Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomoooc, mám tam vira

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
pavel
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 22 lis 2010 22:32

Pomoooc, mám tam vira

#1 Příspěvek od pavel »

výpis z combofixu zde:

ComboFix 10-11-22.02 - pol 22.11.2010 22:10:46.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2715 [GMT 1:00]
Spuštěný z: c:\documents and settings\pol\Plocha\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\pol\Data aplikací\.#
c:\documents and settings\pol\fhlh.exe
c:\documents and settings\pol\Recent\firefox-2.0.0.20.complete.mar
c:\documents and settings\pol\secupdat.dat
c:\documents and settings\pol\wuaucldt.exe
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\regedit.com
c:\windows\system32\Drivers\kvqokqgd.sys
c:\windows\system32\maboula.exe
c:\windows\system32\secupdat.dat
c:\windows\system32\taskmgr.com
c:\windows\system32\Thumbs.db
c:\windows\system32\tura.exe
c:\windows\system32\wuaucldt.exe

Nakažená kopie c:\windows\system32\drivers\cdrom.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\cdrom.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_RKHIT
-------\Legacy_euuouuiob
-------\Legacy_kvqokqgd
-------\Service_euuouuiob
-------\Service_kvqokqgd


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-22 do 2010-11-22 )))))))))))))))))))))))))))))))
.

2010-11-22 20:50 . 2010-11-22 20:50 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2010-11-22 19:52 . 2010-11-22 19:52 -------- d---a-w- c:\windows\rundll16.exe
2010-11-22 19:52 . 2010-11-22 19:52 -------- d---a-w- c:\windows\logo1_.exe
2010-11-22 18:44 . 2010-11-22 18:44 -------- d-----w- C:\_OTM
2010-11-22 18:43 . 2010-11-22 18:43 -------- d-----w- C:\rsit
2010-11-22 18:43 . 2010-11-22 18:43 -------- d-----w- c:\program files\trend micro
2010-11-22 18:33 . 2010-11-22 18:33 -------- d---a-w- c:\windows\VDLL.DLL
2010-11-22 18:33 . 2010-11-22 18:33 -------- d---a-w- c:\windows\system32\runouce.exe
2010-11-22 18:33 . 2010-11-22 18:33 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-11-22 18:33 . 2010-11-22 18:33 -------- d---a-w- c:\windows\logo_1.exe
2010-11-22 18:17 . 2007-03-09 10:25 2321288 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-11-22 18:17 . 2010-11-16 11:01 6273872 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\Definition Updates\{8B84A524-8285-4214-8DDE-BFB6C74AB9CD}\mpengine.dll
2010-11-22 18:17 . 2010-10-19 09:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-11-22 18:17 . 2010-11-22 18:17 -------- d-----w- c:\program files\Windows Defender
2010-11-22 18:00 . 2010-11-22 18:00 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-11-22 17:59 . 2010-11-20 14:34 85504 --sh--r- c:\documents and settings\Administrator\Data aplikací\juzjf.exe
2010-11-22 16:35 . 2010-11-22 16:35 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-11-22 16:35 . 2009-02-28 17:57 632080 ----a-r- c:\windows\system32\msvcr80.dll
2010-11-22 16:35 . 2009-02-28 17:57 554256 ----a-r- c:\windows\system32\msvcp80.dll
2010-11-22 16:35 . 2010-11-22 16:35 -------- d-----w- c:\program files\Common Files\MicroWorld
2010-11-20 15:05 . 2010-11-20 15:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2010-11-20 15:00 . 2010-11-20 15:00 -------- d-----w- c:\program files\ATI Stream
2010-11-20 14:34 . 2010-11-20 14:34 85504 --sh--r- c:\documents and settings\pol\Data aplikací\juzjf.exe
2010-11-20 14:20 . 2010-11-20 14:21 -------- dc-h--w- c:\windows\ie8
2010-11-17 12:36 . 2010-11-17 12:36 -------- d-----w- c:\documents and settings\pol\Local Settings\Data aplikací\Activision
2010-11-17 12:34 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-11-17 12:34 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-11-17 12:34 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-11-17 12:34 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-11-17 12:34 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-11-17 12:34 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-11-17 12:34 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-11-17 12:34 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-11-17 11:33 . 2010-11-17 11:33 -------- d-----w- c:\program files\Activision
2010-11-17 10:18 . 2010-11-22 18:41 -------- d-----w- c:\program files\PowerISO
2010-11-09 17:50 . 2010-11-09 17:50 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-11-09 17:49 . 2010-11-09 17:49 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-11-09 17:46 . 2010-11-09 17:46 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-11-09 17:07 . 2010-11-20 09:41 -------- d-sha-r- c:\windows\kmsem
2010-11-09 16:53 . 2010-11-09 18:57 8192 --sha-w- c:\windows\system32\srvany.exe
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-10-26 15:26 . 2010-10-26 15:26 -------- d-----w- c:\program files\Common Files\Innerpass
2010-10-26 15:25 . 2010-10-26 15:25 143360 ----a-w- c:\windows\system32\unzip32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-22 18:41 . 2010-11-22 18:40 12754785 ----a-w- c:\windows\REGBK00.ZIP
2010-11-21 14:11 . 2009-03-27 17:46 234280 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-11-21 14:11 . 2009-01-05 21:12 234280 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-11-21 12:56 . 2009-01-05 21:12 137976 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-10-27 03:55 . 2008-12-01 22:13 5524480 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-10-27 03:17 . 2009-09-23 21:58 16330752 ----a-w- c:\windows\system32\atioglxx.dll
2010-10-27 03:10 . 2009-09-23 21:31 57344 ----a-w- c:\windows\system32\aticalrt.dll
2010-10-27 03:10 . 2009-09-23 21:31 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-10-27 03:09 . 2009-09-23 21:29 4489216 ----a-w- c:\windows\system32\aticaldd.dll
2010-10-27 03:02 . 2009-09-23 22:11 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-10-27 02:51 . 2008-12-01 20:27 3958784 ----a-w- c:\windows\system32\ati3duag.dll
2010-10-27 02:50 . 2009-09-23 22:39 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-10-27 02:49 . 2008-12-01 20:51 301056 ----a-w- c:\windows\system32\ati2dvag.dll
2010-10-27 02:48 . 2009-09-23 21:27 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-10-27 02:36 . 2008-12-01 20:11 2671744 ----a-w- c:\windows\system32\ativvaxx.dll
2010-10-27 02:30 . 2009-09-23 22:21 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2010-10-27 02:30 . 2009-09-23 22:21 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-10-27 02:30 . 2009-09-23 22:21 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-10-27 02:30 . 2009-09-23 22:20 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-10-27 02:30 . 2009-09-23 22:20 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-10-27 02:28 . 2009-09-23 22:19 614400 ----a-w- c:\windows\system32\ati2evxx.exe
2010-10-27 02:27 . 2009-09-23 22:17 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-10-27 02:26 . 2010-03-03 10:34 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-10-27 02:22 . 2009-09-23 21:32 651264 ----a-w- c:\windows\system32\atikvmag.dll
2010-10-27 02:20 . 2009-09-23 21:36 64512 ----a-w- c:\windows\system32\atimpc32.dll
2010-10-27 02:20 . 2009-09-23 21:36 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2010-10-27 02:20 . 2009-09-23 21:30 196608 ----a-w- c:\windows\system32\atiadlxx.dll
2010-10-27 02:20 . 2009-09-23 21:29 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-10-27 02:19 . 2009-09-23 21:28 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-10-27 02:14 . 2008-12-01 19:45 704512 ----a-w- c:\windows\system32\ati2cqag.dll
2010-09-18 10:23 . 2004-08-17 14:49 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-17 14:49 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2001-10-25 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2001-10-25 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-15 02:50 . 2010-07-27 17:48 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 00:29 . 2008-12-30 09:31 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-10 05:52 . 2004-08-17 14:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2004-08-17 14:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-10 05:52 . 2004-08-17 14:49 43520 ------w- c:\windows\system32\licmgr10.dll
2010-09-05 07:46 . 2010-05-11 18:40 2828 --sha-w- c:\documents and settings\All Users\Data aplikací\KGyGaAvL.sys
2010-09-05 07:46 . 2010-05-11 18:40 88 --sh--r- c:\documents and settings\All Users\Data aplikací\B24EBA441A.sys
2010-09-01 11:52 . 2004-08-17 14:48 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2004-08-17 14:44 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 18:32 . 2009-02-18 17:55 294912 ----a-w- c:\windows\system32\ATIODE.exe
2010-08-27 08:03 . 2004-08-17 14:49 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:54 . 2004-08-17 14:49 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-08-03 22:14 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2008-12-17 22:25 . 2010-06-17 14:44 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-17 22:25 . 2010-06-17 14:44 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-17 22:25 . 2010-06-17 14:44 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-17 22:25 . 2010-06-17 14:44 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-17 22:25 . 2010-06-17 14:44 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-08-03 202024]
"ABBYY Screenshot Reader Bonus"="c:\program files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" [2009-11-25 939272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Ai Nap"="c:\program files\ASUS\Ai Suite\AiNap\AiNap.exe" [2007-09-06 1426432]
"CPU Power Monitor"="c:\program files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe" [2007-10-16 626176]
"Cpu Level Up help"="c:\program files\ASUS\Ai Suite\CpuLevelUpHelp.exe" [2007-09-11 880640]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"PerfectSpeed.exe"="c:\program files\Raxco\PerfectSpeed20\PerfectSpeed.exe" [2010-01-21 7365896]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-05-18 1311312]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2010-09-23 38840]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"ScanSoft OmniPage 16-reminder"="c:\program files\ScanSoft\OmniPage16\Ereg\Ereg.exe" [2007-07-20 328992]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-10-26 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\pol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
3uupggb.exe [2010-11-22 43008]
70plgg6.exe [2010-11-22 43008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29 64592 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\VoipDiscount.com\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX9.EXE"=
"c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX10.EXE"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\server.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Game.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\WINWORD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\POWERPNT.EXE"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE"=
"c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor\\Binaries\\moh.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Activision\\Call of Duty - Black Ops\\BlackOps.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [30.12.2008 9:59 691696]
R1 enport;enport;c:\windows\system32\drivers\enport.sys [30.3.2009 18:50 4992]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [14.5.2009 16:07 759048]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [30.7.2008 6:51 277736]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [23.6.2010 10:29 10448]
R2 Rx2Agent;Rx2Agent;c:\program files\Raxco\PerfectSpeed20\Rx2Agent.exe [21.1.2010 10:33 779528]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
R3 MouseCap;MouseCapture Driver;c:\windows\system32\drivers\MouseCap.sys [8.8.2005 13:44 6640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate1c9869f1b12c30a;Google Update Service (gupdate1c9869f1b12c30a);c:\program files\Google\Update\GoogleUpdate.exe [4.2.2009 9:03 133104]
S2 KMService;KMService;c:\windows\system32\srvany.exe [9.11.2010 17:53 8192]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [30.12.2008 9:23 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [30.12.2008 9:23 13312]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [25.3.2010 10:25 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 21:37 4640000]
S3 Rx2Engine;Rx2Engine;c:\program files\Raxco\PerfectSpeed20\Rx2Engine.exe [21.1.2010 10:33 947464]
S3 SureThing Labelflash service;SureThing Labelflash service;c:\program files\Common Files\SureThing Shared\stllssvr.exe [5.4.2009 23:29 74392]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [18.7.2009 8:36 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 13:08 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 08:03]

2010-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 08:03]

2010-11-13 c:\windows\Tasks\Install_NSS.job
- c:\program files\DivX\Symantec\scstubinstaller.exe [2010-03-08 18:00]

2010-11-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

2010-11-22 c:\windows\Tasks\User_Feed_Synchronization-{000FE45D-1F1A-47C1-A70B-9EEB0B5EBDCC}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://www.google.com
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\pol\Data aplikací\Mozilla\Firefox\Profiles\miq0z65m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?hl=cs
FF - component: c:\documents and settings\pol\Data aplikací\Mozilla\Firefox\Profiles\miq0z65m.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - component: c:\documents and settings\pol\Data aplikací\Mozilla\Firefox\Profiles\miq0z65m.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-wuaucldt - c:\documents and settings\pol\wuaucldt.exe
HKLM-Run-nouvyfoun - c:\windows\system32\maboula.exe
Notify-avgrsstarter - avgrsstx.dll
SafeBoot-kvqokqgd.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-22 22:17
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1048)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

- - - - - - - > 'explorer.exe'(292)
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1029\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft Office\Office14\ONENOTEM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-11-22 22:21:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-22 21:20

Před spuštěním: Volných bajtů: 85 302 468 608
Po spuštění: Volných bajtů: 85 594 857 472

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP on C:\" /FASTDETECT /NoExecute=OptIn

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - AC0ABFFD6AD3DB55CC6B85E9B24EFC6F

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119427
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomoooc, mám tam vira

#2 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\documents and settings\pol\Nabídka Start\Programy\Po spuštění\3uupggb.exe
c:\documents and settings\pol\Nabídka Start\Programy\Po spuštění\70plgg6.exe
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět