
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Security tool
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
tady je
2010-02-20 10:30:58 . 2010-02-20 10:30:58 194 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Meebo Notifier.reg.dat
2010-02-20 10:30:56 . 2010-02-20 10:30:56 901 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}.reg.dat
2010-02-20 10:30:55 . 2010-02-20 10:30:55 901 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{95289393-33EA-4F8D-B952-483415B9C955}.reg.dat
2010-02-20 10:30:52 . 2010-02-20 10:30:52 1,938 ----a-w- C:\Qoobox\Quarantine\Registry_backups\URLSearchHooks-{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}.reg.dat
2010-02-20 10:25:10 . 2010-02-20 10:25:10 6,090 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-02-20 10:13:50 . 2010-02-20 10:16:37 62 ----a-w- C:\Qoobox\Quarantine\catchme.log
2010-02-19 16:59:45 . 2010-02-19 20:27:05 694 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk.vir
2010-02-19 16:59:45 . 2010-02-19 20:27:03 664 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\Desktop\Security Tool.lnk.vir
2009-07-30 16:16:30 . 2009-07-14 15:14:36 150,768 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\serauth2.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\serauth1.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\nsprs.dll.vir
2010-02-20 10:30:58 . 2010-02-20 10:30:58 194 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Meebo Notifier.reg.dat
2010-02-20 10:30:56 . 2010-02-20 10:30:56 901 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}.reg.dat
2010-02-20 10:30:55 . 2010-02-20 10:30:55 901 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{95289393-33EA-4F8D-B952-483415B9C955}.reg.dat
2010-02-20 10:30:52 . 2010-02-20 10:30:52 1,938 ----a-w- C:\Qoobox\Quarantine\Registry_backups\URLSearchHooks-{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}.reg.dat
2010-02-20 10:25:10 . 2010-02-20 10:25:10 6,090 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-02-20 10:13:50 . 2010-02-20 10:16:37 62 ----a-w- C:\Qoobox\Quarantine\catchme.log
2010-02-19 16:59:45 . 2010-02-19 20:27:05 694 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk.vir
2010-02-19 16:59:45 . 2010-02-19 20:27:03 664 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\Desktop\Security Tool.lnk.vir
2009-07-30 16:16:30 . 2009-07-14 15:14:36 150,768 ----a-w- C:\Qoobox\Quarantine\C\Users\NB - Fujitsu\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\serauth2.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\serauth1.dll.vir
2009-06-24 11:24:16 . 2009-06-24 11:24:16 0 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\nsprs.dll.vir
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
tady je obsah textaku
ComboFix 10-02-19.04 - NB - Fujitsu 20.02.2010 11:56:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.420.1029.18.2038.1120 [GMT 1:00]
Spuštěný z: c:\users\NB - Fujitsu\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\NB - Fujitsu\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100219-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1368 [VPS 100219-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-20 do 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-20 11:06 . 2010-02-20 11:07 -------- d-----w- c:\users\NB - Fujitsu\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-19 22:03 . 2010-02-19 22:03 -------- d-----w- C:\_OTL
2010-02-19 19:32 . 2010-02-19 19:32 -------- d-----w- c:\program files\trend micro
2010-02-19 19:32 . 2010-02-19 19:33 -------- d-----w- C:\rsit
2010-02-10 18:16 . 2009-12-11 12:01 307200 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-10 18:16 . 2009-12-11 12:01 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-10 18:16 . 2009-12-08 22:29 3503704 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-10 18:16 . 2009-12-08 22:29 3469912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-10 18:16 . 2009-12-08 17:45 816640 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-10 18:16 . 2009-12-08 22:29 214104 ----a-w- c:\windows\system32\drivers\netio.sys
2010-02-10 18:16 . 2009-12-08 19:58 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2010-02-10 18:16 . 2009-12-08 19:58 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2010-02-10 18:16 . 2009-12-08 19:56 317440 ----a-w- c:\windows\system32\BFE.DLL
2010-02-10 18:16 . 2009-12-08 17:44 85504 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2010-02-10 18:16 . 2009-12-08 20:03 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-02-10 18:16 . 2009-12-08 17:44 22016 ----a-w- c:\windows\system32\netiougc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 19:52 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 19:29 . 2007-10-09 09:06 81404 ----a-w- c:\windows\system32\perfc005.dat
2010-02-10 19:29 . 2007-10-09 09:06 473598 ----a-w- c:\windows\system32\perfh005.dat
2010-01-21 21:29 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\Skype
2010-01-21 15:43 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\skypePM
2010-01-14 10:12 . 2009-10-03 21:11 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-30 21:08 . 2009-12-30 17:57 -------- d-----w- c:\program files\Bacardi
2009-12-28 17:18 . 2009-12-28 17:18 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\U3
2009-12-28 17:12 . 2008-09-19 23:48 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\dvdcss
2009-12-28 12:36 . 2010-02-10 18:15 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 18:15 1327616 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:34 . 2010-02-10 18:15 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:34 . 2010-02-10 18:15 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:34 . 2010-02-10 18:15 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:34 . 2010-02-10 18:15 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:33 . 2010-02-10 18:15 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:32 . 2010-02-10 18:15 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:30 . 2010-02-10 18:15 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:30 . 2010-02-10 18:15 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-19 21:12 . 2009-12-19 21:12 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-18 12:52 . 2010-01-21 21:17 832512 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-21 21:17 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-21 21:17 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-21 21:17 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-21 21:17 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-21 21:17 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-21 21:17 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-12-04 16:14 . 2010-02-10 18:15 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:14 . 2010-02-10 18:15 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-12-04 16:14 . 2010-02-10 18:15 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-24 23:54 . 2009-07-13 07:50 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-07-13 07:50 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-07-13 07:50 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-07-13 07:50 97480 ----a-w- c:\windows\system32\AvastSS.scr
2007-11-04 01:23 . 2007-11-04 00:40 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-12-16 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"ares"="d:\ares\Ares.exe" [2007-12-31 962560]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-13 3276288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-11-03 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-04 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-04 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-04 133912]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-13 4399104]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-27 2658304]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [13.7.2009 8:50 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [13.7.2009 8:50 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [13.7.2009 8:50 53328]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.3.2009 16:47 222456]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [18.10.2008 11:26 685816]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\System32\drivers\Gt51Ip.sys [18.2.2008 16:14 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\System32\drivers\gt72ubus.sys [8.2.2008 12:00 59648]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-19 c:\windows\Tasks\User_Feed_Synchronization-{DC217D56-CBE3-45DB-81A7-2449F2D9D9D8}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {B1FF332D-D34D-4D07-8E6B-BFE75C78E8D3} = 10.154.86.1,10.154.96.6
FF - ProfilePath - c:\users\NB - Fujitsu\AppData\Roaming\Mozilla\Firefox\Profiles\b4rmqx4a.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 12:07
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2010-02-20 12:10:54
ComboFix-quarantined-files.txt 2010-02-20 11:10
ComboFix2.txt 2010-02-20 10:32
Před spuštěním: Volných bajtů: 100 664 860 672
Po spuštění: Volných bajtů: 100 679 233 536
- - End Of File - - 26B47B5A483907030EF454E767E5AF27
musela jsem to zase na flesce prenest z infikovaneho do neinfikovaneho protoze mi na infikovanem nejde zpustit ani mozilla ani internet explorer - oba hazou hlasku "Pokus použít neplatnou operaci na klíč registru, který je označen pro odstranění"
ComboFix 10-02-19.04 - NB - Fujitsu 20.02.2010 11:56:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.420.1029.18.2038.1120 [GMT 1:00]
Spuštěný z: c:\users\NB - Fujitsu\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\NB - Fujitsu\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100219-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1368 [VPS 100219-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-20 do 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-20 11:06 . 2010-02-20 11:07 -------- d-----w- c:\users\NB - Fujitsu\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-19 22:03 . 2010-02-19 22:03 -------- d-----w- C:\_OTL
2010-02-19 19:32 . 2010-02-19 19:32 -------- d-----w- c:\program files\trend micro
2010-02-19 19:32 . 2010-02-19 19:33 -------- d-----w- C:\rsit
2010-02-10 18:16 . 2009-12-11 12:01 307200 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-10 18:16 . 2009-12-11 12:01 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-10 18:16 . 2009-12-08 22:29 3503704 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-10 18:16 . 2009-12-08 22:29 3469912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-10 18:16 . 2009-12-08 17:45 816640 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-10 18:16 . 2009-12-08 22:29 214104 ----a-w- c:\windows\system32\drivers\netio.sys
2010-02-10 18:16 . 2009-12-08 19:58 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2010-02-10 18:16 . 2009-12-08 19:58 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2010-02-10 18:16 . 2009-12-08 19:56 317440 ----a-w- c:\windows\system32\BFE.DLL
2010-02-10 18:16 . 2009-12-08 17:44 85504 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2010-02-10 18:16 . 2009-12-08 20:03 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-02-10 18:16 . 2009-12-08 17:44 22016 ----a-w- c:\windows\system32\netiougc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 19:52 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 19:29 . 2007-10-09 09:06 81404 ----a-w- c:\windows\system32\perfc005.dat
2010-02-10 19:29 . 2007-10-09 09:06 473598 ----a-w- c:\windows\system32\perfh005.dat
2010-01-21 21:29 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\Skype
2010-01-21 15:43 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\skypePM
2010-01-14 10:12 . 2009-10-03 21:11 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-30 21:08 . 2009-12-30 17:57 -------- d-----w- c:\program files\Bacardi
2009-12-28 17:18 . 2009-12-28 17:18 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\U3
2009-12-28 17:12 . 2008-09-19 23:48 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\dvdcss
2009-12-28 12:36 . 2010-02-10 18:15 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 18:15 1327616 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:34 . 2010-02-10 18:15 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:34 . 2010-02-10 18:15 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:34 . 2010-02-10 18:15 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:34 . 2010-02-10 18:15 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:33 . 2010-02-10 18:15 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:32 . 2010-02-10 18:15 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:30 . 2010-02-10 18:15 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:30 . 2010-02-10 18:15 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-19 21:12 . 2009-12-19 21:12 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-18 12:52 . 2010-01-21 21:17 832512 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-21 21:17 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-21 21:17 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-21 21:17 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-21 21:17 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-21 21:17 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-21 21:17 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-12-04 16:14 . 2010-02-10 18:15 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:14 . 2010-02-10 18:15 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-12-04 16:14 . 2010-02-10 18:15 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-24 23:54 . 2009-07-13 07:50 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-07-13 07:50 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-07-13 07:50 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-07-13 07:50 97480 ----a-w- c:\windows\system32\AvastSS.scr
2007-11-04 01:23 . 2007-11-04 00:40 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-12-16 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"ares"="d:\ares\Ares.exe" [2007-12-31 962560]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-13 3276288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-11-03 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-04 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-04 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-04 133912]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-13 4399104]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-27 2658304]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [13.7.2009 8:50 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [13.7.2009 8:50 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [13.7.2009 8:50 53328]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.3.2009 16:47 222456]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [18.10.2008 11:26 685816]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\System32\drivers\Gt51Ip.sys [18.2.2008 16:14 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\System32\drivers\gt72ubus.sys [8.2.2008 12:00 59648]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-19 c:\windows\Tasks\User_Feed_Synchronization-{DC217D56-CBE3-45DB-81A7-2449F2D9D9D8}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {B1FF332D-D34D-4D07-8E6B-BFE75C78E8D3} = 10.154.86.1,10.154.96.6
FF - ProfilePath - c:\users\NB - Fujitsu\AppData\Roaming\Mozilla\Firefox\Profiles\b4rmqx4a.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 12:07
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2010-02-20 12:10:54
ComboFix-quarantined-files.txt 2010-02-20 11:10
ComboFix2.txt 2010-02-20 10:32
Před spuštěním: Volných bajtů: 100 664 860 672
Po spuštění: Volných bajtů: 100 679 233 536
- - End Of File - - 26B47B5A483907030EF454E767E5AF27
musela jsem to zase na flesce prenest z infikovaneho do neinfikovaneho protoze mi na infikovanem nejde zpustit ani mozilla ani internet explorer - oba hazou hlasku "Pokus použít neplatnou operaci na klíč registru, který je označen pro odstranění"
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
dost to trvalo ale už to funguje
co ted?

-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
behem scanovani se mi restartoval pocitac, asi to budu muset spustit znova
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
sorry ze to tak trva, pracuje to hrozne pomalu a jeste se to seka
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
no ja sem to mezitim spustila znova v normalnim rezimu probehlo rychle scanovani to sem si ulozila na plochu, jenomze se s tim hrozne pomalu manipuluje skoro to nereaguje, takze mi to hrozne dlouho trva ... co nejdrive poslu ten textak a pak budu pokracovat podle instrukci
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
tady je ten texta doufam ze je to cele .... jdu pokracovat
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-20 12:51:36
Windows 6.0.6000
Running: gmer.exe; Driver: C:\Users\NB-FUJ~1\AppData\Local\Temp\pxroiaob.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8446C1E8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-20 12:51:36
Windows 6.0.6000
Running: gmer.exe; Driver: C:\Users\NB-FUJ~1\AppData\Local\Temp\pxroiaob.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8446C1E8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
takze sem spustila skenovani, zatim to najizdi az to bude poslu zase log 

-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
to sem rada ale ten dlouhy podle instrukci se nacita, mirne se mi seka komp zatim se ukazuje ze to pracuje, ale vubec nic nenajelo, jsem z toho nervozni
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
předtím to bylo nějaké seknuté když to nenajíždělo, restartovala jsem počítač a spustila to znovu, začalo to najíždět, teď už normálně, ..... hmm program gmer.exe přestal pracovat ... to je na dlouho hruuuza ..... díky moc za tvůj čas a trpělivost 

-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
ok ted mam vypnuty avast, normalni rezim, zkusim to jeste jednou
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
zase se to seklo (pisu neustale z neinfikovaneho kompu)
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
kdyz klinku na scan hlasi mi to error
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
super tohle mi vyjelo
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Processes found
******************************************************************************************
******************************************************************************************
No Kernel Modules found
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: NB-FUJITSU.WN-200R:49523
Remote Address: 164.RED-79-150-20.DYNAMICIP.RIMA-TDE.NET:14652
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49522
Remote Address: 56.214.27.77.DYNAMIC.MUNDO-R.COM:HTTP
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49521
Remote Address: USER7-233.SATFILM.NET.PL:16798
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49520
Remote Address: C-174-54-118-235.HSD1.PA.COMCAST.NET:15422
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49518
Remote Address: 74.125.108.88:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49497
Remote Address: 182-129-235-201.FIBERTEL.COM.AR:12808
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: NB-FUJITSU.WN-200R:49479
Remote Address: FX-IN-F137.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49477
Remote Address: API.SLOVNIK.SEZNAM.CZ:HTTP
Type: TCP
Process: 2940 (PID)
State: CLOSE_WAIT
Local Address: NB-FUJITSU.WN-200R:49466
Remote Address: NUQ04S01-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49464
Remote Address: HB-IN-F103.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49462
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49460
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49459
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49456
Remote Address: FX-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49454
Remote Address: FX-IN-F99.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49450
Remote Address: FX-IN-F99.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49448
Remote Address: FX-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49446
Remote Address: FX-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49424
Remote Address: BW-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49478
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49476
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49465
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49463
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49461
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49458
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49457
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49455
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49453
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49449
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49447
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49445
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49260
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49230
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49210
Remote Address: LOCALHOST:49209
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49209
Remote Address: LOCALHOST:49210
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49197
Remote Address: LOCALHOST:49196
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49196
Remote Address: LOCALHOST:49197
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12143
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12119
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12110
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49478
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49476
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49465
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49463
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49461
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49458
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49457
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49455
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49453
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49449
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49447
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49445
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49260
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49230
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2940 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12025
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: 704 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49157
Remote Address: 0.0.0.0:0
Type: TCP
Process: 576 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1216 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: 720 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1388 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1136 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: 660 (PID)
State: LISTENING
Local Address: NB-FUJITSU:29677
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3432 (PID)
State: LISTENING
Local Address: NB-FUJITSU:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1004 (PID)
State: LISTENING
Local Address: NB-FUJITSU.WN-200R:54239
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:SSDP
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: NB-FUJITSU:64414
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
Local Address: NB-FUJITSU:58491
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:54240
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:SSDP
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:51174
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:29678
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:29677
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:24136
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:20119
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:LLMNR
Remote Address: NA
Type: UDP
Process: 1572 (PID)
State: NA
Local Address: NB-FUJITSU:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
Local Address: NB-FUJITSU:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:500
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found
ale hodilo mi to hlasku ze nejsem admin nebo co ... nicmene vyjelo to tak jako tak
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Processes found
******************************************************************************************
******************************************************************************************
No Kernel Modules found
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: NB-FUJITSU.WN-200R:49523
Remote Address: 164.RED-79-150-20.DYNAMICIP.RIMA-TDE.NET:14652
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49522
Remote Address: 56.214.27.77.DYNAMIC.MUNDO-R.COM:HTTP
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49521
Remote Address: USER7-233.SATFILM.NET.PL:16798
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49520
Remote Address: C-174-54-118-235.HSD1.PA.COMCAST.NET:15422
Type: TCP
Process: 3432 (PID)
State: SYN_SENT
Local Address: NB-FUJITSU.WN-200R:49518
Remote Address: 74.125.108.88:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49497
Remote Address: 182-129-235-201.FIBERTEL.COM.AR:12808
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: NB-FUJITSU.WN-200R:49479
Remote Address: FX-IN-F137.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49477
Remote Address: API.SLOVNIK.SEZNAM.CZ:HTTP
Type: TCP
Process: 2940 (PID)
State: CLOSE_WAIT
Local Address: NB-FUJITSU.WN-200R:49466
Remote Address: NUQ04S01-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49464
Remote Address: HB-IN-F103.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49462
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49460
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49459
Remote Address: FK-IN-F95.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49456
Remote Address: FX-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49454
Remote Address: FX-IN-F99.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49450
Remote Address: FX-IN-F99.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49448
Remote Address: FX-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49446
Remote Address: FX-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:49424
Remote Address: BW-IN-F100.1E100.NET:HTTP
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU.WN-200R:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49478
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49476
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49465
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49463
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49461
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49458
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49457
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49455
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49453
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49449
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49447
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49445
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49260
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49230
Remote Address: LOCALHOST:12080
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49210
Remote Address: LOCALHOST:49209
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49209
Remote Address: LOCALHOST:49210
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49197
Remote Address: LOCALHOST:49196
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:49196
Remote Address: LOCALHOST:49197
Type: TCP
Process: 2768 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12143
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12119
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12110
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49478
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49476
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49465
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49463
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49461
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49458
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49457
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49455
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49453
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49449
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49447
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49445
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49260
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: LOCALHOST:49230
Type: TCP
Process: 2940 (PID)
State: ESTABLISHED
Local Address: NB-FUJITSU:12080
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2940 (PID)
State: LISTENING
Local Address: NB-FUJITSU:12025
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2908 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: 704 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49157
Remote Address: 0.0.0.0:0
Type: TCP
Process: 576 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1216 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: 720 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1388 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1136 (PID)
State: LISTENING
Local Address: NB-FUJITSU:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: 660 (PID)
State: LISTENING
Local Address: NB-FUJITSU:29677
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3432 (PID)
State: LISTENING
Local Address: NB-FUJITSU:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1004 (PID)
State: LISTENING
Local Address: NB-FUJITSU.WN-200R:54239
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:SSDP
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: NB-FUJITSU.WN-200R:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: NB-FUJITSU:64414
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
Local Address: NB-FUJITSU:58491
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:54240
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:SSDP
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:51174
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:29678
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:29677
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:24136
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:20119
Remote Address: NA
Type: UDP
Process: 3432 (PID)
State: NA
Local Address: NB-FUJITSU:LLMNR
Remote Address: NA
Type: UDP
Process: 1572 (PID)
State: NA
Local Address: NB-FUJITSU:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
Local Address: NB-FUJITSU:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1388 (PID)
State: NA
Local Address: NB-FUJITSU:500
Remote Address: NA
Type: UDP
Process: 1216 (PID)
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found
ale hodilo mi to hlasku ze nejsem admin nebo co ... nicmene vyjelo to tak jako tak
-
- Návštěvník
- Příspěvky: 76
- Registrován: 19 úno 2010 21:02
Re: Security tool
no ja sem to delala v normalnim rezim a asi sem to spatne spustila ..... nicmene kdyz najedu na START .. tak tu u Visty nemam SPUSTIT a nemůžu ho bohužel najít mezi programama ....ach jo.. odinstalovat to nejak zvladnu