Service; C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe [2007-04-09 54832]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2006-08-02 327680]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2006-08-02 937984]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2006-10-12 20480]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate1c98ca1f7ba834e;Google Update Service (gupdate1c98ca1f7ba834e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-12 133104]
S2 LVPrcSrv;Logitech Process Monitor; c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe []
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-06-16 68096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-03-31 33560]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Vypinani PC

Napsal: 10 kvě 2010 16:50
od ReQim
Pomuzete mi nekdo prosim? :( Je to nutne a specha to...

Re: Vypinani PC

Napsal: 10 kvě 2010 17:06
od motji
Hezký podvečer :)

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-souhlaste s instalací konzole pro zotavení

- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem

Re: Vypinani PC

Napsal: 10 kvě 2010 17:43
od ReQim
ComboFix 10-05-09.08 - Iveta 10.05.2010 18:28:45.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.502.232 [GMT 2:00]
Spuštěný z: c:\documents and settings\Iveta\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((( Soubory vytvořené od 2010-04-10 do 2010-05-10 )))))))))))))))))))))))))))))))
.

2010-05-09 23:30 . 2010-05-09 23:30 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-05-09 23:29 . 2010-05-09 23:50 -------- d-----w- c:\program files\Spyware Terminator
2010-05-09 22:50 . 2010-05-09 22:51 -------- d-----w- c:\program files\trend micro
2010-05-09 22:50 . 2010-05-09 22:51 -------- d-----w- C:\rsit
2010-05-09 19:36 . 2010-05-09 20:05 87 ----a-w- c:\windows\system32\EpfwUser.dat
2010-05-09 18:54 . 2006-10-12 15:28 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS
2010-05-09 18:54 . 2006-10-12 15:28 86016 ----a-w- c:\windows\system32\preflib.dll
2010-05-09 18:54 . 2006-10-12 15:28 44032 ----a-w- c:\windows\system32\wltrynt.dll
2010-05-09 18:54 . 2006-10-12 15:28 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2010-05-09 18:54 . 2006-10-12 15:28 184320 ----a-w- c:\windows\system32\bcmwlu00.exe
2010-05-09 18:54 . 2006-10-12 15:28 1282048 ----a-w- c:\windows\system32\WLTRAY.EXE
2010-05-09 18:54 . 2006-10-12 15:28 1134592 ----a-w- c:\windows\system32\BCMWLTRY.EXE
2010-05-09 18:54 . 2006-10-12 15:28 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2010-05-09 18:54 . 2006-10-12 15:28 20480 ----a-w- c:\windows\system32\WLTRYSVC.EXE
2010-05-09 18:54 . 2006-10-12 15:28 757760 ----a-w- c:\windows\system32\bcm1xsup.dll
2010-05-08 11:20 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-08 11:20 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-08 11:20 . 2010-05-08 11:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-07 22:50 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-05-07 22:42 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-05-07 22:37 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-07 22:13 . 2010-05-07 22:13 -------- d-----w- c:\program files\ESET

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-08 11:37 . 2008-12-20 22:09 -------- d-----w- c:\program files\ICQ6.5
2010-05-08 08:06 . 2001-11-24 18:02 432242 ----a-w- c:\windows\system32\perfh005.dat
2010-05-08 08:06 . 2001-11-24 18:02 79260 ----a-w- c:\windows\system32\perfc005.dat
2010-05-07 22:25 . 2009-02-01 23:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-07 21:24 . 2009-02-04 17:34 -------- d-----w- c:\program files\DivX
2010-05-07 20:09 . 2007-06-14 16:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-07 20:05 . 2009-02-11 23:38 -------- d-----w- c:\program files\Google
2010-03-31 09:26 . 2010-03-31 09:26 90624 ----a-w- c:\windows\system32\ecFCI.dll
2010-03-31 09:26 . 2010-03-31 09:26 104448 ----a-w- c:\windows\system32\ecFDI.dll
2010-03-31 06:23 . 2010-03-31 06:23 95872 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-03-31 06:22 . 2010-03-31 06:22 114984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-03-31 06:17 . 2010-03-31 06:17 140216 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-03-09 11:11 . 2004-08-17 13:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 05:43 . 2004-08-17 13:49 668160 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 05:43 . 2004-08-17 13:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-24 13:11 . 2004-08-03 21:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:09 . 2004-08-17 13:45 2192128 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:09 . 2004-08-17 15:45 2068992 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:35 . 2004-08-17 13:49 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-03 21:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.

------- Sigcheck -------

[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys
[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

[-] 2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2004-08-17 13:49 . E02E913B3841717A890A644EE167B9A5 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 155648]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 131072]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-31 2145000]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-10-12 1282048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
VisualSalon - reindexace datab zˇ.lnk - c:\program files\VisualSalon\server\index_server.exe [2006-12-14 51066]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 09:06 28672 ----a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 16:04 2879488 ----a-w- c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-05-09 23:30 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPWAUDAP]
2006-09-06 14:38 54824 -c--a-w- c:\program files\Lenovo\HOTKEY\TpWAudAp.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3781:UDP"= 3781:UDP:Windows Media Format SDK (Utherverse.exe)
"3780:UDP"= 3780:UDP:Windows Media Format SDK (Utherverse.exe)
"3783:UDP"= 3783:UDP:Windows Media Format SDK (Utherverse.exe)

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [31.3.2010 8:22 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [31.3.2010 8:23 95872]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [10.5.2010 1:30 142592]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [31.3.2010 8:23 810120]
R2 FNF5SVC;Fn+F5 Service;c:\program files\Lenovo\HOTKEY\FnF5svc.exe [9.4.2007 10:24 54832]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.6.2007 22:57 682232]
S2 gupdate1c98ca1f7ba834e;Google Update Service (gupdate1c98ca1f7ba834e);c:\program files\Google\Update\GoogleUpdate.exe [12.2.2009 1:39 133104]
S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [28.1.2009 19:57 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [28.1.2009 20:01 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [28.1.2009 20:01 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [28.1.2009 20:01 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [28.1.2009 20:01 100008]
.
Obsah adresáře 'Naplánované úlohy'

2010-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 23:39]

2010-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 23:39]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-10 18:33
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(780)
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\windows\System32\BCMLogon.dll
.
Celkový čas: 2010-05-10 18:37:52
ComboFix-quarantined-files.txt 2010-05-10 16:37

Před spuštěním: 8 828 473 344
Po spuštění: 8 867 467 264

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - C0E737BFAA77AADC6DE326F15AC553F7

Re: Vypinani PC

Napsal: 10 kvě 2010 20:31
od motji
:arrow: Otestujte na http://www.virustotal.com

c:\windows\system32\drivers\BCMWLNPF.SYs
c:\windows\system32\drivers\atapi.sys
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\program files\VisualSalon\server\index_server.exe
c:\program files\Lenovo\HOTKEY\TpWAudAp.exe


-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.

:arrow: Změnilo se něco po použití combofixu? nemůže se Vám počítač vypínat, když je přehřátý?

Re: Vypinani PC

Napsal: 11 kvě 2010 00:05
od ReQim
Pokud se neco zmenilo tak nevim...Notas se po pouziti Combofixu zatim nevypnul ale je klidne mozny ze zase odpoledne nebo vecer bude vypinat. Teplotu notasu bouzel nevim jak zjistit.Spis bych rek ze mi to vypina naky vir.

Soubor BCMWLNPF.SYS :

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.05.10 -
AhnLab-V3 2010.05.11.00 2010.05.10 -
AntiVir 8.2.1.236 2010.05.10 -
Antiy-AVL 2.0.3.7 2010.05.10 -
Authentium 5.2.0.5 2010.05.10 -
Avast 4.8.1351.0 2010.05.10 -
Avast5 5.0.332.0 2010.05.10 -
AVG 9.0.0.787 2010.05.10 -
BitDefender 7.2 2010.05.10 -
CAT-QuickHeal 10.00 2010.05.10 -
ClamAV 0.96.0.3-git 2010.05.10 -
Comodo 4818 2010.05.10 -
DrWeb 5.0.2.03300 2010.05.10 -
eSafe 7.0.17.0 2010.05.10 -
eTrust-Vet 35.2.7478 2010.05.10 -
F-Prot 4.5.1.85 2010.05.10 -
F-Secure 9.0.15370.0 2010.05.10 -
Fortinet 4.1.133.0 2010.05.10 -
GData 21 2010.05.10 -
Ikarus T3.1.1.84.0 2010.05.10 -
Jiangmin 13.0.900 2010.05.10 -
Kaspersky 7.0.0.125 2010.05.10 -
McAfee 5.400.0.1158 2010.05.10 -
McAfee-GW-Edition 2010.1 2010.05.10 -
Microsoft 1.5703 2010.05.10 -
NOD32 5103 2010.05.10 -
Norman 6.04.12 2010.05.10 -
nProtect 2010-05-10.01 2010.05.10 -
Panda 10.0.2.7 2010.05.10 -
PCTools 7.0.3.5 2010.05.10 -
Prevx 3.0 2010.05.11 -
Rising 22.47.00.04 2010.05.10 -
Sophos 4.53.0 2010.05.10 -
Sunbelt 6287 2010.05.10 -
Symantec 20091.2.0.41 2010.05.10 -
TheHacker 6.5.2.0.277 2010.05.10 -
TrendMicro 9.120.0.1004 2010.05.10 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.10 -
VBA32 3.12.12.4 2010.05.06 -
ViRobot 2010.5.10.2308 2010.05.10 -
VirusBuster 5.0.27.0 2010.05.10 -
Rozšiřující informace
File size: 33664 bytes
MD5...: 8c31c9db77ed6143ad09dc5fd2c9d9cc
SHA1..: 465c39900a05edfd79da24f680e7c8687ad42b46
SHA256: d79ee8d84d03237981886978c289193a860bd7a5b0f6e5b5243d47f894a2f45b
ssdeep: 768:T1m/nl0wWsIq3JY+FqD/uQzOHS+OD9gYx5l3svA1/GO4DeV:hmfnP5YTgYx5
aA134DeV
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x7305
timedatestamp.....: 0x434f63a0 (Fri Oct 14 07:52:00 2005)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x480 0x6860 0x6880 6.40 ed4e1e3e96b0a2e267100d6762e81c88
.rdata 0x6d00 0x320 0x380 3.76 60903d5256425c0f1a00f727d122de4b
.data 0x7080 0x210 0x280 1.68 a543e0df87517ede146069eaec3355eb
INIT 0x7300 0x68e 0x700 5.10 3681efde98ca9330112da1c307c776f3
.rsrc 0x7a00 0x460 0x480 3.25 9b95ac2386a7065f90dbe5cd4a4a0cdc
.reloc 0x7e80 0x4a8 0x500 5.59 55f1aa5133e4976eee7a59521e471c93

( 3 imports )
> ntoskrnl.exe: _allrem, _alldiv, KeWaitForSingleObject, KeInitializeEvent, _aullrem, _aulldiv, ZwSetInformationThread, KeSetEvent, KeClearEvent, IoCreateNotificationEvent, ObfDereferenceObject, MmMapLockedPagesSpecifyCache, IoFreeMdl, MmBuildMdlForNonPagedPool, KeQuerySystemTime, KeTickCount, KeBugCheckEx, DbgPrint, KeInitializeSpinLock, _allmul, ExfInterlockedRemoveHeadList, ExfInterlockedInsertTailList, IofCompleteRequest, IoDeleteSymbolicLink, IoDeleteDevice, RtlCompareMemory, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, IoCreateDevice, IoCreateSymbolicLink, ZwOpenKey, ZwEnumerateKey, RtlInitUnicodeString, ZwQueryValueKey, ZwClose, ExAllocatePoolWithTag, RtlQueryRegistryValues, RtlWriteRegistryValue, IoAllocateMdl, ExFreePoolWithTag
> HAL.dll: KfReleaseSpinLock, KeQueryPerformanceCounter, KfLowerIrql, KfRaiseIrql, KfAcquireSpinLock
> NDIS.SYS: NdisCloseAdapter, NdisFreePacketPool, NdisSystemProcessorCount, NdisRegisterProtocol, NdisOpenAdapter, NdisResetEvent, NdisRequest, NdisWaitEvent, NdisSetEvent, NdisDeregisterProtocol, NdisInitializeEvent, NdisAllocatePacketPool, NdisFreePacket, NdisAllocatePacket, NdisReset, NdisUnchainBufferAtFront

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (58.4%)
Clipper DOS Executable (13.8%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.7%)
VXD Driver (0.2%)
packers (Kaspersky): PE_Patch
sigcheck:
publisher....: CACE Technologies
copyright....: Copyright (c) 2005 CACE Technologies. Copyright (c) 2003-2005 NetGroup, Politecnico di Torino.
product......: WinPcap Netgroup Packet Filter Driver
description..: npf
original name: npf.sys
internal name: NPF _ TME
file version.: 3, 1, 0, 27
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned

Soubor atapi.sys :

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.05.10 -
AhnLab-V3 2010.05.11.00 2010.05.10 -
AntiVir 8.2.1.236 2010.05.10 -
Antiy-AVL 2.0.3.7 2010.05.10 -
Authentium 5.2.0.5 2010.05.10 -
Avast 4.8.1351.0 2010.05.10 -
Avast5 5.0.332.0 2010.05.10 -
AVG 9.0.0.787 2010.05.11 -
BitDefender 7.2 2010.05.11 -
CAT-QuickHeal 10.00 2010.05.10 -
ClamAV 0.96.0.3-git 2010.05.10 -
Comodo 4818 2010.05.10 -
DrWeb 5.0.2.03300 2010.05.10 -
eSafe 7.0.17.0 2010.05.10 -
eTrust-Vet 35.2.7478 2010.05.10 -
F-Prot 4.5.1.85 2010.05.10 -
F-Secure 9.0.15370.0 2010.05.10 -
Fortinet 4.1.133.0 2010.05.10 -
GData 21 2010.05.10 -
Ikarus T3.1.1.84.0 2010.05.10 -
Jiangmin 13.0.900 2010.05.10 -
Kaspersky 7.0.0.125 2010.05.11 -
McAfee 5.400.0.1158 2010.05.11 -
McAfee-GW-Edition 2010.1 2010.05.10 -
Microsoft 1.5703 2010.05.11 -
NOD32 5103 2010.05.10 -
Norman 6.04.12 2010.05.10 -
nProtect 2010-05-10.01 2010.05.10 -
Panda 10.0.2.7 2010.05.10 -
PCTools 7.0.3.5 2010.05.10 -
Prevx 3.0 2010.05.11 -
Rising 22.47.00.04 2010.05.10 -
Sophos 4.53.0 2010.05.10 -
Sunbelt 6287 2010.05.10 -
Symantec 20091.2.0.41 2010.05.10 -
TheHacker 6.5.2.0.277 2010.05.10 -
TrendMicro 9.120.0.1004 2010.05.10 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.11 -
VBA32 3.12.12.4 2010.05.06 -
ViRobot 2010.5.10.2308 2010.05.10 -
VirusBuster 5.0.27.0 2010.05.10 -
Rozšiřující informace
File size: 95360 bytes
MD5...: cdfe4411a69c224bd1d11b2da92dac51
SHA1..: a42fbfeb5a4d94118b483d7f18113aa8c329a052
SHA256: 0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d
ssdeep: 1536:BVzXEOXUOyD8HT6OhAVJqNoQrPs2W7IDdXBoDZYkvR5TJWBwEsjG0cXFIQ0
bbZPO:BVL/Eiz6OhrNoQzsnwBoDjR51hljrckO
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x155f7
timedatestamp.....: 0x41107b4d (Wed Aug 04 05:59:41 2004)
machinetype.......: 0x14c (I386)

( 9 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0x9672 0x9680 6.45 70b67d65eb28dcccdcba61a31c4d40e2
NONPAGE 0x9a00 0x18e8 0x1900 6.48 5629c7db94fbcf0123c267ec52f0c942
.rdata 0xb300 0xa54 0xa80 4.37 569d2979d21f645730a1a59fd512d25c
.data 0xbd80 0xd94 0xe00 0.44 77b784be18c5257bf3b9c132a03019db
PAGESCAN 0xcb80 0x154f 0x1580 6.15 d1c7adb0c1e5491b58c485d62076561f
PAGE 0xe100 0x5f54 0x5f80 6.46 0951fe4f10eee3d01d5d5aab9a0472bc
INIT 0x14080 0x22a0 0x2300 6.48 4354ab341533bda39d4f4dc3548ef9bd
.rsrc 0x16380 0x3f0 0x400 3.40 0184b21986944fd39532f818b4c642ab
.reloc 0x16780 0xcf0 0xd00 6.46 ae8fd4a932f7899f6257876856210914

( 3 imports )
> ntoskrnl.exe: RtlInitUnicodeString, swprintf, KeSetEvent, IoCreateSymbolicLink, IoGetConfigurationInformation, IoDeleteSymbolicLink, MmFreeMappingAddress, IoFreeErrorLogEntry, IoDisconnectInterrupt, MmUnmapIoSpace, ObReferenceObjectByPointer, IofCompleteRequest, RtlCompareUnicodeString, IofCallDriver, MmAllocateMappingAddress, IoAllocateErrorLogEntry, IoConnectInterrupt, IoDetachDevice, KeWaitForSingleObject, KeInitializeEvent, RtlAnsiStringToUnicodeString, RtlInitAnsiString, IoBuildDeviceIoControlRequest, IoQueueWorkItem, MmMapIoSpace, IoInvalidateDeviceRelations, IoReportDetectedDevice, IoReportResourceForDetection, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, PoRequestPowerIrp, KeInsertByKeyDeviceQueue, PoRegisterDeviceForIdleDetection, sprintf, MmMapLockedPagesSpecifyCache, ObfDereferenceObject, IoGetAttachedDeviceReference, IoInvalidateDeviceState, ZwClose, ObReferenceObjectByHandle, ZwCreateDirectoryObject, IoBuildSynchronousFsdRequest, PoStartNextPowerIrp, PoCallDriver, IoCreateDevice, IoAllocateDriverObjectExtension, RtlQueryRegistryValues, ZwOpenKey, RtlFreeUnicodeString, IoStartTimer, KeInitializeTimer, IoInitializeTimer, KeInitializeDpc, KeInitializeSpinLock, IoInitializeIrp, ZwCreateKey, RtlAppendUnicodeStringToString, RtlIntegerToUnicodeString, ZwSetValueKey, KeInsertQueueDpc, KefAcquireSpinLockAtDpcLevel, IoStartPacket, KefReleaseSpinLockFromDpcLevel, IoBuildAsynchronousFsdRequest, IoFreeMdl, MmUnlockPages, IoWriteErrorLogEntry, KeRemoveByKeyDeviceQueue, MmMapLockedPagesWithReservedMapping, MmUnmapReservedMapping, KeSynchronizeExecution, IoStartNextPacket, KeBugCheckEx, KeRemoveDeviceQueue, KeSetTimer, KeCancelTimer, _allmul, MmProbeAndLockPages, _except_handler3, PoSetPowerState, IoOpenDeviceRegistryKey, RtlWriteRegistryValue, _aulldiv, strstr, _strupr, KeQuerySystemTime, IoWMIRegistrationControl, KeTickCount, IoAttachDeviceToDeviceStack, IoDeleteDevice, ExAllocatePoolWithTag, IoAllocateWorkItem, IoAllocateIrp, IoAllocateMdl, MmBuildMdlForNonPagedPool, MmLockPagableDataSection, IoGetDriverObjectExtension, MmUnlockPagableImageSection, ExFreePoolWithTag, IoFreeIrp, IoFreeWorkItem, InitSafeBootMode, RtlCompareMemory, RtlCopyUnicodeString, memmove, MmHighestUserAddress
> HAL.dll: KfAcquireSpinLock, READ_PORT_UCHAR, KeGetCurrentIrql, KfRaiseIrql, KfLowerIrql, HalGetInterruptVector, HalTranslateBusAddress, KeStallExecutionProcessor, KfReleaseSpinLock, READ_PORT_BUFFER_USHORT, READ_PORT_USHORT, WRITE_PORT_BUFFER_USHORT, WRITE_PORT_UCHAR
> WMILIB.SYS: WmiSystemControl, WmiCompleteRequest

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: IDE/ATAPI Port Driver
original name: atapi.sys
internal name: atapi.sys
file version.: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): PE_Patch


Soubor index_server.exe

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.05.10 -
AhnLab-V3 2010.05.11.00 2010.05.10 -
AntiVir 8.2.1.236 2010.05.10 -
Antiy-AVL 2.0.3.7 2010.05.10 -
Authentium 5.2.0.5 2010.05.10 -
Avast 4.8.1351.0 2010.05.10 -
Avast5 5.0.332.0 2010.05.10 -
AVG 9.0.0.787 2010.05.11 -
BitDefender 7.2 2010.05.11 -
CAT-QuickHeal 10.00 2010.05.10 -
ClamAV 0.96.0.3-git 2010.05.10 -
Comodo 4818 2010.05.10 -
DrWeb 5.0.2.03300 2010.05.11 -
eSafe 7.0.17.0 2010.05.10 -
eTrust-Vet 35.2.7478 2010.05.10 -
F-Prot 4.5.1.85 2010.05.10 -
F-Secure 9.0.15370.0 2010.05.10 -
Fortinet 4.1.133.0 2010.05.10 -
GData 21 2010.05.11 -
Ikarus T3.1.1.84.0 2010.05.10 -
Jiangmin 13.0.900 2010.05.10 -
Kaspersky 7.0.0.125 2010.05.11 -
McAfee 5.400.0.1158 2010.05.11 -
McAfee-GW-Edition 2010.1 2010.05.10 -
Microsoft 1.5703 2010.05.11 -
NOD32 5103 2010.05.10 -
Norman 6.04.12 2010.05.10 -
nProtect 2010-05-10.01 2010.05.10 -
Panda 10.0.2.7 2010.05.10 -
PCTools 7.0.3.5 2010.05.10 -
Rising 22.47.00.04 2010.05.10 -
Sophos 4.53.0 2010.05.10 -
Sunbelt 6287 2010.05.10 -
Symantec 20091.2.0.41 2010.05.10 -
TheHacker 6.5.2.0.277 2010.05.10 -
TrendMicro 9.120.0.1004 2010.05.10 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.11 -
VBA32 3.12.12.4 2010.05.06 -
ViRobot 2010.5.10.2308 2010.05.10 -
VirusBuster 5.0.27.0 2010.05.10 -
Rozšiřující informace
File size: 51066 bytes
MD5...: 5ff474a84a2128b4a7d81c6e8f6bf57f
SHA1..: eece2833f39c4e6777d36ede9adb8898842714c7
SHA256: c495eb80627c50a4640c8a3ce3a1d27bea5e95ab9efc82dbb54f078144609ba3
ssdeep: 1536:1ZbX8X5X8XM8IGmOo+PDyevJ3qWpMUYsh3bAwgOYf1akPyF4f1mwsV2iMd:
1tsps3IGml+PDyex3qWpMUNh3bAwgOpC
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x189e
timedatestamp.....: 0x3f73b447 (Fri Sep 26 03:36:39 2003)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xbca 0xc00 6.12 dbc88d6d59ba1f1d7c5fe3666129917c
.rdata 0x2000 0x4d4 0x600 4.17 84275a0d5097ade82646b64c96ef5cc0
.data 0x3000 0x4fc 0x200 1.60 fdd10bbd589735e52376d0d9a1e46f80
.rsrc 0x4000 0x4528 0x4600 2.22 98583f04938f52703e4ba1a1d31f7e95

( 4 imports )
> MSVCR70.dll: __p__fmode, __set_app_type, __p__commode, _onexit, _controlfp, _except_handler3, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _amsg_exit, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit, _mbschr, _mbsicmp, _access, _mbsrchr, isspace, _splitpath, __dllonexit, _makepath
> KERNEL32.dll: GetModuleHandleA, GetModuleFileNameA, FreeLibrary, GetProcAddress, GetSystemDirectoryA, lstrcatA, GetCurrentDirectoryA, LoadLibraryA, lstrcpyA, _lopen, _lclose, _llseek, _lread, GetStartupInfoA
> USER32.dll: MessageBoxA, LoadStringA, wsprintfA
> ADVAPI32.dll: RegQueryValueA, RegOpenKeyA, RegCloseKey

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win64 Executable Generic (80.9%)
Win32 Executable Generic (8.0%)
Win32 Dynamic Link Library (generic) (7.1%)
Generic Win/DOS Executable (1.8%)
DOS Executable Generic (1.8%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_respon ... 23-0550-99


Soubor tphklock.dll :

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.05.10 -
AhnLab-V3 2010.05.11.00 2010.05.10 -
AntiVir 8.2.1.236 2010.05.10 -
Antiy-AVL 2.0.3.7 2010.05.10 -
Authentium 5.2.0.5 2010.05.10 -
Avast 4.8.1351.0 2010.05.10 -
Avast5 5.0.332.0 2010.05.10 -
AVG 9.0.0.787 2010.05.11 -
BitDefender 7.2 2010.05.11 -
CAT-QuickHeal 10.00 2010.05.10 -
ClamAV 0.96.0.3-git 2010.05.10 -
Comodo 4818 2010.05.10 -
DrWeb 5.0.2.03300 2010.05.11 -
eSafe 7.0.17.0 2010.05.10 -
eTrust-Vet 35.2.7478 2010.05.10 -
F-Prot 4.5.1.85 2010.05.10 -
F-Secure 9.0.15370.0 2010.05.10 -
Fortinet 4.1.133.0 2010.05.10 -
GData 21 2010.05.11 -
Ikarus T3.1.1.84.0 2010.05.10 -
Jiangmin 13.0.900 2010.05.10 -
Kaspersky 7.0.0.125 2010.05.11 -
McAfee 5.400.0.1158 2010.05.11 -
McAfee-GW-Edition 2010.1 2010.05.10 -
Microsoft 1.5703 2010.05.11 -
NOD32 5103 2010.05.10 -
Norman 6.04.12 2010.05.10 -
nProtect 2010-05-10.01 2010.05.10 -
Panda 10.0.2.7 2010.05.10 -
PCTools 7.0.3.5 2010.05.10 -
Prevx 3.0 2010.05.11 -
Rising 22.47.00.04 2010.05.10 -
Sophos 4.53.0 2010.05.10 -
Sunbelt 6287 2010.05.10 -
Symantec 20091.2.0.41 2010.05.10 -
TheHacker 6.5.2.0.277 2010.05.10 -
TrendMicro 9.120.0.1004 2010.05.10 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.11 -
VBA32 3.12.12.4 2010.05.06 -
ViRobot 2010.5.10.2308 2010.05.10 -
VirusBuster 5.0.27.0 2010.05.10 -
Rozšiřující informace
File size: 28672 bytes
MD5...: 04019e3cecbfcfed5bb2b0892ecd3e18
SHA1..: f744b2d5b6406967022a2e823785270ab212fcc2
SHA256: 6bceab6fd85f401c46b8b5f7e6fc72c038d95216f2b1836eab9fbc175cd9bc9e
ssdeep: 384:F9hjwyRM0hQ+Ip67s8cQTjDIFpnINCzL:5UQZhQ+IcQnQTjDIFM+
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x31c7
timedatestamp.....: 0x4580b1b0 (Thu Dec 14 02:06:40 2006)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x229c 0x3000 4.58 a985c061f551f47809dce1806852f0b7
.rdata 0x4000 0x908 0x1000 3.39 98c1603089faddb2a9f40c6cfa352a13
.data 0x5000 0x6a0 0x1000 2.38 55c1ca0210c557e2ea952d7e6676e757
.reloc 0x6000 0x326 0x1000 1.61 e3e4581445a31ff5f66f3dc80dedc5df

( 5 imports )
> KERNEL32.dll: DisableThreadLibraryCalls, OutputDebugStringA, CreateProcessA, SetThreadPriority, LocalReAlloc, LocalSize, OpenFileMappingA, FindClose, FindFirstFileA, ExitThread, WaitForSingleObject, GetExitCodeThread, OpenEventA, SetEvent, CreateFileMappingA, CreateEventA, GetShortPathNameA, CreateThread, CloseHandle, GetVersionExA, GetCurrentThreadId, WaitForMultipleObjects, MapViewOfFile, LocalFree, UnmapViewOfFile, LocalAlloc
> ADVAPI32.dll: RegNotifyChangeKeyValue, RegCreateKeyExA, ImpersonateLoggedOnUser, CreateProcessAsUserA, RevertToSelf, RegSetValueExA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, AllocateAndInitializeSid, SetEntriesInAclA, SetNamedSecurityInfoA, FreeSid
> USER32.dll: OpenInputDesktop, CloseDesktop, GetUserObjectInformationA, GetForegroundWindow, GetWindowThreadProcessId, GetGUIThreadInfo, keybd_event, wsprintfA, GetProcessWindowStation, EnumDesktopsA, GetThreadDesktop, OpenDesktopA, SetThreadDesktop, FindWindowA, PostMessageA
> WTSAPI32.dll: WTSFreeMemory, WTSQuerySessionInformationA
> MSVCRT.dll: malloc, _initterm, free, memset, sprintf, strcpy, strlen, vsprintf, strchr, fopen, fprintf, fflush, fclose, _adjust_fdiv

( 10 exports )
PMSVC_CloseFnFx, PMSVC_IsFnFxEnabled, PMSVC_OpenFnFx, PMSVC_VirtualNotifyFnFx, WLEventLock, WLEventLogoff, WLEventLogon, WLEventShutdown, WLEventStartup, WLEventUnlock
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned


Soubor TpWAudAp.exe :

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.05.10 -
AhnLab-V3 2010.05.11.00 2010.05.10 -
AntiVir 8.2.1.236 2010.05.10 -
Antiy-AVL 2.0.3.7 2010.05.10 -
Authentium 5.2.0.5 2010.05.10 -
Avast 4.8.1351.0 2010.05.10 -
Avast5 5.0.332.0 2010.05.10 -
AVG 9.0.0.787 2010.05.11 -
BitDefender 7.2 2010.05.11 -
CAT-QuickHeal 10.00 2010.05.10 -
ClamAV 0.96.0.3-git 2010.05.10 -
Comodo 4818 2010.05.10 -
DrWeb 5.0.2.03300 2010.05.11 -
eSafe 7.0.17.0 2010.05.10 -
eTrust-Vet 35.2.7478 2010.05.10 -
F-Prot 4.5.1.85 2010.05.10 -
F-Secure 9.0.15370.0 2010.05.10 -
Fortinet 4.1.133.0 2010.05.10 -
GData 21 2010.05.11 -
Ikarus T3.1.1.84.0 2010.05.10 -
Jiangmin 13.0.900 2010.05.10 -
Kaspersky 7.0.0.125 2010.05.11 -
McAfee 5.400.0.1158 2010.05.11 -
McAfee-GW-Edition 2010.1 2010.05.10 -
Microsoft 1.5703 2010.05.11 -
NOD32 5103 2010.05.10 -
Norman 6.04.12 2010.05.10 -
nProtect 2010-05-10.01 2010.05.10 -
Panda 10.0.2.7 2010.05.10 -
PCTools 7.0.3.5 2010.05.10 -
Prevx 3.0 2010.05.11 -
Rising 22.47.00.04 2010.05.10 -
Sophos 4.53.0 2010.05.10 -
Sunbelt 6287 2010.05.10 -
Symantec 20091.2.0.41 2010.05.10 -
TheHacker 6.5.2.0.277 2010.05.10 -
TrendMicro 9.120.0.1004 2010.05.10 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.11 -
VBA32 3.12.12.4 2010.05.06 -
ViRobot 2010.5.10.2308 2010.05.10 -
VirusBuster 5.0.27.0 2010.05.10 -
Rozšiřující informace
File size: 54824 bytes
MD5...: b56c79711af26ff30a6ac2e879d11ef7
SHA1..: aa357c223693ec37552949364b42b0118506b2f3
SHA256: 6d1badbe41a6b8ed50e3a3ccf6634cf624f79ab8bbcf455b6946447bcc1d691c
ssdeep: 768:dE90uQQ6t5ZaDzl3fPPqhoX52daaUbJ+L3TwbO:JuQb4FXPT20bJ+sO
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x17fd
timedatestamp.....: 0x44d01cd6 (Wed Aug 02 03:32:38 2006)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6670 0x7000 6.31 70d9dd72f37a01d3c006221d66da60da
.rdata 0x8000 0x1cea 0x2000 5.21 076c22e0386561a535f12ee273bc3437
.data 0xa000 0x1880 0x1000 2.13 4a6309515eeac0f8750104bb1e8bcf0e
.rsrc 0xc000 0xb0 0x1000 3.06 126e0acb09a50507c388686fa66e205b

( 3 imports )
> KERNEL32.dll: WinExec, GetLastError, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, HeapReAlloc, VirtualAlloc, GetProcAddress, GetModuleHandleA, ExitProcess, GetCommandLineA, HeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, WriteFile, GetStdHandle, GetModuleFileNameA, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, LoadLibraryA, InitializeCriticalSection, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetCPInfo, GetACP, GetOEMCP, Sleep, HeapSize, RtlUnwind, MultiByteToWideChar, GetLocaleInfoA
> USER32.dll: CreateWindowExW, GetMessageW, DispatchMessageW, TranslateMessage, RegisterClassW, KillTimer, PostMessageW, DefWindowProcW, FindWindowW, SetForegroundWindow, SetTimer, LoadCursorW
> TpWAud32.dll: -, -

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: Lenovo (Japan) Ltd
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 9:36 AM 9/6/2006
verified.....: -

Re: Vypinani PC

Napsal: 11 kvě 2010 06:08
od motji
:arrow: Stáhněte Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte

-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.



N atepoty si stahněte nějakou utilitu, třeba http://www.almico.com/sfdownload.php

A napište, jestli se pc už vypnul.

Re: Vypinani PC

Napsal: 11 kvě 2010 10:51
od ReQim
Notebook se zatim nevypnul. Speedfan jsem stahl a nainstaloval a teploty jsou: HD0: 44C , TEMP1: 79C, CORE0: 77C. Jsou ty teploty v poradku? Me se ty posledni teploty zdaji dost.
Zkousel jsem spustit test u Spyware Terminator a naslo mi to dva Trojan.ExOptions.Gen akorat nesly smazat :( Behem druhyho skenu u GMER se mi ukazala modra obrazovka (myslim ze ta obrazovka smrti jak se rika) a potom podruhe.

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe

Prvni log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-11 09:40:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Iveta\LOCALS~1\Temp\kxrdqpow.sys


---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

---- System - GMER 1.0.15 ----

SSDT sptd.sys ZwEnumerateKey [0xF8411E2C]
SSDT sptd.sys ZwEnumerateValueKey [0xF84121BA]

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 82DD91E8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

---- EOF - GMER 1.0.15 ----

Druhy log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-11 10:50:45
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Iveta\LOCALS~1\Temp\kxrdqpow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xAA2EC610]
SSDT sptd.sys ZwCreateKey [0xF840C0D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xAA2ECC10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xAA2EC730]
SSDT sptd.sys ZwEnumerateKey [0xF8411E2C]
SSDT sptd.sys ZwEnumerateValueKey [0xF84121BA]
SSDT sptd.sys ZwOpenKey [0xF840C0B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xAA2EC4B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xAA2EC570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xAA2EC6D0]
SSDT sptd.sys ZwQueryKey [0xF8412292]
SSDT sptd.sys ZwQueryValueKey [0xF8412112]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xAA2EC690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xAA2EC650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xAA2EC7D0]
SSDT sptd.sys ZwSetValueKey [0xF8412324]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xAA2EC510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xAA2EC590]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xAA2EC4D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xAA2EC5D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xAA2EC750]

---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\sptd.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
.text USBPORT.SYS!DllUnload F74EB62C 5 Bytes JMP 82BB21C8
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 F74234D0 48 Bytes [39, 18, 94, 8A, 5D, F4, 6C, ...]
? C:\WINDOWS\System32\Drivers\dtscsi.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1880] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F840CAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F840CC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F840CB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F840D748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F840D61E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8421ACA] sptd.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 82DD91E8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\NetBT \Device\NetBT_Tcpip_{26BAA8C1-882A-4C8A-8295-EC51AE3E2132} 824281E8
Device \Driver\usbuhci \Device\USBPDO-0 82BB11E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 82D6C1E8
Device \Driver\dmio \Device\DmControl\DmConfig 82D6C1E8
Device \Driver\dmio \Device\DmControl\DmPnP 82D6C1E8
Device \Driver\dmio \Device\DmControl\DmInfo 82D6C1E8
Device \Driver\usbuhci \Device\USBPDO-1 82BB11E8
Device \Driver\usbehci \Device\USBPDO-2 82B841E8
Device \Driver\usbuhci \Device\USBPDO-3 82BB11E8
Device \Driver\usbuhci \Device\USBPDO-4 82BB11E8

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

Device \Driver\PCI_NTPNP9442 \Device\00000049 sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 82DDB1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 82DDB1E8
Device \Driver\Cdrom \Device\CdRom0 82B3D1E8
Device \Driver\Cdrom \Device\CdRom1 82B3D1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 82DDA1E8
Device \Driver\atapi \Device\Ide\IdePort0 82DDA1E8
Device \Driver\atapi \Device\Ide\IdePort1 82DDA1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 82DDA1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{3942A2E5-0B0C-4D99-AA5F-1F0C1E42C860} 824281E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 824281E8
Device \Driver\NetBT \Device\NetbiosSmb 824281E8
Device \Driver\usbuhci \Device\USBFDO-0 82BB11E8
Device \Driver\usbuhci \Device\USBFDO-1 82BB11E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 822D31E8
Device \Driver\usbuhci \Device\USBFDO-2 82BB11E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 822D31E8
Device \Driver\usbuhci \Device\USBFDO-3 82BB11E8
Device \Driver\usbehci \Device\USBFDO-4 82B841E8
Device \Driver\Ftdisk \Device\FtControl 82DDB1E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 82A121E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1 82A121E8
Device \FileSystem\Cdfs \Cdfs 824CD7A0

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xBD 0x1A 0x8A 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4C 0x84 0x51 0x8C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0x69 0x57 0x6B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xF1 0x2F 0x60 0x2E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x79 0xEF 0xAA 0x58 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xDB 0xB7 0x82 0x8D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xBD 0x1A 0x8A 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4C 0x84 0x51 0x8C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0x69 0x57 0x6B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xF1 0x2F 0x60 0x2E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x79 0xEF 0xAA 0x58 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xDB 0xB7 0x82 0x8D ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xBD 0x1A 0x8A 0x77 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4C 0x84 0x51 0x8C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0x69 0x57 0x6B ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xF1 0x2F 0x60 0x2E ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x79 0xEF 0xAA 0x58 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xDB 0xB7 0x82 0x8D ...

---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

---- EOF - GMER 1.0.15 ----

Re: Vypinani PC

Napsal: 11 kvě 2010 11:44
od motji
Máte jen jeden disk,že?

:arrow: stáhněte MBR
http://www2.gmer.net/mbr/mbr.exe
-uložte ho na plochu a spusťte
-vytvoří se log s názvem mbr.log, vložte ho zde


:arrow: Ty teploty jsou už dost vysoké, ty restarty tím mohou být způsobeny. Máte stolní pc nebo notebook?
Nemáte náhodou taktovaný proocesor?

:arrow: Ty klíče jsou od Esetu, je to v pořádku, falešná detekce.

Re: Vypinani PC

Napsal: 11 kvě 2010 12:46
od ReQim
Ano mam jen jeden disk ktery je rozdeleny. Mam notebook..taktovany procesor neni a nedela mi to restarty ale jen vypnuti (nekdy ho zapnu a nedostane se to ani k nacteni windowsu a vypne se). Vi.m jak se chova pc kdyz je prehraty a restartne se ale tohle se mi vubec nezda..


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 61 !
copy of MBR has been found in sector 62 !

Re: Vypinani PC

Napsal: 11 kvě 2010 12:55
od motji
Ale i tak jsou ty teploty dost vysoké, zkuste to omezit.
Ted to vypadá s počítačem jak?

Re: Vypinani PC

Napsal: 11 kvě 2010 12:58
od ReQim
A jak bych tu teplotu mohl snizit kdyz mam notebook?
Od pouziti combofix se notebook zatim vubec nevypl tak doufam ze je to uz v poradku.

Re: Vypinani PC

Napsal: 11 kvě 2010 20:11
od motji
:arrow: Půjdete na konzolu zotavení a zadáte příkaz
fixmbr \device\harddisk0

-přesně takto, za FIXMBR je mezera




Ještě zkusíme vyčistit ten Mbr sektor :) .

:arrow: Stáhněte HxD portable http://mh-nexus.de/en/downloads.php?product=HxD
-uložte ho na plochu
-rozbalte ho a program uložte přímo na disk C
-spustte ho
-klikněte na otevřít disk - zvolte pevné disky(fyzické disky) :!: (nepoplette to)
-vyberte pevný disk 1
-do nabídky napište, který sektor chcete otevřít, potvrdíte enter, a budete přímo v tom sektoru
-napište mi, co máte na sektoru 1-64
-podívejte se, na kterém sektoru je Ntfs a Ntdlr

Aby jste měl představu, co hledat, takto vypadá můj 60.sektor, měly by tak vypadat všechny od 1-62, ale Vy je tak mít pravděpodobně nebudete.

Obrázek

Re: Vypinani PC

Napsal: 11 kvě 2010 22:02
od ReQim
Kdyz jsem zadal prikaz: "fixmbr \device\harddisk0" tak me vyskocilo

..UPOZORNENI..

Tento pocitac patrne obsahuje nestardantni nebo neplatny hlavni spousteci zaznam.
Pouzijete-li prikaz FIXMBR muze dojit k poskozeni tabulek oddilu.
V dusledku toho by se mohl zablokovat pristup ke vsem oddilum na aktualnim pevnem disku.
Nemate-li prave problem s pristupem na disk nepokracujte.
Opravdu chcete zapsat novy hlavni spousteci zaznam?

Tak jsem dal EXIT radeji...je jeste nake jine reseni jak omezit tu teplotu?
Nevim jestli jsem to udelal dobre s tim HxD ale snad ano.Trosku jsem to nechapal :lol:

Obrázek

Re: Vypinani PC

Napsal: 12 kvě 2010 06:04
od motji
S tím fixmbr - neprovádějte ho. Podle mě mbr rootkita nemáte, takže to tak raději necháme. Opravy Mbr sektorů mohou být nebezpečné.

K těm teplotám - notebook asi moc nevyčistíte :o , zkuste třeba koupit chladící podložku.

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?