Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc a kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Trsto
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 21 čer 2010 18:47

Prosím o pomoc a kontrolu logu

#1 Příspěvek od Trsto »

Zdravim,
rad by som vas poprosil o pomoc ... neviem ci mam virus alebo nejaku inu haved...ale skusim vysvetlit ... dnes sa mi stala taka vec ... Modeloval som v programe Solid Edge V20 a prislo k vypadku el.energie...odvtedy mi program nesiel ... resp spustit ho spustilo atd...ale prestalo mi fungovat prave tlacitko na myske (len v tomto programe podotykam) , ktore je velmi dolezite pre modelovanie prave.... co som spravil doteraz ... dal som unninstal,vycistil registre a nainstaloval znova ...ale program stale nejde,resp to prave tlacitko :-( kamos mi poradil vas,tak skusam ... stiahol som podla navodu RSIT a tu je log :

Dufam ze to je spravne :-)

Logfile of random's system information tool 1.07 (written by random/random)
Run by Administrator at 2010-06-21 19:51:27
Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (25%) free of 15 GB
Total RAM: 1023 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:51:42, on 21. 6. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Mouse Driver\StartAutorun.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\oodtray.exe
C:\Program Files\Mouse Driver\KMConfig.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Mouse Driver\KMWDSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Flock\flock.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Thoosje\thoosje vista sidebar\Thoosje Sidebar.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\QIP\qip.exe
C:\totalcmd\TOTALCMD.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Extreme Seven 2010 Ultimate
O2 - BHO: (no name) - {0CC676B7-DBF9-4784-9A72-396CDFE59479} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Fadebar] C:\Program Files\E7-Addons\7 Fadebar\Fadebar.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Styler] C:\Program Files\E7-Addons\Styler\Styler.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TT] C:\Program Files\E7-Addons\TrueTransparency\TrueTransparency.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [7Bar] C:\Program Files\E7-Addons\Seven Sidebar\Thoosje Sevenbar.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ViStart] C:\Program Files\E7-Addons\ViStart\ViStart.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\dpnhpast32.dll
O20 - Winlogon Notify: 840cf9bd724 - C:\WINDOWS\System32\dpnhpast32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe

--
End of file - 6754 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CC676B7-DBF9-4784-9A72-396CDFE59479}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
C:\PROGRA~1\INBOXT~1\Inbox.dll [2009-12-18 655344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-07-25 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75}
{D7E97865-918F-41E4-9CD0-25AB1C574CE8} - &Inbox Toolbar - C:\PROGRA~1\INBOXT~1\Inbox.dll [2009-12-18 655344]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"KMCONFIG"=C:\Program Files\Mouse Driver\StartAutorun.exe [2008-05-30 212992]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2007-03-30 262144]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2006-09-18 843776]
"OODefragTray"=C:\WINDOWS\system32\oodtray.exe [2009-02-25 2553088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7Bar]
C:\Program Files\E7-Addons\Seven Sidebar\Thoosje Sevenbar.exe [2009-08-11 605696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-09-13 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CSmileys]
C:\Program Files\Crawler\Smileys\CSmileysIM.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET Smart Security\egui.exe /hide /waitservice []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fadebar]
C:\Program Files\E7-Addons\7 Fadebar\Fadebar.exe [2008-12-25 211333]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe [2009-06-23 745472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-25 1414144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2007-04-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker]
C:\Program Files\SiteRanker\SiteRankTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Styler]
C:\Program Files\E7-Addons\Styler\Styler.exe [2007-04-15 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TT]
C:\Program Files\E7-Addons\TrueTransparency\TrueTransparency.exe [2009-08-10 339456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2009-10-12 289072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol]
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^hamachi.lnk]
C:\PROGRA~1\Hamachi\hamachi.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
C:\PROGRA~1\LimeWire\LimeWire.exe -startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Aktualizovat ESET licenci.lnk]
C:\PROGRA~1\ESET\MINODL~1\MINODL~1.EXE -u -d 10000 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NBService"=3
"MDM"=2
"JavaQuickStarterService"=2
"sp_rssrv"=2
"ose"=3
"WMPNetworkSvc"=3
"ServiceLayer"=3
"idsvc"=3
"gearsec"=2
"Lavasoft Ad-Aware Service"=2
"Hamachi2Svc"=2
"O&O Defrag"=2
"ekrn"=2
"EhttpSrv"=3

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
CoreCenter.lnk - C:\Program Files\MSI\Core Center\CoreCenter.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\System32\dpnhpast32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\840cf9bd724]
C:\WINDOWS\System32\dpnhpast32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2009-09-07 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1
"NoUserNameInStartMenu"=1
"NoSMHelp"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:hlsw"
"C:\Program Files\Quake III Arena\quake3.exe"="C:\Program Files\Quake III Arena\quake3.exe:*:Enabled:quake3"
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
shell\AutoRun\command - L:\LaunchU3.exe -a


======File associations======

.reg - open - "regedit.exe" "%1"

======List of files/folders created in the last 1 months======

2010-06-21 19:51:28 ----D---- C:\Program Files\trend micro
2010-06-21 19:51:27 ----D---- C:\rsit
2010-06-21 18:13:27 ----D---- C:\KRONIKA
2010-06-06 15:40:10 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-06-06 15:36:08 ----A---- C:\WINDOWS\amcap.exe
2010-06-06 15:36:04 ----A---- C:\WINDOWS\vsnpstd3.exe
2010-06-06 15:36:02 ----A---- C:\WINDOWS\tsnpstd3.exe
2010-06-06 15:35:56 ----A---- C:\WINDOWS\snpstd3.ini
2010-06-06 15:35:48 ----A---- C:\WINDOWS\system32\vsnpstd3.dll
2010-06-06 15:35:46 ----A---- C:\WINDOWS\system32\rsnpstd3.dll
2010-06-06 15:35:45 ----D---- C:\Program Files\Common Files\snpstd3
2010-06-06 15:35:45 ----A---- C:\WINDOWS\system32\csnpstd3.dll
2010-06-06 15:35:45 ----A---- C:\WINDOWS\csnpstd3.dll
2010-06-06 15:35:21 ----D---- C:\Documents and Settings\Administrator\Application Data\InstallShield
2010-06-03 19:25:52 ----D---- C:\Documents and Settings\Administrator\Application Data\PC Suite
2010-06-03 19:25:51 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-06-03 19:25:03 ----D---- C:\Program Files\Common Files\PCSuite
2010-06-03 19:24:48 ----D---- C:\Program Files\Common Files\Nokia
2010-06-03 19:24:22 ----D---- C:\Program Files\PC Connectivity Solution
2010-06-03 19:24:04 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
2010-06-03 19:18:24 ----A---- C:\PCSuiteCleanerLogFile_6-3-2010_191824.txt
2010-06-03 19:18:00 ----A---- C:\PCSuiteCleanerLogFile_6-3-2010_191800.txt
2010-06-03 19:00:28 ----D---- C:\Program Files\Nokia
2010-05-28 11:48:57 ----D---- C:\Documents and Settings\Administrator\Application Data\Hamachi
2010-05-25 11:12:35 ----D---- C:\Documents and Settings\Administrator\Application Data\cadenas
2010-05-24 10:30:39 ----D---- C:\Documents and Settings\Administrator\Application Data\SMC

======List of files/folders modified in the last 1 months======

2010-06-21 19:51:28 ----RD---- C:\Program Files
2010-06-21 19:04:21 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-21 19:02:31 ----D---- C:\WINDOWS\Prefetch
2010-06-21 19:02:28 ----RSD---- C:\WINDOWS\assembly
2010-06-21 18:55:40 ----SHD---- C:\WINDOWS\Installer
2010-06-21 18:43:17 ----D---- C:\WINDOWS\system32
2010-06-21 18:42:47 ----RSD---- C:\WINDOWS\Fonts
2010-06-21 18:15:43 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-21 17:48:37 ----D---- C:\WINDOWS\Temp
2010-06-21 17:48:32 ----D---- C:\WINDOWS
2010-06-21 17:48:32 ----D---- C:\Program Files\Flock
2010-06-21 17:47:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-21 17:29:11 ----SH---- C:\boot.ini
2010-06-21 17:29:11 ----A---- C:\WINDOWS\win.ini
2010-06-21 17:29:11 ----A---- C:\WINDOWS\system.ini
2010-06-21 09:34:30 ----D---- C:\Documents and Settings\Administrator\Application Data\uTorrent
2010-06-16 17:08:10 ----D---- C:\Program Files\ICQ6.5
2010-06-13 22:01:17 ----D---- C:\Program Files\ESET
2010-06-13 22:01:14 ----D---- C:\WINDOWS\system32\drivers
2010-06-13 22:01:13 ----HD---- C:\WINDOWS\inf
2010-06-10 11:41:25 ----D---- C:\Documents and Settings\Administrator\Application Data\PrimoPDF
2010-06-08 12:22:21 ----D---- C:\Documents and Settings\Administrator\Application Data\Skype
2010-06-08 11:54:31 ----D---- C:\Documents and Settings\Administrator\Application Data\skypePM
2010-06-06 19:09:16 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 15:47:21 ----D---- C:\WINDOWS\security
2010-06-06 15:36:02 ----D---- C:\WINDOWS\twain_32
2010-06-06 15:35:45 ----D---- C:\Program Files\Common Files
2010-06-06 15:35:38 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-03 19:25:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-03 19:18:42 ----D---- C:\Program Files\Common Files\InstallShield
2010-06-03 18:59:10 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
2010-05-31 08:31:04 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2010-05-28 12:18:08 ----D---- C:\WINDOWS\pss
2010-05-28 11:47:58 ----D---- C:\temp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 36864]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-04-09 31548]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-01-24 4127488]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-28 25280]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 KMWDFilter;KMWDFilter; \??\C:\WINDOWS\System32\Drivers\KMWDFilter.SYS []
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\nvefd2k.sys [2007-07-12 42112]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 PCAlertDriver;PCAlertDriver; \??\C:\Program Files\MSI\Core Center\NTGLM7X.sys []
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-10-12 47360]
R3 RushTopDevice;RushTopDevice; \??\C:\Program Files\MSI\Core Center\RushTop.sys []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-10-06 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-10-06 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2007-04-03 10246144]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-10-06 7936]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-10-06 7936]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 atapi;atapi; C:\WINDOWS\system32\drivers\atapi.sys [2008-04-14 96512]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files\Mouse Driver\KMWDSrv.exe [2008-06-23 208896]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2009-02-25 1352960]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-07-25 153376]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-09-12 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119416
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc a kontrolu logu

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Trsto
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 21 čer 2010 18:47

Re: Prosím o pomoc a kontrolu logu

#3 Příspěvek od Trsto »

ok tak tu je teda ten druhy log z combofix....


ComboFix 10-06-20.06 - Administrator . 06. 2010 20:13:03.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1023.495 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\BIN
c:\bin\RECYCLE\Desktop.ini
c:\documents and settings\Administrator\Application Data\020000007ee5a38c724C.manifest
c:\documents and settings\Administrator\Application Data\020000007ee5a38c724O.manifest
c:\documents and settings\Administrator\Application Data\020000007ee5a38c724P.manifest
c:\documents and settings\Administrator\Application Data\020000007ee5a38c724S.manifest
c:\documents and settings\Administrator\Application Data\inst.exe
c:\documents and settings\Administrator\LegitCheckControl.dll
c:\documents and settings\Administrator\WgaLogon.dll
c:\documents and settings\Administrator\WgaTray.exe
c:\documents and settings\Administrator\xmlUpdater.exe
c:\documents and settings\Default User\LegitCheckControl.dll
c:\documents and settings\Default User\WgaLogon.dll
c:\documents and settings\Default User\WgaTray.exe
c:\documents and settings\Default User\xmlUpdater.exe
c:\windows\system32\bae9e559-b43d-19d5-473e-85658c51b53f.exe
c:\windows\system32\config\systemprofile\LegitCheckControl.dll
c:\windows\system32\config\systemprofile\WgaLogon.dll
c:\windows\system32\config\systemprofile\WgaTray.exe
c:\windows\system32\config\systemprofile\xmlUpdater.exe

.
((((((((((((((((((((((((( Files Created from 2010-05-21 to 2010-06-21 )))))))))))))))))))))))))))))))
.

2010-06-21 17:51 . 2010-06-21 17:51 -------- d-----w- c:\program files\trend micro
2010-06-21 17:51 . 2010-06-21 17:51 -------- d-----w- C:\rsit
2010-06-21 16:13 . 2010-06-21 16:13 -------- d-----w- C:\KRONIKA
2010-06-07 09:00 . 2010-06-07 09:00 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\UGS
2010-06-06 13:41 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-06-06 13:41 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-06-06 13:40 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2010-06-06 13:40 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2010-06-06 13:40 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-06-06 13:40 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-06-06 13:40 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-06-06 13:40 . 2008-04-14 03:42 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-06-06 13:39 . 2008-04-13 22:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-06-06 13:36 . 2006-07-03 08:31 94208 ----a-w- c:\windows\amcap.exe
2010-06-06 13:36 . 2006-09-18 12:12 843776 ----a-w- c:\windows\vsnpstd3.exe
2010-06-06 13:36 . 2007-03-30 15:44 262144 ----a-w- c:\windows\tsnpstd3.exe
2010-06-06 13:35 . 2007-04-03 17:25 10246144 ----a-w- c:\windows\system32\drivers\snpstd3.sys
2010-06-06 13:35 . 2007-03-30 13:09 61440 ----a-w- c:\windows\system32\vsnpstd3.dll
2010-06-06 13:35 . 2007-03-21 13:23 172032 ----a-w- c:\windows\system32\rsnpstd3.dll
2010-06-06 13:35 . 2010-06-06 13:36 -------- d-----w- c:\program files\Common Files\snpstd3
2010-06-06 13:35 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd3.dll
2010-06-06 13:35 . 2005-11-23 11:55 53248 ----a-w- c:\windows\csnpstd3.dll
2010-06-06 13:35 . 2010-06-06 13:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\InstallShield
2010-06-06 13:08 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-06-03 17:25 . 2010-06-03 17:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2010-06-03 17:25 . 2010-06-03 17:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-06-03 17:25 . 2010-06-03 17:25 -------- d-----w- c:\program files\Common Files\PCSuite
2010-06-03 17:24 . 2010-06-03 17:24 -------- d-----w- c:\program files\Common Files\Nokia
2010-06-03 17:24 . 2010-06-03 17:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-06-03 17:24 . 2009-10-06 09:52 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-06-03 17:00 . 2010-06-03 17:24 -------- d-----w- c:\program files\Nokia
2010-06-03 17:00 . 2010-06-03 16:57 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2010-06-03 17:00 . 2010-06-03 17:00 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2010-06-03 17:00 . 2010-06-03 17:00 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-06-03 17:00 . 2010-06-03 17:00 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2010-06-03 17:00 . 2010-06-03 17:00 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2010-06-01 20:08 . 2010-06-01 19:40 34686912 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_slk_web(2).exe
2010-06-01 13:21 . 2010-06-01 13:21 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\FEMAP
2010-05-31 06:31 . 2010-05-31 06:31 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2010-05-31 06:31 . 2010-06-01 12:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2010-05-28 09:48 . 2010-05-28 10:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\Hamachi
2010-05-28 09:16 . 2010-05-28 09:38 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-25 09:12 . 2010-05-25 09:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\cadenas
2010-05-24 08:30 . 2010-05-24 08:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\SMC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-21 15:48 . 2009-10-12 14:21 -------- d-----w- c:\program files\Flock
2010-06-21 14:21 . 2009-10-12 12:34 79064 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-21 07:34 . 2009-10-12 13:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-06-16 15:08 . 2009-10-12 17:34 -------- d-----w- c:\program files\ICQ6.5
2010-06-13 20:01 . 2009-12-03 21:59 -------- d-----w- c:\program files\ESET
2010-06-10 09:41 . 2010-03-29 09:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\PrimoPDF
2010-06-08 10:22 . 2009-10-12 17:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2010-06-08 09:54 . 2009-10-12 17:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2010-06-06 13:35 . 2009-10-12 12:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-03 17:18 . 2009-11-08 14:43 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-03 16:59 . 2009-12-20 13:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-28 09:48 . 2009-09-23 09:41 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-05-11 15:21 . 2009-12-26 21:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\LimeWire
2010-05-10 11:38 . 2010-05-10 11:38 10134 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{81CDDCD6-16F3-44B8-91FA-F9FB3D94B38D}\ARPPRODUCTICON.exe
2010-05-10 11:38 . 2010-05-10 11:29 -------- d-----w- c:\program files\SMC
2010-05-07 13:50 . 2010-05-07 13:50 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-05-07 13:47 . 2010-01-21 17:45 3532 ----a-w- C:\drmHeader.bin
2010-04-23 16:29 . 2010-04-23 16:29 -------- d-----w- c:\program files\OO Software
2010-04-04 08:11 . 2010-04-04 08:11 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-04 08:11 . 2010-04-04 08:11 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-04 08:11 . 2010-04-04 08:11 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-04 08:11 . 2010-04-04 08:11 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-04 08:10 . 2010-04-04 08:11 34686912 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_slk_web.exe
2010-01-17 11:49 . 2010-01-17 11:49 2349 --sha-w- c:\windows\system32\1803.tmp
2010-01-17 15:49 . 2010-01-17 15:49 2349 --sha-w- c:\windows\system32\294C.tmp
2010-02-09 21:41 . 2010-02-09 01:41 2349 --sha-w- c:\windows\system32\493A.tmp
.

------- Sigcheck -------

[-] 2009-09-02 . 035ECDB7929606F3F96805DA2AED355E . 2003968 . . [6.00.2900.5634] . . c:\windows\explorer.exe

[-] 2009-09-07 14:16 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2008-05-30 212992]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-30 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2009-02-25 2553088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Fadebar"="c:\program files\E7-Addons\7 Fadebar\Fadebar.exe" [2008-12-25 211333]
"Styler"="c:\program files\E7-Addons\Styler\Styler.exe" [2007-04-15 307200]
"7Bar"="c:\program files\E7-Addons\Seven Sidebar\Thoosje Sevenbar.exe" [2009-08-11 605696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
CoreCenter.lnk - c:\program files\MSI\Core Center\CoreCenter.exe [2009-10-12 932864]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Aktualizovat ESET licenci.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Aktualizovat ESET licenci.lnk
backup=c:\windows\pss\Aktualizovat ESET licenci.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\7Bar]
2009-08-11 12:48 605696 ----a-w- c:\program files\E7-Addons\Seven Sidebar\Thoosje Sevenbar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 02:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-09-13 09:12 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fadebar]
2008-12-25 20:45 211333 ----a-w- c:\program files\E7-Addons\7 Fadebar\Fadebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
2009-06-23 09:37 745472 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-06-25 13:12 1414144 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2007-04-09 12:23 200704 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 11:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Styler]
2007-04-15 13:28 307200 ----a-w- c:\program files\E7-Addons\Styler\Styler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 03:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TT]
2009-08-10 19:28 339456 ----a-w- c:\program files\E7-Addons\TrueTransparency\TrueTransparency.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-10-12 13:23 289072 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NBService"=3 (0x3)
"MDM"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"sp_rssrv"=2 (0x2)
"ose"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ServiceLayer"=3 (0x3)
"idsvc"=3 (0x3)
"gearsec"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"Hamachi2Svc"=2 (0x2)
"O&O Defrag"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\QIP\\qip.exe"=

R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [12. 10. 2009 15:52 16640]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [23. 6. 2008 22:28 208896]

--- Other Services/Drivers In Memory ---

*Deregistered* - NVR0Dev
*Deregistered* - PCAlertDriver
*Deregistered* - RushTopDevice

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

BHO-{0CC676B7-DBF9-4784-9A72-396CDFE59479} - (no file)
Notify-840cf9bd724 - c:\windows\System32\dpnhpast32.dll
MSConfigStartUp-CSmileys - c:\program files\Crawler\Smileys\CSmileysIM.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET Smart Security\egui.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-SiteRanker - c:\program files\SiteRanker\SiteRankTray.exe
MSConfigStartUp-SpywareTerminatorUpdate - c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
MSConfigStartUp-WinPatrol - c:\program files\BillP Studios\WinPatrol\winpatrol.exe
ActiveSetup-{23MAD6M8-1MAD-77AD-JIM1-73OP5G3369085} - c:\zolander\Polanda\box.exe
ActiveSetup-{31IOP6M8-1DAB-81AD-BOK1-26OC5H3565645} - c:\tender\InterPol\\NkeY.exe
ActiveSetup-{31IOP6M8-1DAB-81AD-BOK1-78OC5H3987645} - c:\heroes\FILES\\NVeB.exe
ActiveSetup-{31IOP6M8-1DAB-81AD-BOK6-18OC5H2007645} - c:\algeria\FAILED\\die.exe
ActiveSetup-{67KLN5J0-4OPM-00WE-AAX5-74CC2A323342} - c:\bin\RECYCLE\Bin.exe
AddRemove-bae9e559-b43d-19d5-473e-85658c51b53f - c:\windows\system32\bae9e559-b43d-19d5-473e-85658c51b53f.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-21 20:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1659004503-1409082233-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,73,9b,c3,fe,a8,1c,43,b6,d8,f0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,73,9b,c3,fe,a8,1c,43,b6,d8,f0,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,73,9b,c3,fe,a8,1c,43,b6,d8,f0,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="82965784B903DAB544A4DFE12D3BC6BE91836190C2E23467EEFD850F91F08997BC155AFCE5911D42D8A177A803CCBD359200F337C6BE138DE156A9D2075DC72D03584B6E51CD8444CE2EC59970CCC270715CF75E47A160E16249B5BBF3A992993FC69D21CDEAA1B36430BA822C3C72BE629D7AFD7EFC65AA391D748BB657023FEE05F93DFC9A74A8EBCFF918BC225A94AC0DBE727CC75CD3C15D6464046E9CA12381BA4F581874624AFCDE6F00077E062B3B3878207D766DEDD838CF61FC60E980EC6FCA2B1E8AC1FBE4F20327F8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74C9DB7CE019D40AA5C5D575E7D6A3B9808CFDCB59EEEF7CF034233EE725BCAC3E201A813BE05F1D59DD765F617F68C81C12AA73FF2215285DCE54D40083E676FE15BEFAE3F8CBBF3A34D0C20AC4E7F14D6E9C058A19F29992BFD1472CD1C005F6E06D2C5E64E47664889F7306BFC6B43FBC5A82074B543CFC22D3F798A39683B2D34E1C11E2D93DCA169B2A5811F15E158E50646745BCFBF7C09AED84C0FD4FE4905569B94BE7DD8C93B6E105B0A231897E6A0107542E0D4341B622E63C8E0FDEF120AE33CCBC9AFE1C47C93AC43A4DF6959655788CC694F4B620226E4C78B5A52E47CBD4AD19E8B893DD667ED06880781446589889245C2A6CF55822CA0B50EA6FD4F5FB88208696AD119D9D9BE23B2181F55A60F6030972E4A4D1A549BA7E5A54FCA96C744759BAB2182CA6E13AD57E7588E467DB44D894EAB79583EB489020E3FD8BFF6AF3AC77F3F762CEE56C4C0B04F8D0FF7C29F27F8C19039901EEBD7A0A909CF8F938D6896B57E89E495E68C36D97340677213D422CE6CD0B2BA40B0A3DD8D4E98EE8C4A277EC57D188DF9304140052A76DFF3CAC2080B44D423DC28619E3F556179B38F6E0C9BB71BB1C6EF9BC0AB3296DA7315D5988DCF64A4FBAEA5A316947C9CE7AE27BFF5FD3E29F768968B73527AE4A613DE1EBA3F18BFBC8BC216324FC074F0EF177369A7994D1F0785C58D969BB70877DF2B7C766AA8A0558F96585E46D379728472342188ACB10F3E89CF21363D744C6345E0E997488EF8E4386C2AECC091A6B97C356B2B0B07169E6231A74995AC6BF4E598A69EBAD0B720807B34D572AC548447F19962DDD9898551D0711915D60525FA7AC84850162623EBB38F6758A093B7F81054D7CF4DA5D64D6EDE2F427C9C0A6801849B0E70ACD4E8E6E14C942BD2AAAD5C5974BFE47E793D6F5ED6598B0C3A02481D66ACD6899C5B8EE7F1F96AD3B8F648F568BF88FA5A7EDA769FC8D37C5413946F3997A24CE81943F00C94612CBED76611A696055567E3DFC0DE350C6FF759C8E9E8701359AB6D45DF8EA07846A0C7ECA2673E8A1C162FCE"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\cscui.dll
.
Completion time: 2010-06-21 20:30:53
ComboFix-quarantined-files.txt 2010-06-21 18:30

Pre-Run: 3 846 152 192 bytes free
Post-Run: 3 860 959 232 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - BCA8BEF37F07FADAA3298D1C23290371

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119416
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc a kontrolu logu

#4 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\system32\1803.tmp
c:\windows\system32\294C.tmp
c:\windows\system32\493A.tmp
C:\WINDOWS\System32\dpnhpast32.dll

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\840cf9bd724]
Uložte na ploch jako CFScript.txt. Pak jej myší přetáhněte nad ikionu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Trsto
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 21 čer 2010 18:47

Re: Prosím o pomoc a kontrolu logu

#5 Příspěvek od Trsto »

no nebol cas par dni ale vykonal som vsetko ...problem pretrvava ..takze ostavaju len moznosti 2 ...

bud je problem s programom ... alebo s win ...nejaka nekompatibilita..skor asi win ... neviem inak kedze program niekolko dni siel bez problemov a zrazu nic ani po vycisteni a reinstale...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119416
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc a kontrolu logu

#6 Příspěvek od Rudy »

Dejte ještě log CF po posledním skenu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět