Stránka 1 z 2

Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 15:57
od cartty
Prosim o pomoc s virom security tools. Notebook mi ide iba v nudzovom rezime, v normalnom mi nejde spustit ziadna aplikacia lebo mi to hlasi ako virus a securitz tool chce aktovaciu pomocou platobnej karty...
Som ONLINE ak vie nekto poradit. mam stiahnuty rsit, combo fix, malwarebytes anti malware, old timer tools
pridavam log z rsit-u

Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-10-31 15:00:04
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 6 GB (22%) free of 25 GB
Total RAM: 1023 MB (81% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Egeytf.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
vShare Plugin - C:\Program Files\vShare\vshare_toolbar.dll [2010-10-10 478800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2010-09-04 312928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{043C5167-00BB-4324-AF7E-62013FAEDACF} - vShare Plugin - C:\Program Files\vShare\vshare_toolbar.dll [2010-10-10 478800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-02-23 106496]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-11-21 7335936]
"nwiz"=nwiz.exe /install []
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-21 761945]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2006-04-14 667718]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2006-04-14 602182]
"EOUApp"=C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe [2006-04-14 569413]
"Power_Gear"=C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-03-06 86016]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe []
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-09-04 198160]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2005-05-27 544768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-09-06 14850560]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
"Media Codec Update Service"=C:\Program Files\Essentials Codec Pack\update.exe [2007-04-08 303104]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\CTFMON.EXE [2004-08-17 15360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"=rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"D:\Counter-Strike 1.6\hl.exe"="D:\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\spoolsv.exe"="C:\WINDOWS\system32\spoolsv.exe:*:Enabled:spoolsv.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-10-31 15:00:09 ----D---- C:\Program Files\trend micro
2010-10-31 15:00:04 ----D---- C:\rsit
2010-10-31 14:59:00 ----ASH---- C:\Documents and Settings\Administrator\Data aplikací\desktop.ini
2010-10-31 14:58:59 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-10-31 14:58:23 ----A---- C:\WINDOWS\ntbtlog.txt
2010-10-26 20:23:55 ----D---- C:\spoolerlogs
2010-10-25 22:25:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-10-24 17:02:16 ----RASH---- C:\WINDOWS\system32\RLOFRDecx.dll
2010-10-24 16:29:03 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-10-24 16:29:03 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-10-24 16:29:02 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-10-19 21:05:12 ----A---- C:\WINDOWS\system32\javaws.exe
2010-10-19 21:05:12 ----A---- C:\WINDOWS\system32\javaw.exe
2010-10-19 21:05:12 ----A---- C:\WINDOWS\system32\java.exe
2010-10-19 21:03:06 ----D---- C:\WINDOWS\Sun
2010-10-19 20:45:36 ----D---- C:\Program Files\vShare
2010-10-13 21:12:18 ----D---- C:\Program Files\uTorrent
2010-10-12 22:31:44 ----D---- C:\Program Files\Xvid
2010-10-11 00:21:54 ----D---- C:\WINDOWS\system32\appmgmt
2010-10-10 21:29:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-10-10 21:23:41 ----D---- C:\Program Files\QuickTime
2010-10-10 21:18:34 ----D---- C:\Program Files\Bonjour
2010-10-10 21:11:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-10-10 21:09:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-10-10 21:07:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-10-05 15:04:28 ----D---- C:\NVIDIA
2010-10-04 22:26:33 ----D---- C:\Program Files\directx
2010-10-04 20:53:23 ----A---- C:\WINDOWS\WDICT32.INI
2010-10-04 20:48:25 ----D---- C:\Program Files\ZipGenius 6
2010-10-04 20:46:34 ----D---- C:\Translator

======List of files/folders modified in the last 1 months======

2010-10-31 15:00:09 ----RD---- C:\Program Files
2010-10-31 14:58:58 ----D---- C:\Documents and Settings
2010-10-31 14:58:23 ----D---- C:\WINDOWS
2010-10-31 14:53:35 ----D---- C:\WINDOWS\Prefetch
2010-10-31 14:53:09 ----D---- C:\WINDOWS\Temp
2010-10-30 09:47:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-26 20:19:30 ----D---- C:\WINDOWS\system32\Lang
2010-10-25 22:30:02 ----A---- C:\WINDOWS\WINCMD.INI
2010-10-25 22:29:10 ----D---- C:\Program Files\Mozilla Firefox
2010-10-25 22:25:23 ----D---- C:\Program Files\Common Files
2010-10-25 17:22:14 ----SHD---- C:\System Volume Information
2010-10-25 17:22:14 ----D---- C:\WINDOWS\system32\Restore
2010-10-24 17:29:31 ----SHD---- C:\WINDOWS\Installer
2010-10-24 17:02:16 ----SD---- C:\WINDOWS\Tasks
2010-10-24 17:02:16 ----D---- C:\WINDOWS\system32
2010-10-24 16:47:00 ----D---- C:\WINDOWS\system32\DirectX
2010-10-24 16:29:03 ----HD---- C:\WINDOWS\inf
2010-10-24 16:29:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-23 16:30:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-10-23 16:30:47 ----D---- C:\WINDOWS\system32\drivers
2010-10-19 21:05:10 ----D---- C:\Program Files\Java
2010-10-13 20:36:49 ----D---- C:\Program Files\Opera
2010-10-11 01:22:18 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-10-11 00:24:15 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-10-10 21:21:57 ----D---- C:\WINDOWS\WinSxS
2010-10-10 21:19:16 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-10-10 21:09:25 ----D---- C:\WINDOWS\system32\QuickTime
2010-10-09 21:37:25 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-05 20:34:41 ----D---- C:\Filmos

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 d347bus;d347bus; C:\WINDOWS\system32\DRIVERS\d347bus.sys [2004-08-22 155136]
R0 d347prt;d347prt; C:\WINDOWS\System32\Drivers\d347prt.sys [2004-08-22 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2002-09-23 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2002-09-23 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2010-09-04 9856]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-21 191936]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-01-31 39808]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
S1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
S2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-09-03 21275]
S2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-04-14 13568]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-08 3959808]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-11-21 3600512]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2005-11-16 78976]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-03 67584]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-05-27 839724]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
S3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-02 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-12-14 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-03 25600]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2006-04-04 1429632]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-07-27 345376]
S2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-12 44032]
S2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2006-04-14 114753]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-19 136176]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
S2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-11-21 143426]
S2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2006-04-14 217164]
S2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2006-04-14 540745]
S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 16:04
od cernohous13
Zdravím,

pokud jsi v nouzovém režimu s prací v síti, tak proveď:
:arrow: Stáhni Rkill z jednoho z odkazů, pokud by ho vir blokoval, zkus stáhnout jiný

Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe

Rkill COM:
http://download.bleepingcomputer.com/grinler/rkill.com

Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr

Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif

-spusť a nechej ho pracovat. Sám se ukončí.

- :!: Teď nesmíš restartovat počítač!

:arrow: Spusť MBAM (malware bytes antimalware)
log vlož sem - zatím nic nemazat

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 16:20
od cartty
podarilo sa mi stiahnut rkill.... po skonceni nabehol textak
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Administrator on . 10. 2010 at 16:12:30.

Services Stopped:
Processes terminated by Rkill or while it was running:
Rkill completed on . 10. 2010 at 16:12:41.

ale na C-cku nic neni iba rkill.txt ziadny log
nainstalovam som MBAM verzia 1.46 ale neda sa mi spustit dvojklik na ikonu a nic ...

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 16:37
od cernohous13
spustíš Rkill ještě jednou - nebude žádný log -> zkusíš MBAM
když nejde, napiš

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 16:45
od cartty
MBAM nejde aj tak ...
ale je tu este jedna vec a to ked skonci rkill naskoci mi okno ze som v nudyovom rezime a ak chcem pokracovat v nom Ano ak chcem ukoncit nudzovy rezim tak NIE a vtedy zmiznu vsetky ikony a ked potvrdim ANO zostat v nudzovom rezime akoby sa restartovala plocha. Dvojklik na MBAM a nic

moze byt problem ze po instalacii MBAM neboj restartovany pc?

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 17:41
od cernohous13
:arrow: restart do normálního režimu

:arrow: Smaž starý ComboFix

:arrow: Stáhni ComboFix zde: http://www.bleepingcomputer.com/downloa ... s/combofix
Ulož ho přejmenovaný jako "zmije.com" na plochu

:arrow: návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix

:arrow: restart do nouzového režimu s prací v síti (F8) - spustit Rkill a pak zmije.com - log sem zkopíruj

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 18:30
od cartty
podarilo sa ...
zmije sa spustila prikladam log

ComboFix 10-10-30.09 - Administrator . 10. 2010 18:23:18.1.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1029.18.1023.843 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Plocha\zmije.com.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\daemon.dll

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-31 )))))))))))))))))))))))))))))))
.

2010-10-31 15:13 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-31 15:13 . 2010-10-31 15:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-31 15:13 . 2010-10-31 15:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-31 15:13 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-31 14:55 . 2010-10-31 17:00 -------- d-----w- C:\problem
2010-10-31 14:00 . 2010-10-31 14:00 -------- d-----w- c:\program files\trend micro
2010-10-31 14:00 . 2010-10-31 14:00 -------- d-----w- C:\rsit
2010-10-31 13:58 . 2010-10-31 13:59 -------- d-----w- c:\documents and settings\Administrator
2010-10-26 19:23 . 2010-10-26 19:23 -------- d-----w- C:\spoolerlogs
2010-10-25 21:25 . 2010-10-25 21:25 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-10-24 21:56 . 2010-10-24 21:56 1245184 ----a-w- c:\documents and settings\Patres\Local Settings\Data aplikací\048328.exe
2010-10-24 16:02 . 2010-10-24 16:02 54784 --sha-r- c:\windows\system32\RLOFRDecx.dll
2010-10-24 15:29 . 2006-09-28 14:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2010-10-24 15:29 . 2006-09-28 14:03 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2010-10-24 15:29 . 2006-09-28 14:04 68888 ----a-w- c:\windows\system32\xinput1_3.dll
2010-10-19 20:05 . 2010-09-15 03:50 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-10-19 20:03 . 2010-10-19 20:03 -------- d-----w- c:\windows\Sun
2010-10-19 19:45 . 2010-10-19 19:45 -------- d-----w- c:\documents and settings\Patres\Data aplikací\vShare
2010-10-19 19:45 . 2010-10-19 19:45 -------- d-----w- c:\program files\vShare
2010-10-13 20:12 . 2010-10-19 13:39 -------- d-----w- c:\program files\uTorrent
2010-10-13 20:11 . 2010-10-31 17:10 -------- d-----w- c:\documents and settings\Patres\Data aplikací\uTorrent
2010-10-12 21:31 . 2010-10-12 21:31 -------- d-----w- c:\program files\Xvid
2010-10-11 00:42 . 2010-10-11 00:42 -------- d-----w- c:\documents and settings\Patres\Data aplikací\SharePod
2010-10-10 20:29 . 2010-10-10 20:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-10-10 20:18 . 2010-10-10 20:18 -------- d-----w- c:\program files\Bonjour
2010-10-10 20:11 . 2010-10-10 20:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-10-10 20:09 . 2010-10-10 20:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple Computer
2010-10-10 20:07 . 2010-10-10 20:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple
2010-10-05 14:04 . 2010-10-05 14:04 -------- d-----w- C:\NVIDIA
2010-10-04 21:26 . 2010-10-04 21:26 -------- d-----w- c:\program files\directx
2010-10-04 19:48 . 2010-10-11 00:31 -------- d-----w- c:\documents and settings\Patres\Data aplikací\ZipGenius
2010-10-04 19:48 . 2010-10-04 19:48 -------- d-----w- c:\program files\ZipGenius 6
2010-10-04 19:46 . 2010-10-04 19:51 -------- d-----w- C:\Translator

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-16 22:33 . 2004-07-17 09:36 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-09-15 20:23 . 2010-09-15 20:23 98304 ----a-w- c:\windows\system32\qttask.exe
2010-09-15 03:50 . 2010-09-04 15:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 01:29 . 2010-09-03 23:17 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-08 10:17 . 2010-09-08 10:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17 . 2010-09-08 10:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-03 23:30 . 2010-09-03 23:30 9856 ----a-w- c:\windows\system32\drivers\pfc.sys
2010-09-03 23:20 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-03 22:26 . 2010-09-03 22:26 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
.

------- Sigcheck -------

[-] 2007-06-25 . 32870B6F41858B75B2358F143DA9C794 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-02-23 106496]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 569413]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-09-03 198160]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"SMSERIAL"="sm56hlpr.exe" [2005-05-26 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-17 100352]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"d:\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [15. 9. 2010 21:08 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [15. 9. 2010 21:08 5248]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19. 9. 2010 22:07 136176]
S3 SynMini;USB2.0 1.3M Web Cam;c:\windows\system32\drivers\SynMini.sys [3. 9. 2010 23:18 720470]
S3 SynScan;USB2.0 1.3M Web Cam Still Image;c:\windows\system32\drivers\SynScan.sys [3. 9. 2010 23:18 8278]
.
Contents of the 'Scheduled Tasks' folder

2010-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-19 21:07]

2010-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-19 21:07]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath -

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{043C5167-00BB-4324-AF7E-62013FAEDACF} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-31 18:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-10-31 18:28:28
ComboFix-quarantined-files.txt 2010-10-31 17:28

Pre-Run: 5 731 782 656
Post-Run: 5 716 164 608

- - End Of File - - 243B8DC627904FE27E6AA4DAC5615DCB

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 18:51
od cernohous13
:arrow: Otevři Poznámkový blok (Notepad) a zkopíruj celý zelený text z "CFscriptu".
Soubor ulož na plochu jako CFscript.txt a jeho ikonu přetáhni myší nad ikonu ComboFixu - tam pusť.
Obrázek
ComboFix se spustí - počkej na log a vlož ho sem.
CFscript

Kód: Vybrat vše

KillAll::

Restore::
c:\windows\system32\drivers\atapi.sys
c:\windows\system32\sfcfiles.dll

File::
c:\documents and settings\Patres\Local Settings\Data aplikací\048328.exe
c:\windows\system32\RLOFRDecx.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"TkBellExe"=-
"QuickTime Task"=-
:arrow: vyzkoušej MBAM

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:23
od cartty
Podarilo sa ... uy ide aj MBAM aky test odporucas staci rychly alebo pomaly

ComboFix 10-10-30.09 - Administrator . 10. 2010 19:05:06.2.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1029.18.1023.806 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Plocha\zmije.com.exe
Command switches used :: c:\documents and settings\Administrator\Plocha\CFScript.txt

FILE ::
"c:\documents and settings\Patres\Local Settings\Data aplikací\048328.exe"
"c:\windows\system32\RLOFRDecx.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\RLOFRDecx.dll

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

c:\windows\system32\sfcfiles.dll . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-31 )))))))))))))))))))))))))))))))
.

2010-10-31 15:13 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-31 15:13 . 2010-10-31 15:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-31 15:13 . 2010-10-31 15:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-31 15:13 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-31 14:55 . 2010-10-31 17:00 -------- d-----w- C:\problem
2010-10-31 14:00 . 2010-10-31 14:00 -------- d-----w- c:\program files\trend micro
2010-10-31 14:00 . 2010-10-31 14:00 -------- d-----w- C:\rsit
2010-10-31 13:58 . 2010-10-31 13:59 -------- d-----w- c:\documents and settings\Administrator
2010-10-26 19:23 . 2010-10-26 19:23 -------- d-----w- C:\spoolerlogs
2010-10-25 21:25 . 2010-10-25 21:25 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-10-24 21:56 . 2010-10-24 21:56 1245184 ----a-w- c:\documents and settings\Patres\Local Settings\Data aplikací\048328.exe
2010-10-24 15:29 . 2006-09-28 14:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2010-10-24 15:29 . 2006-09-28 14:03 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2010-10-24 15:29 . 2006-09-28 14:04 68888 ----a-w- c:\windows\system32\xinput1_3.dll
2010-10-19 20:05 . 2010-09-15 03:50 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-10-19 20:03 . 2010-10-19 20:03 -------- d-----w- c:\windows\Sun
2010-10-19 19:45 . 2010-10-19 19:45 -------- d-----w- c:\documents and settings\Patres\Data aplikací\vShare
2010-10-19 19:45 . 2010-10-19 19:45 -------- d-----w- c:\program files\vShare
2010-10-13 20:12 . 2010-10-19 13:39 -------- d-----w- c:\program files\uTorrent
2010-10-13 20:11 . 2010-10-31 17:10 -------- d-----w- c:\documents and settings\Patres\Data aplikací\uTorrent
2010-10-12 21:31 . 2010-10-12 21:31 -------- d-----w- c:\program files\Xvid
2010-10-11 00:42 . 2010-10-11 00:42 -------- d-----w- c:\documents and settings\Patres\Data aplikací\SharePod
2010-10-10 20:29 . 2010-10-10 20:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-10-10 20:18 . 2010-10-10 20:18 -------- d-----w- c:\program files\Bonjour
2010-10-10 20:11 . 2010-10-10 20:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-10-10 20:09 . 2010-10-10 20:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple Computer
2010-10-10 20:07 . 2010-10-10 20:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple
2010-10-05 14:04 . 2010-10-05 14:04 -------- d-----w- C:\NVIDIA
2010-10-04 21:26 . 2010-10-04 21:26 -------- d-----w- c:\program files\directx
2010-10-04 19:48 . 2010-10-11 00:31 -------- d-----w- c:\documents and settings\Patres\Data aplikací\ZipGenius
2010-10-04 19:48 . 2010-10-04 19:48 -------- d-----w- c:\program files\ZipGenius 6
2010-10-04 19:46 . 2010-10-04 19:51 -------- d-----w- C:\Translator

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-16 22:33 . 2004-07-17 09:36 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-09-15 20:23 . 2010-09-15 20:23 98304 ----a-w- c:\windows\system32\qttask.exe
2010-09-15 03:50 . 2010-09-04 15:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 01:29 . 2010-09-03 23:17 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-08 10:17 . 2010-09-08 10:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17 . 2010-09-08 10:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-03 23:30 . 2010-09-03 23:30 9856 ----a-w- c:\windows\system32\drivers\pfc.sys
2010-09-03 23:20 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-03 22:26 . 2010-09-03 22:26 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
.

------- Sigcheck -------

[-] 2007-06-25 . 32870B6F41858B75B2358F143DA9C794 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-10-31_17.27.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-03 20:59 . 2004-08-03 22:59 95360 c:\windows\system32\drivers\atapi.sys
- 2004-08-03 20:59 . 2004-08-03 21:59 95360 c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-02-23 106496]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 569413]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"SMSERIAL"="sm56hlpr.exe" [2005-05-26 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-17 100352]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"d:\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [15. 9. 2010 21:08 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [15. 9. 2010 21:08 5248]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19. 9. 2010 22:07 136176]
S3 SynMini;USB2.0 1.3M Web Cam;c:\windows\system32\drivers\SynMini.sys [3. 9. 2010 23:18 720470]
S3 SynScan;USB2.0 1.3M Web Cam Still Image;c:\windows\system32\drivers\SynScan.sys [3. 9. 2010 23:18 8278]
.
Contents of the 'Scheduled Tasks' folder

2010-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-19 21:07]

2010-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-19 21:07]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath -

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-31 19:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-10-31 19:12:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-31 18:12
ComboFix2.txt 2010-10-31 17:28

Pre-Run: 5 716 115 456
Post-Run: 5 706 858 496

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 520818455E9C0D3476C786C1EC487DF1

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:28
od cernohous13
Klikni na https://www.virustotal.com/cs/
klik "Procházet" > do zadávacího pole zkopíruj:

c:\windows\system32\sfcfiles.dll

"Odeslat soubor" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/39
Do fóra zkopíruj výsledný log. nebo link na stránku.
:arrow: kontrola MBAM (hlavně aktualizace) - stačí rychlý test

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:29
od cartty
tu je log y MBAM rychly test

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4052

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 6.0.2900.2180

31. 10. 2010 19:27:44
mbam-log-2010-10-31 (19-27-44).txt

Typ skenu: Rychlý sken
Skenované objekty: 119800
Uplynulý čas: 4 minuta(y), 14 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Documents and Settings\Patres\Nabídka Start\Programy\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:34
od cernohous13
:???: test na VT

Jak se chová PC?

Jestli nejsou problémy, tak budeme ještě uklízet :wink:

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:50
od cartty
Tu je adresa zo skenovania:

http://www.virustotal.com/file-scan/rep ... 1288550344

Tu je sprava z tej www-stranky

MD5 : 32870b6f41858b75b2358f143da9c794
SHA1 : aae144aaea6faeb33cb8ffa36610bfb6f8c3bda0
SHA256: 841c178f694ad01f1b387b43d8c82a11c1b128fc83298d2938026554036fb0d1
ssdeep: 3072:mr99o8gaaP3ZlRuuqCC/zqDR2z4yDx8waoaRQ09vqGa9VSaDJpJ8WFU:mgbaECLzqaDxhy
9vqGMSaDH
File size : 1548288 bytes
First seen: 2009-06-11 23:27:11
Last seen : 2010-10-31 18:39:04
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: Windows 2000 System File Checker
original name: sfcfiles.dll
internal name: sfcfiles.dll
file version.: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x120D
timedatestamp....: 0x41107C2B (Wed Aug 04 06:03:23 2004)
machinetype......: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xCBF, 0xE00, 5.91, 42137068c1332859090f264da2f41dad
.data, 0x2000, 0x16EB48, 0x16EC00, 3.27, 96a6a64159d72f8bcbd8fe5d2c7a65c6
.rsrc, 0x171000, 0x418, 0x600, 2.54, c123fdd41b8b0efeb7beb0a0084a77f0
.reloc, 0x172000, 0x9A68, 0x9C00, 5.76, 6255caf193acb80badcce29f8698e69c

[[ 1 import(s) ]]
ntdll.dll: LdrDisableThreadCalloutsForDll, NtClose, NtQueryValueKey, NtOpenKey, RtlInitUnicodeString, RtlGetVersion, NtTerminateProcess, RtlUnhandledExceptionFilter, RtlUnwind, NtQueryVirtualMemory

[[ 1 export(s) ]]
SfcGetFiles
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 3584
CompanyName: Microsoft Corporation
EntryPoint: 0x120d
FileDescription: Windows 2000 System File Checker
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 1512 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileVersionNumber: 5.1.2600.2180
ImageVersion: 5.1
InitializedDataSize: 1543680
InternalName: sfcfiles.dll
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 7.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.1
ObjectFileType: Executable application
OriginalFilename: sfcfiles.dll
PEType: PE32
ProductName: Microsoft Windows Operating System
ProductVersion: 5.1.2600.2180
ProductVersionNumber: 5.1.2600.2180
Subsystem: Windows command line
SubsystemVersion: 4.1
TimeStamp: 2004:08:04 08:03:23+02:00
UninitializedDataSize: 0




tu je novy MBAM log po aktualiyacii:

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Verze databáze: 5008

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 6.0.2900.2180

31. 10. 2010 19:49:33
mbam-log-2010-10-31 (19-49-33).txt

Typ skenu: Rychlý sken
Skenované objekty: 143226
Uplynulý čas: 5 minuta(y), 31 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)


Inak stale som v nudzovom rezime

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:55
od cernohous13
Logy vypadají čisté - restartuj do normálného režimu a napiš čo na to hovorí PC ?

Re: Help s virusom SECURITY TOOLS

Napsal: 31 říj 2010 19:58
od cartty
restartol som pc a security tool sa hned pustil ako to je mozne??? :shock: