Stránka 1 z 2

Prosim o kontrolu

Napsal: 20 říj 2010 13:16
od bebak
mam problem s Pc po istom čase na Pc mi vyskoci hlaska sysinfo.exe - spravana inicializacia sa nepodarila... a zahlti mi to pocitat V procesoch mi to vyhodi okolo 250 procesov a 90 % s toho sa tyka sysinfo.exe a jedine co mi potom zostava je restart.

Prikladam lof s Rsist

Za pomoc vopred dakujem

Logfile of random's system information tool 1.06 (written by random/random)
Run by BebaK at 2010-10-20 14:08:18
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 588 MB (11%) free of 6 GB
Total RAM: 503 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:08:44, on 20. 10. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Beba - dokumenty\Programy\Adobe Reader 9\Reader\Reader_sl.exe
D:\Beba - dokumenty\Programy\DAEMON Tools Lite\daemon.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\Sysinfo.exe
c:\windows\system32\Sysinfo.exe
D:\Beba - dokumenty\Programy\Mozilla Firefox\firefox.exe
D:\Beba - dokumenty\Programy\Mozilla Firefox\plugin-container.exe
D:\Beba - dokumenty\Programy\00 Dolezite\RSIT.exe
C:\Program Files\trend micro\BebaK.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=14597&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: tom for ie - {8AA217B9-D729-4ee0-AED7-E93D695E94A2} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Beba - dokumenty\Programy\Adobe Reader 9\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sysinfo.exe] C:\WINDOWS\System32\Sysinfo.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Beba - dokumenty\Programy\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\BEBA-D~1\Programy\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .cdx: C:\Program Files\Internet Explorer\plugins\Npcdp32.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5695 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-09-23 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA217B9-D729-4ee0-AED7-E93D695E94A2}]
TomBHO Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2006-06-06 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2006-06-06 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2006-06-06 118784]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=D:\Beba - dokumenty\Programy\Adobe Reader 9\Reader\Reader_sl.exe [2008-06-12 34672]
"Sysinfo.exe"=C:\WINDOWS\System32\Sysinfo.exe [2010-02-21 163328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=D:\Beba - dokumenty\Programy\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-18 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-06-06 139264]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Games\Sacred\sacred.exe"="D:\Games\Sacred\sacred.exe:*:Enabled:Sacred"
"C:\WINDOWS\System32\dpvsetup.exe"="C:\WINDOWS\System32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\Games\Sacred\Sacred Underworld\Sacred.exe"="D:\Games\Sacred\Sacred Underworld\Sacred.exe:*:Enabled:Sacred"
"D:\Games\Sacred\Sacred Underworld\gameserver.exe"="D:\Games\Sacred\Sacred Underworld\gameserver.exe:*:Enabled:Sacred Gameserver"
"D:\Warcraft III\Warcraft III.exe"="D:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\WINDOWS\System32\Sysinfo.exe"="C:\WINDOWS\System32\Sysinfo.exe:*:Enabled:sysupdate"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25d13d12-c4b4-11df-a6f4-001a4b593fe8}]
shell\AutoRun\command - H:\idg2.exe
shell\open\command - H:\idg2.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2acda128-f0b3-11de-a58a-001a737089e7}]
shell\AutoRun\command - H:\idg2.exe
shell\open\command - H:\idg2.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6d8e4fdc-4575-11df-a617-001a737089e7}]
shell\AutoRun\command - H:\idg2.exe
shell\open\command - H:\idg2.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9dbfc168-9a20-11df-a69a-001a737089e7}]
shell\AutoRun\command - I:\idg2.exe
shell\open\command - I:\idg2.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba65d910-b7fd-11df-a6dd-001a4b593fe8}]
shell\AutoRun\command - H:\APPInst.exe


======List of files/folders created in the last 1 months======

2010-10-19 21:39:37 ----D---- C:\Program Files\Uniblue
2010-10-19 21:39:21 ----HD---- C:\Documents and Settings\All Users\Data aplikací\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-10-19 20:47:05 ----D---- C:\Documents and Settings\BebaK\Data aplikací\Uniblue
2010-10-19 20:42:58 ----SHD---- C:\FOUND.001
2010-10-18 21:28:08 ----SHD---- C:\FOUND.000
2010-10-16 13:18:55 ----H---- C:\WINDOWS\system32\Sysinfo.exe
2010-09-28 17:36:59 ----D---- C:\Program Files\QIP Infium
2010-09-28 17:22:53 ----D---- C:\Program Files\QIP 2010

======List of files/folders modified in the last 1 months======

2010-10-20 14:03:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-19 23:42:16 ----A---- C:\WINDOWS\WDICT32.INI
2010-10-12 19:24:32 ----A---- C:\WINDOWS\win.ini
2010-10-12 19:13:24 ----A---- C:\WINDOWS\ISISAIM.INI
2010-09-27 15:10:48 ----A---- C:\WINDOWS\ISISAIHP.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-18 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-06-02 29584]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-18 243024]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 SSHDRV65;SSHDRV65; \??\C:\WINDOWS\system32\drivers\SSHDRV65.sys []
R1 SSHDRV85;SSHDRV85; \??\C:\WINDOWS\system32\drivers\SSHDRV85.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-03 87424]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-02-28 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-08-28 1160320]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-11-01 604928]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2005-08-05 45312]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-06-06 1168860]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 aqqj0138;aqqj0138; C:\WINDOWS\system32\drivers\aqqj0138.sys []
S3 axzpi5z1;axzpi5z1; C:\WINDOWS\system32\drivers\axzpi5z1.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\BebaK\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys [2004-08-03 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 PCD65X2;PCD65X2; \??\C:\DOCUME~1\BebaK\LOCALS~1\Temp\PCD65X2.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\WINDOWS\system32\DRIVERS\irstusb.sys [2001-08-17 26624]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-25 921952]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-18 308136]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Re: Prosim o kontrolu

Napsal: 20 říj 2010 14:42
od cernohous13
Zdravím, vyzkoušíme MBAM
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení

Re: Prosim o kontrolu

Napsal: 20 říj 2010 15:32
od bebak
log s MBAM

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Verzia databázy: 4891

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

20. 10. 2010 16:30:10
mbam-log-2010-10-20 (16-30-10).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 139302
Uplynulý čas: 10 min, 16 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
(Škodlivé položky neboli zistené)

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
(Škodlivé položky neboli zistené)

Re: Prosim o kontrolu

Napsal: 20 říj 2010 16:52
od cernohous13
:o MBAM nepovažuje Sysinfo.exe za škůdce
Klikni na https://www.virustotal.com/cs/
klik "Procházet" > do zadávacího pole zkopíruj:

C:\WINDOWS\System32\Sysinfo.exe

"Odeslat soubor" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/39
Do fóra zkopíruj výsledný log nebo odkaz na stránku.

Re: Prosim o kontrolu

Napsal: 20 říj 2010 19:55
od bebak
Takze Virus Total:
19/ 43 (44.2%)

AhnLab-V3 2010.10.20.02 2010.10.20 -
AntiVir 7.10.13.9 2010.10.20 TR/Dldr.Delphi.Gen
Antiy-AVL 2.0.3.7 2010.10.20 -
Authentium 5.2.0.5 2010.10.20 W32/Banload.E.gen!Eldorado
Avast 4.8.1351.0 2010.10.20 -
Avast5 5.0.594.0 2010.10.20 -
AVG 9.0.0.851 2010.10.20 -
BitDefender 7.2 2010.10.20 Gen:Trojan.Heur.DP.jmGfaO6gc3j
CAT-QuickHeal 11.00 2010.10.20 -
ClamAV 0.96.2.0-git 2010.10.20 -
Comodo 6452 2010.10.20 Heur.Packed.Unknown
DrWeb 5.0.2.03300 2010.10.20 DLOADER.IRC.Trojan
Emsisoft 5.0.0.50 2010.10.20 Trojan-Downloader.Delphi!IK
eSafe 7.0.17.0 2010.10.20 -
eTrust-Vet 36.1.7923 2010.10.20 -
F-Prot 4.6.2.117 2010.10.20 W32/Banload.E.gen!Eldorado
F-Secure 9.0.16160.0 2010.10.20 Gen:Trojan.Heur.DP.jmGfaO6gc3j
Fortinet 4.2.249.0 2010.10.20 -
GData 21 2010.10.20 Gen:Trojan.Heur.DP.jmGfaO6gc3j
Ikarus T3.1.1.90.0 2010.10.20 Trojan-Downloader.Delphi
Jiangmin 13.0.900 2010.10.20 -
K7AntiVirus 9.66.2798 2010.10.20 Trojan
Kaspersky 7.0.0.125 2010.10.20 Heur.Trojan.Generic
McAfee 5.400.0.1158 2010.10.20 Suspect-AF!C44F29C9F8B5
McAfee-GW-Edition 2010.1C 2010.10.20 New Malware.ai
Microsoft 1.6301 2010.10.20 -
NOD32 5549 2010.10.20 Win32/Chyzvis.L
Norman 6.06.10 2010.10.20 W32/Obfuscated.FA
nProtect 2010-10-20.01 2010.10.20 -
Panda 10.0.2.7 2010.10.20 -
PCTools 7.0.3.5 2010.10.20 -
Prevx 3.0 2010.10.20 -
Rising 22.70.01.08 2010.10.20 Trojan.Win32.DownldrU.a
Sophos 4.58.0 2010.10.20 Mal/TinyDL-T
Sunbelt 7102 2010.10.20 -
SUPERAntiSpyware 4.40.0.1006 2010.10.20 -
Symantec 20101.2.0.161 2010.10.20 Suspicious.MH690.A
TheHacker 6.7.0.1.063 2010.10.20 -
TrendMicro 9.120.0.1004 2010.10.20 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.20 -
VBA32 3.12.14.1 2010.10.20 -
ViRobot 2010.10.20.4103 2010.10.20 -
VirusBuster 12.69.9.0 2010.10.20 -

Additional information
Show all
MD5 : 0500b189805bfeca80ac446900e56dec
SHA1 : 9fe1516dd3f2610e18995b45d8cd7eae384a90e6
SHA256: e475e04117b962b7d23c61658ed240f761b2d8f53af081065e12a88d5f163757

Re: Prosim o kontrolu

Napsal: 20 říj 2010 19:58
od vyosek
Zdravim a pekny vecer preji :)

Zaskocim za kolegu :wink:

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA217B9-D729-4ee0-AED7-E93D695E94A2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=-
    "Adobe Reader Speed Launcher"=-
    "Sysinfo.exe"=-
    
    :files
    C:\WINDOWS\System32\Sysinfo.exe
    C:\Program Files\Ask.com
    C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    
  • Kliknete na cervene tlacitko MoveIt!
  • Sem pote dejte obsah okna Results (pod zelenou carou)
  • Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles
:arrow: Zapojte do PC vsechny USB klice (flashky, ext. disky apod.)

Re: Prosim o kontrolu

Napsal: 20 říj 2010 20:25
od bebak
Dobry vecer! Tu je vysledok z OTM:

All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA217B9-D729-4ee0-AED7-E93D695E94A2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AA217B9-D729-4ee0-AED7-E93D695E94A2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Sysinfo.exe deleted successfully.
========== FILES ==========
C:\WINDOWS\System32\Sysinfo.exe moved successfully.
C:\Program Files\Ask.com folder moved successfully.
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\CSC\csc1.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: BebaK
->Temp folder emptied: 65079291 bytes
->Temporary Internet Files folder emptied: 12783749 bytes
->Java cache emptied: 63370250 bytes
->FireFox cache emptied: 74212317 bytes
->Google Chrome cache emptied: 96127939 bytes
->Flash cache emptied: 90444 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82683 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 297,00 mb


OTM by OldTimer - Version 3.1.16.1 log created on 10202010_211846

Files moved on Reboot...

Registry entries deleted on Reboot...

Re: Prosim o kontrolu

Napsal: 20 říj 2010 20:26
od bebak
USBfix sa mi nepodarilo stiahnut. Link je asi nefunkcny.

Re: Prosim o kontrolu

Napsal: 20 říj 2010 20:29
od vyosek
USBFix jsem Vam tedy uploadnul sem http://leteckaposta.cz/490521298 Omlouvam se za problem :oops:

Re: Prosim o kontrolu

Napsal: 20 říj 2010 21:13
od bebak
vyosek píše:USBFix jsem Vam tedy uploadnul sem http://leteckaposta.cz/490521298 Omlouvam se za problem :oops:
Ziaden problem. Dakujem za taku skoru odpoved :D

Tu je log z USBfixu:

############################## | UsbFix 7.014 | [Deletion]

User: BebaK (Administrator) # BEBA [ ]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 21:40:58 | 20/10/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Celeron(R) M CPU 520 @ 1.60GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 2
Internet Explorer 6.0.2900.2180

Windows Firewall: Enabled
Antivirus: AVG Anti-Virus Free 9.0 [Enabled | Updated]
RAM -> 503 Mb
C:\ (%systemdrive%) -> Fixed drive # 5 Gb (1 Mb free - 19%) [] # FAT32
D:\ -> Fixed drive # 69 Gb (7 Mb free - 10%) [] # FAT32
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Removable drive # 2 Gb (551 Mb free - 29%) [] # FAT32
I:\ -> Removable drive # 4 Gb (4 Mb free - 99%) [] # FAT32
J:\ -> Fixed drive # 466 Gb (136 Mb free - 29%) [] # FAT32
K:\ -> Removable drive # 4 Gb (914 Mb free - 24%) [] # FAT32

################## | Files # Infected Folders |

Deleted ! J:\idg2.exe
Deleted ! J:\Autorun.inf
Deleted ! K:\Autorun.inf
Deleted ! I:\UNUCI
Deleted ! J:\CAROBNJAK
Deleted ! J:\IVANA

################## | Registry |

Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

################## | Mountpoints2 |

Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{9dbfc168-9a20-11df-a69a-001a737089e7}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{ba65d910-b7fd-11df-a6dd-001a4b593fe8}

################## | Listing |

[20/10/2010 - 21:20:52 | ASH | 792723456] C:\pagefile.sys
[15/07/2009 - 14:24:00 | D ] C:\WINDOWS
[11/05/2010 - 17:10:00 | A | 230432] C:\PA207.DAT
[25/10/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
[03/08/2004 - 20:59:38 | RASH | 250048] C:\ntldr
[03/08/2004 - 20:38:34 | RASH | 47564] C:\NTDETECT.COM
[13/04/2010 - 17:22:34 | RASH | 281] C:\boot.ini
[15/07/2009 - 14:29:56 | D ] C:\Documents and Settings
[15/07/2009 - 14:41:42 | RD ] C:\Program Files
[15/07/2009 - 14:42:40 | A | 0] C:\CONFIG.SYS
[15/07/2009 - 14:42:40 | A | 0] C:\AUTOEXEC.BAT
[15/07/2009 - 14:42:40 | RASH | 0] C:\IO.SYS
[15/07/2009 - 14:42:40 | RASH | 0] C:\MSDOS.SYS
[15/07/2009 - 14:48:00 | SHD ] C:\System Volume Information
[22/07/2009 - 20:49:00 | D ] C:\Games
[13/04/2010 - 17:22:28 | RASHD ] C:\cmdcons
[10/04/2010 - 20:57:04 | D ] C:\rsit
[24/05/2001 - 12:59:30 | A | 162304] C:\UNWISE.EXE
[30/01/2010 - 00:53:32 | A | 1119] C:\INSTALL.LOG
[21/04/2010 - 20:33:38 | HD ] C:\$AVG
[13/04/2010 - 18:14:46 | D ] C:\32788R22FWJFW
[13/04/2010 - 17:32:40 | SHD ] C:\Recycled
[03/08/2004 - 23:00:04 | A | 261312] C:\cmldr
[18/10/2010 - 21:28:08 | SHD ] C:\FOUND.000
[15/07/2009 - 14:56:08 | A | 90] C:\bcmwl5.log
[15/07/2009 - 14:36:02 | A | 211] C:\Boot.bak
[19/10/2010 - 20:42:58 | SHD ] C:\FOUND.001
[13/04/2010 - 17:31:56 | A | 12607] C:\ComboFix.txt
[11/04/2010 - 10:16:30 | D ] C:\Qoobox
[20/10/2010 - 21:40:30 | D ] C:\UsbFix
[20/10/2010 - 21:41:00 | A | 1006] C:\UsbFix.txt
[20/10/2010 - 21:18:48 | D ] D:\_OTM
[21/04/2010 - 21:05:42 | HD ] D:\$AVG
[07/09/2007 - 10:16:50 | SHD ] D:\System Volume Information
[23/06/2010 - 17:05:02 | SHD ] D:\Recycled
[31/12/2009 - 21:49:08 | D ] D:\Warcraft III
[09/08/2010 - 16:36:18 | D ] D:\Games Mini
[23/08/2010 - 17:20:06 | SHD ] D:\Config.Msi
[15/07/2009 - 15:04:00 | RD ] D:\Beba - dokumenty
[07/09/2007 - 18:29:22 | D ] D:\Games
[20/10/2010 - 20:51:42 | D ] H:\Girls Dead Monster - Keep The Beats!
[20/10/2010 - 20:53:46 | D ] H:\Angels And Airwaves - Love
[20/10/2010 - 20:57:22 | D ] H:\30 seconds to Mars - A beautiful lie
[20/10/2010 - 20:58:22 | D ] H:\4lyn - Hello
[20/10/2010 - 20:59:38 | D ] H:\Cold - Year of the spider
[20/10/2010 - 21:00:42 | D ] H:\Disturbed - Ten thousand fists
[20/10/2010 - 21:04:36 | D ] H:\Hardcore superstar - No Regrets
[20/10/2010 - 21:08:20 | D ] H:\Ine Kafe - 2 In 1
[20/10/2010 - 21:09:50 | D ] H:\Lacuna Coil - Shallow life
[20/10/2010 - 21:16:44 | D ] H:\Saliva - Cinco diablo
[20/10/2010 - 21:12:42 | D ] H:\My chemical romance - Life on the murder scene
[20/10/2010 - 21:17:54 | D ] H:\Simple Plan - Simple Plan
[20/10/2010 - 21:29:46 | D ] H:\Stone Sour - Audio secrecy
[20/10/2010 - 21:32:12 | D ] H:\Fall Out Boy - Infinity On High
[20/10/2010 - 21:34:18 | D ] H:\Aloha from hell - No more days to waste
[20/10/2010 - 21:35:14 | D ] H:\Band of Horses - Infinite Arms
[20/10/2010 - 21:37:06 | D ] H:\Rise against - Siren song of the counter culture
[29/09/2010 - 09:44:18 | RSHD ] I:\SHORTI
[29/08/2010 - 15:07:06 | SHD ] I:\FOUND.000
[13/10/2010 - 12:17:50 | RSHD ] I:\BMW
[21/02/2010 - 01:02:28 | H | 163328] I:\idg2.exe
[17/10/2010 - 21:03:50 | A | 685314] I:\Prednaska 5.pdf
[17/10/2010 - 21:04:14 | A | 1755828] I:\Prednaska 6.pdf
[09/08/2010 - 14:12:34 | A | 13470591] I:\basic_kanji_book.pdf
[15/06/2010 - 18:44:38 | RSHD ] I:\GoogleUpdate
[24/12/2009 - 18:39:12 | SHD ] J:\System Volume Information
[24/12/2009 - 18:40:24 | SHD ] J:\Recycled
[24/12/2009 - 21:46:54 | D ] J:\Komiksy CZ a SK
[24/12/2009 - 22:48:48 | D ] J:\Komiksy Magik
[24/12/2009 - 22:57:18 | D ] J:\Programy
[24/12/2009 - 23:26:26 | RD ] J:\Filmy
[24/12/2009 - 23:30:58 | D ] J:\Hry
[24/12/2009 - 23:43:34 | RD ] J:\Hudba
[25/12/2009 - 00:23:34 | D ] J:\Komiksy AJ
[05/01/2010 - 15:13:14 | D ] J:\Incoming
[10/02/2010 - 15:38:48 | RSD ] J:\Fonts
[16/02/2010 - 18:49:32 | RD ] J:\Internet
[16/02/2010 - 18:55:42 | D ] J:\Vselico
[31/03/2010 - 19:16:32 | RSHD ] J:\LJUBAVNICA
[03/04/2010 - 17:03:18 | SHD ] J:\tempstorage
[05/04/2010 - 19:07:02 | RSHD ] J:\usb-sys
[09/04/2010 - 22:40:48 | RSHD ] J:\usb
[23/04/2010 - 15:27:26 | SHD ] J:\$RECYCLE.BIN
[23/08/2010 - 14:57:58 | D ] J:\Preklad
[14/09/2010 - 09:00:46 | HD ] K:\Private
[13/09/2010 - 19:57:36 | HD ] K:\system
[13/09/2010 - 19:58:54 | HD ] K:\cities
[13/09/2010 - 11:14:54 | D ] K:\Installs
[13/09/2010 - 11:14:54 | D ] K:\Images
[16/09/2010 - 21:58:40 | D ] K:\data
[14/09/2010 - 13:00:34 | D ] K:\Hudba
[20/09/2010 - 22:41:36 | D ] K:\Komiksy
[20/09/2010 - 22:41:52 | D ] K:\Other
[21/02/2010 - 01:02:28 | H | 163328] K:\idg2.exe
[20/10/2010 - 17:13:53 | D ] Z:\Incoming
[23/09/2010 - 16:52:21 | A | 467] Z:\Hladaj.Garda.sk.txt
[16/09/2010 - 13:49:18 | D ] Z:\Software
[16/09/2010 - 13:49:23 | D ] Z:\Skola
[16/09/2010 - 13:57:48 | D ] Z:\E-Book
[16/09/2010 - 13:49:30 | D ] Z:\Hudba
[08/12/2009 - 23:14:37 | A | 27] Z:\Funguje.DC.hub.txt
[16/09/2010 - 13:50:27 | D ] Z:\Filmy.a.Serialy
[05/10/2010 - 19:42:25 | D ] Z:\Hry
[16/09/2010 - 13:50:21 | D ] Z:\Foto.garda.akcie

################## | Vaccin |

C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
H:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
I:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
J:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
K:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_BEBA.zip
http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution.

################## | E.O.F |



PS: Jednotku Z si nevsimajte, je to sietova jednotka nasej intrakovskej siete.

Re: Prosim o kontrolu

Napsal: 20 říj 2010 21:15
od bebak
Teraz som si uvedomila, ze som USBfix nemala na ploche ale v dokumentoch. Dufam ze to nie je velky problem.

Re: Prosim o kontrolu

Napsal: 21 říj 2010 22:22
od vyosek
:arrow: Zapojte vsechny USB disky, jeste se nam tam neco skryva za havet :?: (Dulezita je hlavne jednotka K:\ -> Removable drive # 4 Gb (914 Mb free - 24%))

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosim o kontrolu

Napsal: 23 říj 2010 11:42
od bebak
ComboFix 10-10-22.05 - BebaK . 10. 2010 12:35:05.3.1 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.182 [GMT 2:00]
Spuštěný z: c:\documents and settings\BebaK\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-09-23 do 2010-10-23 )))))))))))))))))))))))))))))))
.

2010-10-20 19:40 . 2010-10-20 19:40 -------- d-----w- C:\UsbFix
2010-10-20 14:18 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 14:18 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-19 19:39 . 2010-10-19 19:39 -------- d-----w- c:\program files\Uniblue
2010-10-19 19:39 . 2010-10-19 19:39 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-10-19 18:47 . 2010-10-19 18:47 -------- d-----w- c:\documents and settings\BebaK\Data aplikací\Uniblue
2010-10-19 18:42 . 2010-10-19 18:42 -------- d-----w- C:\FOUND.001
2010-10-18 19:28 . 2010-10-18 19:28 -------- d-----w- C:\FOUND.000
2010-09-28 15:36 . 2010-09-28 15:37 -------- d-----w- c:\program files\QIP Infium
2010-09-28 15:22 . 2010-09-28 15:22 -------- d-----w- c:\program files\QIP 2010

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-20 20:01 . 2010-10-20 20:01 164749 ----a-w- C:\UsbFix_Upload_Me_BEBA.zip
2010-08-12 08:00 . 2010-09-06 13:39 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\beba - dokumenty\Programy\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-18 20:34 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Games\\Sacred\\Sacred Underworld\\Sacred.exe"=
"d:\\Games\\Sacred\\Sacred Underworld\\gameserver.exe"=
"d:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\QIP Infium\\infium.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7. 4. 2010 12:54 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7. 4. 2010 12:54 243024]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [20. 11. 2009 20:37 120320]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [20. 11. 2009 21:08 78848]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [18. 7. 2010 22:34 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [18. 7. 2010 22:34 308136]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14. 5. 2007 10:26 508288]
S3 PCD65X2;PCD65X2;\??\c:\docume~1\BebaK\LOCALS~1\Temp\PCD65X2.sys --> c:\docume~1\BebaK\LOCALS~1\Temp\PCD65X2.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16. 7. 2009 10:06 691696]
.
.
------- Doplňkový sken -------
.
uCustomizeSearch = hxxp://www.Google.com/
uSearchAssistant = hxxp://www.Google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Stylish Profile\ct.htm
FF - ProfilePath - c:\documents and settings\BebaK\Data aplikací\Mozilla\Firefox\Profiles\2j0sky2w.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.kocogel.info/index.php?action=forum
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=FF&o=14594&locale=en_EU&apn_uid=4EA38834-95BE-4290-97A1-2B066DD6E549&apn_ptnrs=FV&apn_sauid=565A066D-FAD8-464C-B80D-842F86477A20&apn_dtid=YYYYYYYYSK&q=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\beba - dokumenty\Programy\Adobe Reader 9\Reader\browser\nppdf32.dll

---- NASTAVENÍ FIREFOXU ----
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
d:\beba - dokumenty\Programy\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
d:\beba - dokumenty\Programy\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files\Ask.com\GenericAskToolbar.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 12:37
Windows 5.1.2600 Service Pack 2 FAT NTAPI

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(1876)
c:\windows\system32\msi.dll
.
Celkový čas: 2010-10-23 12:38:56
ComboFix-quarantined-files.txt 2010-10-23 10:38
ComboFix2.txt 2010-04-13 15:31
ComboFix3.txt 2010-04-11 10:32

Před spuštěním: 775 606 272
Po spuštění: 757 964 800

- - End Of File - - ED67873AD225B82B679F8C4EBA590A47

Re: Prosim o kontrolu

Napsal: 23 říj 2010 15:08
od vyosek
:arrow: Mela jste pripojenou tu jednotku K:\, je to fleska, jsou na ni tyto dokumenty
[16/09/2010 - 21:58:40 | D ] K:\data
[14/09/2010 - 13:00:34 | D ] K:\Hudba
[20/09/2010 - 22:41:36 | D ] K:\Komiksy
[20/09/2010 - 22:41:52 | D ] K:\Other
[21/02/2010 - 01:02:28 | H | 163328] K:\idg2.exe HAVET
:arrow: Je tedy bezpodninecne nutne abyste ji ted pripojila, abychom havet smazli

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Collect::
    K:\idg2.exe
    c:\docume~1\BebaK\LOCALS~1\Temp\PCD65X2.sys
    
    Folder::
    c:\docume~1\BebaK\LOCALS~1\Temp
    
    Driver::
    PCD65X2
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\BebaK\Data aplikací\Mozilla\Firefox\Profiles\2j0sky2w.default\
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?clien ... YYYYYSK&q=
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Prosim o kontrolu

Napsal: 24 říj 2010 21:34
od bebak
ComboFix 10-10-22.05 - BebaK . 10. 2010 15:41:23.4.1 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.200 [GMT 2:00]
Spuštěný z: c:\documents and settings\BebaK\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\BebaK\Plocha\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: K:\idg2.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\BebaK\LOCALS~1\Temp
c:\docume~1\BebaK\LOCALS~1\Temp\amt.log
c:\docume~1\BebaK\LOCALS~1\Temp\Av-test.txt
c:\docume~1\BebaK\LOCALS~1\Temp\csxs-PHSP.log
c:\docume~1\BebaK\LOCALS~1\Temp\TWAIN.LOG
c:\docume~1\BebaK\LOCALS~1\Temp\Twain001.Mtx
c:\docume~1\BebaK\LOCALS~1\Temp\Twunk001.MTX
c:\docume~1\BebaK\LOCALS~1\Temp\Twunk002.MTX
K:\idg2.exe

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_PCD65X2


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-24 do 2010-10-24 )))))))))))))))))))))))))))))))
.

2010-10-20 19:40 . 2010-10-20 19:40 -------- d-----w- C:\UsbFix
2010-10-20 14:18 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 14:18 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-19 19:39 . 2010-10-19 19:39 -------- d-----w- c:\program files\Uniblue
2010-10-19 19:39 . 2010-10-19 19:39 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-10-19 18:47 . 2010-10-19 18:47 -------- d-----w- c:\documents and settings\BebaK\Data aplikací\Uniblue
2010-10-19 18:42 . 2010-10-19 18:42 -------- d-----w- C:\FOUND.001
2010-10-18 19:28 . 2010-10-18 19:28 -------- d-----w- C:\FOUND.000
2010-09-28 15:36 . 2010-09-28 15:37 -------- d-----w- c:\program files\QIP Infium
2010-09-28 15:22 . 2010-09-28 15:22 -------- d-----w- c:\program files\QIP 2010

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-20 20:01 . 2010-10-20 20:01 164749 ----a-w- C:\UsbFix_Upload_Me_BEBA.zip
2010-08-12 08:00 . 2010-09-06 13:39 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-10-23_10.37.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-24 13:45 . 2010-10-24 13:45 16384 c:\windows\temp\Perflib_Perfdata_4c0.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-18 20:34 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Games\\Sacred\\Sacred Underworld\\Sacred.exe"=
"d:\\Games\\Sacred\\Sacred Underworld\\gameserver.exe"=
"d:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\QIP Infium\\infium.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7. 4. 2010 12:54 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7. 4. 2010 12:54 243024]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [20. 11. 2009 20:37 120320]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [20. 11. 2009 21:08 78848]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [18. 7. 2010 22:34 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [18. 7. 2010 22:34 308136]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14. 5. 2007 10:26 508288]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16. 7. 2009 10:06 691696]
.
.
------- Doplňkový sken -------
.
uCustomizeSearch = hxxp://www.Google.com/
uSearchAssistant = hxxp://www.Google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Stylish Profile\ct.htm
FF - ProfilePath - c:\documents and settings\BebaK\Data aplikací\Mozilla\Firefox\Profiles\2j0sky2w.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.kocogel.info/index.php?action=forum
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\beba - dokumenty\Programy\Adobe Reader 9\Reader\browser\nppdf32.dll

---- NASTAVENÍ FIREFOXU ----
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
d:\beba - dokumenty\Programy\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
d:\beba - dokumenty\Programy\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
d:\beba - dokumenty\Programy\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-24 15:46
Windows 5.1.2600 Service Pack 2 FAT NTAPI

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(588)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Celkový čas: 2010-10-24 15:47:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-24 13:47
ComboFix2.txt 2010-10-23 10:38
ComboFix3.txt 2010-04-13 15:31
ComboFix4.txt 2010-04-11 10:32

Před spuštěním: 699 883 520
Po spuštění: 619 995 136

- - End Of File - - E6589B349A3251EB5633F52C4D4ED012
Nahr nˇ probŘhlo ŁspŘçnŘ