Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu logu,problem s yourgot.com

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
rastak
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 21 led 2008 21:06

Prosim o kontrolu logu,problem s yourgot.com

#1 Příspěvek od rastak »

Po pripojeni na net mi vybehne okno od antiviru-blokovanie yourgot.com. Prosim o kontrolu logu:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Rasto at 2010-02-14 14:34:38
Microsoft Windows XP Professional Service Pack 3
System drive C: has 59 GB (45%) free of 131 GB
Total RAM: 2047 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:10, on 14. 2. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rasto\Desktop\RSIT.exe
C:\Program Files\trend micro\Rasto.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 5307 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-08 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-08 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-03-01 577536]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2005-03-08 53248]
"VTTrayp"=C:\WINDOWS\system32\VTtrayp.exe [2005-08-03 163840]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-03-19 2029640]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-20 98304]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-05-16 155648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\sdc203\StrongDC.exe"="C:\Program Files\sdc203\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\utorent\utorrent.exe"="C:\Program Files\utorent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-14 14:34:38 ----D---- C:\rsit
2010-02-14 14:34:38 ----D---- C:\Program Files\trend micro
2010-02-14 14:20:13 ----A---- C:\ComboFix.txt
2010-02-14 14:03:03 ----A---- C:\WINDOWS\MBR.exe
2010-02-14 14:03:00 ----A---- C:\WINDOWS\PEV.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\zip.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWSC.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWREG.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\sed.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\grep.exe
2010-02-11 17:17:04 ----D---- C:\New Folder
2010-02-10 19:27:15 ----D---- C:\Documents and Settings\Rasto\Application Data\Broken Sword 2.5
2010-02-09 20:46:08 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-02-09 20:45:54 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-09 20:41:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\x3daudio1_2.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-02-09 19:15:59 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-02-09 19:15:58 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-02-09 19:15:56 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-02-09 19:15:49 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-02-09 19:06:57 ----D---- C:\Program Files\DAEMON Tools Lite
2010-02-09 19:05:50 ----D---- C:\Documents and Settings\Rasto\Application Data\DAEMON Tools Lite
2010-02-09 19:05:46 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
2010-02-09 12:20:17 ----D---- C:\WINDOWS\Sun
2010-02-08 21:11:22 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-02-08 21:11:18 ----D---- C:\Program Files\Common Files\Java
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\java.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-02-08 21:09:48 ----D---- C:\Program Files\Java
2010-02-08 18:44:20 ----D---- C:\MAMA NAPALIT
2010-02-07 20:43:05 ----A---- C:\WINDOWS\doom3.ini
2010-02-07 13:55:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-02-04 16:38:28 ----D---- C:\instalacky
2010-02-02 17:22:26 ----SHD---- C:\WINDOWS\ftpcache
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\Rasto\Application Data\ATI
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\All Users\Application Data\ATI
2010-02-01 19:00:51 ----D---- C:\Program Files\Common Files\ATI Technologies
2010-02-01 18:59:12 ----D---- C:\WINDOWS\RegisteredPackages
2010-02-01 18:57:35 ----A---- C:\WINDOWS\system32\psisdecd.dll
2010-02-01 18:57:23 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2010-02-01 18:53:11 ----RSD---- C:\WINDOWS\assembly
2010-02-01 18:52:04 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-01 18:50:35 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2010-02-01 18:50:29 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2010-02-01 18:50:21 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
2010-02-01 18:49:17 ----D---- C:\Program Files\ATI Technologies
2010-01-28 17:11:41 ----D---- C:\Program Files\PC Wizard 2008
2010-01-27 17:47:19 ----D---- C:\technicke info
2010-01-26 17:31:46 ----D---- C:\obrazky
2010-01-25 19:02:35 ----D---- C:\WINDOWS\system32\languages
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer Pro
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer
2010-01-25 16:00:37 ----D---- C:\Samsung

======List of files/folders modified in the last 1 months======

2010-02-14 14:34:57 ----D---- C:\WINDOWS\temp
2010-02-14 14:34:38 ----RD---- C:\Program Files
2010-02-14 14:30:25 ----D---- C:\Program Files\Mozilla Firefox
2010-02-14 14:20:05 ----D---- C:\Qoobox
2010-02-14 14:18:15 ----D---- C:\WINDOWS\ERDNT
2010-02-14 14:18:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-14 14:14:41 ----AD---- C:\WINDOWS
2010-02-14 14:14:41 ----A---- C:\WINDOWS\system.ini
2010-02-14 14:13:12 ----D---- C:\WINDOWS\system32\drivers
2010-02-14 14:10:57 ----D---- C:\WINDOWS\system32\config
2010-02-14 14:09:11 ----D---- C:\WINDOWS\system32
2010-02-14 14:09:09 ----D---- C:\Program Files\ICQ6.5
2010-02-14 14:08:02 ----D---- C:\WINDOWS\AppPatch
2010-02-14 14:07:56 ----D---- C:\Program Files\Common Files
2010-02-14 14:03:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-14 13:58:44 ----A---- C:\WINDOWS\wincmd.ini
2010-02-14 13:40:18 ----A---- C:\WINDOWS\wininit.ini
2010-02-13 23:00:32 ----D---- C:\WINDOWS\Prefetch
2010-02-13 22:30:25 ----SD---- C:\WINDOWS\Tasks
2010-02-13 21:44:23 ----D---- C:\torenty
2010-02-13 21:35:17 ----D---- C:\Documents and Settings\Rasto\Application Data\Skype
2010-02-13 19:55:41 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 15:18:35 ----D---- C:\instalacky programov
2010-02-12 18:15:11 ----D---- C:\hry
2010-02-12 16:29:36 ----HD---- C:\WINDOWS\inf
2010-02-12 13:22:44 ----D---- C:\Program Files\BSplayer
2010-02-11 21:17:35 ----D---- C:\Documents and Settings\All Users\Application Data\NFS Underground
2010-02-11 17:18:18 ----D---- C:\Documents and Settings\Rasto\Application Data\uTorrent
2010-02-11 17:01:05 ----D---- C:\Filmy
2010-02-10 12:55:33 ----D---- C:\Documents and Settings\Rasto\Application Data\ICQ
2010-02-09 20:41:27 ----SHD---- C:\WINDOWS\Installer
2010-02-09 19:16:02 ----D---- C:\WINDOWS\system32\DirectX
2010-02-09 18:14:54 ----D---- C:\instalacky hier
2010-02-07 13:14:00 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-06 19:19:27 ----SD---- C:\Documents and Settings\Rasto\Application Data\Microsoft
2010-02-06 18:43:28 ----RSD---- C:\WINDOWS\Fonts
2010-02-04 23:45:56 ----D---- C:\WINDOWS\Minidump
2010-02-01 19:03:41 ----D---- C:\WINDOWS\WinSxS
2010-02-01 18:59:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-01 18:56:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-01 18:52:14 ----D---- C:\Program Files\Internet Explorer
2010-02-01 18:48:12 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-28 17:35:04 ----D---- C:\Program Files\Adobe
2010-01-25 19:02:37 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-25 19:01:38 ----A---- C:\WINDOWS\iun6002.exe
2010-01-23 18:09:14 ----D---- C:\Documents and Settings\Rasto\Application Data\Happy Foto
2010-01-16 14:15:12 ----D---- C:\faktury slovanet

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BIOS;BIOS; \??\C:\WINDOWS\System32\drivers\BIOS.sys []
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-03-19 107256]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-03-19 55768]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 36352]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-03-19 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-03-19 131976]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-05-19 3965056]
R3 AnyDVD;AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [2009-03-18 103744]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-05-16 4069888]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-03-19 33096]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-05-24 47360]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ayk4v5st;ayk4v5st; C:\WINDOWS\system32\drivers\ayk4v5st.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mbr;mbr; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\mbr.sys []
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 nv4;nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [2001-08-17 731648]
S3 S3chipid;S3chipid; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-08-11 237312]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AGWinService;AG Windows Service; C:\Program Files\AGI\common\win32\PythonService.exe [2009-01-26 10240]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-05-16 602112]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-08 153376]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-10 66872]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-05-15 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-03-19 20680]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#2 Příspěvek od motji »

Hezké odpoledne :)
Obsah tohoto logu vložte zde :)
C:\ComboFix.txt
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rastak
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 21 led 2008 21:06

Re: Prosim o kontrolu logu,problem s yourgot.com

#3 Příspěvek od rastak »

dobry den.

ComboFix 10-02-12.01 - Rasto . 02. 2010 14:05:18.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1645 [GMT 1:00]
Running from: c:\documents and settings\Rasto\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ICQ6.5\ICQLRun.exe
c:\program files\RegGenie
c:\program files\RegGenie\RegGenie.ini
c:\windows\RegGenieOnUninstall.exe
c:\windows\system32\sshnas21.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS
-------\Service_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-01-14 to 2010-02-14 )))))))))))))))))))))))))))))))
.

2010-02-12 18:11 . 2010-02-12 18:11 -------- d-----w- c:\documents and settings\Rasto\Local Settings\Application Data\NFS Underground 2
2010-02-11 16:17 . 2010-02-11 16:17 -------- d-----w- C:\New Folder
2010-02-10 18:27 . 2010-02-10 19:25 -------- d-----w- c:\documents and settings\Rasto\Application Data\Broken Sword 2.5
2010-02-09 19:46 . 2010-02-10 16:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-09 19:46 . 2010-02-11 16:55 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-09 19:45 . 2010-02-11 16:55 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-09 19:41 . 2010-02-09 19:41 -------- d-----w- c:\windows\system32\LogFiles
2010-02-09 18:16 . 2007-06-20 19:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2010-02-09 18:16 . 2007-06-20 19:45 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll
2010-02-09 18:16 . 2007-05-16 15:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2010-02-09 18:16 . 2007-05-16 15:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2010-02-09 18:15 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2010-02-09 18:15 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2010-02-09 18:15 . 2007-04-04 17:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
2010-02-09 18:15 . 2007-03-15 15:57 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
2010-02-09 18:15 . 2007-03-12 15:42 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
2010-02-09 18:15 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2010-02-09 18:15 . 2007-03-05 11:42 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2010-02-09 18:15 . 2007-01-24 14:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2010-02-09 18:07 . 2010-02-09 18:07 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-09 18:06 . 2010-02-09 18:10 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-02-09 18:05 . 2010-02-11 20:24 -------- d-----w- c:\documents and settings\Rasto\Application Data\DAEMON Tools Lite
2010-02-09 18:05 . 2010-02-09 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-02-09 11:20 . 2010-02-09 11:20 -------- d-----w- c:\windows\Sun
2010-02-08 20:11 . 2010-02-08 20:11 -------- d-----w- c:\program files\Common Files\Java
2010-02-08 20:11 . 2010-02-08 20:11 503808 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\msvcp71.dll
2010-02-08 20:11 . 2010-02-08 20:11 499712 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\jmc.dll
2010-02-08 20:11 . 2010-02-08 20:11 348160 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\msvcr71.dll
2010-02-08 20:11 . 2010-02-08 20:11 61440 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6e02e7df-n\decora-sse.dll
2010-02-08 20:11 . 2010-02-08 20:11 12800 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6e02e7df-n\decora-d3d.dll
2010-02-08 20:10 . 2010-02-08 20:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-08 20:09 . 2010-02-08 20:09 -------- d-----w- c:\program files\Java
2010-02-08 17:44 . 2010-02-08 18:57 -------- d-----w- C:\MAMA NAPALIT
2010-02-07 12:55 . 2010-02-07 12:55 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-02-04 15:38 . 2010-02-04 15:38 -------- d-----w- C:\instalacky
2010-02-02 16:22 . 2010-02-02 16:22 -------- d-sh--w- c:\windows\ftpcache
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\Rasto\Local Settings\Application Data\ATI
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\Rasto\Application Data\ATI
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-02-01 18:07 . 2010-02-01 18:07 0 ----a-w- c:\windows\ativpsrm.bin
2010-02-01 18:00 . 2010-02-01 18:00 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-02-01 17:50 . 2009-05-15 20:05 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-01 17:50 . 2009-05-16 02:51 311296 ----a-r- c:\windows\system32\atiiiexx.dll
2010-02-01 17:50 . 2009-05-16 03:39 442368 ----a-r- c:\windows\system32\ATIDEMGX.dll
2010-02-01 17:50 . 2009-05-16 02:54 887724 ----a-r- c:\windows\system32\ativva6x.dat
2010-02-01 17:50 . 2009-05-16 02:54 3 ----a-r- c:\windows\system32\ativva5x.dat
2010-02-01 17:50 . 2009-04-23 19:04 189051 ----a-r- c:\windows\system32\atiicdxx.dat
2010-02-01 17:49 . 2010-02-01 18:03 -------- d-----w- c:\program files\ATI Technologies
2010-01-28 16:27 . 2010-01-28 16:27 4096 ----a-w- c:\windows\d3dx.dat
2010-01-28 16:11 . 2010-01-28 16:11 -------- d-----w- c:\program files\PC Wizard 2008
2010-01-27 16:47 . 2010-01-28 17:50 -------- d-----w- C:\technicke info
2010-01-26 16:31 . 2010-01-26 16:35 -------- d-----w- C:\obrazky
2010-01-25 18:02 . 2010-01-25 18:02 -------- d-----w- c:\windows\system32\languages
2010-01-25 16:29 . 2010-02-06 15:45 -------- d-----w- c:\documents and settings\Rasto\Application Data\BSplayer
2010-01-25 16:29 . 2010-01-25 16:29 -------- d-----w- c:\documents and settings\Rasto\Application Data\BSplayer Pro
2010-01-25 15:00 . 2010-01-25 15:00 -------- d-----w- C:\Samsung

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 13:09 . 2009-03-11 18:32 -------- d-----w- c:\program files\ICQ6.5
2010-02-13 20:35 . 2008-11-11 21:43 -------- d-----w- c:\documents and settings\Rasto\Application Data\Skype
2010-02-13 18:55 . 2009-12-15 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-12 12:22 . 2009-01-10 16:46 -------- d-----w- c:\program files\BSplayer
2010-02-11 20:17 . 2009-12-20 08:40 -------- d-----w- c:\documents and settings\All Users\Application Data\NFS Underground
2010-02-11 16:18 . 2009-05-16 13:14 -------- d-----w- c:\documents and settings\Rasto\Application Data\uTorrent
2010-02-10 11:55 . 2008-11-11 21:40 -------- d-----w- c:\documents and settings\Rasto\Application Data\ICQ
2010-02-07 12:14 . 2008-11-11 20:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-07 12:00 . 2008-11-11 21:28 20208 ----a-w- c:\documents and settings\Rasto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 17:48 . 2008-11-11 20:20 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-25 18:05 . 2008-11-13 15:13 2404 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 18:02 . 2009-01-10 16:38 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-25 18:01 . 2009-01-10 16:38 737280 ----a-w- c:\windows\iun6002.exe
2010-01-23 17:18 . 2008-11-22 23:14 330868 ----a-w- c:\documents and settings\Rasto\Application Data\mdbu.bin
2010-01-23 17:09 . 2009-05-16 18:39 -------- d-----w- c:\documents and settings\Rasto\Application Data\Happy Foto
2010-01-14 08:30 . 2010-01-14 08:30 79488 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-30 19:31 . 2009-12-30 19:31 -------- d-----w- c:\program files\Regino v4.5
2009-12-30 18:18 . 2009-05-17 20:40 -------- d-----w- c:\program files\Total Video Converter
2009-12-20 08:40 . 2009-12-20 08:40 -------- d-----w- c:\program files\Common Files\DirectX
2009-12-18 21:44 . 2008-12-19 22:27 -------- d-----w- c:\documents and settings\Rasto\Application Data\gtk-2.0
2009-12-17 23:10 . 2009-12-17 23:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Martau
2009-12-17 23:10 . 2009-12-17 23:10 -------- d-----w- c:\program files\Total Uninstall 5
2009-11-22 21:01 . 2008-12-08 19:54 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-09-23 07:24 . 2009-09-23 07:24 968224 ----a-w- c:\program files\Citrid_13.exe
2007-04-02 09:14 . 2007-04-02 09:14 721216 ----a-w- c:\program files\MaeCi3D.ocx
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"VTTrayp"="VTtrayp.exe" [2005-08-03 163840]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\sdc203\\StrongDC.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\utorent\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9. 2. 2010 19:07 691696]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [11. 11. 2008 21:18 13696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19. 3. 2009 10:44 107256]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [26. 1. 2009 21:30 10240]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [19. 3. 2009 10:44 731840]
S3 S3chipid;S3chipid;\??\c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys --> c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys [?]
.
.
------- Supplementary Scan -------
.
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Rasto\Application Data\Mozilla\Firefox\Profiles\w2d2tb83.default\
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMaeC3D.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 14:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys spra.sys hal.dll >>UNKNOWN [0x8A8C8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e74cb8
\Driver\atapi -> atapi.sys @ 0xb9e09b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xb9d12bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d01a0d
SendHandler -> NDIS.sys @ 0xb9d15b40
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\VTTimer.exe
.
**************************************************************************
.
Completion time: 2010-02-14 14:20:10 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-14 13:20
ComboFix2.txt 2009-05-17 18:55

Pre-Run: 62 330 216 448 bytes free
Post-Run: 62 258 307 072 bytes free

Current=4 Default=4 Failed=3 LastKnownGood=2 Sets=1,2,3,4
- - End Of File - - F0432C18CBDE0DF58AB6E9D67E62B9DC

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#4 Příspěvek od motji »

:arrow: Dejte soubor otestovat na http://www.virustotal.com

c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys
c:\program files\Citrid_13.exe
c:\program files\MaeCi3D.ocx


-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rastak
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 21 led 2008 21:06

Re: Prosim o kontrolu logu,problem s yourgot.com

#5 Příspěvek od rastak »

prvy - c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys - ani v Tempe nevidim,ked dam tu cestu,tak to je prazdne (systemove subory mam ukazovane)

druhy:
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.02.14 -
AVG 9.0.0.730 2010.02.14 -
BitDefender 7.2 2010.02.14 -
ClamAV 0.96.0.0-git 2010.02.13 -
Comodo 3935 2010.02.14 -
DrWeb 5.0.1.12222 2010.02.14 -
eSafe 7.0.17.0 2010.02.14 -
F-Secure 9.0.15370.0 2010.02.13 -
GData 19 2010.02.14 -
Ikarus T3.1.1.80.0 2010.02.14 -
Jiangmin 13.0.900 2010.02.14 -
K7AntiVirus 7.10.972 2010.02.12 -
Kaspersky 7.0.0.125 2010.02.14 -
McAfee 5891 2010.02.13 -
McAfee+Artemis 5891 2010.02.13 -
McAfee-GW-Edition 6.8.5 2010.02.14 -
Microsoft 1.5406 2010.02.14 -
NOD32 4865 2010.02.14 -
Norman 6.04.08 2010.02.14 -
nProtect 2009.1.8.0 2010.02.14 -
PCTools 7.0.3.5 2010.02.14 -
Sophos 4.50.0 2010.02.14 -
Sunbelt 5676 2010.02.13 -
Symantec 20091.2.0.41 2010.02.14 Suspicious.Insight
VBA32 3.12.12.2 2010.02.14 -
Additional information
File size: 968224 bytes
MD5...: 43d66a83945b30ccb106f6666d1ab026
SHA1..: 91b4e827c95abdf3a2c9e4227cedf6537c95d45b
SHA256: 75a97bfd592ff1a0b7b041c44da3175ce6f62631d1afc74dea9a15d275bc0a8b
ssdeep: 24576:opB4xzYJWV6Ky8xDGSOA76eSlohyxiTHDmkm2T24y:AB4FY4lVxGtl9oCk
vT2l
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x89f10
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x58000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x59000 0x32000 0x31200 7.92 a6555b56d0862b1a350c7886141856aa
.rsrc 0x8b000 0x4000 0x3e00 3.26 d62d0ab5d60874d824f55c4496053c4e

( 9 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> advapi32.dll: RegCloseKey
> comctl32.dll: ImageList_Add
> gdi32.dll: SaveDC
> ole32.dll: IsEqualGUID
> oleaut32.dll: LoadTypeLib
> shell32.dll: ShellExecuteA
> user32.dll: GetDC
> version.dll: VerQueryValueA

( 0 exports )
RDS...: NSRL Reference Data Set
-
packers (Kaspersky): UPX

ten treti:
File MaeCi3D.ocx received on 2010.02.14 14:40:59 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.02.14 -
AhnLab-V3 5.0.0.2 2010.02.14 -
AntiVir 7.9.1.160 2010.02.12 -
Antiy-AVL 2.0.3.7 2010.02.14 -
Authentium 5.2.0.5 2010.02.13 -
Avast 4.8.1351.0 2010.02.14 -
AVG 9.0.0.730 2010.02.14 -
BitDefender 7.2 2010.02.14 -
CAT-QuickHeal 10.00 2010.02.13 -
ClamAV 0.96.0.0-git 2010.02.13 -
Comodo 3935 2010.02.14 -
DrWeb 5.0.1.12222 2010.02.14 -
eSafe 7.0.17.0 2010.02.14 -
eTrust-Vet 35.2.7300 2010.02.12 -
F-Prot 4.5.1.85 2010.02.13 -
F-Secure 9.0.15370.0 2010.02.13 -
Fortinet 4.0.14.0 2010.02.14 -
GData 19 2010.02.14 -
Ikarus T3.1.1.80.0 2010.02.14 -
Jiangmin 13.0.900 2010.02.14 -
K7AntiVirus 7.10.972 2010.02.12 -
Kaspersky 7.0.0.125 2010.02.14 -
McAfee 5891 2010.02.13 -
McAfee+Artemis 5891 2010.02.13 -
McAfee-GW-Edition 6.8.5 2010.02.14 -
Microsoft 1.5406 2010.02.14 -
NOD32 4865 2010.02.14 -
Norman 6.04.08 2010.02.14 -
nProtect 2009.1.8.0 2010.02.14 -
Panda 10.0.2.2 2010.02.14 -
PCTools 7.0.3.5 2010.02.14 -
Prevx 3.0 2010.02.14 -
Rising 22.34.01.03 2010.02.11 -
Sophos 4.50.0 2010.02.14 -
Sunbelt 5676 2010.02.13 -
Symantec 20091.2.0.41 2010.02.14 -
TheHacker 6.5.1.4.193 2010.02.14 -
TrendMicro 9.120.0.1004 2010.02.14 -
VBA32 3.12.12.2 2010.02.14 -
ViRobot 2010.2.13.2186 2010.02.13 -
VirusBuster 5.0.21.0 2010.02.13 -

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#6 Příspěvek od motji »

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Driver::
S3chipid
File::
c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys
Dirlook::
c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}


-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#7 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rastak
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 21 led 2008 21:06

Re: Prosim o kontrolu logu,problem s yourgot.com

#8 Příspěvek od rastak »

vcera som bol mimo,tak tu je ten log:

ComboFix 10-02-12.01 - Rasto . 02. 2010 23:46:24.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1647 [GMT 1:00]
Running from: c:\documents and settings\Rasto\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Rasto\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active


FILE ::
"c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_S3CHIPID
-------\Service_S3chipid


((((((((((((((((((((((((( Files Created from 2010-01-14 to 2010-02-14 )))))))))))))))))))))))))))))))
.

2010-02-14 13:34 . 2010-02-14 13:35 -------- d-----w- C:\rsit
2010-02-14 13:34 . 2010-02-14 13:35 -------- d-----w- c:\program files\trend micro
2010-02-12 18:11 . 2010-02-12 18:11 -------- d-----w- c:\documents and settings\Rasto\Local Settings\Application Data\NFS Underground 2
2010-02-11 16:17 . 2010-02-11 16:17 -------- d-----w- C:\New Folder
2010-02-10 18:27 . 2010-02-10 19:25 -------- d-----w- c:\documents and settings\Rasto\Application Data\Broken Sword 2.5
2010-02-09 19:46 . 2010-02-10 16:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-09 19:46 . 2010-02-11 16:55 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-09 19:45 . 2010-02-11 16:55 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-09 19:41 . 2010-02-09 19:41 -------- d-----w- c:\windows\system32\LogFiles
2010-02-09 18:16 . 2007-06-20 19:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2010-02-09 18:16 . 2007-06-20 19:45 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll
2010-02-09 18:16 . 2007-05-16 15:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2010-02-09 18:16 . 2007-05-16 15:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2010-02-09 18:15 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2010-02-09 18:15 . 2007-04-04 17:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2010-02-09 18:15 . 2007-04-04 17:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
2010-02-09 18:15 . 2007-03-15 15:57 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
2010-02-09 18:15 . 2007-03-12 15:42 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
2010-02-09 18:15 . 2007-03-12 15:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2010-02-09 18:15 . 2007-03-05 11:42 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2010-02-09 18:15 . 2007-01-24 14:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2010-02-09 18:07 . 2010-02-09 18:07 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-09 18:06 . 2010-02-09 18:10 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-02-09 18:05 . 2010-02-11 20:24 -------- d-----w- c:\documents and settings\Rasto\Application Data\DAEMON Tools Lite
2010-02-09 18:05 . 2010-02-09 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-02-09 11:20 . 2010-02-09 11:20 -------- d-----w- c:\windows\Sun
2010-02-08 20:11 . 2010-02-08 20:11 -------- d-----w- c:\program files\Common Files\Java
2010-02-08 20:11 . 2010-02-08 20:11 503808 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\msvcp71.dll
2010-02-08 20:11 . 2010-02-08 20:11 499712 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\jmc.dll
2010-02-08 20:11 . 2010-02-08 20:11 348160 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4719e4e7-n\msvcr71.dll
2010-02-08 20:11 . 2010-02-08 20:11 61440 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6e02e7df-n\decora-sse.dll
2010-02-08 20:11 . 2010-02-08 20:11 12800 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6e02e7df-n\decora-d3d.dll
2010-02-08 20:10 . 2010-02-08 20:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-08 20:09 . 2010-02-08 20:09 -------- d-----w- c:\program files\Java
2010-02-08 17:44 . 2010-02-08 18:57 -------- d-----w- C:\MAMA NAPALIT
2010-02-07 12:55 . 2010-02-07 12:55 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-02-04 15:38 . 2010-02-04 15:38 -------- d-----w- C:\instalacky
2010-02-02 16:22 . 2010-02-02 16:22 -------- d-sh--w- c:\windows\ftpcache
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\Rasto\Local Settings\Application Data\ATI
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\Rasto\Application Data\ATI
2010-02-01 18:09 . 2010-02-01 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-02-01 18:07 . 2010-02-01 18:07 0 ----a-w- c:\windows\ativpsrm.bin
2010-02-01 18:00 . 2010-02-01 18:00 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-02-01 17:50 . 2009-05-15 20:05 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-01 17:50 . 2009-05-16 02:51 311296 ----a-r- c:\windows\system32\atiiiexx.dll
2010-02-01 17:50 . 2009-05-16 03:39 442368 ----a-r- c:\windows\system32\ATIDEMGX.dll
2010-02-01 17:50 . 2009-05-16 02:54 887724 ----a-r- c:\windows\system32\ativva6x.dat
2010-02-01 17:50 . 2009-05-16 02:54 3 ----a-r- c:\windows\system32\ativva5x.dat
2010-02-01 17:50 . 2009-04-23 19:04 189051 ----a-r- c:\windows\system32\atiicdxx.dat
2010-02-01 17:49 . 2010-02-01 18:03 -------- d-----w- c:\program files\ATI Technologies
2010-01-28 16:27 . 2010-01-28 16:27 4096 ----a-w- c:\windows\d3dx.dat
2010-01-28 16:11 . 2010-01-28 16:11 -------- d-----w- c:\program files\PC Wizard 2008
2010-01-27 16:47 . 2010-01-28 17:50 -------- d-----w- C:\technicke info
2010-01-26 16:31 . 2010-01-26 16:35 -------- d-----w- C:\obrazky
2010-01-25 18:02 . 2010-01-25 18:02 -------- d-----w- c:\windows\system32\languages
2010-01-25 16:29 . 2010-02-06 15:45 -------- d-----w- c:\documents and settings\Rasto\Application Data\BSplayer
2010-01-25 16:29 . 2010-01-25 16:29 -------- d-----w- c:\documents and settings\Rasto\Application Data\BSplayer Pro
2010-01-25 15:00 . 2010-01-25 15:00 -------- d-----w- C:\Samsung

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 18:11 . 2009-12-20 08:40 -------- d-----w- c:\documents and settings\All Users\Application Data\NFS Underground
2010-02-14 13:09 . 2009-03-11 18:32 -------- d-----w- c:\program files\ICQ6.5
2010-02-13 20:35 . 2008-11-11 21:43 -------- d-----w- c:\documents and settings\Rasto\Application Data\Skype
2010-02-13 18:55 . 2009-12-15 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-12 12:22 . 2009-01-10 16:46 -------- d-----w- c:\program files\BSplayer
2010-02-11 16:18 . 2009-05-16 13:14 -------- d-----w- c:\documents and settings\Rasto\Application Data\uTorrent
2010-02-10 11:55 . 2008-11-11 21:40 -------- d-----w- c:\documents and settings\Rasto\Application Data\ICQ
2010-02-07 12:14 . 2008-11-11 20:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-07 12:00 . 2008-11-11 21:28 20208 ----a-w- c:\documents and settings\Rasto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 17:48 . 2008-11-11 20:20 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-25 18:05 . 2008-11-13 15:13 2404 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 18:02 . 2009-01-10 16:38 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-25 18:01 . 2009-01-10 16:38 737280 ----a-w- c:\windows\iun6002.exe
2010-01-23 17:18 . 2008-11-22 23:14 330868 ----a-w- c:\documents and settings\Rasto\Application Data\mdbu.bin
2010-01-23 17:09 . 2009-05-16 18:39 -------- d-----w- c:\documents and settings\Rasto\Application Data\Happy Foto
2010-01-14 08:30 . 2010-01-14 08:30 79488 ----a-w- c:\documents and settings\Rasto\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-30 19:31 . 2009-12-30 19:31 -------- d-----w- c:\program files\Regino v4.5
2009-12-30 18:18 . 2009-05-17 20:40 -------- d-----w- c:\program files\Total Video Converter
2009-12-20 08:40 . 2009-12-20 08:40 -------- d-----w- c:\program files\Common Files\DirectX
2009-12-18 21:44 . 2008-12-19 22:27 -------- d-----w- c:\documents and settings\Rasto\Application Data\gtk-2.0
2009-12-17 23:10 . 2009-12-17 23:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Martau
2009-12-17 23:10 . 2009-12-17 23:10 -------- d-----w- c:\program files\Total Uninstall 5
2009-11-22 21:01 . 2008-12-08 19:54 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-09-23 07:24 . 2009-09-23 07:24 968224 ----a-w- c:\program files\Citrid_13.exe
2007-04-02 09:14 . 2007-04-02 09:14 721216 ----a-w- c:\program files\MaeCi3D.ocx
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\docume~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515} ----



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"VTTrayp"="VTtrayp.exe" [2005-08-03 163840]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\sdc203\\StrongDC.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\utorent\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9. 2. 2010 19:07 691696]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [11. 11. 2008 21:18 13696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19. 3. 2009 10:44 107256]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [26. 1. 2009 21:30 10240]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [19. 3. 2009 10:44 731840]
.
.
------- Supplementary Scan -------
.
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Rasto\Application Data\Mozilla\Firefox\Profiles\w2d2tb83.default\
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMaeC3D.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 23:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys spha.sys hal.dll >>UNKNOWN [0x8A8C8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e74cb8
\Driver\atapi -> atapi.sys @ 0xb9e09b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xb9d12bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d1fa21
SendHandler -> NDIS.sys @ 0xb9cfd87b
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\VTTimer.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-15 00:00:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-14 23:00
ComboFix2.txt 2010-02-14 13:20
ComboFix3.txt 2009-05-17 18:55

Pre-Run: 62 182 162 432 bytes free
Post-Run: 62 145 232 896 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Current=4 Default=4 Failed=3 LastKnownGood=2 Sets=1,2,3,4
- - End Of File - - 8022D2C5C025CC2A586B81DC4ED83CC8

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#9 Příspěvek od motji »

Jak to ted vypadá s počítačem? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rastak
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 21 led 2008 21:06

Re: Prosim o kontrolu logu,problem s yourgot.com

#10 Příspěvek od rastak »

No vyzera ze to pomohlo,uz to nerobi. Velmi pekne dakujem.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu logu,problem s yourgot.com

#11 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- ]nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********


:arrow: Při použití combofixu byl vypnut autorun - nefunguje automatické spouštění cd rom a pod. Doporučovala bych nechat vypnuté, ale pokud je chcete zapnout, zde je návod

ObrázekOtevřete si Poznámkový blok a zkopírujte do něj text

Kód: Vybrat vše

Windows Registry Editor Version 5.00 

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CDRom] 
"AutoRun"=dword:00000001 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 
"NoDriveTypeAutoRun"=- 
"NoDriveAutoRun"=- 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 
"NoDriveTypeAutoRun"=- 
"NoDriveAutoRun"=- 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 
"NoDriveTypeAutoRun"=- 
"NoDriveAutoRun"=-
 
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
-klikněte na uložit,
- pak na soubor standardně 2x klikněte a potvrďte dialogové okno.


***********


:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět