PC nekomunikuje v síti, web nelze prohlížet, ...
Napsal: 31 črc 2011 08:03
Dobrý den,
mám tu počítač kolegy a už druhý den se snažím jej odvirovat. S počítačem nelze nic prohlížet na webu(po zadání adresy IE dlouho načítá stránku a pak ji stejně nezobrazí), nelze stahovat aktualizace(žádného programu, ani Avast), Skype se pravidelně odpojujuje a zase připojuje, cyklicky probíhá jakási aktivita na síti(dle poblikávajích počítačů v pravo dole), k počítači do sdílené složky se nelze připojit.
Včera jsem provedl důkladnou kontrolu Avastem. Nalezen Win32:DELF-RT v souboru pxwma.dll(odstraněn). Stav nezměněn. PC nekomunikuje.
Pokoušel jsem se také o vše, co je popsáno v tomto vlákně http://www.viry.cz/forum/viewtopic.php?f=13&t=112191, opět bezvýsledně.
Combofix po spuštění se chová takto:
Naskočí hláška systému:
"system windows nemuze najit polozku NIRKMD" po odkliknuti napise:
nelze vytisknout smerovaci tabulku:system nemuze nalezt uvedeny soubor"
po chvilce vyhodi windows dalsi hlasku:
:"system windows nemuze najit polozku NIRKMD" a po odkliknuti hodi combofix jeste tyhle hlasky:
"NIRCMDC neni nazvem vnitrniho ani venkovniho prikazu..."
" MTEEneni nazvem vnitrniho ani venkovniho prikazu..."
a pak uz jenom blika kurzor a nic se nedeje
Aplikoval jsem RKIL, MBR, GMER, OTL(se skriptem ve výše uvedeném vlákně), TDsskiller,..
ale stále bezúspěšně.
Dnes CCleaner(i registry).
Prosím pomozte.
Níže jsou logy RSKIT(log.txt, info.txt):
Logfile of random's system information tool 1.09 (written by random/random)
Run by Velký Vezír at 2011-07-31 08:38:38
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (33%) free of 39 GB
Total RAM: 383 MB (44% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\zálohaD.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2011-07-04 3493720]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-06-15 15141768]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\HP_CP1510_Default_Install_4.0\setup\hppniprint01.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppniprint01.exe:*:Enabled:hppniprint01.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hppniprint64.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppniprint64.exe:*:Enabled:hppniprint64.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hppnicifs01.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppnicifs01.exe:*:Enabled:hppnicifs01.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hpbtpg.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hpbtpg.exe:*:Enabled:hpbtpg.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\LaunchApp.exe"="C:\HP_CP1510_Default_Install_4.0\setup\LaunchApp.exe:*:Enabled:launchapp.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.DIVX"=divx.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
======List of files/folders created in the last 1 month======
2011-07-31 08:38:40 ----D---- C:\Program Files\trend micro
2011-07-31 08:38:38 ----D---- C:\rsit
2011-07-31 08:32:12 ----D---- C:\Program Files\CCleaner
2011-07-31 00:16:21 ----ASH---- C:\hiberfil.sys
2011-07-31 00:12:26 ----A---- C:\TDSSKiller.2.5.13.0_31.07.2011_00.12.26_log.txt
2011-07-31 00:10:56 ----SD---- C:\ComboFix
2011-07-31 00:08:55 ----D---- C:\WINDOWS\Minidump
2011-07-30 22:35:15 ----SHD---- C:\WINDOWS\CSC
2011-07-30 22:32:12 ----RA---- C:\ComboFix.exe
2011-07-30 22:29:03 ----A---- C:\WINDOWS\PEV.exe
2011-07-30 22:29:03 ----A---- C:\WINDOWS\MBR.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\zip.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWSC.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWREG.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\sed.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\NIRCMD.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\grep.exe
2011-07-30 21:44:03 ----D---- C:\WINDOWS\ERDNT
2011-07-30 21:44:00 ----A---- C:\WINDOWS\system32\CF7086.exe
2011-07-30 21:43:54 ----D---- C:\Qoobox
2011-07-21 17:00:32 ----RD---- C:\Program Files\Skype
2011-07-21 16:45:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-07-21 16:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-07-21 16:44:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-07-21 16:44:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-07-21 16:43:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-07-21 16:43:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-07-21 16:43:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-07-21 16:43:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-07-21 16:42:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-07-21 16:42:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-07-21 16:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-07-21 16:41:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-07-21 16:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2530548$
2011-07-21 16:40:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-21 16:40:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2011-07-21 16:40:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-07-21 16:39:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2503665$
2011-07-21 16:39:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-07-21 16:39:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-07-21 16:38:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2011-07-21 16:38:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2011-07-21 16:34:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-07-21 16:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-07-21 16:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-07-21 16:33:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-07-21 16:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276$
2011-07-21 16:33:21 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-07-21 16:33:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-07-21 16:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-07-21 16:32:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-07-21 16:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-07-21 16:31:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-07-21 16:31:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893$
2011-07-21 16:31:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-07-21 16:30:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-07-21 16:30:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2011-07-21 16:30:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-07-21 16:29:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-07-21 16:29:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-07-21 16:29:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-07-21 16:28:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
======List of files/folders modified in the last 1 month======
2011-07-31 08:38:40 ----RD---- C:\Program Files
2011-07-31 08:37:19 ----D---- C:\WINDOWS\Temp
2011-07-31 08:36:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-07-31 08:36:49 ----D---- C:\WINDOWS\SoftwareDistribution
2011-07-31 08:36:49 ----D---- C:\WINDOWS\Debug
2011-07-31 08:36:49 ----D---- C:\WINDOWS
2011-07-31 08:36:49 ----D---- C:\Documents and Settings\Velký Vezír\Data aplikací\Skype
2011-07-31 08:35:41 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-31 08:30:55 ----A---- C:\WINDOWS\wincmd.ini
2011-07-31 00:33:35 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-07-31 00:12:27 ----D---- C:\WINDOWS\system32\drivers
2011-07-30 23:44:18 ----D---- C:\WINDOWS\Prefetch
2011-07-30 23:43:06 ----SHD---- C:\System Volume Information
2011-07-30 23:35:52 ----HD---- C:\WINDOWS\inf
2011-07-30 22:37:32 ----SHD---- C:\RECYCLER
2011-07-30 22:35:38 ----D---- C:\Documents and Settings
2011-07-30 22:33:23 ----D---- C:\WINDOWS\system32
2011-07-30 22:33:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-07-21 17:03:04 ----SHD---- C:\WINDOWS\Installer
2011-07-21 17:03:04 ----HD---- C:\Config.Msi
2011-07-21 17:00:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-07-21 17:00:11 ----D---- C:\Program Files\Common Files
2011-07-21 16:52:18 ----D---- C:\Documents and Settings\Velký Vezír\Data aplikací\skypePM
2011-07-21 16:45:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-21 16:45:08 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-21 16:43:50 ----D---- C:\WINDOWS\WinSxS
2011-07-21 16:29:04 ----D---- C:\Program Files\Outlook Express
2011-07-04 14:43:51 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-07-01 09:54:42 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-07-04 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-07-04 43608]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-07-04 102616]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-06-15 611664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-07-04 42184]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
mám tu počítač kolegy a už druhý den se snažím jej odvirovat. S počítačem nelze nic prohlížet na webu(po zadání adresy IE dlouho načítá stránku a pak ji stejně nezobrazí), nelze stahovat aktualizace(žádného programu, ani Avast), Skype se pravidelně odpojujuje a zase připojuje, cyklicky probíhá jakási aktivita na síti(dle poblikávajích počítačů v pravo dole), k počítači do sdílené složky se nelze připojit.
Včera jsem provedl důkladnou kontrolu Avastem. Nalezen Win32:DELF-RT v souboru pxwma.dll(odstraněn). Stav nezměněn. PC nekomunikuje.
Pokoušel jsem se také o vše, co je popsáno v tomto vlákně http://www.viry.cz/forum/viewtopic.php?f=13&t=112191, opět bezvýsledně.
Combofix po spuštění se chová takto:
Naskočí hláška systému:
"system windows nemuze najit polozku NIRKMD" po odkliknuti napise:
nelze vytisknout smerovaci tabulku:system nemuze nalezt uvedeny soubor"
po chvilce vyhodi windows dalsi hlasku:
:"system windows nemuze najit polozku NIRKMD" a po odkliknuti hodi combofix jeste tyhle hlasky:
"NIRCMDC neni nazvem vnitrniho ani venkovniho prikazu..."
" MTEEneni nazvem vnitrniho ani venkovniho prikazu..."
a pak uz jenom blika kurzor a nic se nedeje
Aplikoval jsem RKIL, MBR, GMER, OTL(se skriptem ve výše uvedeném vlákně), TDsskiller,..
ale stále bezúspěšně.
Dnes CCleaner(i registry).
Prosím pomozte.
Níže jsou logy RSKIT(log.txt, info.txt):
Logfile of random's system information tool 1.09 (written by random/random)
Run by Velký Vezír at 2011-07-31 08:38:38
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (33%) free of 39 GB
Total RAM: 383 MB (44% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\zálohaD.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2011-07-04 3493720]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-06-15 15141768]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\HP_CP1510_Default_Install_4.0\setup\hppniprint01.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppniprint01.exe:*:Enabled:hppniprint01.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hppniprint64.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppniprint64.exe:*:Enabled:hppniprint64.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hppnicifs01.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hppnicifs01.exe:*:Enabled:hppnicifs01.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\hpbtpg.exe"="C:\HP_CP1510_Default_Install_4.0\setup\hpbtpg.exe:*:Enabled:hpbtpg.exe"
"C:\HP_CP1510_Default_Install_4.0\setup\LaunchApp.exe"="C:\HP_CP1510_Default_Install_4.0\setup\LaunchApp.exe:*:Enabled:launchapp.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.DIVX"=divx.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
======List of files/folders created in the last 1 month======
2011-07-31 08:38:40 ----D---- C:\Program Files\trend micro
2011-07-31 08:38:38 ----D---- C:\rsit
2011-07-31 08:32:12 ----D---- C:\Program Files\CCleaner
2011-07-31 00:16:21 ----ASH---- C:\hiberfil.sys
2011-07-31 00:12:26 ----A---- C:\TDSSKiller.2.5.13.0_31.07.2011_00.12.26_log.txt
2011-07-31 00:10:56 ----SD---- C:\ComboFix
2011-07-31 00:08:55 ----D---- C:\WINDOWS\Minidump
2011-07-30 22:35:15 ----SHD---- C:\WINDOWS\CSC
2011-07-30 22:32:12 ----RA---- C:\ComboFix.exe
2011-07-30 22:29:03 ----A---- C:\WINDOWS\PEV.exe
2011-07-30 22:29:03 ----A---- C:\WINDOWS\MBR.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\zip.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWSC.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\SWREG.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\sed.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\NIRCMD.exe
2011-07-30 21:44:26 ----A---- C:\WINDOWS\grep.exe
2011-07-30 21:44:03 ----D---- C:\WINDOWS\ERDNT
2011-07-30 21:44:00 ----A---- C:\WINDOWS\system32\CF7086.exe
2011-07-30 21:43:54 ----D---- C:\Qoobox
2011-07-21 17:00:32 ----RD---- C:\Program Files\Skype
2011-07-21 16:45:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-07-21 16:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-07-21 16:44:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-07-21 16:44:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-07-21 16:43:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-07-21 16:43:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-07-21 16:43:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-07-21 16:43:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-07-21 16:42:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-07-21 16:42:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-07-21 16:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-07-21 16:41:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-07-21 16:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2530548$
2011-07-21 16:40:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-21 16:40:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2011-07-21 16:40:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-07-21 16:39:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2503665$
2011-07-21 16:39:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-07-21 16:39:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-07-21 16:38:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2011-07-21 16:38:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2011-07-21 16:34:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-07-21 16:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-07-21 16:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-07-21 16:33:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-07-21 16:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276$
2011-07-21 16:33:21 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-07-21 16:33:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-07-21 16:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-07-21 16:32:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-07-21 16:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-07-21 16:31:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-07-21 16:31:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893$
2011-07-21 16:31:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-07-21 16:30:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-07-21 16:30:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2011-07-21 16:30:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-07-21 16:29:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-07-21 16:29:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-07-21 16:29:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-07-21 16:28:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
======List of files/folders modified in the last 1 month======
2011-07-31 08:38:40 ----RD---- C:\Program Files
2011-07-31 08:37:19 ----D---- C:\WINDOWS\Temp
2011-07-31 08:36:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-07-31 08:36:49 ----D---- C:\WINDOWS\SoftwareDistribution
2011-07-31 08:36:49 ----D---- C:\WINDOWS\Debug
2011-07-31 08:36:49 ----D---- C:\WINDOWS
2011-07-31 08:36:49 ----D---- C:\Documents and Settings\Velký Vezír\Data aplikací\Skype
2011-07-31 08:35:41 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-31 08:30:55 ----A---- C:\WINDOWS\wincmd.ini
2011-07-31 00:33:35 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-07-31 00:12:27 ----D---- C:\WINDOWS\system32\drivers
2011-07-30 23:44:18 ----D---- C:\WINDOWS\Prefetch
2011-07-30 23:43:06 ----SHD---- C:\System Volume Information
2011-07-30 23:35:52 ----HD---- C:\WINDOWS\inf
2011-07-30 22:37:32 ----SHD---- C:\RECYCLER
2011-07-30 22:35:38 ----D---- C:\Documents and Settings
2011-07-30 22:33:23 ----D---- C:\WINDOWS\system32
2011-07-30 22:33:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-07-21 17:03:04 ----SHD---- C:\WINDOWS\Installer
2011-07-21 17:03:04 ----HD---- C:\Config.Msi
2011-07-21 17:00:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-07-21 17:00:11 ----D---- C:\Program Files\Common Files
2011-07-21 16:52:18 ----D---- C:\Documents and Settings\Velký Vezír\Data aplikací\skypePM
2011-07-21 16:45:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-21 16:45:08 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-21 16:43:50 ----D---- C:\WINDOWS\WinSxS
2011-07-21 16:29:04 ----D---- C:\Program Files\Outlook Express
2011-07-04 14:43:51 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-07-01 09:54:42 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-07-04 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-07-04 43608]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-07-04 102616]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-06-15 611664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-07-04 42184]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------