Stránka 1 z 2

obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 18:10
od Jetyx
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jetyxx at 2011-12-04 18:09:45
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 85 GB (45%) free of 191 GB
Total RAM: 1023 MB (51% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-09 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-11-09 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"=C:\WINDOWS\mHotkey.exe [2002-07-23 477184]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-01-20 77824]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-11-17 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-11-17 86016]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-03-08 585728]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-10-13 17351304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\BitTorrent\BitTorrent.exe"="C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Garena Classic\Garena.exe"="C:\Program Files\Garena Classic\Garena.exe:*:Enabled:Garena"
"C:\Program Files\Garena Plus\Room\garena_room.exe"="C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Orcs Must Die!\Build\release\OrcsMustDie.exe"="C:\Program Files\Orcs Must Die!\Build\release\OrcsMustDie.exe:*:Enabled:Orcs Must Die!"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.lhacm"=lhacm.acm

======List of files/folders created in the last 1 month======

2011-12-04 17:33:53 ----RD---- C:\Program Files\Skype
2011-12-04 17:19:57 ----A---- C:\ComboFix.txt
2011-12-04 17:11:57 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\9.exe
2011-12-04 17:11:47 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\6.exe
2011-12-04 17:11:44 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\2.exe
2011-12-02 00:15:13 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\1704.exe
2011-12-02 00:14:52 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\1700.exe
2011-12-02 00:14:45 ----A---- C:\Documents and Settings\Jetyxx\Data aplikací\16FF.exe
2011-12-01 20:53:38 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\TeamViewer
2011-11-29 13:41:57 ----D---- C:\Program Files\NVIDIA Corporation
2011-11-29 13:10:46 ----D---- C:\Program Files\Orcs Must Die!
2011-11-29 09:43:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2011-11-29 08:28:20 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2011-11-29 08:28:20 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2011-11-29 08:28:20 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2011-11-29 08:28:19 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2011-11-29 08:28:19 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2011-11-29 08:28:19 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2011-11-29 08:28:19 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2011-11-29 08:28:19 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2011-11-29 08:28:18 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-11-29 08:28:18 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-11-29 08:28:18 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-11-29 08:28:18 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-11-29 08:22:03 ----D---- C:\Program Files\Robot Entertainment
2011-11-29 00:31:48 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\uTorrent
2011-11-28 21:27:39 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\OnLive App
2011-11-28 21:27:01 ----D---- C:\Program Files\OnLive
2011-11-25 07:00:36 ----RD---- C:\Documents and Settings\Jetyxx\Data aplikací\Brother
2011-11-24 09:32:04 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2011-11-16 07:45:44 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\LolClient
2011-11-16 00:40:12 ----D---- C:\Riot Games
2011-11-10 13:56:14 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\Malwarebytes
2011-11-10 13:56:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-10 13:56:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-10 13:56:03 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-10 13:55:25 ----A---- C:\TDSSKiller.2.5.1.0_10.11.2011_13.55.25_log.txt
2011-11-10 11:50:01 ----A---- C:\Boot.bak
2011-11-10 11:49:58 ----RASHD---- C:\cmdcons
2011-11-10 11:48:14 ----A---- C:\WINDOWS\NIRCMD.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\zip.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\SWSC.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\SWREG.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\sed.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\PEV.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\MBR.exe
2011-11-10 11:38:45 ----A---- C:\WINDOWS\grep.exe
2011-11-10 11:38:35 ----D---- C:\WINDOWS\ERDNT
2011-11-10 11:34:37 ----D---- C:\Qoobox
2011-11-10 11:24:23 ----D---- C:\Program Files\trend micro
2011-11-10 11:24:22 ----D---- C:\rsit
2011-11-09 23:24:19 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\ESET
2011-11-09 23:22:50 ----D---- C:\Program Files\Common Files\Java
2011-11-09 23:22:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2011-11-09 23:22:42 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-09 23:22:42 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-09 23:22:42 ----A---- C:\WINDOWS\system32\java.exe
2011-11-09 23:22:42 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-11-09 23:22:34 ----D---- C:\Program Files\Java
2011-11-09 23:21:54 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\Sun
2011-11-09 23:21:13 ----D---- C:\Program Files\ESET
2011-11-08 19:27:29 ----D---- C:\Program Files\CCleaner
2011-11-07 23:44:13 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2011-11-06 20:30:55 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2011-11-05 18:12:26 ----A---- C:\WINDOWS\system32\drivers\usb8023x.sys
2011-11-05 18:12:26 ----A---- C:\WINDOWS\system32\drivers\rndismpx.sys
2011-11-05 17:39:20 ----A---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2011-11-05 17:39:20 ----A---- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys
2011-11-05 17:39:18 ----D---- C:\Program Files\Spirent Communications
2011-11-05 17:38:52 ----D---- C:\WINDOWS\system32\drivers\umdf
2011-11-05 14:47:42 ----D---- C:\Config.Msi
2011-11-05 13:31:36 ----AH---- C:\WINDOWS\system32\ezsidmv.dat
2011-11-05 13:31:34 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\skypePM
2011-11-05 13:30:37 ----D---- C:\Program Files\Skype(2)

======List of files/folders modified in the last 1 month======

2011-12-04 17:50:55 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\Skype
2011-12-04 17:43:00 ----D---- C:\WINDOWS\system32
2011-12-04 17:43:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-12-04 17:33:54 ----SHD---- C:\WINDOWS\Installer
2011-12-04 17:33:53 ----RD---- C:\Program Files
2011-12-04 17:33:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-12-04 17:30:57 ----D---- C:\WINDOWS\Prefetch
2011-12-04 17:30:12 ----D---- C:\Program Files\Common Files
2011-12-04 17:20:05 ----D---- C:\WINDOWS\Temp
2011-12-04 17:18:43 ----D---- C:\WINDOWS
2011-12-04 17:18:43 ----A---- C:\WINDOWS\system.ini
2011-12-04 17:18:36 ----D---- C:\WINDOWS\system32\drivers\etc
2011-12-04 17:17:06 ----D---- C:\WINDOWS\system32\drivers
2011-12-04 17:17:06 ----D---- C:\WINDOWS\AppPatch
2011-12-04 17:14:19 ----D---- C:\WINDOWS\system32\CatRoot2
2011-12-04 17:13:29 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-12-04 17:09:34 ----D---- C:\WINDOWS\system32\config
2011-12-04 17:09:22 ----D---- C:\WINDOWS\system32\wbem
2011-12-04 17:09:21 ----D---- C:\WINDOWS\Registration
2011-12-03 19:53:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-12-03 00:26:52 ----D---- C:\Program Files\Warcraft III Frozen Throne eSK
2011-12-02 13:44:48 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\BitTorrent
2011-12-01 19:03:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\GarenaMessenger
2011-11-29 11:53:22 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\GarenaPlus
2011-11-29 09:58:24 ----D---- C:\WINDOWS\Logs
2011-11-29 08:28:21 ----D---- C:\WINDOWS\system32\DirectX
2011-11-29 08:28:20 ----HD---- C:\WINDOWS\inf
2011-11-29 08:27:53 ----RSD---- C:\WINDOWS\assembly
2011-11-18 04:13:43 ----SD---- C:\Documents and Settings\Jetyxx\Data aplikací\Microsoft
2011-11-16 00:40:11 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-14 18:41:54 ----D---- C:\Documents and Settings\Jetyxx\Data aplikací\HTC
2011-11-14 18:04:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2011-11-14 17:28:26 ----D---- C:\WINDOWS\SoftwareDistribution
2011-11-14 13:54:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-11-14 07:17:30 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-14 00:49:10 ----D---- C:\WINDOWS\WinSxS
2011-11-14 00:48:45 ----D---- C:\WINDOWS\system32\mui
2011-11-14 00:48:45 ----D---- C:\Program Files\Internet Explorer
2011-11-13 14:07:13 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-11-12 11:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2011-11-12 09:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-11-10 14:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2011-11-10 11:55:30 ----SD---- C:\WINDOWS\Tasks
2011-11-10 11:50:01 ----RASH---- C:\boot.ini
2011-11-05 18:12:33 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-05 17:39:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-11-05 17:39:17 ----D---- C:\Program Files\HTC
2011-11-05 17:39:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-11-05 17:39:06 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-11-05 17:38:52 ----D---- C:\Program Files\Windows Media Player
2011-11-05 17:38:49 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2011-11-05 16:14:58 ----D---- C:\Program Files\Garena Plus
2011-11-05 15:06:14 ----D---- C:\WINDOWS\system32\CatRoot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-18 61056]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-10-10 232512]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-01-28 2310272]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-18 60800]
R3 catchme;catchme; \??\C:\DOCUME~1\Jetyxx\LOCALS~1\Temp\catchme.sys []
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 htcnprot;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-18 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-11-17 3994688]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-05-17 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-05-17 12928]
R3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2004-08-03 12672]
S3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 15295]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys []
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-01-19 503144]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-11-09 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-11-17 159811]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 18:40
od Rudy
Poprosím o log z CobmoFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 20:35
od Jetyx
ComboFix 11-12-04.02 - Jetyxx 04.12.2011 20:26:11.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1023.535 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jetyxx\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-04 do 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 16:33 . 2011-12-04 16:33 -------- d-----r- c:\program files\Skype
2011-12-04 16:11 . 2011-12-04 16:11 352256 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\9.exe
2011-12-04 16:11 . 2011-12-04 16:11 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\6.exe
2011-12-04 16:11 . 2011-12-04 16:11 379077 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\2.exe
2011-12-04 16:09 . 2011-12-04 16:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-01 23:15 . 2011-12-01 23:15 137024 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1704.exe
2011-12-01 23:14 . 2011-12-01 23:14 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1700.exe
2011-12-01 23:14 . 2011-12-01 23:14 388535 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
2011-12-01 19:53 . 2011-12-01 19:53 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\TeamViewer
2011-11-29 12:41 . 2011-11-29 12:41 -------- d-----w- c:\program files\NVIDIA Corporation
2011-11-29 12:10 . 2011-11-29 12:28 -------- d-----w- c:\program files\Orcs Must Die!
2011-11-29 08:43 . 2011-11-29 08:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NVIDIA
2011-11-29 07:30 . 2011-11-29 07:30 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\SKIDROW
2011-11-29 07:28 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-11-29 07:28 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-11-29 07:28 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-11-29 07:28 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-11-29 07:28 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-11-29 07:28 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-11-29 07:22 . 2011-11-29 07:22 -------- d-----w- c:\program files\Robot Entertainment
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\uTorrent
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\uTorrent
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\OnLive App
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\program files\OnLive
2011-11-25 06:00 . 2011-11-25 06:00 -------- d-----r- c:\documents and settings\Jetyxx\Data aplikací\Brother
2011-11-16 12:52 . 2011-12-02 20:02 -------- d-----w- c:\documents and settings\Jetyxx\riotsGamesLogs
2011-11-16 06:45 . 2011-11-16 06:45 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\LolClient
2011-11-15 23:40 . 2011-11-15 23:40 -------- d-----w- C:\Riot Games
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-21 13:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-10 12:56 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- c:\program files\trend micro
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- C:\rsit
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\ESET
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\ESET
2011-11-09 22:23 . 2011-11-09 22:23 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-09 22:22 . 2011-11-09 22:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-09 22:22 . 2011-11-09 22:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Java
2011-11-09 22:21 . 2011-11-10 10:42 -------- d-----w- c:\program files\ESET
2011-11-08 18:27 . 2011-11-08 18:27 -------- d-----w- c:\program files\CCleaner
2011-11-06 19:30 . 2007-11-27 02:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-11-05 17:12 . 2004-08-03 22:04 12672 -c--a-w- c:\windows\system32\dllcache\usb8023x.sys
2011-11-05 17:12 . 2004-08-03 22:04 12672 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2011-11-05 17:12 . 2004-08-03 22:04 30080 -c--a-w- c:\windows\system32\dllcache\rndismpx.sys
2011-11-05 17:12 . 2004-08-03 22:04 30080 ----a-w- c:\windows\system32\drivers\rndismpx.sys
2011-11-05 16:39 . 2011-11-05 16:39 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\Downloaded Installations
2011-11-05 16:39 . 2009-06-09 23:49 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2011-11-05 16:39 . 2009-06-09 13:41 1122664 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-11-05 16:39 . 2011-11-05 16:39 -------- d-----w- c:\program files\Spirent Communications
2011-11-05 16:38 . 2011-11-05 16:38 -------- d-----w- c:\windows\system32\drivers\umdf
2011-11-05 12:31 . 2011-12-04 09:05 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\skypePM
2011-11-04 20:49 . 2011-11-14 17:41 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\HTC
2011-11-04 20:47 . 2011-11-05 16:39 -------- d-----w- c:\program files\HTC
2011-11-04 20:47 . 2011-11-05 16:39 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-11-04 20:46 . 2011-11-04 20:46 -------- d-----w- c:\program files\MSXML 4.0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 19:41 . 2011-10-27 19:41 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-10-11 15:32 . 2011-10-11 15:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 17:23 . 2011-10-10 17:23 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-04_16.18.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-18 12:00 . 2011-12-04 16:14 60376 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 60376 c:\windows\system32\perfc009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 399964 c:\windows\system32\perfh009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 397586 c:\windows\system32\perfh005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 397586 c:\windows\system32\perfh005.dat
+ 2011-12-04 16:33 . 2011-12-04 16:33 371272 c:\windows\Installer\{AA59DDE4-B672-4621-A016-4C248204957A}\SkypeIcon.exe
+ 2011-12-04 16:33 . 2011-12-04 16:33 1527808 c:\windows\Installer\128019.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.

Re: obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 21:18
od Rudy
Log není kompletní.

Re: obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 21:33
od Jetyx
ComboFix 11-12-04.02 - Jetyxx 04.12.2011 20:26:11.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1023.535 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jetyxx\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-04 do 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 16:33 . 2011-12-04 16:33 -------- d-----r- c:\program files\Skype
2011-12-04 16:11 . 2011-12-04 16:11 352256 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\9.exe
2011-12-04 16:11 . 2011-12-04 16:11 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\6.exe
2011-12-04 16:11 . 2011-12-04 16:11 379077 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\2.exe
2011-12-04 16:09 . 2011-12-04 16:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-01 23:15 . 2011-12-01 23:15 137024 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1704.exe
2011-12-01 23:14 . 2011-12-01 23:14 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1700.exe
2011-12-01 23:14 . 2011-12-01 23:14 388535 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
2011-12-01 19:53 . 2011-12-01 19:53 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\TeamViewer
2011-11-29 12:41 . 2011-11-29 12:41 -------- d-----w- c:\program files\NVIDIA Corporation
2011-11-29 12:10 . 2011-11-29 12:28 -------- d-----w- c:\program files\Orcs Must Die!
2011-11-29 08:43 . 2011-11-29 08:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NVIDIA
2011-11-29 07:30 . 2011-11-29 07:30 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\SKIDROW
2011-11-29 07:28 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-11-29 07:28 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-11-29 07:28 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-11-29 07:28 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-11-29 07:28 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-11-29 07:28 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-11-29 07:22 . 2011-11-29 07:22 -------- d-----w- c:\program files\Robot Entertainment
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\uTorrent
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\uTorrent
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\OnLive App
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\program files\OnLive
2011-11-25 06:00 . 2011-11-25 06:00 -------- d-----r- c:\documents and settings\Jetyxx\Data aplikací\Brother
2011-11-16 12:52 . 2011-12-02 20:02 -------- d-----w- c:\documents and settings\Jetyxx\riotsGamesLogs
2011-11-16 06:45 . 2011-11-16 06:45 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\LolClient
2011-11-15 23:40 . 2011-11-15 23:40 -------- d-----w- C:\Riot Games
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-21 13:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-10 12:56 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- c:\program files\trend micro
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- C:\rsit
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\ESET
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\ESET
2011-11-09 22:23 . 2011-11-09 22:23 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-09 22:22 . 2011-11-09 22:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-09 22:22 . 2011-11-09 22:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Java
2011-11-09 22:21 . 2011-11-10 10:42 -------- d-----w- c:\program files\ESET
2011-11-08 18:27 . 2011-11-08 18:27 -------- d-----w- c:\program files\CCleaner
2011-11-06 19:30 . 2007-11-27 02:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-11-05 17:12 . 2004-08-03 22:04 12672 -c--a-w- c:\windows\system32\dllcache\usb8023x.sys
2011-11-05 17:12 . 2004-08-03 22:04 12672 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2011-11-05 17:12 . 2004-08-03 22:04 30080 -c--a-w- c:\windows\system32\dllcache\rndismpx.sys
2011-11-05 17:12 . 2004-08-03 22:04 30080 ----a-w- c:\windows\system32\drivers\rndismpx.sys
2011-11-05 16:39 . 2011-11-05 16:39 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\Downloaded Installations
2011-11-05 16:39 . 2009-06-09 23:49 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2011-11-05 16:39 . 2009-06-09 13:41 1122664 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-11-05 16:39 . 2011-11-05 16:39 -------- d-----w- c:\program files\Spirent Communications
2011-11-05 16:38 . 2011-11-05 16:38 -------- d-----w- c:\windows\system32\drivers\umdf
2011-11-05 12:31 . 2011-12-04 09:05 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\skypePM
2011-11-04 20:49 . 2011-11-14 17:41 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\HTC
2011-11-04 20:47 . 2011-11-05 16:39 -------- d-----w- c:\program files\HTC
2011-11-04 20:47 . 2011-11-05 16:39 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-11-04 20:46 . 2011-11-04 20:46 -------- d-----w- c:\program files\MSXML 4.0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 19:41 . 2011-10-27 19:41 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-10-11 15:32 . 2011-10-11 15:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 17:23 . 2011-10-10 17:23 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-04_16.18.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-18 12:00 . 2011-12-04 16:14 60376 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 60376 c:\windows\system32\perfc009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 399964 c:\windows\system32\perfh009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-04 19:06 397586 c:\windows\system32\perfh005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 397586 c:\windows\system32\perfh005.dat
+ 2011-12-04 16:33 . 2011-12-04 16:33 371272 c:\windows\Installer\{AA59DDE4-B672-4621-A016-4C248204957A}\SkypeIcon.exe
+ 2011-12-04 16:33 . 2011-12-04 16:33 1527808 c:\windows\Installer\128019.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="mHotkey.exe" [2002-07-23 477184]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480]
"nwiz"="nwiz.exe" [2006-11-17 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-03-08 585728]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Garena Classic\\Garena.exe"=
"c:\\Program Files\\Garena Plus\\Room\\garena_room.exe"=
"c:\\Program Files\\Orcs Must Die!\\Build\\release\\OrcsMustDie.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [10.10.2011 18:23 232512]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [16.9.2010 14:06 80896]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [22.6.2010 18:01 21248]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [5.11.2011 17:39 24576]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 20:29
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwEnumerateValueKey, ZwQueryDirectoryFile
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Ipnunc = c:\documents and settings\Jetyxx\Data aplikac?\Ipnunc.exe
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ipnunc"="c:\\Documents and Settings\\Jetyxx\\Data aplikací\\Ipnunc.exe"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(320)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2011-12-04 20:31:11
ComboFix-quarantined-files.txt 2011-12-04 19:31
ComboFix2.txt 2011-12-04 16:19
ComboFix3.txt 2011-11-16 12:09
ComboFix4.txt 2011-11-14 21:10
ComboFix5.txt 2011-12-04 19:25
.
Před spuštěním: Volných bajtů: 89 535 832 064
Po spuštění: Volných bajtů: 89 545 285 632
.
- - End Of File - - FC7E2A6A4ED56992B5BEF9914DB68214


Promin mam jestě problem s monitorem nevim jestli je to vir nebo odešel monitor ale cca po 2s se vypina a když ho opět zapnu a tak zas jde a pak zas vypne tak je to obtižne davat sem log:)

Re: obččasne seknuti myši cca20 s

Napsal: 04 pro 2011 22:26
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\documents and settings\Jetyxx\Data aplikací\9.exe
c:\documents and settings\Jetyxx\Data aplikací\6.exe
c:\documents and settings\Jetyxx\Data aplikací\2.exe
c:\documents and settings\Jetyxx\Data aplikací\1704.exe
c:\documents and settings\Jetyxx\Data aplikací\1700.exe
c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Po akci ještě zkontrolujte online na www.virustotal.com soubor: c:\Documents and Settings\Jetyxx\Data aplikací\Ipnunc.exe .

Re: obččasne seknuti myši cca20 s

Napsal: 05 pro 2011 20:47
od Jetyx
ComboFix 11-12-04.02 - Jetyxx 05.12.2011 20:31:02.10.1 - x86
haMicrosoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1023.699 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jetyxx\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jetyxx\Plocha\CFScript.txt
.
file zipped: c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\1700.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\1704.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\2.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\6.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\9.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Jetyxx\Data aplikací\16.exe
c:\documents and settings\Jetyxx\Data aplikací\4.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-05 do 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-12-04 21:06 . 2011-12-05 13:55 352256 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\5.exe
2011-12-04 21:06 . 2011-12-05 13:55 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\3.exe
2011-12-04 20:59 . 2011-12-04 20:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\nView_Profiles
2011-12-04 16:33 . 2011-12-04 16:33 -------- d-----r- c:\program files\Skype
2011-12-04 16:11 . 2011-12-04 16:11 352256 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\9.exe
2011-12-04 16:11 . 2011-12-04 16:11 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\6.exe
2011-12-04 16:11 . 2011-12-05 13:55 379077 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\2.exe
2011-12-04 16:09 . 2011-12-04 16:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-01 23:15 . 2011-12-01 23:15 137024 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1704.exe
2011-12-01 23:14 . 2011-12-01 23:14 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1700.exe
2011-12-01 23:14 . 2011-12-01 23:14 388535 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
2011-12-01 19:53 . 2011-12-01 19:53 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\TeamViewer
2011-11-29 12:41 . 2011-11-29 12:41 -------- d-----w- c:\program files\NVIDIA Corporation
2011-11-29 12:10 . 2011-11-29 12:28 -------- d-----w- c:\program files\Orcs Must Die!
2011-11-29 08:43 . 2011-11-29 08:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NVIDIA
2011-11-29 07:30 . 2011-11-29 07:30 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\SKIDROW
2011-11-29 07:28 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-11-29 07:28 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-11-29 07:28 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-11-29 07:28 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-11-29 07:28 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-11-29 07:28 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-11-29 07:22 . 2011-11-29 07:22 -------- d-----w- c:\program files\Robot Entertainment
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\uTorrent
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\uTorrent
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\OnLive App
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\program files\OnLive
2011-11-25 06:00 . 2011-11-25 06:00 -------- d-----r- c:\documents and settings\Jetyxx\Data aplikací\Brother
2011-11-16 12:52 . 2011-12-02 20:02 -------- d-----w- c:\documents and settings\Jetyxx\riotsGamesLogs
2011-11-16 06:45 . 2011-11-16 06:45 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\LolClient
2011-11-15 23:40 . 2011-11-15 23:40 -------- d-----w- C:\Riot Games
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-21 13:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-10 12:56 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- c:\program files\trend micro
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- C:\rsit
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\ESET
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\ESET
2011-11-09 22:23 . 2011-11-09 22:23 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-09 22:22 . 2011-11-09 22:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-09 22:22 . 2011-11-09 22:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Java
2011-11-09 22:21 . 2011-11-10 10:42 -------- d-----w- c:\program files\ESET
2011-11-08 18:27 . 2011-11-08 18:27 -------- d-----w- c:\program files\CCleaner
2011-11-07 22:44 . 2011-11-07 22:44 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2011-11-06 19:30 . 2007-11-27 02:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 19:41 . 2011-10-27 19:41 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-10-11 15:32 . 2011-10-11 15:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 17:23 . 2011-10-10 17:23 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-04_16.18.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-05 19:36 . 2011-12-05 19:36 16384 c:\windows\Temp\Perflib_Perfdata_630.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 60376 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2011-12-05 14:01 60376 c:\windows\system32\perfc009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-05 14:01 71282 c:\windows\system32\perfc005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-05 14:01 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-05 14:01 397586 c:\windows\system32\perfh005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 397586 c:\windows\system32\perfh005.dat
+ 2011-12-04 16:33 . 2011-12-04 16:33 371272 c:\windows\Installer\{AA59DDE4-B672-4621-A016-4C248204957A}\SkypeIcon.exe
+ 2011-12-04 16:33 . 2011-12-04 16:33 1527808 c:\windows\Installer\128019.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="mHotkey.exe" [2002-07-23 477184]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480]
"nwiz"="nwiz.exe" [2006-11-17 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-03-08 585728]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Garena Classic\\Garena.exe"=
"c:\\Program Files\\Garena Plus\\Room\\garena_room.exe"=
"c:\\Program Files\\Orcs Must Die!\\Build\\release\\OrcsMustDie.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [10.10.2011 18:23 232512]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [16.9.2010 14:06 80896]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [22.6.2010 18:01 21248]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [5.11.2011 17:39 24576]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-05 20:36
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwEnumerateValueKey, ZwQueryDirectoryFile
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Ipnunc = c:\documents and settings\Jetyxx\Data aplikac?\Ipnunc.exe
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2784)
c:\windows\system32\nview.dll
c:\windows\system32\msi.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\mHotkey.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\HTC\Internet Pass-Through\htcnat.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Celkový čas: 2011-12-05 20:38:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-05 19:38
ComboFix2.txt 2011-12-04 19:31
ComboFix3.txt 2011-12-04 16:19
ComboFix4.txt 2011-11-16 12:09
ComboFix5.txt 2011-12-05 19:30
.
Před spuštěním: Volných bajtů: 89 006 018 560
Po spuštění: Volných bajtů: 88 995 938 304
.
- - End Of File - - 28E08128F01CDA40DBF960B1C39C0D74
Nahr nˇ probŘhlo ŁspŘçnŘ



Ten posledni ukol mi nejde stranka nenalezene je funkčni?

Re: obččasne seknuti myši cca20 s

Napsal: 05 pro 2011 20:53
od Rudy
Ono se to vrací. Zkuste spustit znovu se skriptem:
Collect::
c:\documents and settings\Jetyxx\Data aplikací\9.exe
c:\documents and settings\Jetyxx\Data aplikací\6.exe
c:\documents and settings\Jetyxx\Data aplikací\2.exe
c:\documents and settings\Jetyxx\Data aplikací\1704.exe
c:\documents and settings\Jetyxx\Data aplikací\1700.exe
c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
c:\documents and settings\Jetyxx\Data aplikací\5.exe
c:\documents and settings\Jetyxx\Data aplikací\3.exe
Soubor zkuste testnout na www.virusscan. jotti.org .

Re: obččasne seknuti myši cca20 s

Napsal: 05 pro 2011 21:19
od Jetyx
ComboFix 11-12-04.02 - Jetyxx 05.12.2011 21:04:54.11.1 - x86
haMicrosoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1023.596 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jetyxx\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jetyxx\Plocha\CFScript.txt
.
file zipped: c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\1700.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\1704.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\2.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\3.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\5.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\6.exe
file zipped: c:\documents and settings\Jetyxx\Data aplikací\9.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Jetyxx\Data aplikací\5.exe
c:\documents and settings\Jetyxx\Data aplikací\6.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-05 do 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-12-05 19:40 . 2011-12-05 19:40 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\4.exe
2011-12-04 21:06 . 2011-12-05 19:40 379077 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\3.exe
2011-12-04 20:59 . 2011-12-04 20:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\nView_Profiles
2011-12-04 16:33 . 2011-12-04 16:33 -------- d-----r- c:\program files\Skype
2011-12-04 16:11 . 2011-12-04 16:11 352256 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\9.exe
2011-12-04 16:11 . 2011-12-05 13:55 379077 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\2.exe
2011-12-04 16:09 . 2011-12-04 16:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-01 23:15 . 2011-12-01 23:15 137024 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1704.exe
2011-12-01 23:14 . 2011-12-01 23:14 398081 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\1700.exe
2011-12-01 23:14 . 2011-12-01 23:14 388535 ----a-w- c:\documents and settings\Jetyxx\Data aplikací\16FF.exe
2011-12-01 19:53 . 2011-12-01 19:53 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\TeamViewer
2011-11-29 12:41 . 2011-11-29 12:41 -------- d-----w- c:\program files\NVIDIA Corporation
2011-11-29 12:10 . 2011-11-29 12:28 -------- d-----w- c:\program files\Orcs Must Die!
2011-11-29 08:43 . 2011-11-29 08:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NVIDIA
2011-11-29 07:30 . 2011-11-29 07:30 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\SKIDROW
2011-11-29 07:28 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-11-29 07:28 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-11-29 07:28 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-11-29 07:28 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-11-29 07:28 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-11-29 07:28 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-11-29 07:28 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-11-29 07:28 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-11-29 07:22 . 2011-11-29 07:22 -------- d-----w- c:\program files\Robot Entertainment
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\uTorrent
2011-11-28 23:31 . 2011-11-28 23:31 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\uTorrent
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\OnLive App
2011-11-28 20:27 . 2011-11-28 20:27 -------- d-----w- c:\program files\OnLive
2011-11-25 06:00 . 2011-11-25 06:00 -------- d-----r- c:\documents and settings\Jetyxx\Data aplikací\Brother
2011-11-16 12:52 . 2011-12-02 20:02 -------- d-----w- c:\documents and settings\Jetyxx\riotsGamesLogs
2011-11-16 06:45 . 2011-11-16 06:45 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\LolClient
2011-11-15 23:40 . 2011-11-15 23:40 -------- d-----w- C:\Riot Games
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-10 12:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-10 12:56 . 2011-11-21 13:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-10 12:56 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- c:\program files\trend micro
2011-11-10 10:24 . 2011-11-10 10:24 -------- d-----w- C:\rsit
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Local Settings\Data aplikací\ESET
2011-11-09 22:24 . 2011-11-09 22:24 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\ESET
2011-11-09 22:23 . 2011-11-09 22:23 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-09 22:22 . 2011-11-09 22:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-09 22:22 . 2011-11-09 22:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-09 22:22 . 2011-11-09 22:22 -------- d-----w- c:\program files\Java
2011-11-09 22:21 . 2011-11-10 10:42 -------- d-----w- c:\program files\ESET
2011-11-08 18:27 . 2011-11-08 18:27 -------- d-----w- c:\program files\CCleaner
2011-11-07 22:44 . 2011-11-07 22:44 -------- d-----w- c:\documents and settings\Jetyxx\Data aplikací\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2011-11-06 19:30 . 2007-11-27 02:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 19:41 . 2011-10-27 19:41 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-10-11 15:32 . 2011-10-11 15:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 17:23 . 2011-10-10 17:23 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-04_16.18.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-05 20:10 . 2011-12-05 20:10 16384 c:\windows\Temp\Perflib_Perfdata_20c.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 60376 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2011-12-05 19:40 60376 c:\windows\system32\perfc009.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 71282 c:\windows\system32\perfc005.dat
+ 2004-08-18 12:00 . 2011-12-05 19:40 71282 c:\windows\system32\perfc005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-05 19:40 399964 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2011-12-05 19:40 397586 c:\windows\system32\perfh005.dat
- 2004-08-18 12:00 . 2011-12-04 16:14 397586 c:\windows\system32\perfh005.dat
+ 2011-12-04 16:33 . 2011-12-04 16:33 371272 c:\windows\Installer\{AA59DDE4-B672-4621-A016-4C248204957A}\SkypeIcon.exe
+ 2011-12-04 16:33 . 2011-12-04 16:33 1527808 c:\windows\Installer\128019.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="mHotkey.exe" [2002-07-23 477184]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480]
"nwiz"="nwiz.exe" [2006-11-17 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-03-08 585728]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Garena Classic\\Garena.exe"=
"c:\\Program Files\\Garena Plus\\Room\\garena_room.exe"=
"c:\\Program Files\\Orcs Must Die!\\Build\\release\\OrcsMustDie.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [10.10.2011 18:23 232512]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [16.9.2010 14:06 80896]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [22.6.2010 18:01 21248]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Plus\Room\safedrv.sys --> c:\program files\Garena Plus\Room\safedrv.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [5.11.2011 17:39 24576]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-05 21:10
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwEnumerateValueKey, ZwQueryDirectoryFile
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Ipnunc = c:\documents and settings\Jetyxx\Data aplikac?\Ipnunc.exe
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ipnunc"="c:\\Documents and Settings\\Jetyxx\\Data aplikací\\Ipnunc.exe"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2984)
c:\windows\system32\nview.dll
c:\windows\system32\msi.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\mHotkey.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\HTC\Internet Pass-Through\htcnat.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-05 21:12:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-05 20:12
ComboFix2.txt 2011-12-05 19:40
ComboFix3.txt 2011-12-04 19:31
ComboFix4.txt 2011-12-04 16:19
ComboFix5.txt 2011-12-05 20:04
.
Před spuštěním: Volných bajtů: 88 995 278 848
Po spuštění: Volných bajtů: 88 984 821 760
.
- - End Of File - - EFBFEC0B08CF788D648F248E9903D386
Nahr nˇ probŘhlo ŁspŘçnŘ


Opět posledni ukol kontory na uvedene strance mi nejde stranka nenalezena nevim jestli to děla jen mě nebo nejde

Re: obččasne seknuti myši cca20 s

Napsal: 05 pro 2011 21:40
od Rudy
Stále se ty soubory vrací. Udělejte kompletní sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.

Re: obččasne seknuti myši cca20 s

Napsal: 06 pro 2011 20:13
od Jetyx
tento programa ma udělat log?

Re: obččasne seknuti myši cca20 s

Napsal: 06 pro 2011 20:16
od Rudy
Jetyx píše:tento programa ma udělat log?

Měl by, pokud něco najde.

Re: obččasne seknuti myši cca20 s

Napsal: 06 pro 2011 20:20
od Jetyx
progam mě informoval o nalezu dal jsem smazat a potese pc restartoval

Re: obččasne seknuti myši cca20 s

Napsal: 06 pro 2011 20:34
od Rudy
OK. Nastala nějaká změna?

Re: obččasne seknuti myši cca20 s

Napsal: 06 pro 2011 20:36
od Jetyx
zatim se myš nesekla tak ok ikdyž jedina věc pada mi pořád skype ale to asi nebude tim že?