Stránka 1 z 3

pravděpodobně WIN32 brání spuštění antiviru a blokuje web

Napsal: 17 črc 2011 18:34
od Huhu111
Nevíte někdo prosím jak odstranit win32/agent.cb? našel jsem ho AVG, ale pak se mi už nepodařilo AVG spustit (hláška nemáte přístupová práva). podobně se zablokují za několik sekund i ostatní antivirové programy a různé odstraňovače nežádoucího softwaru. Ještě to původně zřejmě přenastavilo firewall a blokuje to část internetových stránek (a posílá vyskakovací okna s reklamou).

díky

M:

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 18:37
od vyosek
Zdravim, pekny den preji a vitam Vas u nas na foru :welcome:

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com :arrow: Aplikujte exeHelper by Raktor :arrow: RKill i eXeHelper by mely udelat logy, vlozte mi je sem

:arrow: Dejte log z RSIT - viz muj podpis

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 18:49
od Huhu111
Děkuji. Tady to je:


RKill se nepodařilo instalovat (aspoň to napsalo takovou hlášku), podruhé už nešel spustit.

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 17.07.2011 at 19:43:23.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

\\.\globalroot\Device\svchost.exe\svchost.exe


Rkill completed on 17.07.2011 at 19:43:23.


Rkill completed on 17.07.2011 at 19:43:30.


exeHelper:

Ok Loading BitDefender Engines
State 0
Sleeping 3 seconds...
Ok Loading BitDefender Engines
State 0
Sleeping 3 seconds...
Found so far : 0x0 files/regs
Searching for Downadup file ....
- System folder
Found so far : 0x0 files/regs
Searching for Downadup file ....
- System folder
- Temporary folder
- Program Files
- Application Data
Found so far : 0x0 files/regs
No Traces of Downadup Worm were found

A tady je log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2011-07-17 19:26:20
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 59 GB (39%) free of 153 GB
Total RAM: 2046 MB (54% free)


======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-814357175-3262550480-3581846099-500.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-814357175-3262550480-3581846099-500.job
C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\WINDOWS\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\tch9cdwa.default

prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:1.1, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2, engine@conduit.com:3.2.3.3, {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.2.3.3, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18"
prefs.js - "keyword.URL" - "http://search.avg.com/route/?d=4b2016a8 ... &lng=cs&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files\real\realplayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647]
"Description"=12.0.1.647
"Path"=c:\program files\real\realplayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll

C:\Program Files\Mozilla Firefox\searchplugins\
avg_igeared.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\tch9cdwa.default\extensions\
engine@conduit.com
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{20a82645-c095-46ed-80e3-08825760534b}
{88c7f2aa-f93f-432c-8f0e-b7d85967a527}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-07-05 386264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngin0.dll [2011-01-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\tbBit1.dll [2011-01-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-30 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-06-30 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\tbBit1.dll [2011-01-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngin0.dll [2011-01-09 3911776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SetRefresh"=C:\Program Files\Compaq\SetRefresh\SetRefresh.exe [2003-11-20 525824]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-09-29 1783808]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-21 61440]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2006-07-11 69632]
"WinFast Schedule"=C:\Program Files\WinFast\WFTVFM\WFWIZ.exe [2006-07-07 348160]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"602PC SUITE PDF Saver"=C:\Program Files\Common Files\soft602\pdfSaver.exe [2005-08-31 49152]
"TkBellExe"=C:\program files\real\realplayer\update\realsched.exe [2011-07-05 273544]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=cmd.exe /c start http://www.avg.cz/cz.special-uninstalla ... er=9.0.894 []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-04-06 26102056]
"BitTorrent"=C:\Program Files\BitTorrent\BitTorrent.exe [2011-04-30 400760]
"SoftAuto.exe"=C:\Program Files\Creative\Software Update 3\SoftAuto.exe [2008-08-13 405504]
"pdfSaver3"=c:\Program Files\PDF\pdfSaver\pdfSaver3.exe [2004-05-19 385024]
"8DDYX0ZBPZ"=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Awr.exe [2011-07-16 241152]
"ASUS SmartDoctor"=C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe /start []
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
BDARemote.lnk - C:\Program Files\USB TV\EM28XX\BDARemote.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
WDSmartWare.lnk - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-07-21 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\DC++\DCPlusPlus.exe"="C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\SAS\SAS Learning Edition 4.1\sas.exe"="C:\Program Files\SAS\SAS Learning Edition 4.1\sas.exe:*:Enabled:SAS 9.1 for Windows"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\BitTorrent\BitTorrent.exe"="C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent"
"C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\SweetImSetup.exe"="C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\SweetImSetup.exe:*:Enabled:SweetIM Installer"
"C:\Documents and Settings\Administrator\Local Settings\Temp\SweetIMReinstall\SweetImSetup.exe"="C:\Documents and Settings\Administrator\Local Settings\Temp\SweetIMReinstall\SweetImSetup.exe:*:Enabled:SweetIM Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"J:\wow\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="J:\wow\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Real\RealUpgrade\realupgrade.exe"="C:\Program Files\Real\RealUpgrade\realupgrade.exe:*:Disabled:RealUpgrade Launcher"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Windows Doctor\WindowsDoctor.exe"="C:\Program Files\Windows Doctor\WindowsDoctor.exe:*:Enabled:Windows Doctor"
"C:\Documents and Settings\Administrator\Local Settings\Temp\Awr.exe"="C:\Documents and Settings\Administrator\Local Settings\Temp\Awr.exe:*:Enabled:Microjy setup "
"C:\Program Files\Mozilla Firefox\plugin-container.exe"="C:\Program Files\Mozilla Firefox\plugin-container.exe:*:Enabled:Plugin Container for Firefox"
"C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe"="C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe:*:Enabled:WD SmartWare"
"C:\WINDOWS\Axusaa.exe"="C:\WINDOWS\Axusaa.exe:*:Enabled:wMicroN setup H"
"C:\Program Files\Google\Update\GoogleUpdate.exe"="C:\Program Files\Google\Update\GoogleUpdate.exe:*:Enabled:Instalační program Google"
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"="C:\Program Files\Common Files\Java\Java Update\jusched.exe:*:Enabled:Java(TM) Update Scheduler"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.asv2"=asusasv2.dll
"MSVideo8"=VfWWDM32.dll
"vidc.ffds"=ffdshow.ax
"msacm.ac3filter"=ac3filter.acm
"VIDC.ACDV"=ACDV.dll
"wave2"=wdmaud.drv
"vidc.tscc"=tsccvid.dll

======List of files/folders created in the last 1 month======

2011-07-17 19:26:20 ----D---- C:\rsit
2011-07-17 19:26:20 ----D---- C:\Program Files\trend micro
2011-07-17 19:18:05 ----D---- C:\Program Files\Ultimate Process Manager
2011-07-16 14:24:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2011-07-16 13:59:23 ----D---- C:\Program Files\Best Spyware Scanner
2011-07-16 13:51:23 ----D---- C:\Program Files\ESET
2011-07-16 13:51:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-07-16 12:10:14 ----A---- C:\WINDOWS\Axusaa.exe
2011-07-16 12:09:59 ----A---- C:\WINDOWS\system32\sshnas21.dll
2011-07-16 12:08:16 ----A---- C:\WINDOWS\system32\drivers\1210921679.sys
2011-07-15 19:40:47 ----A---- C:\WINDOWS\system32\javaws.exe
2011-07-15 19:40:47 ----A---- C:\WINDOWS\system32\javaw.exe
2011-07-15 19:40:47 ----A---- C:\WINDOWS\system32\java.exe
2011-07-13 20:22:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-13 20:19:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-07-05 08:43:51 ----D---- C:\Program Files\Common Files\xing shared
2011-07-05 08:43:26 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2011-07-05 08:42:56 ----A---- C:\WINDOWS\system32\pndx5032.dll
2011-07-05 08:42:56 ----A---- C:\WINDOWS\system32\pndx5016.dll
2011-06-29 09:48:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-06-27 08:51:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.TMP
2011-06-25 02:03:59 ----D---- C:\fotky
2011-06-18 03:01:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-06-18 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2503665$
2011-06-18 03:01:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-06-18 03:00:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276$
2011-06-18 03:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893$

======List of files/folders modified in the last 1 month======

2011-07-17 19:26:20 ----RD---- C:\Program Files
2011-07-17 19:22:48 ----D---- C:\Documents and Settings\Administrator\Data aplikací\BitTorrent
2011-07-17 19:18:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Easybits GO
2011-07-17 19:18:37 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-17 19:18:21 ----SD---- C:\WINDOWS\Tasks
2011-07-17 19:11:20 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Adobe
2011-07-17 19:03:32 ----D---- C:\WINDOWS\system32\config
2011-07-17 19:03:14 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-07-17 19:01:47 ----D---- C:\WINDOWS\Temp
2011-07-17 18:59:35 ----D---- C:\WINDOWS\system32\drivers
2011-07-17 18:59:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-07-17 18:36:15 ----ASH---- C:\boot.ini
2011-07-17 18:36:15 ----A---- C:\WINDOWS\win.ini
2011-07-17 18:36:15 ----A---- C:\WINDOWS\system.ini
2011-07-17 18:02:19 ----D---- C:\WINDOWS\system32\CatRoot
2011-07-17 17:56:28 ----D---- C:\WINDOWS\system32\wbem
2011-07-17 17:56:27 ----D---- C:\WINDOWS\Registration
2011-07-17 17:56:14 ----SHD---- C:\WINDOWS\Installer
2011-07-17 17:56:10 ----SHD---- C:\Config.Msi
2011-07-17 17:56:09 ----D---- C:\WINDOWS
2011-07-17 17:48:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\go
2011-07-17 17:45:47 ----HD---- C:\WINDOWS\inf
2011-07-16 14:31:42 ----D---- C:\WINDOWS\system32
2011-07-16 14:24:35 ----D---- C:\Program Files\Common Files
2011-07-16 14:15:03 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PriceGong
2011-07-16 13:42:23 ----D---- C:\Program Files\Spyware Terminator
2011-07-16 13:35:19 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-07-16 13:34:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-07-16 13:27:26 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-07-16 13:22:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\avg9
2011-07-16 13:16:17 ----D---- C:\Program Files\Windows Doctor
2011-07-16 12:39:54 ----RSHD---- C:\WINDOWS\system32\dllcache
2011-07-16 11:37:39 ----D---- C:\Program Files\Fillets
2011-07-16 11:03:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-07-15 23:13:13 ----D---- C:\Program Files\Cyklotrasy
2011-07-15 19:41:17 ----D---- C:\WINDOWS\Prefetch
2011-07-15 19:41:16 ----D---- C:\Program Files\Common Files\Java
2011-07-15 19:40:42 ----D---- C:\Program Files\Java
2011-07-14 23:46:03 ----D---- C:\Program Files\Google
2011-07-13 20:19:54 ----A---- C:\WINDOWS\system32\MRT.exe
2011-07-13 20:19:49 ----A---- C:\WINDOWS\imsins.BAK
2011-07-13 08:47:20 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-11 01:57:39 ----A---- C:\WINDOWS\system32\Dvbpws.dll
2011-07-10 23:56:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\vlc
2011-07-10 20:10:39 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-07-07 20:55:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-07-05 08:44:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2011-07-05 08:44:49 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Real
2011-07-05 08:43:57 ----D---- C:\Program Files\Real
2011-07-05 08:42:55 ----A---- C:\WINDOWS\system32\pncrt.dll
2011-07-05 08:42:41 ----D---- C:\Program Files\Common Files\Real
2011-06-30 18:17:43 ----D---- C:\Documents and Settings\Administrator\Data aplikací\dvdcss
2011-06-28 19:39:03 ----D---- C:\WINDOWS\Microsoft.NET
2011-06-28 19:38:59 ----RSD---- C:\WINDOWS\assembly
2011-06-27 08:51:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-06-27 08:51:05 ----D---- C:\WINDOWS\WinSxS
2011-06-23 19:17:23 ----D---- C:\Program Files\Mozilla Firefox
2011-06-18 03:03:49 ----D---- C:\WINDOWS\system32\cs-cz
2011-06-18 03:03:49 ----D---- C:\Program Files\Internet Explorer

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 18:52
od vyosek
:arrow: Log z RSIT neni kompletni, mohl byste mi jej uploadnout sem prosim http://leteckaposta.cz/

:arrow: Trvate na antiviru AVG :???: U nas nepatri mezi oblibene - vysoka zatez systemu, slabsi detekce. Zvolil bych spise Avast, Aviru ci MSE

:arrow: ESET bych tam nedaval, jelikoz je placeny a cracknout jej snad nepredpokladate :?:

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 18:56
od Huhu111
Log je tady http://leteckaposta.cz/955794664 . diky.

na AVG netrvam, je mi to jedno. zkousel jsem tam pak, po AVG, instalovat ruzne veci, jestli se to rozbehne

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:01
od vyosek
:arrow: vemte avg po hlave removerem http://download.avg.com/filedir/util/su ... 1_1184.exe

:arrow: ESET dejte tez do pryc a dejte tam Avast, ten je free a pro bezneho uzivatele staci

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:05
od Huhu111
Díky. Mám tam ještě Spyware Terminator a nejde mi odstranit. Nevíte prosím, co s tím?

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:09
od vyosek
Zkuste takto http://www.spywareterminator.com/cs/sup ... _instal_st pripadne jej tam nechte a odstranime jej posleze...ten nam zas tolik nevadi. Proc vubec nejde, dava nejakou hlasku :???:

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:17
od Huhu111
Zobrazuje se jen v systray, ale zdá se, že v počítači fakt je.

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:21
od vyosek
Zatim jej tam nechte, odstranime prvotne havet. Takze spustte ComboFix dle navodu jak jsem psal

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 19:52
od Huhu111
Díky. ComboFix se zastavil už docela dlouho na hlášce, že restartuje Windows. A že se ho nemám pokoušet restartovat sám. Ještě se tam otevřelo nějaké prázdné okno s logem skype. Nemám zavřít aspoň to Skype?

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 20:06
od vyosek
Nechte to jeste 10 min, pokud nic, tak PC restartujte natvrdo do nouzoveho rezimu (restart, mackat F8, zvolit Stav nouze s praci v siti) a provedte ComboFix zde

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 20:45
od Huhu111
Odpojilo mi to od internetu, takze jsem pocitacal odpojil natvrdo a pak dokoncil ComboFix. ComboFix mi hlasil, ze ho mam spustit jeste jednou. Ze je tam nejaky virus. Mam to prosim spustit znovu? V normalnim nebo nouzovem rezimu?


ComboFix 11-07-17.03 - Administrator 17.07.2011 20:29:51.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.973 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Best Spyware Scanner
c:\program files\Best Spyware Scanner\bcfile.lst
c:\program files\Best Spyware Scanner\BestSpywareScanner.url
c:\program files\Best Spyware Scanner\hrdb.hrl
c:\program files\Best Spyware Scanner\tmp5
c:\program files\Best Spyware Scanner\twcfile.lst
c:\program files\Best Spyware Scanner\unins000.dat
c:\program files\Best Spyware Scanner\update1
c:\program files\Best Spyware Scanner\update2
c:\program files\Best Spyware Scanner\update3
c:\program files\Best Spyware Scanner\wcfile.lst
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\Axusaa.exe
c:\windows\system32\drivers\1210921679.sys
c:\windows\system32\Dvbpws.dll
c:\windows\system32\sshnas21.dll
.
Nakažená kopie c:\windows\system32\wuauclt.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\wuauclt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Legacy_SSHNAS
-------\Service_1210921679
-------\Service_RkHit
-------\Service_SSHNAS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-17 do 2011-07-17 )))))))))))))))))))))))))))))))
.
.
2011-07-17 17:26 . 2011-07-17 17:26 -------- d-----w- c:\program files\trend micro
2011-07-17 17:26 . 2011-07-17 17:26 -------- d-----w- C:\rsit
2011-07-17 17:18 . 2011-07-17 17:21 -------- d-----w- c:\program files\Ultimate Process Manager
2011-07-17 15:56 . 2011-07-17 15:56 -------- d-----w- c:\windows\system32\wbem\Repository
2011-07-16 12:24 . 2011-07-17 15:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MicroWorld
2011-07-16 11:51 . 2011-07-16 11:51 -------- d-----w- c:\program files\ESET
2011-07-16 11:51 . 2011-07-16 11:51 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-07-05 06:44 . 2011-07-05 06:44 11776 ----a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-07-05 06:43 . 2011-07-05 06:43 -------- d-----w- c:\program files\Common Files\xing shared
2011-07-05 06:43 . 2011-07-05 06:43 150712 ----a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-07-05 06:43 . 2011-07-05 06:43 105472 ----a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2011-06-27 06:51 . 2011-06-27 06:51 4778 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-06-25 00:03 . 2011-06-26 16:55 -------- d-----w- C:\fotky
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 11:35 . 2004-08-17 22:44 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-04 02:52 . 2010-05-03 05:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2008-05-16 10:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:32 . 2004-08-17 22:49 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-17 22:49 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-04 06:15 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2004-08-17 22:49 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-26 11:07 . 2004-08-17 22:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-25 15:45 . 2004-08-17 22:49 832512 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 15:45 . 2004-08-17 22:49 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 15:45 . 2004-08-17 22:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-04-25 15:45 . 2004-08-17 22:49 17408 ----a-w- c:\windows\system32\corpol.dll
2011-04-25 12:01 . 2004-08-17 22:44 389120 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-04 06:15 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2011-01-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-09 00:05 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngin0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-01-09 00:05 3911776 ----a-w- c:\program files\BitTorrentBar\tbBit1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2011-01-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2011-01-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2011-01-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2011-04-30 400760]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"pdfSaver3"="c:\program files\PDF\pdfSaver\pdfSaver3.exe" [2004-05-19 385024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-09-28 1783808]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2006-07-11 69632]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2006-07-07 348160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"602PC SUITE PDF Saver"="c:\program files\Common Files\soft602\pdfSaver.exe" [2005-08-31 49152]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-07-05 273544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.cz/cz.special-uninstalla ... er=9.0.894" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-3 113664]
BDARemote.lnk - c:\program files\USB TV\EM28XX\BDARemote.exe [2009-9-30 81997]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\SAS\\SAS Learning Edition 4.1\\sas.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"j:\\wow\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
"c:\\Program Files\\Real\\RealUpgrade\\realupgrade.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Western Digital\\WD SmartWare\\Front Parlor\\WDSmartWare.exe"=
"c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5452:TCP"= 5452:TCP:vjgquyyq
.
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [29.9.2009 1:39 141312]
R1 wfcxacap;WinFast TV PCI Audio Capture Driver;c:\windows\system32\drivers\wfcxacap.sys [31.12.2009 21:15 9856]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [16.5.2008 12:19 540184]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13.11.2009 11:28 114688]
R2 wfcxatun;WinFast TV Analog Tuner Driver;c:\windows\system32\drivers\wfcxatun.sys [31.12.2009 21:15 31616]
R2 WFCXVCAP;WinFast TV Video Capture Driver;c:\windows\system32\drivers\wfcxvcap.sys [31.12.2009 21:15 167296]
R3 wfcxdtun;WinFast DTV BDA Tuner/Demod Driver;c:\windows\system32\drivers\wfcxdtun.sys [31.12.2009 21:15 21248]
R3 wfcxtcap;WinFast DTV BDA Transport Stream Capture Driver;c:\windows\system32\drivers\wfcxtcap.sys [31.12.2009 21:15 15872]
R3 wfcxxbar;WinFast TV Crossbar Driver;c:\windows\system32\drivers\wfcxxbar.sys [31.12.2009 21:15 10368]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [31.12.2009 21:30 9446]
S2 gupdate1ca427c2919aa6a;Služba Google Update (gupdate1ca427c2919aa6a);c:\program files\Google\Update\GoogleUpdate.exe [1.10.2009 11:47 133104]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16.6.2009 8:58 20480]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21.5.2008 13:42 64000]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1.10.2009 11:47 133104]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [24.4.2010 21:32 11520]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
sjzlnj
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-01 09:47]
.
2011-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-01 09:47]
.
2011-07-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-814357175-3262550480-3581846099-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 08:47]
.
2011-07-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-814357175-3262550480-3581846099-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 08:47]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=CS_CZ&c=74&bd=smb&pf=desktop
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\tch9cdwa.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b2016a8&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=cs&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Garmin Communicator: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - %profile%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-ASUS SmartDoctor - c:\program files\ASUS\SmartDoctor\SmartDoctor.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-17 21:32
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\windows\$NtUninstallKB1094$:SummaryInformation 0 bytes hidden from API
c:\docume~1\ADMINI~1\LOCALS~1\Temp\etilqs_AdQvKRcytBtU1Ag2vPgg 0 bytes
c:\docume~1\ADMINI~1\LOCALS~1\Temp\etilqs_cMPb84fveCoaLieVJpgR 0 bytes
c:\docume~1\ADMINI~1\LOCALS~1\Temp\etilqs_IdOfzXe6zC5lVMO4TEP4 512 bytes
.
sken byl úspešně dokončen
skryté soubory: 4
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(868)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(924)
c:\windows\system32\mswsock.dll
mswsock.dll 71a30000 262144 \\?\globalroot\systemroot\system32\mswsock.dll
.
- - - - - - - > 'explorer.exe'(3244)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2011-07-17 21:40:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-17 19:40
.
Před spuštěním: Volných bajtů: 65 325 531 136
Po spuštění: Volných bajtů: 67 426 623 488
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 3F1B2F64392DC21526C63E3B4C268747

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 20:50
od Huhu111
Ještě, pořád je tam něco, co přesměrovává z některých stránek (třeba AVASTu) někam jinam.

Re: pravděpodobně WIN32 brání spuštění antiviru a blokuje we

Napsal: 17 črc 2011 21:06
od vyosek
:arrow: Zustante v nouzovem rezimu

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\docume~1\ADMINI~1\LOCALS~1\Temp
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\tch9cdwa.default\
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b2016a8 ... &lng=cs&q=
    FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
    
    DDS::
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    
    NetSvc::
    sjzlnj
    
    Driver::
    sjzlnj
    gupdate1ca427c2919aa6a
    gupdatem
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.jo
    c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-814357175-3262550480-3581846099-500.job
    c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-814357175-3262550480-3581846099-500.job
    C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
    C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    C:\WINDOWS\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5452:TCP"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "AvgUninstallURL"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "602PC SUITE PDF Saver"=-
    "TkBellExe"=-
    "SunJavaUpdateSched"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skype"=-
    "BitTorrent"=-
    "SoftAuto.exe"=-
    "pdfSaver3"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"=-
    [-HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\SweetImSetup.exe"=-
    "C:\Documents and Settings\Administrator\Local Settings\Temp\SweetIMReinstall\SweetImSetup.exe"=-
    "C:\WINDOWS\Axusaa.exe"=-
    
    Rootkit::
    C:\WINDOWS\system32\drivers\1210921679.sys
    
    Folder::
    c:\program files\BitTorrentBar
    c:\documents and settings\All Users\Data aplikací\ESET
    c:\program files\ESET
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci