Stránka 1 z 1

Kontrola LOGu divné chování PC

Napsal: 01 říj 2010 09:49
od phz^
Pomůžete mi prosím zkontrolovat LOG? děkuji :roll:


Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2010-10-01 10:49:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 10 GB (20%) free of 50 GB
Total RAM: 1023 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:49, on 2010-10-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60446
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60446
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BC914F-9394-4596-8F89-80F6D4F58FB1}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 8942 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2008-09-08 1194496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-08-02 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-28 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-28 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-08-16 962808]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\ctbr.dll [2008-09-08 1194496]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-07-29 2171904]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-10-08 57344]
"AudioDeck"=C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [2007-08-09 528384]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-06-28 74752]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2009-07-29 3055616]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-25 1414144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo RX420 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE [2004-04-09 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-25 1414144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-28 148888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\SweetIM\Messenger\SweetIM.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-06-28 74752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ WinCinema Manager.lnk]
C:\PROGRA~1\Sandisk\Common\Bin\WINCIN~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2004-02-03 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-06 267304]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Codemasters\DiRT2 Demo\dirt2.exe"="C:\Program Files\Codemasters\DiRT2 Demo\dirt2.exe:*:Enabled:DiRT2 Demo"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Miranda IM KP v5.0.8.15\miranda32.exe"="C:\Program Files\Miranda IM KP v5.0.8.15\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-09-30 20:38:08 ----D---- C:\Program Files\Winamp Detect
2010-09-30 20:37:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar
2010-09-30 20:37:49 ----D---- C:\Program Files\Winamp Toolbar
2010-09-30 20:36:38 ----D---- C:\Program Files\Winamp
2010-09-30 20:36:38 ----D---- C:\Documents and Settings\Admin\Data aplikací\Winamp

======List of files/folders modified in the last 1 months======

2010-10-01 10:49:26 ----D---- C:\Program Files\Trend Micro
2010-10-01 10:49:24 ----D---- C:\WINDOWS\Prefetch
2010-10-01 10:18:58 ----D---- C:\Program Files\Mozilla Firefox
2010-10-01 08:47:22 ----D---- C:\WINDOWS\temp
2010-09-30 23:34:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-30 23:03:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-09-30 23:03:08 ----D---- C:\Program Files\Spyware Terminator
2010-09-30 23:00:35 ----D---- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
2010-09-30 20:38:08 ----D---- C:\Program Files
2010-09-30 20:36:59 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-30 16:16:15 ----D---- C:\Documents and Settings\Admin\Data aplikací\dvdcss
2010-09-28 13:08:23 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-27 22:48:31 ----D---- C:\Documents and Settings\Admin\Data aplikací\uTorrent
2010-09-27 08:55:58 ----D---- C:\Documents and Settings\Admin\Data aplikací\ICQ
2010-09-26 13:48:35 ----D---- C:\WINDOWS\Minidump
2010-09-26 13:48:35 ----D---- C:\WINDOWS
2010-09-21 10:05:26 ----D---- C:\Program Files\EA GAMES
2010-09-10 19:49:35 ----D---- C:\Program Files\ESET
2010-09-06 21:41:22 ----D---- C:\WINDOWS\system32
2010-09-06 21:41:21 ----D---- C:\Program Files\ICQ6.5

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-05-27 721904]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2003-07-02 27904]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1997-12-23 23936]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-04 11868]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2002-10-29 40960]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-04 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-04 220032]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2007-06-27 207488]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-04 685056]
S1 946bdca7;946bdca7; C:\WINDOWS\System32\drivers\946bdca7.sys []
S2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
S2 qxhqnkzx;qxhqnkzx; \??\C:\WINDOWS\system32\drivers\dakikf.sys []
S3 a24ulgw3;a24ulgw3; C:\WINDOWS\system32\drivers\a24ulgw3.sys []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-10-09 475788]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-05-02 8064]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 wpdusb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-08-16 222968]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2008-02-05 331776]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-03-27 75064]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-07-29 487424]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-28 152984]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Kontrola LOGu divné chování PC

Napsal: 01 říj 2010 16:54
od Rudy
Vidím tam pár šmejdů, vč. rootkitu. Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Kontrola LOGu divné chování PC

Napsal: 09 říj 2010 18:24
od phz^
ComboFix 10-10-09.01 - Administrator 2010-10-09 18:38:28.5.1 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.1023.832 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Admin\Data aplikací\AD ON Multimedia
c:\documents and settings\Admin\Data aplikací\AD ON Multimedia\eBay Shortcuts\config.ini
c:\documents and settings\Admin\Data aplikací\AD ON Multimedia\eBay Shortcuts\eBayShortcuts.exe
c:\documents and settings\Admin\Dokumenty\cc_20101001_123451.reg

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-09 do 2010-10-09 )))))))))))))))))))))))))))))))
.

2010-10-09 16:26 . 2010-10-09 16:27 3876009 ----a-w- C:\ComboFix.exe
2010-10-01 11:55 . 2010-10-01 11:55 -------- d-----w- c:\program files\ESET
2010-09-30 18:38 . 2010-09-30 18:38 -------- d-----w- c:\program files\Winamp Detect
2010-09-30 18:37 . 2010-09-30 18:37 -------- d-----w- c:\program files\Winamp Toolbar
2010-09-30 18:36 . 2010-10-01 11:46 -------- d-----w- c:\program files\Winamp

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-01 11:43 . 2010-07-29 17:48 -------- d-----w- c:\program files\Ask.com
2010-10-01 08:49 . 2009-03-15 14:19 -------- d-----w- c:\program files\Trend Micro
2010-09-21 08:05 . 2009-06-29 15:44 -------- d-----w- c:\program files\EA GAMES
2010-09-06 19:41 . 2010-08-21 11:00 -------- d-----w- c:\program files\ICQ6.5
2010-08-25 15:47 . 2008-09-23 11:58 -------- d-----w- c:\program files\Crawler
2010-08-25 14:10 . 2010-08-09 10:03 2516 --sha-w- c:\documents and settings\All Users\Data aplikací\KGyGaAvL.sys
2010-08-22 08:05 . 2008-09-11 14:50 -------- d-----w- c:\program files\ICQ6Toolbar
2010-08-18 17:49 . 2010-08-18 17:49 -------- d-----w- c:\program files\Any Video Converter
2010-08-17 19:49 . 2010-08-17 19:49 -------- d-----w- c:\program files\Monte Cristo
2010-08-12 16:24 . 2010-08-12 16:24 -------- d-----w- c:\program files\Common Files\Protexis
2010-08-12 16:20 . 2010-08-12 16:20 -------- d-----w- c:\program files\Common Files\Corel
2010-08-12 16:19 . 2010-08-12 16:19 -------- d-----w- c:\program files\Corel
2010-08-12 15:45 . 2010-08-12 15:45 -------- d-----w- c:\program files\VS Revo Group
2010-08-10 11:16 . 2010-08-09 10:03 88 --sh--r- c:\documents and settings\All Users\Data aplikací\F339789486.sys
2010-08-02 09:44 . 2010-08-05 19:17 127440 ----a-w- c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\tlqb4s7p.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
2010-08-02 09:44 . 2010-08-05 19:17 149968 ----a-w- c:\documents and settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2010-07-28 15:36 . 2010-07-28 15:36 180224 ----a-w- c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\winamptbres.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot_2010-03-12_12.21.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-10-25 16:00 . 2009-12-06 12:59 68156 c:\windows\system32\perfc009.dat
+ 2001-10-25 16:00 . 2010-03-28 07:08 68156 c:\windows\system32\perfc009.dat
- 2001-10-25 16:00 . 2009-12-06 12:59 79062 c:\windows\system32\perfc005.dat
+ 2001-10-25 16:00 . 2010-03-28 07:08 79062 c:\windows\system32\perfc005.dat
+ 2003-03-18 18:44 . 2003-03-18 18:44 49152 c:\windows\system32\MFC71KOR.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 49152 c:\windows\system32\MFC71JPN.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 61440 c:\windows\system32\MFC71ITA.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 45056 c:\windows\system32\MFC71CHT.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 40960 c:\windows\system32\MFC71CHS.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 61440 c:\windows\system32\MFC71FRA.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 61440 c:\windows\system32\MFC71ESP.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 57344 c:\windows\system32\MFC71ENU.DLL
+ 2003-03-18 18:44 . 2003-03-18 18:44 65536 c:\windows\system32\MFC71DEU.DLL
+ 2009-12-10 19:59 . 2008-04-13 17:45 26112 c:\windows\system32\drivers\usbser.sys
- 2009-12-10 19:59 . 2008-04-13 18:45 26112 c:\windows\system32\drivers\usbser.sys
+ 2009-02-06 12:24 . 2009-02-06 12:24 56280 c:\windows\system32\drivers\epfwtdi.sys
+ 2009-02-06 12:24 . 2009-02-06 12:24 33096 c:\windows\system32\drivers\epfwndis.sys
+ 2008-05-02 08:58 . 2008-05-02 08:58 20864 c:\windows\system32\drivers\ccdcmbo.sys
+ 2008-05-02 08:58 . 2008-05-02 08:58 17536 c:\windows\system32\drivers\ccdcmb.sys
+ 2009-12-10 19:59 . 2008-04-13 17:45 26112 c:\windows\system32\dllcache\usbser.sys
- 2009-12-10 19:59 . 2008-04-13 18:45 26112 c:\windows\system32\dllcache\usbser.sys
+ 2010-08-12 16:24 . 2010-08-12 16:24 86016 c:\windows\Installer\{FFFE7261-2318-4227-B827-E9E05E16DFE5}\ARPPRODUCTICON.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 10134 c:\windows\Installer\{CE2DA11A-917F-4CF5-AB55-755EC115DD10}\ARPPRODUCTICON.exe
+ 2010-10-01 11:57 . 2010-10-01 11:57 97360 c:\windows\Installer\{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}\egui.exe
+ 2010-10-01 11:57 . 2010-10-01 11:57 10134 c:\windows\Installer\{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}\callmsi.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 86016 c:\windows\Installer\{BF439B41-0252-48DE-8B8B-0430CB26A181}\ARPPRODUCTICON.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 10134 c:\windows\Installer\{9D0798D0-AF6C-4E62-94B1-AEBF1A43E00A}\ARPPRODUCTICON.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 86016 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\ARPPRODUCTICON.exe
+ 2010-08-12 16:23 . 2010-08-12 16:23 10134 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF017}\ARPPRODUCTICON.exe
+ 2010-08-12 16:23 . 2010-08-12 16:23 22758 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF016}\ARPPRODUCTICON.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 22758 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF014}\ARPPRODUCTICON.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 86016 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF013}\NewShortcut1.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 22758 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF013}\ARPPRODUCTICON.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 22758 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF012}\ARPPRODUCTICON.exe
+ 2010-08-12 16:26 . 2010-08-12 16:26 10134 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF010}\ARPPRODUCTICON.exe
+ 2008-05-02 08:58 . 2008-05-02 08:58 8064 c:\windows\system32\drivers\usbser_lowerfltj.sys
+ 2008-05-02 08:58 . 2008-05-02 08:58 8064 c:\windows\system32\drivers\usbser_lowerflt.sys
- 2001-10-25 16:00 . 2009-12-06 12:59 435260 c:\windows\system32\perfh009.dat
+ 2001-10-25 16:00 . 2010-03-28 07:08 435260 c:\windows\system32\perfh009.dat
+ 2001-10-25 16:00 . 2010-03-28 07:08 432004 c:\windows\system32\perfh005.dat
- 2001-10-25 16:00 . 2009-12-06 12:59 432004 c:\windows\system32\perfh005.dat
+ 2008-05-02 08:58 . 2008-05-02 08:58 148992 c:\windows\system32\nsesetup.dll
+ 2008-05-02 08:58 . 2008-05-02 08:58 733696 c:\windows\system32\nmwcdcocls.dll
+ 2008-02-05 18:54 . 2010-08-13 07:15 201736 c:\windows\system32\FNTCACHE.DAT
+ 2009-02-06 12:24 . 2009-02-06 12:24 130952 c:\windows\system32\drivers\epfw.sys
+ 2009-02-06 12:23 . 2009-02-06 12:23 106208 c:\windows\system32\drivers\ehdrv.sys
+ 2009-02-06 12:19 . 2009-02-06 12:19 113448 c:\windows\system32\drivers\eamon.sys
+ 2010-06-20 10:20 . 2010-06-20 10:20 390144 c:\windows\system32\CF20669.exe
+ 2010-08-12 16:26 . 2010-08-12 16:26 621568 c:\windows\Installer\82b89.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 247296 c:\windows\Installer\82b82.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 267264 c:\windows\Installer\82b7b.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 944640 c:\windows\Installer\82b75.msi
+ 2010-08-12 16:23 . 2010-08-12 16:23 980480 c:\windows\Installer\82b52.msi
+ 2010-08-12 16:23 . 2010-08-12 16:23 944128 c:\windows\Installer\82b4b.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 135168 c:\windows\Installer\{DB81779E-7CC5-4630-BCFC-754004956444}\misc.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 135168 c:\windows\Installer\{B61D21B6-469D-4423-B161-62DB20B8A70E}\misc.exe
+ 2010-07-29 17:49 . 2010-07-29 17:49 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut93_CC5820041A9C446BB9018F9ECF582DD1.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut92_CC5820041A9C446BB9018F9ECF582DD1.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut913_CC5820041A9C446BB9018F9ECF582DD1.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut912.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut911.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut9101.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut9100.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut910.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut91.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut903_CC5820041A9C446BB9018F9ECF582DD1.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut902.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut901.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut9001.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut9000.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut900.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut90.exe
+ 2010-08-12 16:25 . 2010-08-12 16:25 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF019}\NewShortcut9_1.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF014}\NewShortcut2.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 335872 c:\windows\Installer\{7F05E704-30A6-421A-97A7-8EEB1C7FF012}\NewShortcut8.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 335872 c:\windows\Installer\{44A27085-0616-4181-A0C3-81C7ECA17F73}\NewShortcut5.exe
+ 2010-08-12 16:22 . 2010-08-12 16:22 335872 c:\windows\Installer\{44A27085-0616-4181-A0C3-81C7ECA17F73}\NewShortcut4.exe
+ 2008-05-02 08:59 . 2008-05-02 08:59 1419232 c:\windows\system32\wdfcoinstaller01005.dll
+ 2003-03-18 19:12 . 2003-03-18 19:12 1047552 c:\windows\system32\mfc71u.dll
+ 2010-08-12 16:25 . 2010-08-12 16:25 1254912 c:\windows\Installer\82b6e.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 7011840 c:\windows\Installer\82b67.msi
+ 2010-08-12 16:25 . 2010-08-12 16:25 2314240 c:\windows\Installer\82b60.msi
+ 2010-08-12 16:24 . 2010-08-12 16:24 1617408 c:\windows\Installer\82b59.msi
+ 2010-08-12 16:22 . 2010-08-12 16:22 1583616 c:\windows\Installer\82b44.msi
+ 2010-08-12 16:22 . 2010-08-12 16:22 1611264 c:\windows\Installer\82b3d.msi
+ 2010-08-12 16:22 . 2010-08-12 16:22 1464320 c:\windows\Installer\82b36.msi
+ 2010-08-12 16:21 . 2010-08-12 16:21 2804736 c:\windows\Installer\82b2f.msi
+ 2010-07-29 17:49 . 2010-07-29 17:49 1847808 c:\windows\Installer\549abe.msi
+ 2010-07-29 17:46 . 2010-07-29 17:46 2664960 c:\windows\Installer\549ab8.msi
+ 2010-10-01 11:57 . 2010-10-01 11:57 1125376 c:\windows\Installer\34ca9.msi
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2009-02-03 240544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"SoundMan"="SOUNDMAN.EXE" [2003-10-08 57344]
"AudioDeck"="c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 528384]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ WinCinema Manager.lnk
backup=c:\windows\pss\ WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo RX420 Series]
2004-04-09 03:00 98304 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATI9CE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2009-11-16 15:36 172792 ----a-w- c:\program files\ICQ6.5\ICQ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-06-25 14:12 1414144 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-28 12:47 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-06-28 21:39 74752 ----a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=

S1 946bdca7;946bdca7;c:\windows\system32\drivers\946bdca7.sys [2009-06-17 0]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-02-06 106208]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-09-11 222968]
S2 qxhqnkzx;qxhqnkzx;\??\c:\windows\system32\drivers\dakikf.sys --> c:\windows\system32\drivers\dakikf.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-05-27 721904]
.
.
------- Doplňkový sken -------
.
TCP: {56BC914F-9394-4596-8F89-80F6D4F58FB1} = 192.168.1.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\ovuc4wb8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
MSConfigStartUp-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Data aplikací\\ESET\\ESET Smart Security\\"
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\"
"LanguageId"=dword:00000405
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000001
"ProductCode"="{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="4.0.314.0"
"UniqueId"="0004A44F4CA5CC91"
"ScannerBuild"=dword:00001124
"ScannerVersionId"=dword:00000ef8
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007
.
Celkový čas: 2010-10-09 18:43:33
ComboFix-quarantined-files.txt 2010-10-09 16:43
ComboFix2.txt 2010-06-20 10:29
ComboFix3.txt 2010-03-12 12:22
ComboFix4.txt 2009-05-11 17:41
ComboFix5.txt 2010-10-09 16:36

Před spuštěním: Volných bajtů: 14,567,800,832
Po spuštění: Volných bajtů: 14,559,485,952

- - End Of File - - 0C6AC03B6AFB21F21526EDAE19F40AC0

Re: Kontrola LOGu divné chování PC

Napsal: 09 říj 2010 19:07
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Folder::
c:\program files\Ask.com

Collect::
c:\windows\system32\drivers\946bdca7.sys
c:\windows\system32\drivers\dakikf.sys

Driver::
qxhqnkzx
946bdca7

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pustte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Kontrola LOGu divné chování PC

Napsal: 15 říj 2010 16:58
od phz^
/edit: doublepost

Re: Kontrola LOGu divné chování PC

Napsal: 15 říj 2010 16:59
od phz^
ComboFix 10-10-14.04 - Administrator 2010-10-15 17:42:59.7.1 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.1023.717 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!

file zipped: c:\windows\system32\drivers\946bdca7.sys
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\windows\system32\drivers\946bdca7.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_QXHQNKZX
-------\Service_946bdca7
-------\Service_qxhqnkzx


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-15 do 2010-10-15 )))))))))))))))))))))))))))))))
.

2010-10-15 15:39 . 2010-10-15 15:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Lišta Centrum.cz Toolbar
2010-10-14 11:22 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-14 11:22 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-14 11:22 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-11 15:01 . 2010-10-11 15:01 -------- d-----w- c:\documents and settings\Admin\Local Settings\Data aplikací\Lišta Centrum.cz Toolbar
2010-10-11 15:00 . 2010-10-11 15:01 -------- d-----w- c:\documents and settings\All Users\Data aplikací\CentrumczToolbar
2010-10-11 15:00 . 2010-10-11 15:00 -------- d-----w- c:\program files\CentrumczToolbar
2010-10-11 11:16 . 2010-10-14 11:23 -------- d-----w- c:\documents and settings\Admin\Local Settings\Data aplikací\Temp
2010-10-09 18:19 . 2008-04-14 03:22 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-09 18:07 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-10-09 18:03 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-10-09 18:00 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-10-09 18:00 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-10-09 18:00 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-10-09 17:56 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-10-09 17:55 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-10-09 17:50 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-10-09 17:50 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-10-09 17:50 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-10-09 17:50 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-10-09 17:50 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-10-09 17:50 . 2009-06-25 08:27 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-10-09 17:50 . 2009-02-09 10:56 709632 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-10-09 17:50 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-10-09 17:50 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-10-09 17:45 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-10-09 17:40 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-10-09 17:32 . 2009-08-06 17:24 15072 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-10-01 11:57 . 2010-10-01 11:57 -------- d-----w- c:\documents and settings\Admin\Data aplikací\ESET
2010-10-01 11:55 . 2010-10-01 11:55 -------- d-----w- c:\program files\ESET
2010-10-01 11:55 . 2010-10-01 11:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2010-09-30 18:38 . 2010-09-30 18:38 -------- d-----w- c:\program files\Winamp Detect
2010-09-30 18:37 . 2010-09-30 18:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Winamp Toolbar
2010-09-30 18:37 . 2010-09-30 18:37 -------- d-----w- c:\program files\Winamp Toolbar
2010-09-30 18:36 . 2010-10-01 11:46 -------- d-----w- c:\program files\Winamp
2010-09-30 18:36 . 2010-09-30 18:42 -------- d-----w- c:\documents and settings\Admin\Data aplikací\Winamp
2010-09-18 10:23 . 2010-09-18 10:23 974848 -c----w- c:\windows\system32\dllcache\mfc42u.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2010-07-28 1267024]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"Google Update"="c:\documents and settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-10-11 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"SoundMan"="SOUNDMAN.EXE" [2003-10-08 57344]
"AudioDeck"="c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 528384]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-02-06 106208]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-05-27 721904]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0026ca14-41f3-11de-93ab-000d87b4a994}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\m.exe /s

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16468020-775f-11dd-91d5-000d87b4a994}]
\Shell\Auto\command - F:\sxs.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24c59679-665f-11de-9417-000d87b4a994}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61671350-c5a7-11df-a5a9-000d87b4a994}]
\Shell\AutoRun\command - G:\Install_Nokia_Ovi_Suite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{947210d0-d615-11dc-a60a-806d6172696f}]
\Shell\AutoRun\command - E:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adb45700-9970-11df-a51f-000d87b4a994}]
\Shell\AutoRun\command - G:\Install_Nokia_Ovi_Suite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b844e2c2-d41b-11dc-9ffb-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://search.qip.ru/ie
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {56BC914F-9394-4596-8F89-80F6D4F58FB1} = 192.168.1.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\tlqb4s7p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search13.net/search.php?clid=486&q=
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/index.php?toolbar=centrum-1.0.0&q=
FF - component: c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\tlqb4s7p.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\tlqb4s7p.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils2.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils3.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils35.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----

FF - user.js: browser.sessionstore.resume_from_crash - false
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Data aplikací\\ESET\\ESET Smart Security\\"
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\"
"LanguageId"=dword:00000405
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000001
"ProductCode"="{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="4.0.314.0"
"UniqueId"="0004A44F4CA5CC91"
"ScannerBuild"=dword:00001124
"ScannerVersionId"=dword:00000ef8
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\SOUNDMAN.EXE
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Celkový čas: 2010-10-15 17:52:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-15 15:52
ComboFix2.txt 2010-10-15 15:38
ComboFix3.txt 2010-10-09 16:43
ComboFix4.txt 2010-06-20 10:29
ComboFix5.txt 2010-10-15 15:42

Před spuštěním: Volných bajtů: 11,789,684,736
Po spuštění: Volných bajtů: 11,737,665,536

- - End Of File - - EB083C18BEA95443F471E12950B9CEC5
Nahr nˇ probŘhlo ŁspŘçnŘ

Re: Kontrola LOGu divné chování PC

Napsal: 15 říj 2010 17:33
od Rudy
Spusťte CF ještě jednou tímto skriptem:
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0026ca14-41f3-11de-93ab-000d87b4a994}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16468020-775f-11dd-91d5-000d87b4a994}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24c59679-665f-11de-9417-000d87b4a994}]