Stránka 1 z 1

Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 14:40
od honzikuh
Logfile of random's system information tool 1.08 (written by random/random)
Run by Honza at 2011-07-06 15:39:31
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 129 GB (63%) free of 205 GB
Total RAM: 3584 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:39:38, on 6.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Honza.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Honza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{1056045E-C017-49CB-AEEC-7815862E1FC5}: NameServer = 10.145.100.25,85.92.54.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1056045E-C017-49CB-AEEC-7815862E1FC5}: NameServer = 10.145.100.25,85.92.54.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1056045E-C017-49CB-AEEC-7815862E1FC5}: NameServer = 10.145.100.25,85.92.54.1
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: ABBYY.Licensing.FineReader.ScreenshotReader.9.0 - ABBYY (BIT Software) - C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdagent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7377 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\COMODO\COMODO GeekBuddy\CLPS.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"taskhost.exe"
"C:\Windows\system32\taskmgr.exe" /4
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
"C:\Program Files\Windows Media Player\wmprph.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1460.5398d00.933899766 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" "Mozilla.Firefox.5.0" -omnijar C:\Program Files (x86)\Mozilla Firefox\omni.jar 1460 \\.\pipe\gecko-crash-server-pipe.1460 plugin
"C:\Windows\system32\mspaint.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Honza\Downloads\RSITx64(1).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4032493769-2605325388-1694172860-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4032493769-2605325388-1694172860-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-13 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-10-05 11474024]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-07-05 9048392]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"Google Update"=C:\Users\Honza\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-15 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol]
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [2010-11-13 329096]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"COMODO"=C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [2011-05-26 213304]
"CPA"=C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [2011-05-26 184120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-04-10 249344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-07-06 13:11:38 ----D---- C:\Program Files (x86)\SpeedFan
2011-07-06 13:08:16 ----D---- C:\Program Files\CPUID
2011-07-06 13:08:16 ----A---- C:\Windows\system32\drivers\cpuz135_x64.sys
2011-07-06 12:38:46 ----HD---- C:\VritualRoot
2011-07-05 19:07:34 ----D---- C:\ProgramData\Comodo Downloader
2011-07-05 19:01:20 ----D---- C:\ProgramData\Comodo
2011-07-05 19:01:14 ----D---- C:\Program Files\COMODO
2011-07-05 19:01:13 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2011-07-05 19:01:12 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-06-26 11:46:39 ----D---- C:\Program Files (x86)\Google
2011-06-26 11:05:50 ----A---- C:\Windows\MSVCR71.DLL
2011-06-26 11:05:50 ----A---- C:\Windows\MFC71.DLL
2011-06-26 11:05:45 ----D---- C:\Program Files (x86)\SIM editor
2011-06-26 11:05:36 ----A---- C:\Windows\wininit.ini
2011-06-26 10:08:50 ----D---- C:\Windows\Downloaded Installations
2011-06-26 07:50:45 ----D---- C:\Program Files (x86)\Adobe
2011-06-26 07:50:30 ----SHD---- C:\Config.Msi
2011-06-19 11:07:41 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-19 11:07:41 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-19 11:07:40 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-19 11:07:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-19 11:07:40 ----A---- C:\Windows\system32\iertutil.dll
2011-06-19 11:07:39 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-19 11:07:39 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-19 11:07:39 ----A---- C:\Windows\system32\jscript9.dll
2011-06-19 11:07:39 ----A---- C:\Windows\system32\jscript.dll
2011-06-19 11:07:39 ----A---- C:\Windows\system32\ieui.dll
2011-06-19 11:07:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-19 11:07:38 ----A---- C:\Windows\system32\urlmon.dll
2011-06-19 11:07:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-19 11:07:36 ----A---- C:\Windows\system32\mshtml.dll
2011-06-19 11:07:35 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-19 11:07:35 ----A---- C:\Windows\system32\ieframe.dll
2011-06-19 10:09:42 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-19 10:09:41 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-19 10:09:39 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-19 10:09:39 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-19 10:09:39 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-19 10:09:34 ----A---- C:\Windows\system32\win32k.sys
2011-06-19 10:09:32 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-19 10:09:32 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-19 10:09:32 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-19 10:09:31 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-19 10:09:30 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-19 10:09:28 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-19 10:09:28 ----A---- C:\Windows\system32\inetcomm.dll

======List of files/folders modified in the last 1 months======

2011-07-06 15:39:34 ----D---- C:\Program Files\trend micro
2011-07-06 15:31:51 ----D---- C:\Windows\Microsoft.NET
2011-07-06 15:31:50 ----RSD---- C:\Windows\assembly
2011-07-06 14:30:31 ----D---- C:\Windows\temp
2011-07-06 13:29:20 ----D---- C:\Windows\System32
2011-07-06 13:29:20 ----D---- C:\Windows\inf
2011-07-06 13:29:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-06 13:11:38 ----RD---- C:\Program Files (x86)
2011-07-06 13:11:38 ----D---- C:\Windows\SysWOW64
2011-07-06 13:11:38 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-06 13:08:16 ----RD---- C:\Program Files
2011-07-06 13:08:16 ----D---- C:\Windows\system32\drivers
2011-07-06 13:05:40 ----D---- C:\Windows\winsxs
2011-07-06 13:04:49 ----D---- C:\Windows\system32\config
2011-07-06 13:04:40 ----SHD---- C:\Windows\Installer
2011-07-06 12:38:09 ----SHD---- C:\System Volume Information
2011-07-05 19:15:00 ----D---- C:\Windows
2011-07-05 19:11:55 ----A---- C:\Windows\system32\guard64.dll
2011-07-05 19:11:54 ----A---- C:\Windows\SYSWOW64\guard32.dll
2011-07-05 19:07:34 ----D---- C:\ProgramData
2011-07-05 19:05:49 ----D---- C:\Windows\system32\catroot2
2011-07-05 19:05:49 ----D---- C:\Windows\system32\catroot
2011-07-05 19:03:04 ----D---- C:\Windows\system32\DriverStore
2011-07-05 19:02:11 ----D---- C:\Windows\Prefetch
2011-07-05 19:00:24 ----D---- C:\Windows\debug
2011-07-05 18:58:43 ----HD---- C:\Windows\system32\GroupPolicy
2011-06-26 13:07:33 ----D---- C:\Windows\system32\wdi
2011-06-26 12:00:42 ----RD---- C:\Program Files (x86)\Skype
2011-06-26 11:48:54 ----D---- C:\Program Files\Zrychleni Pocitace
2011-06-26 11:05:35 ----A---- C:\Windows\SimTestDll.dll
2011-06-26 09:59:04 ----D---- C:\Windows\system32\Tasks
2011-06-26 09:56:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-06-26 09:56:22 ----D---- C:\Program Files (x86)\Realtek
2011-06-26 07:50:47 ----D---- C:\ProgramData\Adobe
2011-06-26 07:50:45 ----D---- C:\Program Files (x86)\Common Files
2011-06-19 15:05:24 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-19 15:05:23 ----D---- C:\Program Files\Internet Explorer
2011-06-19 11:09:39 ----A---- C:\Windows\system32\MRT.exe
2011-06-19 11:08:31 ----D---- C:\ProgramData\Microsoft Help
2011-06-19 11:07:11 ----D---- C:\Program Files (x86)\Microsoft Silverlight

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2010-12-18 25280]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2011-07-05 16016]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-07-05 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-07-05 41712]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-07-05 92688]
R1 sensorsview;sensorsview; \??\C:\Program Files (x86)\SensorsViewPro41\drv\sensorsview32_64.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-10-05 2511464]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S2 cpuz135;cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-07-30 19456]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-07-30 26624]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RSUSBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-07-30 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2010-07-30 9216]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0;ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe [2008-10-27 759072]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-05-26 161080]
R2 cmdagent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-07-05 2528096]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-10-20 630272]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-28 1255736]

-----------------EOF-----------------

Re: Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 15:14
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 15:43
od honzikuh
Musím už odjet,pokračování když tak v sobotu , díky

ComboFix 11-07-06.02 - Honza 06.07.2011 16:23:29.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3584.2114 [GMT 2:00]
Spuštěný z: c:\users\Honza\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51}
FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-06 do 2011-07-06 )))))))))))))))))))))))))))))))
.
.
2011-07-06 14:29 . 2011-07-06 14:29 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-07-06 14:29 . 2011-07-06 14:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-06 11:11 . 2011-07-06 14:10 -------- d-----w- c:\program files (x86)\SpeedFan
2011-07-06 11:08 . 2011-07-06 11:08 -------- d-----w- c:\program files\CPUID
2011-07-06 10:38 . 2011-07-06 10:38 -------- d-----w- C:\VritualRoot
2011-07-05 17:11 . 2003-04-14 07:10 208896 ----a-w- c:\program files (x86)\Mozilla Firefox\Restoration.exe
2011-07-05 17:11 . 2002-03-31 17:35 6144 ----a-w- c:\program files (x86)\Mozilla Firefox\DLL16.DLL
2011-07-05 17:11 . 2002-03-21 22:20 204849 ----a-w- c:\program files (x86)\Mozilla Firefox\DLL32.DLL
2011-07-05 17:07 . 2011-07-05 17:07 -------- d-----w- c:\programdata\Comodo Downloader
2011-07-05 17:01 . 2011-07-05 17:03 -------- d-----w- c:\programdata\Comodo
2011-07-05 17:01 . 2011-07-05 17:01 -------- d-----w- c:\program files\COMODO
2011-07-05 17:01 . 2011-07-05 17:01 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2011-07-05 17:01 . 2011-07-05 17:01 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2011-06-26 09:46 . 2011-06-26 09:46 -------- d-----w- c:\program files (x86)\Google
2011-06-26 09:05 . 2011-06-26 09:06 348160 ----a-w- c:\windows\MSVCR71.DLL
2011-06-26 09:05 . 2011-06-26 09:06 1060864 ----a-w- c:\windows\MFC71.DLL
2011-06-26 09:05 . 2011-06-26 09:11 -------- d-----w- c:\program files (x86)\SIM editor
2011-06-26 08:08 . 2011-06-26 08:08 -------- d-----w- c:\windows\Downloaded Installations
2011-06-26 05:50 . 2011-06-26 05:50 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-06-25 04:38 . 2011-06-16 04:30 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-06-25 04:38 . 2010-01-01 08:00 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-25 04:38 . 2010-01-01 08:00 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-19 08:09 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-19 08:09 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-19 08:09 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-19 08:09 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-19 08:09 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-19 08:09 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-19 08:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-19 08:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-19 08:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-19 08:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-19 08:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-19 08:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-19 08:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-10 16:01 . 2011-06-19 13:07 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-05 17:11 . 2011-05-02 18:36 363560 ----a-w- c:\windows\system32\guard64.dll
2011-07-05 17:11 . 2011-05-07 14:17 92688 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-07-05 17:11 . 2011-05-02 18:36 41712 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-07-05 17:11 . 2011-05-02 18:36 16016 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-07-05 17:11 . 2011-05-02 18:36 285256 ----a-w- c:\windows\SysWow64\guard32.dll
2011-07-05 17:11 . 2011-05-02 18:36 252344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-06-26 09:05 . 2007-01-17 12:47 40960 ----a-w- c:\windows\SimTestDll.dll
2011-05-29 07:11 . 2011-04-10 08:16 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-05-29 07:11 . 2011-04-10 08:16 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-22 22:15 . 2011-05-27 17:11 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 14:13 . 2011-04-13 14:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-04-10 09:51 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-10 09:51 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-04-10 09:01 . 2011-04-10 09:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-10 09:01 . 2011-04-10 09:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-04-10 09:01 . 2011-04-10 09:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-04-10 09:01 . 2011-04-10 09:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-04-10 09:01 . 2011-04-10 09:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-04-10 09:01 . 2011-04-10 09:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-04-10 09:01 . 2011-04-10 09:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-04-10 09:01 . 2011-04-10 09:01 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-04-10 09:01 . 2011-04-10 09:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-04-10 09:01 . 2011-04-10 09:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-04-10 09:01 . 2011-04-10 09:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-04-10 09:01 . 2011-04-10 09:01 222208 ----a-w- c:\windows\system32\msls31.dll
2011-04-10 09:01 . 2011-04-10 09:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-04-10 09:01 . 2011-04-10 09:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-04-10 09:01 . 2011-04-10 09:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-04-10 09:01 . 2011-04-10 09:01 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-04-10 09:01 . 2011-04-10 09:01 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-04-10 09:01 . 2011-04-10 09:01 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-04-10 09:01 . 2011-04-10 09:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-04-10 09:01 . 2011-04-10 09:01 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-04-10 09:01 . 2011-04-10 09:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-04-10 09:01 . 2011-04-10 09:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-10 09:01 . 2011-04-10 09:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-10 09:01 . 2011-04-10 09:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-04-10 09:01 . 2011-04-10 09:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-04-10 09:01 . 2011-04-10 09:01 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-04-10 09:01 . 2011-04-10 09:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-04-10 09:01 . 2011-04-10 09:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-10 09:01 . 2011-04-10 09:01 448512 ----a-w- c:\windows\system32\html.iec
2011-04-10 09:01 . 2011-04-10 09:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-10 09:01 . 2011-04-10 09:01 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-10 09:01 . 2011-04-10 09:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-04-10 09:01 . 2011-04-10 09:01 160256 ----a-w- c:\windows\system32\wextract.exe
2011-04-10 09:01 . 2011-04-10 09:01 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-10 09:01 . 2011-04-10 09:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-10 09:01 . 2011-04-10 09:01 12288 ----a-w- c:\windows\system32\mshta.exe
2011-04-10 09:01 . 2011-04-10 09:01 114176 ----a-w- c:\windows\system32\admparse.dll
2011-04-10 09:01 . 2011-04-10 09:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-09 07:02 . 2011-05-15 08:17 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:58 . 2011-05-22 04:53 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-04-09 06:02 . 2011-05-15 08:17 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-15 08:17 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-22 04:53 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-05-26 213304]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-05-26 184120]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
R1 sensorsview;sensorsview;c:\program files (x86)\SensorsViewPro41\drv\sensorsview32_64.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\DRIVERS\RtsUCcid.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0;ABBYY.Licensing.FineReader.ScreenshotReader.9.0;c:\program files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe [2008-10-27 759072]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-05-26 161080]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4032493769-2605325388-1694172860-1000Core.job
- c:\users\Honza\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-15 19:04]
.
2011-07-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4032493769-2605325388-1694172860-1000UA.job
- c:\users\Honza\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-15 19:04]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-10-05 11474024]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-07-05 9048392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: Interfaces\{1056045E-C017-49CB-AEEC-7815862E1FC5}: NameServer = 10.145.100.25,85.92.54.1
FF - ProfilePath - c:\users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\ubf4o3e4.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q=
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-06 16:35:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-06 14:35
.
Před spuštěním: Volných bajtů: 135 726 714 880
Po spuštění: Volných bajtů: 135 459 725 312
.
- - End Of File - - 1F7DF93DE94D2ED81E2E2FF8CFA44367

Re: Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 16:26
od Rudy
Log vypoadá čistý. Patrně se jedná o falešnou detekci.

Re: Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 16:32
od honzikuh
Tak to jsem rád, moc děkuji. Můžete mi prosím doporučit sestavu pro Win 7 antivirus, Firewall ??

Re: Antivir našel Trojany prosím o kontrolu

Napsal: 06 črc 2011 17:39
od Rudy
Pokud chcete free, mohu doporučit AV Avira: http://www.avira.com/en/avira-free-antivirus a firewall Comodo: http://www.comodo.com/ , nebo Zone Alarm: http://www.zonealarm.com/security/en-us ... rewall.htm . jako placený bych doporučil komplexní balík buď KIS: http://www.kaspersky.cz/produkty/domaci ... -security/ , nebo NIS: http://www.slunecnice.cz/sw/norton-internet-security/ .