Stránka 1 z 1

Facebook foto virus

Napsal: 04 úno 2011 19:25
od DomCZ
Dobry den, vcera vecer jsem od kamarada obdrzel zpravu, ktera vypadala neco jako:
hahaha foto :D
A za tim odkaz. Ten jsem otevrel a nabidlo mi to stazeni exe souboru s nazvem photo[cislo]. Dal jsem otevrit a nic se nestalo. Dnes rano jsem se pripojil na Facebook a mym online pratelum se tato zprava zacala hromadne posilat. Pokazde, kdyz se pripojim, situace se opakuje. Nize prikladam log z RSIT. Mohl by mi nekdo pomoct? Predem dekuji.

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-329068152-1606980848-725345543-1004.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-329068152-1606980848-725345543-1005.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-329068152-1606980848-725345543-1004.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-329068152-1606980848-725345543-1005.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{44651203-EC85-4B8B-86FD-EB9891218828}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-01-15 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-06 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-24 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-06 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R300 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2003-05-27 99840]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-11-06 8523776]
"nwiz"=nwiz.exe /install []
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 1983816]
"SkyTel"=SkyTel.EXE []
"RTHDCPL"=RTHDCPL.EXE []
"Alcmtr"=ALCMTR.EXE []
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2011-01-15 202256]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe [2011-02-03 98304]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-03-16 39408]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
WDSmartWare.lnk - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=253

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Pro Cycling Manager 2007\PCM.exe"="C:\Program Files\Pro Cycling Manager 2007\PCM.exe:*:Disabled:Pro Cycling Manager 2007"
"C:\Program Files\Codemasters\DiRT\DiRT.exe"="C:\Program Files\Codemasters\DiRT\DiRT.exe:*:Disabled:DiRT"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Disabled:ICQ6"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Counter-Strike Source\hl2.exe"="C:\Program Files\Counter-Strike Source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\TrackMania Sunrise\TmSunrise.exe"="C:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"C:\Program Files\Trackmania\TmOriginal.exe"="C:\Program Files\Trackmania\TmOriginal.exe:*:Enabled:TmOriginal"
"C:\Program Files\Trackmania\Nová složka\TmOriginal.exe"="C:\Program Files\Trackmania\Nová složka\TmOriginal.exe:*:Enabled:TmOriginal"
"C:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe"="C:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"C:\Program Files\EA Games\Need For Speed Underground\Speed.exe"="C:\Program Files\EA Games\Need For Speed Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Free Running\FreeRunning.exe"="C:\Program Files\Free Running\FreeRunning.exe:*:Enabled:FreeRunning"
"C:\Program Files\l4d\left4dead.exe"="C:\Program Files\l4d\left4dead.exe:*:Enabled:left4dead"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Launcher.exe"
"C:\Program Files\World of Warcraft\Repair.exe"="C:\Program Files\World of Warcraft\Repair.exe:*:Enabled:Repair.exe"
"C:\Program Files\TrackMania United\TmUnited.exe"="C:\Program Files\TrackMania United\TmUnited.exe:*:Enabled:TmUnited"
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe"="C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Enabled:Reactor Application"
"C:\Program Files\ijji\ijji REACTOR\ijjiOptimizer.exe"="C:\Program Files\ijji\ijji REACTOR\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Documents and Settings\All Users\Data aplikací\Electronic Arts\Need For Speed World\Data\nfsw.exe"="C:\Documents and Settings\All Users\Data aplikací\Electronic Arts\Need For Speed World\Data\nfsw.exe:*:Enabled:Need for Speed World"
"C:\UDK\UDK-2010-08\Binaries\Win32\UDK.exe"="C:\UDK\UDK-2010-08\Binaries\Win32\UDK.exe:*:Enabled:UDK"
"C:\UDK\UDK-2010-08\Binaries\SwarmAgent.exe"="C:\UDK\UDK-2010-08\Binaries\SwarmAgent.exe:*:Enabled:SwarmAgent"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Documents and Settings\vecera\Local Settings\Temp\FJ_Downloader.exe"="C:\Documents and Settings\vecera\Local Settings\Temp\FJ_Downloader.exe:*:Enabled:FreeJack_Downloader"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\XIII\system\XIII.exe"="C:\Program Files\XIII\system\XIII.exe:*:Enabled:XIII"
"C:\Program Files\Disney Interactive Studios\Split Second\SplitSecond.exe"="C:\Program Files\Disney Interactive Studios\Split Second\SplitSecond.exe:*:Enabled:Split/Second"
"C:\Program Files\Activision\Call of Duty - Black Ops\BlackOps.exe"="C:\Program Files\Activision\Call of Duty - Black Ops\BlackOps.exe:*:Enabled:BlackOps"
"C:\Program Files\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe"="C:\Program Files\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit"
"C:\Program Files\Aspyr\Guitar Hero World Tour\GHWT.exe"="C:\Program Files\Aspyr\Guitar Hero World Tour\GHWT.exe:*:Enabled:Guitar Hero World Tour"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\Prince of Persia.exe"="C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\Prince of Persia.exe:*:Enabled:Prince of Persia Zapomenuté písky"
"C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\GameSettings.exe"="C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\GameSettings.exe:*:Enabled:Prince of Persia Zapomenuté písky Settings"
"C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\gu.exe"="C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\gu.exe:*:Enabled:Prince of Persia Zapomenuté písky Update"
"C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\UPlayBrowser.exe"="C:\Program Files\Ubisoft\Prince of Persia Zapomenuté písky\UPlayBrowser.exe:*:Enabled:Prince of Persia Zapomenuté písky UPlay"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\R4c3rCz\Local Settings\Temporary Internet Files\Content.IE5\5TRLHF4K\facebook-pic000934519[1].exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2011-02-04 18:17:24 ----D---- C:\rsit
2011-02-04 18:17:24 ----D---- C:\Program Files\trend micro
2011-02-04 11:09:10 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-02-04 11:09:10 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-02-04 11:09:09 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-02-04 11:09:08 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-02-04 11:09:07 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-02-04 11:09:07 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-02-04 11:09:06 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-02-04 11:08:54 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-02-04 11:08:46 ----D---- C:\Program Files\Alwil Software
2011-02-04 11:08:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2011-02-03 19:34:09 ----RSH---- C:\WINDOWS\nvsvc32.exe
2011-02-01 18:02:29 ----D---- C:\Program Files\Microsoft Silverlight
2011-01-24 20:23:49 ----D---- C:\Program Files\Valve
2011-01-15 21:48:37 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2011-01-15 21:48:32 ----A---- C:\WINDOWS\system32\pndx5032.dll
2011-01-15 21:48:32 ----A---- C:\WINDOWS\system32\pndx5016.dll
2011-01-15 21:48:24 ----D---- C:\Program Files\Common Files\xing shared
2011-01-15 21:48:10 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-01-15 21:48:10 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-01-15 21:48:08 ----D---- C:\Program Files\Real
2011-01-14 22:14:44 ----D---- C:\Program Files\Realtek
2011-01-14 22:14:39 ----A---- C:\WINDOWS\RtlExUpd.dll
2011-01-14 19:40:15 ----A---- C:\WINDOWS\system32\ipconfig_results.txt
2011-01-14 19:40:14 ----D---- C:\Program Files\SecurityKISS Tunnel
2011-01-12 22:08:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-01-10 19:31:47 ----D---- C:\Program Files\Ubisoft
2011-01-07 19:03:24 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll

======List of files/folders modified in the last 1 months======

2011-02-04 19:14:07 ----SD---- C:\WINDOWS\Tasks
2011-02-04 19:07:19 ----D---- C:\Documents and Settings\vecera\Data aplikací\Skype
2011-02-04 19:02:50 ----D---- C:\WINDOWS\Prefetch
2011-02-04 18:17:24 ----RD---- C:\Program Files
2011-02-04 18:09:51 ----D---- C:\WINDOWS\Temp
2011-02-04 17:58:10 ----D---- C:\Documents and Settings\vecera\Data aplikací\skypePM
2011-02-04 17:54:58 ----A---- C:\WINDOWS\system32\log.txt
2011-02-04 13:41:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-04 12:34:59 ----A---- C:\WINDOWS\WINCMD.INI
2011-02-04 12:18:13 ----D---- C:\Documents and Settings
2011-02-04 11:09:10 ----D---- C:\WINDOWS\system32\drivers
2011-02-04 11:09:04 ----SHD---- C:\WINDOWS\Installer
2011-02-04 11:09:02 ----D---- C:\WINDOWS\WinSxS
2011-02-04 11:08:54 ----D---- C:\WINDOWS\system32
2011-02-04 11:08:54 ----D---- C:\WINDOWS
2011-02-04 10:48:18 ----D---- C:\Documents and Settings\vecera\Data aplikací\vlc
2011-02-04 09:20:17 ----D---- C:\Documents and Settings\vecera\Data aplikací\dvdcss
2011-02-04 09:20:17 ----A---- C:\WINDOWS\NeroDigital.ini
2011-02-03 23:34:40 ----D---- C:\Program Files\FreeRapid
2011-02-03 14:09:34 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-02 18:52:08 ----A---- C:\WINDOWS\win.ini
2011-02-01 22:09:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\CanonIJPLM
2011-02-01 18:02:38 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-01-24 20:23:48 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-16 12:18:56 ----D---- C:\Program Files\Electronic Arts
2011-01-16 10:20:15 ----RSD---- C:\WINDOWS\assembly
2011-01-16 10:20:15 ----D---- C:\WINDOWS\system32\DirectX
2011-01-15 21:49:43 ----A---- C:\WINDOWS\cdplayer.ini
2011-01-15 21:49:15 ----D---- C:\Documents and Settings\vecera\Data aplikací\Real
2011-01-15 21:48:40 ----D---- C:\Program Files\Common Files\Real
2011-01-15 21:48:24 ----D---- C:\Program Files\Common Files
2011-01-15 21:48:10 ----A---- C:\WINDOWS\system32\pncrt.dll
2011-01-14 22:14:51 ----HD---- C:\WINDOWS\inf
2011-01-12 22:09:12 ----A---- C:\WINDOWS\system32\MRT.exe
2011-01-12 22:09:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-01-12 22:08:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-12 08:56:48 ----HD---- C:\WINDOWS\$hf_mig$
2011-01-09 09:41:52 ----D---- C:\Program Files\ICQ7.0
2011-01-08 20:33:55 ----SD---- C:\Documents and Settings\vecera\Data aplikací\Microsoft
2011-01-07 19:25:40 ----D---- C:\WINDOWS\system32\CatRoot
2011-01-07 19:13:40 ----D---- C:\Program Files\Intel Audio Studio
2011-01-07 14:16:25 ----D---- C:\Program Files\instalacky
2011-01-07 13:35:57 ----D---- C:\Program Files\Notepad++
2011-01-07 13:35:27 ----D---- C:\Documents and Settings\vecera\Data aplikací\Notepad++

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 pe3ah4nc;DiRT Environment Driver (pe3ah4nc); C:\WINDOWS\system32\drivers\pe3ah4nc.sys [2007-05-18 64880]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-11-25 77248]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 ps6ah4nc;DiRT Synchronization Driver (ps6ah4nc); C:\WINDOWS\system32\drivers\ps6ah4nc.sys [2007-05-18 55160]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-05-18 44944]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-10-24 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-01-13 29392]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-01-13 23632]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-01-13 294608]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-01-13 47440]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-11-25 54368]
R2 acedrv11;acedrv11; \??\C:\WINDOWS\system32\drivers\acedrv11.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-01-13 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-01-13 100176]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-05-21 278728]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-05-21 25416]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2006-06-05 230400]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2006-06-01 43264]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2007-08-02 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-11-06 7429088]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-10-05 47360]
R3 sfng32;Sonic Focus Plugin for Sigmatel HDA; C:\WINDOWS\system32\drivers\sfng32.sys [2005-12-02 41728]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-05-26 1177032]
R3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2008-11-19 25216]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys []
S3 atq5hv3q;atq5hv3q; C:\WINDOWS\system32\drivers\atq5hv3q.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys []
S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 LMS;Intel(R) Active Management Technology LMS Service; C:\Program Files\Intel\AMT\LMS.exe [2006-06-29 98304]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-11-06 155716]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-05-08 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-09-28 215128]
R2 WDDMService;WD SmartWare Drive Manager; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-16 182768]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-11-15 382248]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2010-04-28 3555568]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2008-11-19 15872]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Facebook foto virus

Napsal: 04 úno 2011 19:30
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Facebook foto virus

Napsal: 04 úno 2011 21:18
od DomCZ
Zde je log z ComboFix:

ComboFix 11-01-31.02 - ****** 04.02.2011 21:03:28.1.2 - x86
Spuštěný z: c:\documents and settings\******\Dokumenty\ComboFix.exe
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\desktop.ini
C:\Thumbs.db
c:\windows\123.exe
c:\windows\nvsvc32.exe
c:\windows\regedit.com
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-04 do 2011-02-04 )))))))))))))))))))))))))))))))
.

2011-02-04 17:17 . 2011-02-04 18:14 -------- d-----w- c:\program files\trend micro
2011-02-04 17:17 . 2011-02-04 17:17 -------- d-----w- C:\rsit
2011-02-04 10:09 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-04 10:09 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-04 10:09 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-04 10:09 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-04 10:09 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-04 10:09 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-04 10:09 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-04 10:08 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-04 10:08 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-04 10:08 . 2011-02-04 10:08 -------- d-----w- c:\program files\Alwil Software
2011-02-04 10:08 . 2011-02-04 10:08 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2011-02-03 19:11 . 2011-02-03 19:11 -------- d-----w- c:\documents and settings\R4c3rCz\Data aplikací\skypePM
2011-02-03 19:10 . 2011-02-03 19:27 -------- d-----w- c:\documents and settings\R4c3rCz\Data aplikací\Skype
2011-02-01 17:02 . 2011-02-01 17:02 -------- d-----w- c:\program files\Microsoft Silverlight
2011-01-24 19:23 . 2011-01-24 19:43 -------- d-----w- c:\program files\Valve
2011-01-24 19:23 . 2011-01-24 19:23 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-01-24 19:23 . 2011-01-24 19:23 184452 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-01-24 19:23 . 2003-09-03 01:28 724992 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-01-24 19:23 . 2003-09-03 01:27 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-01-24 19:23 . 2003-09-03 01:26 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-01-24 19:23 . 2003-09-03 01:26 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-01-24 19:23 . 2003-09-03 01:25 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-01-15 20:48 . 2011-01-15 20:48 -------- d-----w- c:\program files\Common Files\xing shared
2011-01-15 20:48 . 2011-01-15 20:48 569397 ----a-w- c:\program files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll
2011-01-15 20:48 . 2011-01-15 20:48 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-01-15 20:48 . 2011-01-15 20:48 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-01-15 20:48 . 2011-01-15 20:48 -------- d-----w- c:\program files\Real
2011-01-14 21:14 . 2010-08-31 15:28 1251944 ----a-w- c:\windows\RtlExUpd.dll
2011-01-14 18:40 . 2011-02-01 17:00 -------- d-----w- c:\program files\SecurityKISS Tunnel
2011-01-10 18:31 . 2011-01-10 18:39 -------- d-----w- c:\program files\Ubisoft
2011-01-07 18:03 . 2010-11-11 12:27 55912 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2011-01-07 17:56 . 2006-02-07 14:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-01-07 17:56 . 2006-02-07 14:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-01-07 17:56 . 2006-02-07 14:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-01-07 17:56 . 2006-02-07 14:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-01-07 17:56 . 2005-11-13 22:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-01-07 17:56 . 2011-01-07 17:56 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-01-07 17:56 . 2011-01-07 17:56 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 19:54 . 2010-12-21 19:54 1388544 ----a-w- c:\documents and settings\msvbvm60.dll
2010-12-18 10:36 . 2010-12-18 10:36 1749461 ----a-w- c:\documents and settings\Michael Buble - Crazy Love.zip
2010-12-15 17:57 . 2010-12-15 17:57 692613 ----a-w- c:\documents and settings\gamemagic.zip
2010-11-23 16:27 . 2010-11-23 16:27 412908 ----a-w- C:\utorrent-setup.zip
2010-11-18 18:15 . 2009-01-21 07:50 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2007-08-02 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
.

------- Sigcheck -------

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2007-08-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-16 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]
"nwiz"="nwiz.exe" [2007-11-06 1626112]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2011-01-15 202256]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\R4c3rCz\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 2.1.lnk - c:\program files\OpenOffice.org 2.1\program\quickstart.exe [N/A]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\l4d\\left4dead.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Disney Interactive Studios\\Split Second\\SplitSecond.exe"=
"c:\\Program Files\\Activision\\Call of Duty - Black Ops\\BlackOps.exe"=
"c:\\Program Files\\Aspyr\\Guitar Hero World Tour\\GHWT.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Ubisoft\\Prince of Persia Zapomenuté písky\\Prince of Persia.exe"=
"c:\\Program Files\\Ubisoft\\Prince of Persia Zapomenuté písky\\GameSettings.exe"=
"c:\\Program Files\\Ubisoft\\Prince of Persia Zapomenuté písky\\gu.exe"=
"c:\\Program Files\\Ubisoft\\Prince of Persia Zapomenuté písky\\UPlayBrowser.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
R3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-04-28 3555568]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S0 pe3ah4nc;DiRT Environment Driver (pe3ah4nc);c:\windows\system32\drivers\pe3ah4nc.sys [2007-05-18 64880]
S0 ps6ah4nc;DiRT Synchronization Driver (ps6ah4nc);c:\windows\system32\drivers\ps6ah4nc.sys [2007-05-18 55160]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-24 691696]
S1 aswSP;aswSP; [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
S2 aswFsBlk;aswFsBlk; [x]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

.
Obsah adresáře 'Naplánované úlohy'

2011-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 14:44]

2011-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 14:44]

2011-02-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-329068152-1606980848-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2011-02-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-329068152-1606980848-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2011-02-04 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-329068152-1606980848-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2011-02-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-329068152-1606980848-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]

2011-02-04 c:\windows\Tasks\User_Feed_Synchronization-{44651203-EC85-4B8B-86FD-EB9891218828}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-SkyTel - SkyTel.EXE
HKLM-Run-RTHDCPL - RTHDCPL.EXE
AddRemove-PAF CS Source Map Pack 1 - c:\program files\COUNTER-STRIKE SOURCE\CSTRIKE\MAPS\Uninstal.exe
AddRemove-SnadBoy's Revelation v2 - c:\progra~1\SNADBO~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-04 21:08
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-329068152-1606980848-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:fb,35,cb,13,b4,b5,55,6b,95,fd,ff,f8,c1,ed,3f,b4,9d,aa,d7,9c,32,b6,18,
70,9b,4b,91,54,66,fa,9c,06,00,c5,8c,dc,27,ea,f8,28,4b,a3,98,1c,f2,21,eb,1c,\
"??"=hex:db,f6,bc,97,31,d1,d8,7e,0e,c6,93,bf,31,ec,b8,cc

[HKEY_USERS\S-1-5-21-329068152-1606980848-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:21,b9,70,fc,5a,82,f2,d8,7d,53,37,da,c1,2c,7b,33,33,4c,10,a7,93,
4a,f0,06,4d,bf,11,7c,4a,8a,86,53,2c,d6,4c,37,d4,39,7c,71,7e,af,34,2c,ea,e6,\
"rkeysecu"=hex:7e,6d,46,f8,9d,2d,ef,84,ab,37,7c,1e,53,15,9e,ca

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2011-02-04 21:09:47
ComboFix-quarantined-files.txt 2011-02-04 20:09

Před spuštěním: Volných bajtů: 81 992 855 552
Po spuštění: Volných bajtů: 83 498 213 376

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 52E5FADE12F50F1945BB5104158FD655

Re: Facebook foto virus

Napsal: 04 úno 2011 21:28
od Rudy
Vir by měl být pryč a dále byly smazány ještě další infikované položky. Zbytek logu vypadá čistý.

Re: Facebook foto virus

Napsal: 04 úno 2011 21:46
od DomCZ
Dekuji moc. Vse jiz funguje v poradku.

Re: Facebook foto virus

Napsal: 04 úno 2011 22:42
od Rudy
Nemáte zač!

Re: Facebook foto virus

Napsal: 03 úno 2013 18:25
od pochec
Mohu také poprosit o kontrolu logu ? mám ten samý vir předem děkuji

ComboFix 13-02-03.02 - Uživatel 03.02.2013 18:03:38.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2014.852 [GMT 1:00]
Spuštěný z: c:\users\Uživatel\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-03 do 2013-02-03 )))))))))))))))))))))))))))))))
.
.
2013-02-03 17:11 . 2013-02-03 17:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-02-03 17:11 . 2013-02-03 17:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-03 17:09 . 2013-02-03 17:09 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AC7F8125-3FE1-4D5F-8C73-FBEFBB7ABA83}\offreg.dll
2013-02-01 10:46 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AC7F8125-3FE1-4D5F-8C73-FBEFBB7ABA83}\mpengine.dll
2013-02-01 10:13 . 2013-02-01 10:23 139424 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-02-01 10:13 . 2013-02-01 10:22 282104 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-02-01 10:13 . 2013-02-01 10:23 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-01-31 20:00 . 2013-01-31 20:00 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-01-31 18:37 . 2013-01-31 18:37 -------- d-----w- c:\program files\Lame For Audacity
2013-01-31 17:48 . 2013-01-31 18:42 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Audacity
2013-01-31 17:48 . 2013-01-31 17:48 -------- d-----w- c:\program files\Audacity
2013-01-31 16:45 . 2010-07-10 23:28 416522 ----a-w- c:\windows\AutoKMS.exe
2013-01-31 16:30 . 2013-01-31 16:30 -------- d-----w- c:\program files\Microsoft Synchronization Services
2013-01-31 16:29 . 2013-01-31 16:29 -------- d-----w- c:\windows\PCHEALTH
2013-01-31 16:29 . 2013-01-31 16:29 -------- d-----w- c:\program files\Microsoft Sync Framework
2013-01-31 16:29 . 2013-01-31 16:29 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2013-01-31 16:28 . 2013-01-31 16:28 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2013-01-31 16:26 . 2013-01-31 16:26 -------- d-----w- c:\program files\Microsoft Analysis Services
2013-01-31 16:26 . 2013-01-31 16:26 -------- d-----w- c:\users\Uživatel\AppData\Local\Microsoft Help
2013-01-31 16:25 . 2013-02-01 13:22 -------- d-----w- c:\programdata\Microsoft Help
2013-01-31 16:25 . 2013-01-31 16:25 -------- d-----r- C:\MSOCache
2013-01-30 15:59 . 2013-01-30 15:59 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Publish Providers
2013-01-29 16:16 . 2013-01-29 16:16 -------- d-----w- c:\users\Uživatel\AppData\Local\Avg2013
2013-01-27 17:16 . 2013-01-30 15:59 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Sony
2013-01-27 17:16 . 2013-01-27 17:17 -------- d-----w- c:\users\Uživatel\AppData\Local\Sony
2013-01-27 17:13 . 2013-01-27 17:13 -------- d-----w- c:\programdata\Sony
2013-01-27 17:12 . 2013-01-27 17:12 -------- d-----w- c:\program files\Sony
2013-01-27 16:29 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-01-27 16:29 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-01-27 16:29 . 2012-10-15 16:59 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-01-27 16:29 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-01-27 16:29 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-01-27 16:29 . 2012-10-30 22:51 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-01-27 16:28 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-01-27 16:28 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-01-27 16:28 . 2013-01-27 16:28 -------- d-----w- c:\programdata\AVAST Software
2013-01-27 16:28 . 2013-01-27 16:28 -------- d-----w- c:\program files\AVAST Software
2013-01-26 21:38 . 2013-01-27 10:50 -------- d-sh--r- c:\users\Uživatel\46357865364647353
2013-01-26 09:36 . 2013-01-26 09:36 -------- d-----w- c:\program files\MSI Kombustor 2.5
2013-01-26 09:36 . 2013-01-26 09:36 -------- d-----w- c:\users\Uživatel\AppData\Local\Programs
2013-01-26 09:27 . 2013-01-26 09:28 -------- d-----w- c:\program files\MSI Afterburner
2013-01-25 10:02 . 2013-01-25 10:02 -------- d-----w- c:\program files\Common Files\Skype
2013-01-25 10:02 . 2013-01-25 10:02 -------- d-----r- c:\program files\Skype
2013-01-24 10:32 . 2013-01-24 10:32 -------- d-----w- c:\program files\VirtualDJ
2013-01-23 20:55 . 2013-01-23 20:56 -------- d-----w- c:\users\Uživatel\AppData\Local\Anvil Studio
2013-01-23 15:22 . 2013-01-23 15:22 -------- d-----w- c:\program files\BitTorrent
2013-01-23 15:22 . 2013-01-31 19:56 -------- d-----w- c:\users\Uživatel\AppData\Roaming\BitTorrent
2013-01-21 16:13 . 2013-01-21 16:13 -------- d-----w- c:\programdata\Electronic Arts
2013-01-21 15:39 . 2013-01-21 15:39 -------- d-----w- c:\program files\Microsoft WSE
2013-01-21 15:25 . 2013-01-21 15:25 -------- d-----w- c:\program files\Electronic Arts
2013-01-20 16:53 . 2013-01-20 16:53 -------- d-----w- c:\users\Uživatel\AppData\Local\AVG Secure Search
2013-01-20 16:53 . 2013-01-20 16:53 -------- d-----w- c:\programdata\AVG Security Toolbar
2013-01-20 16:53 . 2013-01-20 16:53 -------- d-----w- c:\programdata\AVG Secure Search
2013-01-20 16:52 . 2013-01-20 16:52 31576 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-01-20 16:52 . 2013-01-20 16:52 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2013-01-20 16:52 . 2013-01-20 16:52 -------- d-----w- c:\program files\AVG Secure Search
2013-01-20 16:45 . 2013-01-20 16:47 -------- d-----w- c:\programdata\AVG January 2013 Campaign
2013-01-20 12:10 . 2013-01-20 12:10 -------- d-----w- c:\programdata\Orbit
2013-01-20 10:25 . 2009-03-11 20:57 6257467 ----a-w- c:\program files\Microsoft Games\Age of Empires III\aoe3cz1.01a.exe
2013-01-19 20:00 . 2013-01-19 20:02 -------- d-----w- c:\program files\Counter-Strike 1.6
2013-01-19 19:52 . 2013-01-19 19:53 -------- d-----w- c:\program files\TeamSpeak 3 Client
2013-01-19 15:35 . 2013-01-19 15:35 -------- d-----w- c:\users\Uživatel\AppData\Local\Application Data
2013-01-19 15:34 . 2013-01-24 10:29 -------- d-----w- c:\program files\Mixxx
2013-01-19 15:24 . 2013-01-12 02:30 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-18 15:23 . 2013-01-18 15:23 773968 ----a-w- c:\windows\system32\msvcr100.dll
2013-01-18 15:23 . 2013-01-18 15:23 421200 ----a-w- c:\windows\system32\msvcp100.dll
2013-01-17 16:03 . 2013-01-17 16:03 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Leadertech
2013-01-17 15:09 . 2012-12-29 10:26 8904632 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-01-17 15:09 . 2012-12-29 10:26 889784 ----a-w- c:\windows\system32\nvdispgenco32.dll
2013-01-17 15:09 . 2012-12-29 10:26 7931896 ----a-w- c:\windows\system32\nvcuda.dll
2013-01-17 15:09 . 2012-12-29 10:26 6263784 ----a-w- c:\windows\system32\nvopencl.dll
2013-01-17 15:09 . 2012-12-29 10:26 2720696 ----a-w- c:\windows\system32\nvcuvid.dll
2013-01-17 15:09 . 2012-12-29 10:26 20450232 ----a-w- c:\windows\system32\nvoglv32.dll
2013-01-17 15:09 . 2012-12-29 10:26 1985976 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-01-17 15:09 . 2012-12-29 10:26 17560504 ----a-w- c:\windows\system32\nvcompiler.dll
2013-01-17 15:09 . 2012-12-29 10:26 15129064 ----a-w- c:\windows\system32\nvd3dum.dll
2013-01-17 15:09 . 2012-12-29 10:26 12641120 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-01-17 15:09 . 2012-12-29 10:26 1017272 ----a-w- c:\windows\system32\nvdispco32.dll
2013-01-17 14:35 . 2013-01-17 14:35 -------- d-----w- c:\program files\EA Sports
2013-01-11 15:42 . 2013-01-11 16:02 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Notepad++
2013-01-11 15:42 . 2013-01-11 15:42 -------- d-----w- c:\program files\Notepad++
2013-01-11 13:52 . 2013-01-11 13:52 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2013-01-10 19:02 . 2013-01-10 19:02 -------- d-----w- c:\program files\MSXML 4.0
2013-01-09 12:51 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-01-07 15:43 . 2011-02-19 06:30 805376 ----a-w- c:\windows\system32\FntCache.dll
2013-01-07 15:43 . 2011-02-19 06:30 739840 ----a-w- c:\windows\system32\d2d1.dll
2013-01-07 15:21 . 2013-01-07 15:21 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Ubisoft
2013-01-07 15:09 . 2013-01-07 15:09 -------- d-----w- c:\programdata\Ubisoft
2013-01-07 14:58 . 2013-01-20 12:08 -------- d-----w- c:\program files\Ubisoft
2013-01-07 14:57 . 2013-01-07 14:57 -------- d-----w- c:\users\Uživatel\AppData\Roaming\InstallShield
2013-01-06 11:14 . 2013-01-06 11:14 -------- d--h--w- c:\program files\Common Files\EAInstaller
2013-01-06 11:14 . 2008-10-15 05:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2013-01-06 11:14 . 2008-10-15 05:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2013-01-06 11:14 . 2008-10-15 05:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2013-01-04 19:08 . 2013-01-04 19:09 -------- d-----w- c:\program files\Clownfish
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-01 10:22 . 2012-12-27 11:56 282104 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-02-01 10:13 . 2012-12-27 11:42 138056 ----a-w- c:\users\Uživatel\AppData\Roaming\PnkBstrK.sys
2013-02-01 10:13 . 2012-12-27 11:42 138056 ----a-w- c:\users\Uživatel\AppData\Roaming\PnkBstrK.sys
2013-01-29 20:49 . 2012-12-27 11:42 281688 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-01-17 00:28 . 2012-10-18 15:01 232336 ------w- c:\windows\system32\MpSigStub.exe
2012-12-29 10:26 . 2012-12-22 13:43 2504248 ----a-w- c:\windows\system32\nvapi.dll
2012-12-29 08:26 . 2012-12-22 13:44 4129720 ----a-w- c:\windows\system32\nvcpl.dll
2012-12-29 08:26 . 2012-12-22 13:44 3001272 ----a-w- c:\windows\system32\nvsvc.dll
2012-12-29 08:25 . 2012-12-22 13:44 639928 ----a-w- c:\windows\system32\nvvsvc.exe
2012-12-29 08:25 . 2012-12-22 13:44 62904 ----a-w- c:\windows\system32\nvshext.dll
2012-12-29 08:25 . 2012-12-22 13:44 108984 ----a-w- c:\windows\system32\nvmctray.dll
2012-12-29 01:54 . 2012-12-29 01:54 550328 ----a-w- c:\windows\system32\nvStreaming.exe
2012-12-25 16:44 . 2012-12-25 16:44 163056 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
2012-12-22 21:09 . 2012-12-22 21:09 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-12-22 13:32 . 2012-12-22 13:32 859072 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-12-22 13:32 . 2012-12-22 13:32 779704 ----a-w- c:\windows\system32\deployJava1.dll
2012-12-22 12:46 . 2012-12-22 12:46 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-12-22 12:46 . 2012-12-22 12:46 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-12-22 12:46 . 2012-12-22 12:46 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-12-22 12:46 . 2012-12-22 12:46 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-12-22 12:46 . 2012-12-22 12:46 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-22 12:46 . 2012-12-22 12:46 367104 ----a-w- c:\windows\system32\html.iec
2012-12-22 12:46 . 2012-12-22 12:46 161792 ----a-w- c:\windows\system32\msls31.dll
2012-12-22 12:46 . 2012-12-22 12:46 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-12-22 12:46 . 2012-12-22 12:46 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-12-22 12:46 . 2012-12-22 12:46 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-12-22 12:46 . 2012-12-22 12:46 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-12-22 12:46 . 2012-12-22 12:46 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-12-22 12:46 . 2012-12-22 12:46 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-22 12:46 . 2012-12-22 12:46 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-22 12:46 . 2012-12-22 12:46 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-12-22 12:46 . 2012-12-22 12:46 152064 ----a-w- c:\windows\system32\wextract.exe
2012-12-22 12:46 . 2012-12-22 12:46 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-12-22 12:46 . 2012-12-22 12:46 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-22 12:46 . 2012-12-22 12:46 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-22 12:46 . 2012-12-22 12:46 11776 ----a-w- c:\windows\system32\mshta.exe
2012-12-22 12:46 . 2012-12-22 12:46 101888 ----a-w- c:\windows\system32\admparse.dll
2012-12-16 14:13 . 2012-12-22 23:10 295424 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-22 23:10 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-03 15:39 . 2012-12-22 13:44 52584 ----a-w- c:\windows\system32\OpenCL.dll
2012-12-01 04:37 . 2012-12-22 13:44 2557288 ----a-w- c:\windows\system32\nvsvcr.dll
2012-11-09 04:42 . 2012-12-22 13:10 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-01-20 16:52 1883824 ----a-w- c:\program files\AVG Secure Search\14.0.0.14\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\14.0.0.14\AVG Secure Search_toolbar.dll" [2013-01-20 1883824]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Clownfish"="c:\program files\Clownfish\Clownfish.exe" [2012-09-27 1122040]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-14 2255360]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2013-01-20 1101488]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\DRIVERS\zghsmdm.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-01 08:06 1607120 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-22 12:59]
.
2013-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-22 12:59]
.
2013-01-21 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-20 16:07]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-RGSC - c:\program files\Rockstar Games(GTA)\Rockstar Games Social Club\RGSCLauncher.exe
HKCU-Run-AdobeBridge - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1960281371-784375549-2458736988-1000\Software\SecuROM\License information*]
"datasecu"=hex:52,3d,71,21,f8,7a,ae,b3,34,4f,9b,3d,9f,dc,c0,f4,14,12,54,b8,fc,
b7,d2,e8,ef,86,1d,98,57,1a,06,2f,11,7e,b7,b7,85,fc,99,3a,8c,94,15,06,20,78,\
"rkeysecu"=hex:26,f7,83,91,40,da,8a,b4,79,8c,9a,4c,92,dd,17,c3
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-02-03 18:12:46
ComboFix-quarantined-files.txt 2013-02-03 17:12
.
Před spuštěním: Volných bajtů: 80 924 196 864
Po spuštění: Volných bajtů: 82 663 886 848
.
- - End Of File - - 91DC24D3BC5924DD66E56C4287896C8E

Re: Facebook foto virus

Napsal: 03 úno 2013 18:32
od Rudy
2pochec: Založte si, prosím, vlastní topic. Děkujeme.