Facebook vir
Napsal: 26 črc 2011 06:57
Dobrý den prosím o pomoc s PC mé dcery , včera ho lapla :
Logfile of random's system information tool 1.09 (written by random/random)
Run by Katka at 2011-07-26 07:51:03
Microsoft Windows 7 Ultimate
System drive C: has 178 GB (80%) free of 221 GB
Total RAM: 1013 MB (38% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-26 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-06-16 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-06-16 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-06-16 150552]
"IntelWirelessWiMAX"=C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [2010-03-17 1445888]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-06-22 9292392]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"wxpdrv"=C:\Windows\services32.exe [2011-07-25 1185280]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-25 1185280]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1658504.exe"=C:\Users\Katka\AppData\Local\Temp\1658504.exe [2011-07-25 247296]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 256000]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 256000]
"560391.exe"=C:\Windows\Temp\560391.exe [2011-07-25 256000]
"1288310.exe"=C:\Windows\Temp\1288310.exe [2011-07-25 256000]
"8253496.exe"=C:\Windows\Temp\8253496.exe [2011-07-25 495616]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-25 232960]
"84823780-loader2.exe"=C:\Windows\Temp\84823780-loader2.exe [2011-07-25 252928]
"9052930.exe"=C:\Windows\Temp\9052930.exe [2011-07-25 256000]
"3185653.exe"=C:\Users\Katka\AppData\Local\Temp\3185653.exe [2011-07-25 256000]
"6229622.exe"=C:\Users\Katka\AppData\Local\Temp\6229622.exe [2011-07-25 256000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-04-19 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.avis"=ff_acm.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-26 07:51:04 ----D---- C:\Program Files\trend micro
2011-07-26 07:51:03 ----D---- C:\rsit
2011-07-25 23:13:09 ----D---- C:\Windows\ufa
2011-07-25 23:13:09 ----D---- C:\Windows\rpcminer
2011-07-25 23:13:09 ----D---- C:\Windows\phoenix
2011-07-25 23:06:54 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-25 23:04:43 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-25 23:04:10 ----HD---- C:\Windows\update.5.0
2011-07-25 23:02:26 ----A---- C:\Windows\l1rezerv.exe
2011-07-25 23:01:56 ----HD---- C:\Windows\update.2
2011-07-25 22:57:35 ----A---- C:\Windows\unrar.exe
2011-07-25 22:56:40 ----SHD---- C:\Config.Msi
2011-07-25 22:56:25 ----A---- C:\Windows\iplist.txt
2011-07-25 22:54:42 ----A---- C:\Windows\sysdriver32_.exe
2011-07-25 22:54:28 ----A---- C:\Windows\sysdriver32.exe
2011-07-25 22:54:11 ----A---- C:\Windows\front_ip_list.txt
2011-07-25 22:54:06 ----D---- C:\Windows\av_ico
2011-07-25 22:52:49 ----HD---- C:\Windows\update.1
2011-07-25 22:52:47 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-25 22:52:47 ----HD---- C:\Windows\update.tray-7-0
2011-07-25 22:41:09 ----A---- C:\Windows\winlog-ids.txt
2011-07-25 22:41:09 ----A---- C:\Windows\winlog-dirs.txt
2011-07-25 22:41:01 ----A---- C:\Windows\services32.exe
2011-07-13 22:53:57 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 22:53:56 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 22:53:55 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 22:53:54 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 22:53:53 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 22:53:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 22:53:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
Logfile of random's system information tool 1.09 (written by random/random)
Run by Katka at 2011-07-26 07:51:03
Microsoft Windows 7 Ultimate
System drive C: has 178 GB (80%) free of 221 GB
Total RAM: 1013 MB (38% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-26 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-06-16 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-06-16 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-06-16 150552]
"IntelWirelessWiMAX"=C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [2010-03-17 1445888]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-06-22 9292392]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"wxpdrv"=C:\Windows\services32.exe [2011-07-25 1185280]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-25 1185280]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1658504.exe"=C:\Users\Katka\AppData\Local\Temp\1658504.exe [2011-07-25 247296]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 256000]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 256000]
"560391.exe"=C:\Windows\Temp\560391.exe [2011-07-25 256000]
"1288310.exe"=C:\Windows\Temp\1288310.exe [2011-07-25 256000]
"8253496.exe"=C:\Windows\Temp\8253496.exe [2011-07-25 495616]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-25 232960]
"84823780-loader2.exe"=C:\Windows\Temp\84823780-loader2.exe [2011-07-25 252928]
"9052930.exe"=C:\Windows\Temp\9052930.exe [2011-07-25 256000]
"3185653.exe"=C:\Users\Katka\AppData\Local\Temp\3185653.exe [2011-07-25 256000]
"6229622.exe"=C:\Users\Katka\AppData\Local\Temp\6229622.exe [2011-07-25 256000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-04-19 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.avis"=ff_acm.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-26 07:51:04 ----D---- C:\Program Files\trend micro
2011-07-26 07:51:03 ----D---- C:\rsit
2011-07-25 23:13:09 ----D---- C:\Windows\ufa
2011-07-25 23:13:09 ----D---- C:\Windows\rpcminer
2011-07-25 23:13:09 ----D---- C:\Windows\phoenix
2011-07-25 23:06:54 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-25 23:04:43 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-25 23:04:10 ----HD---- C:\Windows\update.5.0
2011-07-25 23:02:26 ----A---- C:\Windows\l1rezerv.exe
2011-07-25 23:01:56 ----HD---- C:\Windows\update.2
2011-07-25 22:57:35 ----A---- C:\Windows\unrar.exe
2011-07-25 22:56:40 ----SHD---- C:\Config.Msi
2011-07-25 22:56:25 ----A---- C:\Windows\iplist.txt
2011-07-25 22:54:42 ----A---- C:\Windows\sysdriver32_.exe
2011-07-25 22:54:28 ----A---- C:\Windows\sysdriver32.exe
2011-07-25 22:54:11 ----A---- C:\Windows\front_ip_list.txt
2011-07-25 22:54:06 ----D---- C:\Windows\av_ico
2011-07-25 22:52:49 ----HD---- C:\Windows\update.1
2011-07-25 22:52:47 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-25 22:52:47 ----HD---- C:\Windows\update.tray-7-0
2011-07-25 22:41:09 ----A---- C:\Windows\winlog-ids.txt
2011-07-25 22:41:09 ----A---- C:\Windows\winlog-dirs.txt
2011-07-25 22:41:01 ----A---- C:\Windows\services32.exe
2011-07-13 22:53:57 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 22:53:56 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 22:53:55 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 22:53:54 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 22:53:53 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 22:53:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 22:53:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 22:53:46 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll