Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

problem se security tool

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

problem se security tool

#1 Příspěvek od galimatyas »

prosim o pomoc, na pocitaci radi Security Tool a nefunguje vubec nic... RSIT mam stazeny, ale spustit mi nejde :-(

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#2 Příspěvek od galimatyas »

po restatu F8?

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#3 Příspěvek od galimatyas »

jo tak snad... nacita se to... jsem tam...

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#4 Příspěvek od galimatyas »

nabizi mi to obnoveni, pomuze to..?

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#5 Příspěvek od galimatyas »

mam to tam - vypsane, co dal..?

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#6 Příspěvek od galimatyas »

mam tam 2 soubory .info a log..?

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#7 Příspěvek od galimatyas »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Klaudie at 2010-02-12 19:40:05
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (10%) free of 20 GB
Total RAM: 446 MB (50% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-1343024091-725345543-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-1343024091-725345543-1004UA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e}]
C:\Program Files\Starware347\bin\Starware347.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-30 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-30 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1962c5bc-e475-465b-823b-133e711bceb9} - Starware Jokes Toolbar - C:\Program Files\Starware347\bin\Starware347.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-12-11 344064]
"AAWTray"=C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe []
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"Internet Connection Wizard Setup Tool"=C:\Program Files\Internet Explorer\Connection Wizard\icwsetup.exe []
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2009-09-13 1048392]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-12-30 149280]
"HP Software Update"=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
"00112408"=C:\DOCUME~1\ALLUSE~1\DATAAP~1\00112408\00112408.exe [2010-02-12 1053184]
"CTFMON"=C:\WINDOWS\Temp\_ex-08.exe [2010-02-12 411648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2007-12-29 486856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020 []
"ISUSPM"=C:\Documents and Settings\All Users\Data aplikací\Macrovision\FLEXnet Connect\6\ISUSPM.exe [2007-07-12 226904]
"Google Update"=C:\Documents and Settings\Klaudie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-09-18 133104]

C:\Documents and Settings\All Users\Application Data\Microsoft\Shortcuts
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-12 47104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\3DO\Heroes3\HEROES3.EXE"="C:\Program Files\3DO\Heroes3\HEROES3.EXE:*:Enabled:Heroes of Might and Magic® III"
"C:\Program Files\14 Degrees East\Fallout Tactics\BOS.exe"="C:\Program Files\14 Degrees East\Fallout Tactics\BOS.exe:*:Enabled:BOS"
"C:\Program Files\Psygnosis\Rollcage\Direct3D\Rollcage.exe"="C:\Program Files\Psygnosis\Rollcage\Direct3D\Rollcage.exe:*:Enabled:Rollcage Main Game Executable"
"C:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe"="C:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe:*:Enabled:Speed"
"C:\Documents and Settings\Klaudie\Plocha\NFK070\NFK.exe"="C:\Documents and Settings\Klaudie\Plocha\NFK070\NFK.exe:*:Enabled:NFK"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\WINDOWS\Temp\_ex-08.exe"="C:\WINDOWS\Temp\_ex-08.exe:*:Enabled:Promo"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09a54320-2e3a-11de-97bb-bc240aee419f}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0bb7d94e-a846-11de-9a04-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17fc1173-ec27-11de-9a65-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17fc1174-ec27-11de-9a65-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19f4e17e-a84a-11de-9a05-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19f4e183-a84a-11de-9a05-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19f4e185-a84a-11de-9a05-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19f4e187-a84a-11de-9a05-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19f4e188-a84a-11de-9a05-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{379f7551-8e18-11de-99cf-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{379f7554-8e18-11de-99cf-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4392b18e-ff83-11dd-975c-0016363c5c07}]
shell\AutoRun\command - G:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66c5d062-afd0-11dd-96f2-0016363c5c07}]
shell\AutoRun\command - G:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86cc9601-8e0c-11de-99cb-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86cc9604-8e0c-11de-99cb-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e002be8-8e12-11de-99cd-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e002beb-8e12-11de-99cd-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a9dae4e7-2ae0-11dd-95f5-0016363c5c07}]
shell\Auto\command - G:\auto.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cdbce37c-6456-11dd-9664-0016363c5c07}]
shell\AutoRun\command - G:\CAMEL_USB.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ded072be-6610-11de-998e-0016363c5c07}]
shell\AutoRun\command - G:\RECYCLER\lassas.exe
shell\OpEn\command - G:\RECYCLER\lassas.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eca5da44-66e4-11de-998f-0016363c5c07}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2c2e43e-14db-11df-9a85-0016363c5c07}]
shell\AutoRun\command - G:\__DTMEDIA\DTMedia.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2e22a75-c2f7-11de-9a29-0016363c5c07}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2e22a76-c2f7-11de-9a29-0016363c5c07}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f88751d6-afd2-11dd-96f3-0016363c5c07}]
shell\AutoRun\command - G:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f97bd592-a7f9-11de-9a03-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f97bd595-a7f9-11de-9a03-0016363c5c07}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feeec426-d8be-11dc-95a2-0016363c5c07}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
shell\Open(0)\command - Recycled\ctfmon.exe


======List of files/folders created in the last 1 months======

2010-02-12 19:40:15 ----D---- C:\Program Files\trend micro
2010-02-12 19:40:05 ----D---- C:\rsit
2010-02-12 19:34:32 ----A---- C:\WINDOWS\ntbtlog.txt
2010-02-12 18:10:08 ----D---- C:\Program Files\WinPcap
2010-02-12 18:07:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\00112408
2010-02-10 10:39:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 10:38:45 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 10:35:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 10:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 10:35:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 10:35:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 10:35:10 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 10:33:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 10:33:38 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-10 10:28:39 ----D---- C:\Documents and Settings\Klaudie\Data aplikací\HpUpdate
2010-02-10 10:28:36 ----D---- C:\WINDOWS\Hewlett-Packard
2010-01-22 22:06:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\WEBREG
2010-01-22 22:05:32 ----D---- C:\Documents and Settings\Klaudie\Data aplikací\HP
2010-01-22 22:02:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2010-01-22 22:01:26 ----D---- C:\Program Files\Common Files\HP
2010-01-22 22:00:56 ----D---- C:\Program Files\Hewlett-Packard
2010-01-22 22:00:25 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-01-22 21:58:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2010-01-22 21:57:58 ----RA---- C:\WINDOWS\system32\hpzids01.dll
2010-01-22 21:57:52 ----A---- C:\WINDOWS\system32\hpz3l4v2.dll
2010-01-22 21:56:38 ----RA---- C:\WINDOWS\system32\hppldcoi.dll
2010-01-22 21:56:38 ----RA---- C:\WINDOWS\system32\hpovst11.dll
2010-01-22 21:56:38 ----RA---- C:\WINDOWS\system32\hpotiop4.dll
2010-01-22 21:56:38 ----RA---- C:\WINDOWS\system32\difxapi.dll
2010-01-22 21:56:37 ----RA---- C:\WINDOWS\system32\hpowiax4.dll
2010-01-22 21:51:09 ----D---- C:\Program Files\HP
2010-01-22 21:50:30 ----HD---- C:\Config.Msi
2010-01-13 22:33:14 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-13 22:32:15 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-13 10:56:30 ----D---- C:\Program Files\Common Files\PCSuite
2010-01-13 10:55:04 ----D---- C:\Program Files\Common Files\Nokia
2010-01-13 10:51:10 ----D---- C:\Program Files\PC Connectivity Solution
2010-01-13 10:49:46 ----A---- C:\WINDOWS\system32\wdfcoinstaller01007.dll
2010-01-13 10:49:46 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll

======List of files/folders modified in the last 1 months======

2010-02-12 19:40:15 ----D---- C:\Program Files
2010-02-12 19:34:32 ----D---- C:\WINDOWS
2010-02-12 19:32:44 ----A---- C:\WINDOWS\ModemLog_AC97 Data Fax SoftModem with SmartCP.txt
2010-02-12 19:32:42 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-12 19:32:38 ----SD---- C:\WINDOWS\Tasks
2010-02-12 19:28:50 ----D---- C:\WINDOWS\Temp
2010-02-12 19:28:40 ----D---- C:\WINDOWS\system32\ias
2010-02-12 19:28:32 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-12 19:27:25 ----D---- C:\WINDOWS\system32
2010-02-12 19:24:12 ----D---- C:\WINDOWS\Prefetch
2010-02-12 18:19:55 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2010-02-12 18:16:14 ----SHD---- C:\WINDOWS\Installer
2010-02-12 18:10:16 ----D---- C:\WINDOWS\system32\drivers
2010-02-12 17:30:22 ----D---- C:\Program Files\Mozilla Thunderbird
2010-02-10 10:39:47 ----HD---- C:\WINDOWS\inf
2010-02-10 10:39:42 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-10 10:38:51 ----A---- C:\WINDOWS\imsins.BAK
2010-02-10 10:38:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-04 11:24:13 ----D---- C:\Program Files\Mozilla Firefox
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-25 17:58:51 ----D---- C:\Program Files\ICQ6.5
2010-01-22 22:10:10 ----D---- C:\Program Files\Internet Explorer
2010-01-22 22:07:51 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #3.txt
2010-01-22 22:04:47 ----A---- C:\WINDOWS\win.ini
2010-01-22 22:03:31 ----D---- C:\WINDOWS\WinSxS
2010-01-22 22:01:26 ----D---- C:\Program Files\Common Files
2010-01-22 22:01:12 ----D---- C:\WINDOWS\twain_32
2010-01-22 21:52:16 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-01-14 11:12:06 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-01-14 08:32:07 ----D---- C:\WINDOWS\AppPatch
2010-01-13 12:09:20 ----D---- C:\Documents and Settings\Klaudie\Data aplikací\PC Suite
2010-01-13 12:09:07 ----D---- C:\Documents and Settings\Klaudie\Data aplikací\Nokia
2010-01-13 10:55:43 ----D---- C:\Program Files\Nokia
2010-01-13 10:45:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Installations

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
S1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2009-06-18 142832]
S2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
S2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-15 34064]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
S2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-03-02 63232]
S2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-03-02 55936]
S3 afo98mgo;afo98mgo; C:\WINDOWS\system32\drivers\afo98mgo.sys []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-12-12 1414656]
S3 CAMCAUD;Conexant AMC 3D Environmental Audio; C:\WINDOWS\system32\drivers\camc6aud.sys [2007-04-09 38144]
S3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2007-04-09 352000]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-12-06 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-12-06 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-12-06 21568]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-11-29 936960]
S3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-11-29 225792]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-03-28 101120]
S3 LTower;LEGO USB Tower Driver; C:\WINDOWS\System32\Drivers\LTower.sys [2001-04-25 36981]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-10-06 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-10-06 22016]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-10-06 7936]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-10-06 7936]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-11-29 669696]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-07-02 17904]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-12-12 393216]
S2 gupdate1ca3a3067b7956a;Služba Google Update (gupdate1ca3a3067b7956a); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-20 133104]
S2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-30 153376]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#8 Příspěvek od galimatyas »

warning:
CD-emulation drivers are running on this machine. ComboFix needs to temporarily disable them

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#9 Příspěvek od galimatyas »

dal jsem "OK" a restartoval se comp...

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#10 Příspěvek od galimatyas »

ted to po me chce stahnout KONZOLU, ale ja nejsem pripojen k netu a nevim, jestli mi ted podari se pripojit - mam mobilni propojeni...?

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#11 Příspěvek od galimatyas »

preskocil, skenuju...

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#12 Příspěvek od galimatyas »

ComboFix 10-02-11.04 - Klaudie 12.02.2010 20:21:26.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.446.64 [GMT 1:00]
Spuštěný z: E:\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Data aplikací\00112408
c:\documents and settings\All Users\Data aplikací\00112408\00112408.exe
c:\documents and settings\Klaudie\Plocha\Security Tool.lnk
c:\program files\ICQ6.5\ICQLRun.exe
c:\program files\temp
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\recycler\S-1-5-21-4759255605-3587331678-271007240-3368
c:\recycler\S-1-5-21-7181290315-4182501369-353899132-4039
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_npf


((((((((((((((((((((((((( Soubory vytvořené od 2010-01-12 do 2010-02-12 )))))))))))))))))))))))))))))))
.

2010-02-12 18:40 . 2010-02-12 18:40 -------- d-----w- c:\program files\trend micro
2010-02-12 18:40 . 2010-02-12 18:40 -------- d-----w- C:\rsit
2010-02-10 09:28 . 2010-02-10 09:28 -------- d-----w- c:\windows\Hewlett-Packard
2010-01-22 21:01 . 2010-01-22 21:01 -------- d-----w- c:\program files\Common Files\HP
2010-01-22 21:00 . 2010-01-22 21:00 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-22 21:00 . 2010-01-22 21:00 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-01-22 20:58 . 2006-12-06 06:02 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-01-22 20:58 . 2006-12-06 06:02 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-01-22 20:57 . 2006-12-15 16:36 258048 ----a-r- c:\windows\system32\hpzids01.dll
2010-01-22 20:57 . 2006-12-29 08:57 273920 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp4v2.dll
2010-01-22 20:57 . 2006-12-29 08:57 117760 ----a-w- c:\windows\system32\hpz3l4v2.dll
2010-01-22 20:57 . 2006-12-06 06:02 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-01-22 20:56 . 2006-12-06 06:02 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-01-22 20:56 . 2006-12-06 06:02 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-01-22 20:56 . 2006-12-06 05:50 294912 ----a-r- c:\windows\system32\hpovst11.dll
2010-01-22 20:56 . 2006-12-06 05:50 892928 ----a-r- c:\windows\system32\hpotiop4.dll
2010-01-22 20:56 . 2006-12-06 05:50 675840 ----a-r- c:\windows\system32\hpowiax4.dll
2010-01-22 20:56 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-22 20:56 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-22 20:51 . 2010-02-10 09:28 -------- d-----w- c:\program files\HP
2010-01-22 20:51 . 2008-04-13 18:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-01-22 20:51 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-01-22 20:44 . 2010-01-22 21:06 145538 ----a-w- c:\windows\hpoins13.dat
2010-01-22 20:44 . 2007-01-22 16:05 811 ------w- c:\windows\hpomdl13.dat
1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\program files\temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 19:27 . 2009-08-25 13:24 -------- d-----w- c:\program files\ICQ6.5
2010-02-12 16:30 . 2008-02-15 17:25 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-01-14 10:12 . 2009-10-04 21:33 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 09:56 . 2010-01-13 09:56 -------- d-----w- c:\program files\Common Files\PCSuite
2010-01-13 09:55 . 2010-01-13 09:55 -------- d-----w- c:\program files\Common Files\Nokia
2010-01-13 09:55 . 2009-10-04 18:15 -------- d-----w- c:\program files\Nokia
2010-01-13 09:51 . 2010-01-13 09:51 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 12:26 . 2009-12-30 12:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-30 12:26 . 2007-12-22 11:49 -------- d-----w- c:\program files\Java
2009-12-21 19:08 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 22:45 . 2009-12-18 22:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-17 07:42 . 2007-04-09 17:03 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-16 19:05 . 2009-12-16 19:05 -------- d-----w- c:\program files\MSECache
2009-12-14 07:10 . 2006-03-02 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-12 13:39 . 2006-03-02 12:00 79440 ----a-w- c:\windows\system32\perfc005.dat
2009-12-12 13:39 . 2006-03-02 12:00 432516 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 10:11 . 2006-03-02 12:00 2191360 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11 . 2004-08-17 15:45 2068224 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2006-03-02 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2006-03-02 12:00 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2006-03-02 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2006-03-02 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:09 . 2006-03-02 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 16:03 . 2006-03-02 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-29 486856]
"ISUSPM"="c:\documents and settings\All Users\Data aplikací\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]
"Google Update"="c:\documents and settings\Klaudie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-09-18 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-11 344064]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-30 149280]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]

c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13364:UDP"= 13364:UDP:Print Server Utility
"13107:UDP"= 13107:UDP:Print Server Utility
"69:UDP"= 69:UDP:Print Server Utility
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"53:UDP"= 53:UDP:Promo

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.1.2008 19:46 715248]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [29.11.2005 22:50 225792]
S2 gupdate1ca3a3067b7956a;Služba Google Update (gupdate1ca3a3067b7956a);c:\program files\Google\Update\GoogleUpdate.exe [20.9.2009 21:24 133104]
S3 LTower;LEGO USB Tower Driver;c:\windows\system32\drivers\LTower.sys [20.1.2008 19:47 36981]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'

2010-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 20:24]

2010-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 20:24]

2010-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-02 15:36]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/skinit/icq/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {3C772FCC-4252-4376-A966-589A92CFBFB4} = 194.228.2.1,212.83.68.130
FF - ProfilePath - c:\documents and settings\Klaudie\Data aplikací\Mozilla\Firefox\Profiles\lpgnnmdg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\Klaudie\Data aplikací\Mozilla\Firefox\Profiles\lpgnnmdg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} - c:\program files\Starware347\bin\Starware347.dll
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKLM-Run-AAWTray - c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Internet Connection Wizard Setup Tool - c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe
AddRemove-Icy Tower_is1 - c:\games\icytower1.3\unins000.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9c.exe
AddRemove-Totalcmd - c:\totalcmd\tcuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-12 20:33
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys spyo.sys hal.dll >>UNKNOWN [0x84F94944]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf778ff28
\Driver\ACPI -> ACPI.sys @ 0xf75eccb8
\Driver\atapi -> atapi.sys @ 0xf7589b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7480bd4
PacketIndicateHandler -> NDIS.sys @ 0xf746ea0d
SendHandler -> NDIS.sys @ 0xf7482b40
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-02-12 20:40:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-12 19:40

Před spuštěním: 1 922 093 056
Po spuštění: 2 125 295 616

- - End Of File - - 1E08AE32FBB686DE6EA9726103554A0C

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#13 Příspěvek od galimatyas »

aaa... sorry :-(

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#14 Příspěvek od galimatyas »

tyhle vete nerozumim:

Rozbal tak Aby Region spousteci soubr v Zadne složce

???

galimatyas
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 12 úno 2010 18:46

Re: problem se security tool

#15 Příspěvek od galimatyas »

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-12 21:06:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Klaudie\LOCALS~1\Temp\kxrdqpog.sys


---- System - GMER 1.0.15 ----

SSDT spsf.sys ZwEnumerateKey [0xF760ECA2]
SSDT spsf.sys ZwEnumerateValueKey [0xF760F030]

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 84F8A1F8
Device \FileSystem\Fastfat \Fat 842171F8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Odpovědět