Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vir...

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
dopa
Návštěvník
Návštěvník
Příspěvky: 307
Registrován: 12 říj 2006 08:52

vir...

#1 Příspěvek od dopa »

Zdravím, tak jsem tu zase s prosbou o kontrolu logu. Přijdu domů a počítač byl napaden XP Antispy. Ten jsem pomoci MBAM odstranil, ale ted mi nejde nainstalovat Eset Smart security.
Hlásí, že nemám přístup ke složce, kam chce kopírovat soubory.


Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-03-09 14:09:48
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 60 GB (79%) free of 76 GB
Total RAM: 2005 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:57, on 9.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LINKMAGIC\LINKMAGIC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\KXKH81G4\RSIT[1].exe
C:\Program Files\trend micro\admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: LINKMAGIC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8054592625
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe

--
End of file - 6468 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"atchk"=C:\Program Files\Intel\AMT\atchk.exe [2007-06-12 408344]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-08-01 1036288]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-05-29 150040]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-05-29 170520]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-05-29 141848]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
LINKMAGIC.lnk - C:\Program Files\LINKMAGIC\LINKMAGIC.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-04-02 212992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-03-09 14:09:48 ----D---- C:\rsit
2010-03-09 14:09:48 ----D---- C:\Program Files\trend micro
2010-03-09 14:08:26 ----D---- C:\Documents and Settings\admin\Application Data\LangSoft
2010-03-09 13:46:27 ----D---- C:\Program Files\TRANSLAT
2010-03-09 13:46:22 ----D---- C:\Documents and Settings\All Users\Application Data\LangSoft
2010-03-09 13:26:34 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-09 13:22:34 ----D---- C:\Documents and Settings\admin\Application Data\Malwarebytes
2010-03-09 13:22:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-09 13:22:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-03-09 13:21:40 ----D---- C:\Documents and Settings\admin\Application Data\Mozilla
2010-03-08 17:29:06 ----SHD---- C:\RECYCLER
2010-03-08 15:35:14 ----SHD---- C:\WINDOWS\CSC
2010-03-08 15:33:41 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Adobe
2010-03-08 15:14:03 ----D---- C:\PP1390MF_v1.67
2010-03-08 15:13:17 ----D---- C:\LinkMagic
2010-03-08 15:13:14 ----A---- C:\WINDOWS\install.ini
2010-03-08 15:13:13 ----N---- C:\WINDOWS\rmreg.exe
2010-03-08 15:13:13 ----N---- C:\WINDOWS\Cm3.ini
2010-03-08 15:13:13 ----D---- C:\FBBM
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ASM.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ALM.dll
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv98.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv2k.exe
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lttwn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltkrn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltfil12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltefx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LTDIS12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftif12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftga12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfpcx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lffax12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LFCMP12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfbmp12n.dll
2010-03-08 15:13:11 ----D---- C:\Program Files\LINKMAGIC
2010-03-08 15:12:27 ----D---- C:\Program Files\WinRAR
2010-03-08 15:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-03-08 15:09:08 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-03-08 15:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-03-08 15:06:54 ----D---- C:\WINDOWS\ie7updates
2010-03-08 15:06:01 ----D---- C:\WINDOWS\WBEM
2010-03-08 15:03:45 ----HDC---- C:\WINDOWS\ie7
2010-03-08 15:03:28 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-03-08 15:03:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-03-08 14:51:16 ----D---- C:\Program Files\Mozilla Firefox
2010-03-08 14:45:56 ----D---- C:\WINDOWS\system32\1029
2010-03-08 14:44:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-03-08 14:43:56 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-08 14:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-03-08 14:43:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-03-08 14:43:43 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-03-08 14:43:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-03-08 14:43:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-03-08 14:43:29 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-03-08 14:43:26 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-03-08 14:43:22 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-03-08 14:43:14 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-03-08 14:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-03-08 14:43:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-03-08 14:43:00 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-03-08 14:42:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-03-08 14:42:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-03-08 14:42:48 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-03-08 14:42:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-03-08 14:42:39 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-03-08 14:42:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-03-08 14:42:31 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-03-08 14:42:28 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-03-08 14:42:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-03-08 14:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-03-08 14:42:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-03-08 14:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-03-08 14:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-03-08 14:42:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-03-08 14:42:03 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-03-08 14:41:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-03-08 14:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-03-08 14:41:39 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-03-08 14:41:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-03-08 14:41:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-03-08 14:41:28 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-03-08 14:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-03-08 14:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-03-08 14:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-03-08 14:41:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-03-08 14:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-03-08 14:41:04 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-03-08 14:41:00 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-03-08 14:40:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-03-08 14:40:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-03-08 14:40:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-03-08 14:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-03-08 14:39:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-03-08 14:39:37 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-03-08 14:39:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-03-08 14:39:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-03-08 14:39:22 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-03-08 14:39:17 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-03-08 14:39:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-03-08 14:39:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-03-08 14:39:02 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-03-08 14:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-03-08 14:38:48 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-03-08 14:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-03-08 14:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-03-08 14:38:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-03-08 14:38:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-03-08 14:38:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-03-08 14:38:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-03-08 14:38:01 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-08 14:31:51 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-03-08 14:31:26 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-03-08 14:31:07 ----D---- C:\Program Files\Microsoft Works
2010-03-08 14:30:50 ----D---- C:\Program Files\MSBuild
2010-03-08 14:30:03 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-08 14:30:03 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-08 14:29:58 ----D---- C:\Public
2010-03-08 14:25:10 ----D---- C:\WINDOWS\SHELLNEW
2010-03-08 14:24:56 ----D---- C:\Program Files\Microsoft Office
2010-03-08 14:24:55 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-03-08 14:24:46 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-08 14:24:27 ----RHD---- C:\MSOCache
2010-03-08 14:22:39 ----D---- C:\ZALOHA
2010-03-08 14:20:25 ----D---- C:\totalcmd
2010-03-08 14:20:25 ----D---- C:\Documents and Settings\admin\Application Data\GHISLER

======List of files/folders modified in the last 1 months======

2010-03-09 14:09:48 ----RD---- C:\Program Files
2010-03-09 14:09:00 ----A---- C:\WINDOWS\system32\log.txt
2010-03-09 14:08:26 ----SHD---- C:\WINDOWS\Installer
2010-03-09 14:07:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-09 14:05:30 ----D---- C:\WINDOWS\system32\Restore
2010-03-09 13:59:39 ----D---- C:\WINDOWS\Prefetch
2010-03-09 13:59:10 ----D---- C:\WINDOWS\system32
2010-03-09 13:59:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-09 13:57:43 ----D---- C:\WINDOWS\Temp
2010-03-09 13:54:47 ----D---- C:\WINDOWS\system32\drivers
2010-03-09 13:42:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-09 13:40:02 ----D---- C:\WINDOWS
2010-03-09 13:21:32 ----SD---- C:\Documents and Settings\admin\Application Data\Microsoft
2010-03-09 13:20:59 ----HD---- C:\WINDOWS\inf
2010-03-09 13:20:51 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-09 13:20:39 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-08 15:40:18 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-08 15:35:08 ----D---- C:\WINDOWS\Help
2010-03-08 15:35:08 ----D---- C:\Program Files\Internet Explorer
2010-03-08 15:33:42 ----D---- C:\WINDOWS\WinSxS
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files
2010-03-08 15:14:07 ----D---- C:\Documents and Settings
2010-03-08 15:13:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-08 15:12:52 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-08 15:09:33 ----A---- C:\WINDOWS\imsins.BAK
2010-03-08 15:08:41 ----D---- C:\WINDOWS\system32\en-us
2010-03-08 15:06:03 ----D---- C:\WINDOWS\system32\config
2010-03-08 15:05:50 ----D---- C:\WINDOWS\Media
2010-03-08 15:01:46 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-08 14:53:52 ----D---- C:\WINDOWS\system32\wbem
2010-03-08 14:52:48 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-08 14:48:57 ----D---- C:\WINDOWS\mui
2010-03-08 14:48:57 ----D---- C:\WINDOWS\AppPatch
2010-03-08 14:46:51 ----D---- C:\WINDOWS\pchealth
2010-03-08 14:46:19 ----D---- C:\Program Files\Windows Media Player
2010-03-08 14:45:56 ----D---- C:\Program Files\Common Files\System
2010-03-08 14:41:26 ----D---- C:\Program Files\Outlook Express
2010-03-08 14:38:51 ----D---- C:\Program Files\Messenger
2010-03-08 14:31:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-08 14:29:07 ----RSD---- C:\WINDOWS\Fonts
2010-03-08 14:25:29 ----A---- C:\WINDOWS\win.ini
2010-03-08 14:24:07 ----SD---- C:\WINDOWS\Downloaded Program Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-08-03 307712]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2007-06-12 45056]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-02 6008704]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 atchksrv;Intel(R) Active Management Technology System Status Service; C:\Program Files\Intel\AMT\atchksrv.exe [2007-06-12 183064]
R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2007-06-12 109336]
R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Intel\AMT\UNS.exe [2007-06-12 2521880]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: vir...

#2 Příspěvek od Caroprd111 »

Zdravím :)

Na logu se pracuje, prosím o strpení.
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: vir...

#3 Příspěvek od Caroprd111 »

Obrázek Příště nic v MBAM nemažte bez kontroly logu. Máte někde uložený log z MBAM :???:



Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Obrázek Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary

Obrázek Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrází stránka s licenčnímy podmínkami, pokračujte stisknutím tlačítka "Ano"

Obrázek Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:

Obrázek Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.

Obrázek Během skenování může být počítač restartován.
Obrázek

dopa
Návštěvník
Návštěvník
Příspěvky: 307
Registrován: 12 říj 2006 08:52

Re: vir...

#4 Příspěvek od dopa »

no, ona nešla žádná stránka.. všechno zablokoval.
zřejmě to ale bude problém ESETu, jelikož na jiným PC mi taky nejde. Ale zkušební verze jde.
Asi mají chybu v souboru.
projedu combofixem a dám log :)

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: vir...

#5 Příspěvek od Caroprd111 »

OK :)
Obrázek

dopa
Návštěvník
Návštěvník
Příspěvky: 307
Registrován: 12 říj 2006 08:52

Re: vir...

#6 Příspěvek od dopa »

ComboFix 10-03-08.02 - Hanka 09.03.2010 14:38:33.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.2005.1510 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\Programs\Startup\LINKMAGIC.lnk
c:\documents and settings\Hanka\Local Settings\Temporary Internet Files\4j8Y0L.jpg
c:\documents and settings\Hanka\Local Settings\Temporary Internet Files\a61yJm.jpg
c:\documents and settings\Hanka\Local Settings\Temporary Internet Files\nKyylB.jpg
c:\documents and settings\Hanka\Local Settings\Temporary Internet Files\OM478526.jpg

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-09 do 2010-03-09 )))))))))))))))))))))))))))))))
.

2010-03-09 13:30 . 2010-03-09 13:30 3883629 ----a-r- C:\ComboFix.exe
2010-03-09 13:19 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-03-09 13:19 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2010-03-09 13:19 . 2010-03-09 13:19 -------- d-----w- c:\program files\Microsoft.NET
2010-03-09 13:12 . 2010-03-09 13:12 -------- d-----w- c:\program files\ESET
2010-03-09 13:12 . 2010-03-09 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-03-09 13:09 . 2010-03-09 13:09 -------- d-----w- C:\rsit
2010-03-09 13:09 . 2010-03-09 13:09 -------- d-----w- c:\program files\trend micro
2010-03-09 13:08 . 2010-03-09 13:11 -------- d-----w- c:\documents and settings\admin\Application Data\LangSoft
2010-03-09 12:49 . 2010-03-09 12:49 45056 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\TRNOEH.DLL
2010-03-09 12:49 . 2010-03-09 12:49 26624 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\OETRN.EXE
2010-03-09 12:49 . 2010-03-09 12:49 200704 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\TRNOET.DLL
2010-03-09 12:49 . 2010-03-09 12:49 798771 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
2010-03-09 12:49 . 2010-03-09 12:49 299008 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\TrnWord.dll
2010-03-09 12:49 . 2010-03-09 12:49 356352 ----a-w- c:\documents and settings\Hanka\Application Data\LangSoft\TrnOutl.dll
2010-03-09 12:46 . 2010-03-09 12:50 -------- d-----w- c:\program files\TRANSLAT
2010-03-09 12:46 . 2010-03-09 12:46 -------- d-----w- c:\documents and settings\All Users\Application Data\LangSoft
2010-03-09 12:44 . 2010-03-09 13:08 -------- d-----w- c:\documents and settings\Hanka\Application Data\LangSoft
2010-03-09 12:41 . 2010-03-09 12:41 -------- d-----w- c:\documents and settings\Hanka\Application Data\Malwarebytes
2010-03-09 12:22 . 2010-03-09 12:22 -------- d-----w- c:\documents and settings\admin\Application Data\Malwarebytes
2010-03-09 12:22 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-09 12:22 . 2010-03-09 12:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-09 12:22 . 2010-03-09 12:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-09 12:22 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-09 12:21 . 2010-03-09 12:21 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Mozilla
2010-03-09 10:02 . 2010-03-09 10:02 212480 -c--a-w- c:\windows\system32\dllcache\ndis.sys
2010-03-08 15:40 . 2010-03-08 15:41 -------- d-----w- c:\documents and settings\Hanka\Local Settings\Application Data\Adobe
2010-03-08 14:39 . 2010-03-08 14:39 69232 ----a-w- c:\documents and settings\Hanka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-08 14:33 . 2010-03-08 14:33 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-08 14:29 . 2008-04-13 19:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-08 14:29 . 2008-04-13 19:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-08 14:14 . 2010-03-09 13:36 494 ----a-w- c:\windows\system32\SP701ASM.dat
2010-03-08 14:14 . 2010-03-08 14:14 -------- d-----w- C:\PP1390MF_v1.67
2010-03-08 14:08 . 2010-03-08 14:08 0 ----a-w- c:\windows\nsreg.dat
2010-03-08 14:07 . 2010-03-08 14:07 -------- d-----w- c:\documents and settings\Hanka\Local Settings\Application Data\Mozilla
2010-03-08 14:07 . 2008-04-13 19:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-03-08 14:07 . 2008-04-13 19:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-08 14:06 . 2010-01-05 10:00 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-08 14:06 . 2010-01-05 10:00 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-08 14:06 . 2010-01-05 10:00 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-03-08 14:06 . 2010-01-05 10:00 6067200 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-03-08 14:06 . 2010-01-05 10:00 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2010-03-08 14:06 . 2009-12-31 15:33 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2010-03-08 14:06 . 2010-01-05 10:00 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2010-03-08 14:06 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2010-03-08 14:02 . 2010-03-08 14:08 -------- d-----w- c:\documents and settings\Hanka\Local Settings\Application Data\GHISLER
2010-03-08 14:01 . 2010-03-08 14:01 -------- d-----w- c:\documents and settings\Hanka\Application Data\GHISLER
2010-03-08 13:55 . 2010-03-08 13:55 -------- d-sh--w- c:\documents and settings\Hanka\UserData
2010-03-08 13:47 . 2010-03-08 13:47 -------- d-----w- c:\windows\system32\wbem\MUI
2010-03-08 13:45 . 2010-03-08 13:46 -------- d-----w- c:\windows\system32\1029
2010-03-08 13:38 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-08 13:37 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-08 13:36 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-08 13:36 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-08 13:36 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-08 13:36 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-08 13:33 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-08 13:32 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-08 13:29 . 2010-03-08 13:35 -------- d-----w- C:\Public
2010-03-08 13:29 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-08 13:29 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-08 13:29 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-08 13:28 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-08 13:27 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-08 13:27 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-08 13:25 . 2010-03-09 13:30 -------- d-----w- c:\windows\SHELLNEW
2010-03-08 13:25 . 2010-03-08 13:25 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Microsoft Help
2010-03-08 13:24 . 2010-03-09 13:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-08 13:24 . 2010-03-08 13:24 -------- d-----r- C:\MSOCache
2010-03-08 13:24 . 2010-03-08 13:24 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\GHISLER
2010-03-08 13:22 . 2010-03-08 13:25 -------- d-----w- C:\ZALOHA
2010-03-08 13:20 . 2010-03-08 13:20 -------- d-----w- C:\totalcmd
2010-03-08 13:20 . 2010-03-08 13:20 -------- d-----w- c:\documents and settings\admin\Application Data\GHISLER
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\UC.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\RAR.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\LHA.PIF
2010-03-08 13:20 . 2009-09-24 06:50 545 ----a-w- c:\windows\ARJ.PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-09 13:30 . 2010-03-08 13:31 -------- d-----w- c:\program files\Microsoft Works
2010-03-09 12:21 . 2010-03-08 14:13 -------- d-----w- c:\program files\LINKMAGIC
2010-03-09 10:02 . 2004-08-04 12:00 212480 ----a-w- c:\windows\system32\drivers\ndis.sys
2010-03-08 14:13 . 2008-09-03 13:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-08 14:12 . 2008-09-03 13:06 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-05 10:00 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2004-08-04 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43 . 2008-09-03 12:45 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
.

------- Sigcheck -------

[-] 2010-03-09 10:02 . A96053CD60EA94D8CCC401BE9B4586A6 . 212480 . . [------] . . c:\windows\system32\drivers\ndis.sys
[-] 2010-03-09 10:02 . A96053CD60EA94D8CCC401BE9B4586A6 . 212480 . . [------] . . c:\windows\system32\dllcache\ndis.sys
[7] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
[7] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="c:\documents and settings\Hanka\Application Data\LangSoft\OETRN.EXE" [2010-03-09 26624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"atchk"="c:\program files\Intel\AMT\atchk.exe" [2007-06-12 408344]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-29 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-29 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-29 141848]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 9:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 9:06 96408]
R2 atchksrv;Intel(R) Active Management Technology System Status Service;c:\program files\Intel\AMT\atchksrv.exe [3.9.2008 14:05 183064]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 9:04 735960]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [3.9.2008 14:05 2521880]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\Hanka\Application Data\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\m8jg0h9o.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-Nektra OEAPI - (no file)
AddRemove-PC Translator - c:\docume~1\Hanka\LOCALS~1\Temp\UN32.EXE



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
Celkový čas: 2010-03-09 14:41:25
ComboFix-quarantined-files.txt 2010-03-09 13:41

Před spuštěním: 60 955 095 040 bytes free
Po spuštění: 61 042 741 248 bytes free

- - End Of File - - A26DCA85BC6C8FF42D8805DE05B139C6

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: vir...

#7 Příspěvek od Caroprd111 »

Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

Restore::
c:\windows\system32\drivers\ndis.sys
c:\windows\system32\dllcache\ndis.sys
  • Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

    Obrázek
  • Po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Obrázek

Odpovědět