prosim o radu,zkousel jsem už vsechny programy,ale nic se mi nenaslo nebo to nepomohlo posilam log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:03:30, on 26.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F3 - REG:win.ini: load=C:\WINDOWS\destrub.exe
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdiyz.exe] C:\WINDOWS\system32\kdiyz.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: OnScreen Manager.lnk = C:\Program Files\softOSD\softOSM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6673 bytes
díky
malware nebo co
-
- nováček
- Příspěvky: 5
- Registrován: červenec 08
- Pohlaví:
- Stav:
Offline
- fredik
- člen Security týmu
-
Master Level 7
- Příspěvky: 4680
- Registrován: červenec 06
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
Vítej na fóru
Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
-
- nováček
- Příspěvky: 5
- Registrován: červenec 08
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
tahle verze na kterou me odkazujes nefungovala,tak jsem stahhnul Combofix jinde, snad to nebude vadit...
ComboFix 08-07-13.11 - Pepa 2008-07-30 17:24:56.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1634 [GMT 2:00]
Running from: C:\Documents and Settings\Pepa\Plocha\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))
.
2008-07-27 08:23 . 2008-07-30 17:21 3,533 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-26 22:03 . 2008-07-26 22:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-26 21:43 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-07-26 21:29 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-26 21:29 . 2008-07-26 21:43 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\SUPERAntiSpyware.com
2008-07-26 21:29 . 2008-07-26 21:29 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2008-07-26 20:27 . 2008-07-26 21:45 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-07-26 20:17 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-26 20:17 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-26 20:17 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-26 20:17 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-26 20:17 . 2008-07-26 20:17 3,194 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-07-26 19:03 . 2008-06-04 05:20 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-07-26 19:03 . 2008-07-26 19:03 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-26 18:42 . 2008-07-26 19:59 <DIR> d-------- C:\Program Files\Common Files\Softwin
2008-07-26 18:24 . 2008-07-26 18:31 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Spyware Terminator
2008-07-26 17:39 . 2008-07-26 17:39 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-26 17:39 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 17:39 . 2008-07-26 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2008-07-26 17:15 . 2008-07-26 17:15 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\ESET
2008-07-17 11:12 . 2008-07-17 11:14 36,363 --a------ C:\WINDOWS\CSTBox.INI
2008-07-14 19:24 . 2008-07-14 19:24 47,104 -r--s---- C:\WINDOWS\destrub.exe
2008-07-02 19:12 . 2008-07-02 19:19 <DIR> d-------- C:\Program Files\ICQ6
2008-07-02 19:12 . 2008-07-02 19:19 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\ICQ
2008-07-02 18:04 . 2008-07-24 18:09 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\skypePM
2008-07-02 18:04 . 2008-07-02 18:04 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Program Files\Skype
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-07-02 18:02 . 2008-07-24 19:09 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Skype
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Skype
2008-07-02 17:37 . 2008-07-26 17:37 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-26 22:48 . 2004-08-17 15:49 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-26 15:31 . 2008-07-26 12:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-26 15:31 . 2008-06-26 15:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-13 21:20 . 2008-06-13 21:23 <DIR> d-------- C:\Program Files\Return to Castle Wolfenstein
2008-06-13 21:10 . 2008-06-13 21:23 810 --a------ C:\WINDOWS\Rtcw.INI
2008-06-13 21:03 . 2008-06-13 21:03 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Apple Computer
2008-06-13 19:41 . 2007-10-12 04:00 3,647,384 -ra------ C:\WINDOWS\system32\drivers\lvuvc.sys
2008-06-13 19:41 . 2007-10-12 03:59 1,920,920 -ra------ C:\WINDOWS\system32\drivers\lvpopflt.sys
2008-06-13 19:41 . 2007-10-12 04:00 490,008 -ra------ C:\WINDOWS\system32\LVUI2.dll
2008-06-13 19:41 . 2007-10-12 04:00 465,432 -ra------ C:\WINDOWS\system32\LVUI2RC.dll
2008-06-13 19:41 . 2007-10-12 03:57 416,280 -ra------ C:\WINDOWS\system32\lvcodec2.dll
2008-06-13 19:41 . 2007-10-12 03:57 195,096 -ra------ C:\WINDOWS\system32\lvci1150.dll
2008-06-13 19:41 . 2007-10-12 03:11 59,500 -ra------ C:\WINDOWS\system32\lvcoinst.ini
2008-06-13 19:41 . 2007-10-12 04:00 41,752 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-06-13 19:41 . 2007-10-12 04:01 23,832 -ra------ C:\WINDOWS\system32\drivers\lvuvcflt.sys
2008-06-13 19:41 . 2007-10-12 03:18 21,138 -ra------ C:\WINDOWS\system32\Repository.reg
2008-06-13 19:38 . 2008-06-13 19:41 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2008-06-13 19:09 . 2008-06-13 19:09 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-06-13 19:07 . 2008-07-30 17:22 0 --a------ C:\WINDOWS\system32\drivers\lvuvc.hs
2008-06-13 19:06 . 2004-08-03 23:08 48,640 --a------ C:\WINDOWS\system32\drivers\stream.sys
2008-06-13 19:06 . 2004-08-03 23:08 48,640 --a--c--- C:\WINDOWS\system32\dllcache\stream.sys
2008-06-13 19:06 . 2008-07-30 17:22 0 --a------ C:\WINDOWS\system32\drivers\logiflt.iad
2008-06-13 19:05 . 2008-06-13 19:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-13 19:04 . 2008-06-13 19:37 <DIR> d-------- C:\Program Files\Logitech
2008-06-13 19:04 . 2008-06-13 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Logitech
2008-06-13 19:04 . 2008-06-13 19:38 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Logishrd
2008-06-13 18:56 . 2004-08-17 15:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-13 18:56 . 2004-08-17 15:45 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-13 18:51 . 2008-06-13 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2008-06-13 18:50 . 2008-06-13 18:50 <DIR> d-------- C:\Program Files\IVT Corporation
2008-06-13 18:50 . 2008-06-13 18:51 32 --a------ C:\WINDOWS\0
2008-06-13 18:50 . 2008-06-13 18:50 0 --a------ C:\WINDOWS\system32\0
2008-06-10 18:56 . 2008-06-10 18:56 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-06-10 18:48 . 2008-06-10 18:48 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-06-10 18:47 . 2008-06-10 18:47 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2008-06-04 19:56 . 2008-06-04 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CanonIJPLM
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\Program Files\CanonBJ
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
2008-06-04 19:55 . 2007-04-16 07:00 215,040 --a------ C:\WINDOWS\system32\CNMLM8V.DLL
2008-06-04 19:49 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-06-04 19:49 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-06-04 19:03 . 2008-06-04 19:06 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Canon
2008-06-04 18:56 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-04 18:56 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-04 18:55 . 2008-06-04 19:56 <DIR> d-------- C:\Program Files\Canon
2008-06-04 18:55 . 2008-06-04 18:55 <DIR> d--h----- C:\CanoScan
2008-06-04 18:55 . 2005-06-23 22:17 352,256 --a------ C:\WINDOWS\system32\CNQL1213.DLL
2008-06-04 18:55 . 2005-02-28 13:20 57,344 --a------ C:\WINDOWS\system32\CNQU110.DLL
2008-06-04 18:10 . 2008-06-04 18:10 59 --a------ C:\WINDOWS\wininit.ini
2008-06-04 18:02 . 2008-06-04 18:02 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Ahead
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Program Files\Nero
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Nero
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Real
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Common Files\Real
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Program Files\QuickTime
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple
2008-06-04 17:40 . 2008-07-26 17:15 <DIR> d-------- C:\Program Files\ESET
2008-06-04 17:38 . 2008-06-04 17:38 <DIR> d-------- C:\Program Files\FastStone Image Viewer
2008-06-04 17:38 . 2008-06-04 17:38 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\FastStone
2008-06-04 17:37 . 2008-06-04 17:37 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-04 17:34 . 2008-07-30 10:12 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\OpenOffice.org2
2008-06-04 17:32 . 2008-06-04 17:37 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2008-06-04 17:31 . 2008-06-04 18:08 <DIR> d-------- C:\Program Files\Java
2008-06-04 17:31 . 2008-06-04 17:31 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-04 17:31 . 2008-06-04 17:31 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-04 17:31 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-04 17:28 . 2008-06-05 17:53 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-04 17:23 . 2008-06-04 17:23 <DIR> d-------- C:\Program Files\Winamp
2008-06-04 17:23 . 2008-06-04 17:23 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Winamp
2008-06-04 17:15 . 2008-07-30 17:12 <DIR> d-------- C:\Program Files\Altap Salamander 2.5
2008-06-04 17:14 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-04 00:13 . 2008-06-04 00:13 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-06-04 00:13 . 2008-06-04 00:13 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-06-04 00:13 . 2008-06-04 00:13 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-06-04 00:07 . 2005-05-03 18:43 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2008-06-03 23:59 . 2008-06-04 00:07 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-06-03 23:58 . 2008-06-03 23:58 <DIR> d-------- C:\Program Files\Realtek
2008-06-03 23:58 . 2008-07-02 19:15 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-03 23:58 . 2008-03-05 18:07 520,192 --a------ C:\WINDOWS\RtlExUpd.dll
2008-06-03 23:58 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-03 23:56 . 2008-04-30 17:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-06-03 23:56 . 2006-03-23 20:51 208,896 --------- C:\WINDOWS\system32\nvusmb.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 03:23 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 13:39 16,862,208 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-04-02 07:27 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 13:06 40048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-04 17:43 185896]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 18:52 1447168]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 15:39 16862208 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\se32.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Altap Salamander 2.5\\SALAMAND.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Return to Castle Wolfenstein\\WolfMP.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-06-10 18:56]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-02-20 13:34]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-02-20 13:34]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 17:49]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-C:\WINDOWS\system32\kdiyz.exe - C:\WINDOWS\system32\kdiyz.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-30 17:25:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\ComboFix\CreateD00
C:\ComboFix\CreateD00
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2008-07-30 17:26:53
Adresářů: 5, Volných bajtů: 4,114,477,056
Adresářů: 9, Volných bajtů: 4,105,515,008
209
ComboFix 08-07-13.11 - Pepa 2008-07-30 17:24:56.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1634 [GMT 2:00]
Running from: C:\Documents and Settings\Pepa\Plocha\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))
.
2008-07-27 08:23 . 2008-07-30 17:21 3,533 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-26 22:03 . 2008-07-26 22:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-26 21:43 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-07-26 21:29 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-26 21:29 . 2008-07-26 21:43 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\SUPERAntiSpyware.com
2008-07-26 21:29 . 2008-07-26 21:29 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2008-07-26 20:27 . 2008-07-26 21:45 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-07-26 20:17 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-26 20:17 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-26 20:17 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-26 20:17 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-26 20:17 . 2008-07-26 20:17 3,194 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-07-26 19:03 . 2008-06-04 05:20 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-07-26 19:03 . 2008-06-04 04:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-07-26 19:03 . 2008-07-26 19:03 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-26 18:42 . 2008-07-26 19:59 <DIR> d-------- C:\Program Files\Common Files\Softwin
2008-07-26 18:24 . 2008-07-26 18:31 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Spyware Terminator
2008-07-26 17:39 . 2008-07-26 17:39 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-26 17:39 . 2008-07-26 21:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 17:39 . 2008-07-26 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2008-07-26 17:15 . 2008-07-26 17:15 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\ESET
2008-07-17 11:12 . 2008-07-17 11:14 36,363 --a------ C:\WINDOWS\CSTBox.INI
2008-07-14 19:24 . 2008-07-14 19:24 47,104 -r--s---- C:\WINDOWS\destrub.exe
2008-07-02 19:12 . 2008-07-02 19:19 <DIR> d-------- C:\Program Files\ICQ6
2008-07-02 19:12 . 2008-07-02 19:19 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\ICQ
2008-07-02 18:04 . 2008-07-24 18:09 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\skypePM
2008-07-02 18:04 . 2008-07-02 18:04 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Program Files\Skype
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-07-02 18:02 . 2008-07-24 19:09 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Skype
2008-07-02 18:02 . 2008-07-02 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Skype
2008-07-02 17:37 . 2008-07-26 17:37 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-26 22:48 . 2004-08-17 15:49 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-26 15:31 . 2008-07-26 12:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-26 15:31 . 2008-06-26 15:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-13 21:20 . 2008-06-13 21:23 <DIR> d-------- C:\Program Files\Return to Castle Wolfenstein
2008-06-13 21:10 . 2008-06-13 21:23 810 --a------ C:\WINDOWS\Rtcw.INI
2008-06-13 21:03 . 2008-06-13 21:03 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Apple Computer
2008-06-13 19:41 . 2007-10-12 04:00 3,647,384 -ra------ C:\WINDOWS\system32\drivers\lvuvc.sys
2008-06-13 19:41 . 2007-10-12 03:59 1,920,920 -ra------ C:\WINDOWS\system32\drivers\lvpopflt.sys
2008-06-13 19:41 . 2007-10-12 04:00 490,008 -ra------ C:\WINDOWS\system32\LVUI2.dll
2008-06-13 19:41 . 2007-10-12 04:00 465,432 -ra------ C:\WINDOWS\system32\LVUI2RC.dll
2008-06-13 19:41 . 2007-10-12 03:57 416,280 -ra------ C:\WINDOWS\system32\lvcodec2.dll
2008-06-13 19:41 . 2007-10-12 03:57 195,096 -ra------ C:\WINDOWS\system32\lvci1150.dll
2008-06-13 19:41 . 2007-10-12 03:11 59,500 -ra------ C:\WINDOWS\system32\lvcoinst.ini
2008-06-13 19:41 . 2007-10-12 04:00 41,752 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-06-13 19:41 . 2007-10-12 04:01 23,832 -ra------ C:\WINDOWS\system32\drivers\lvuvcflt.sys
2008-06-13 19:41 . 2007-10-12 03:18 21,138 -ra------ C:\WINDOWS\system32\Repository.reg
2008-06-13 19:38 . 2008-06-13 19:41 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2008-06-13 19:09 . 2008-06-13 19:09 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-06-13 19:07 . 2008-07-30 17:22 0 --a------ C:\WINDOWS\system32\drivers\lvuvc.hs
2008-06-13 19:06 . 2004-08-03 23:08 48,640 --a------ C:\WINDOWS\system32\drivers\stream.sys
2008-06-13 19:06 . 2004-08-03 23:08 48,640 --a--c--- C:\WINDOWS\system32\dllcache\stream.sys
2008-06-13 19:06 . 2008-07-30 17:22 0 --a------ C:\WINDOWS\system32\drivers\logiflt.iad
2008-06-13 19:05 . 2008-06-13 19:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-13 19:04 . 2008-06-13 19:37 <DIR> d-------- C:\Program Files\Logitech
2008-06-13 19:04 . 2008-06-13 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Logitech
2008-06-13 19:04 . 2008-06-13 19:38 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Logishrd
2008-06-13 18:56 . 2004-08-17 15:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-13 18:56 . 2004-08-17 15:45 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-13 18:51 . 2008-06-13 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Bluetooth
2008-06-13 18:50 . 2008-06-13 18:50 <DIR> d-------- C:\Program Files\IVT Corporation
2008-06-13 18:50 . 2008-06-13 18:51 32 --a------ C:\WINDOWS\0
2008-06-13 18:50 . 2008-06-13 18:50 0 --a------ C:\WINDOWS\system32\0
2008-06-10 18:56 . 2008-06-10 18:56 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-06-10 18:48 . 2008-06-10 18:48 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-06-10 18:47 . 2008-06-10 18:47 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2008-06-04 19:56 . 2008-06-04 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CanonIJPLM
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\Program Files\CanonBJ
2008-06-04 19:55 . 2008-06-04 19:55 <DIR> d--h----- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
2008-06-04 19:55 . 2007-04-16 07:00 215,040 --a------ C:\WINDOWS\system32\CNMLM8V.DLL
2008-06-04 19:49 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-06-04 19:49 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-06-04 19:03 . 2008-06-04 19:06 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Canon
2008-06-04 18:56 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-04 18:56 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-04 18:55 . 2008-06-04 19:56 <DIR> d-------- C:\Program Files\Canon
2008-06-04 18:55 . 2008-06-04 18:55 <DIR> d--h----- C:\CanoScan
2008-06-04 18:55 . 2005-06-23 22:17 352,256 --a------ C:\WINDOWS\system32\CNQL1213.DLL
2008-06-04 18:55 . 2005-02-28 13:20 57,344 --a------ C:\WINDOWS\system32\CNQU110.DLL
2008-06-04 18:10 . 2008-06-04 18:10 59 --a------ C:\WINDOWS\wininit.ini
2008-06-04 18:02 . 2008-06-04 18:02 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Ahead
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Program Files\Nero
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-04 17:52 . 2008-06-04 17:52 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Nero
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Real
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-06-04 17:43 . 2008-06-04 17:43 <DIR> d-------- C:\Program Files\Common Files\Real
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Program Files\QuickTime
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-06-04 17:42 . 2008-06-04 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple
2008-06-04 17:40 . 2008-07-26 17:15 <DIR> d-------- C:\Program Files\ESET
2008-06-04 17:38 . 2008-06-04 17:38 <DIR> d-------- C:\Program Files\FastStone Image Viewer
2008-06-04 17:38 . 2008-06-04 17:38 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\FastStone
2008-06-04 17:37 . 2008-06-04 17:37 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-04 17:34 . 2008-07-30 10:12 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\OpenOffice.org2
2008-06-04 17:32 . 2008-06-04 17:37 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2008-06-04 17:31 . 2008-06-04 18:08 <DIR> d-------- C:\Program Files\Java
2008-06-04 17:31 . 2008-06-04 17:31 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-04 17:31 . 2008-06-04 17:31 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-04 17:31 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-04 17:28 . 2008-06-05 17:53 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-04 17:23 . 2008-06-04 17:23 <DIR> d-------- C:\Program Files\Winamp
2008-06-04 17:23 . 2008-06-04 17:23 <DIR> d-------- C:\Documents and Settings\Pepa\Data aplikací\Winamp
2008-06-04 17:15 . 2008-07-30 17:12 <DIR> d-------- C:\Program Files\Altap Salamander 2.5
2008-06-04 17:14 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-04 00:13 . 2008-06-04 00:13 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-06-04 00:13 . 2008-06-04 00:13 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-06-04 00:13 . 2008-06-04 00:13 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-06-04 00:07 . 2005-05-03 18:43 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2008-06-03 23:59 . 2008-06-04 00:07 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-06-03 23:58 . 2008-06-03 23:58 <DIR> d-------- C:\Program Files\Realtek
2008-06-03 23:58 . 2008-07-02 19:15 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-03 23:58 . 2008-03-05 18:07 520,192 --a------ C:\WINDOWS\RtlExUpd.dll
2008-06-03 23:58 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-03 23:56 . 2008-04-30 17:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-06-03 23:56 . 2006-03-23 20:51 208,896 --------- C:\WINDOWS\system32\nvusmb.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 03:23 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 13:39 16,862,208 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-04-02 07:27 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 13:06 40048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-04 17:43 185896]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 18:52 1447168]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 15:39 16862208 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\se32.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Altap Salamander 2.5\\SALAMAND.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Return to Castle Wolfenstein\\WolfMP.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-06-10 18:56]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-02-20 13:34]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-02-20 13:34]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 17:49]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-C:\WINDOWS\system32\kdiyz.exe - C:\WINDOWS\system32\kdiyz.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-30 17:25:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\ComboFix\CreateD00
C:\ComboFix\CreateD00
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2008-07-30 17:26:53
Adresářů: 5, Volných bajtů: 4,114,477,056
Adresářů: 9, Volných bajtů: 4,105,515,008
209
- fredik
- člen Security týmu
-
Master Level 7
- Příspěvky: 4680
- Registrován: červenec 06
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
Spusť znovu HijackThis a zaškrtni v něm okénka před řádky pokud tam budou:
F3 - REG:win.ini: load=C:\WINDOWS\destrub.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdiyz.exe] C:\WINDOWS\system32\kdiyz.exe
po zaškrtnutí klikni na tlačítko Fix Checked
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Otestuj tento soubor na VirusTotal
C:\WINDOWS\destrub.exe
stačí jen zkopírovat na té stránce do toho prázdného okénka celou cestu a dát odeslat. Pak sem vlož výsledek.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující text označený zeleně:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE
Pak dej Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: fixp.reg
Uložit jako typ: tak tam vyber Všechny soubory
Ulož si daný soubor na plochu
Na ploše by se měl objevit soubor
fixp.reg
- spusť ho vyskočí hláška kde odklikni Ano poté je další hláška kde odklikni OK
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Doporučil bych ti aktualizovat Javu:
- Stáhni si poslední verzi Java Runtime Environment (JRE) 6 Update 7
- Posuň se dolů kde je napsáno Java Runtime Environment (JRE) 6 Update 7 a klikni na tlačítko Download
- Načte se ti nová stránka
- Pod nadpisem Select Platform and Language for your download:
* u položky Platform: vyber OS který používáš
* zatrhni možnost kde je napsáno: I agree to the Java SE Runtime Environment 6 License Agreement
* klikni na tlačítko Continue >>
- Načte se ti nová stránka
- Klikni na odkaz pro stažení pod položkou: Windows Offline Installation

a ulož si ho na disk
- Ukonči běžící programy které máš spuštěné, hlavě webový prohlížeč
- Jdi přes Start -> Ovládací panely -> Přidat nebo odebrat programy a odinstaluj všechny staré verze Javy
- Podívej se po položkách s názvem Java Runtime Environment (JRE or J2SE)
* příklady starých verzí v Přidat nebo odebrat programy:
- Odinstaluj postupně po sobě případné všechny staré verze Javy
- Po skončení odinstalovaní restartuj Pc.
- Pak už jen spusť instalaci poslední verze ze souboru jre-6u7-windows-i586-p.exe, který sis stáhl na začátku
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Dej sem pak i nový log z HJT.
F3 - REG:win.ini: load=C:\WINDOWS\destrub.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdiyz.exe] C:\WINDOWS\system32\kdiyz.exe
po zaškrtnutí klikni na tlačítko Fix Checked
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Otestuj tento soubor na VirusTotal
C:\WINDOWS\destrub.exe
stačí jen zkopírovat na té stránce do toho prázdného okénka celou cestu a dát odeslat. Pak sem vlož výsledek.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující text označený zeleně:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE
Kód: Vybrat vše
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
Pak dej Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: fixp.reg
Uložit jako typ: tak tam vyber Všechny soubory
Ulož si daný soubor na plochu
Na ploše by se měl objevit soubor

- spusť ho vyskočí hláška kde odklikni Ano poté je další hláška kde odklikni OK
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Doporučil bych ti aktualizovat Javu:
- Stáhni si poslední verzi Java Runtime Environment (JRE) 6 Update 7
- Posuň se dolů kde je napsáno Java Runtime Environment (JRE) 6 Update 7 a klikni na tlačítko Download
- Načte se ti nová stránka
- Pod nadpisem Select Platform and Language for your download:
* u položky Platform: vyber OS který používáš
* zatrhni možnost kde je napsáno: I agree to the Java SE Runtime Environment 6 License Agreement
* klikni na tlačítko Continue >>
- Načte se ti nová stránka
- Klikni na odkaz pro stažení pod položkou: Windows Offline Installation
a ulož si ho na disk
- Ukonči běžící programy které máš spuštěné, hlavě webový prohlížeč
- Jdi přes Start -> Ovládací panely -> Přidat nebo odebrat programy a odinstaluj všechny staré verze Javy
- Podívej se po položkách s názvem Java Runtime Environment (JRE or J2SE)
* příklady starých verzí v Přidat nebo odebrat programy:
- J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment, SE v1.4.2
- Odinstaluj postupně po sobě případné všechny staré verze Javy
- Po skončení odinstalovaní restartuj Pc.
- Pak už jen spusť instalaci poslední verze ze souboru jre-6u7-windows-i586-p.exe, který sis stáhl na začátku
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Dej sem pak i nový log z HJT.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
-
- nováček
- Příspěvky: 5
- Registrován: červenec 08
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
VIRUS TOTAL :
Soubor destrub.exe přijatý 2008.08.06 16:14:14 (CET)
Současný stav: Dokončeno
Výsledek: 10/36 (27.78%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2008.8.6.2 2008.08.06 -
AntiVir 7.8.1.15 2008.08.06 -
Authentium 5.1.0.4 2008.08.05 -
Avast 4.8.1195.0 2008.08.06 Win32:Trojan-gen {Other}
AVG 8.0.0.156 2008.08.06 SHeur.BVPU
BitDefender 7.2 2008.08.06 -
CAT-QuickHeal 9.50 2008.08.06 -
ClamAV 0.93.1 2008.08.06 -
DrWeb 4.44.0.09170 2008.08.06 -
eSafe 7.0.17.0 2008.08.06 Suspicious File
eTrust-Vet 31.6.6015 2008.08.06 -
Ewido 4.0 2008.08.06 -
F-Prot 4.4.4.56 2008.08.05 -
F-Secure 7.60.13501.0 2008.08.06 Hoax.Win32.Agent.dw
Fortinet 3.14.0.0 2008.08.06 Misc/Agent
GData 2.0.7306.1023 2008.08.06 Hoax.Win32.Agent.dw
Ikarus T3.1.1.34.0 2008.08.06 Virus.Win32.Trojan
K7AntiVirus 7.10.405 2008.08.06 -
Kaspersky 7.0.0.125 2008.08.06 Hoax.Win32.Agent.dw
McAfee 5354 2008.08.05 -
Microsoft 1.3807 2008.08.06 -
NOD32v2 3332 2008.08.06 -
Norman 5.80.02 2008.08.06 W32/Agent.GRYL
Panda 9.0.0.4 2008.08.06 -
PCTools 4.4.2.0 2008.08.06 -
Prevx1 V2 2008.08.06 -
Rising 20.56.22.00 2008.08.06 -
Sophos 4.31.0 2008.08.06 -
Sunbelt 3.1.1537.1 2008.08.06 -
Symantec 10 2008.08.06 -
TheHacker 6.2.96.393 2008.08.04 -
TrendMicro 8.700.0.1004 2008.08.06 PAK_Generic.001
VBA32 3.12.8.2 2008.08.05 -
ViRobot 2008.8.6.1326 2008.08.06 -
VirusBuster 4.5.11.0 2008.08.05 -
Webwasher-Gateway 6.6.2 2008.08.06 -
Rozšiřující informace
File size: 47104 bytes
MD5...: 5458c618bf7c23c52614b6c751870730
SHA1..: 011f0eb01b83b6b7ac0d82ced9e54f6319db22d0
SHA256: e8cd9b1f917fd26ee66113a32ad9f767085a16076e4f5106fd9d2e8b95ed42a1
SHA512: cbdaf90fce3731d819e8ba3fc567c6a487ed1d0f34b7c9b710bd0c1061712656
c721136ac64091465b01c7d6321f945ac4fc987e7d16390b1e28c1794f38d98a
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x416a00
timedatestamp.....: 0x4872844e (Mon Jul 07 21:02:06 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x11000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x12000 0x5000 0x4c00 7.86 1c467324c7b9d1ee64d1b3ce0c448b78
.rsrc 0x17000 0x7000 0x6800 5.28 ff12745a5527489167878fa64c60102e
( 5 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: RegCloseKey
> ntdll.dll: ZwSystemDebugControl
> SHELL32.dll: ShellExecuteA
> USER32.dll: LoadIconA
( 0 exports )
ThreatExpert info: http://www.threatexpert.com/report.aspx ... c751870730
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX, embedded
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:50:55, on 6.8.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6512 bytes
Soubor destrub.exe přijatý 2008.08.06 16:14:14 (CET)
Současný stav: Dokončeno
Výsledek: 10/36 (27.78%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2008.8.6.2 2008.08.06 -
AntiVir 7.8.1.15 2008.08.06 -
Authentium 5.1.0.4 2008.08.05 -
Avast 4.8.1195.0 2008.08.06 Win32:Trojan-gen {Other}
AVG 8.0.0.156 2008.08.06 SHeur.BVPU
BitDefender 7.2 2008.08.06 -
CAT-QuickHeal 9.50 2008.08.06 -
ClamAV 0.93.1 2008.08.06 -
DrWeb 4.44.0.09170 2008.08.06 -
eSafe 7.0.17.0 2008.08.06 Suspicious File
eTrust-Vet 31.6.6015 2008.08.06 -
Ewido 4.0 2008.08.06 -
F-Prot 4.4.4.56 2008.08.05 -
F-Secure 7.60.13501.0 2008.08.06 Hoax.Win32.Agent.dw
Fortinet 3.14.0.0 2008.08.06 Misc/Agent
GData 2.0.7306.1023 2008.08.06 Hoax.Win32.Agent.dw
Ikarus T3.1.1.34.0 2008.08.06 Virus.Win32.Trojan
K7AntiVirus 7.10.405 2008.08.06 -
Kaspersky 7.0.0.125 2008.08.06 Hoax.Win32.Agent.dw
McAfee 5354 2008.08.05 -
Microsoft 1.3807 2008.08.06 -
NOD32v2 3332 2008.08.06 -
Norman 5.80.02 2008.08.06 W32/Agent.GRYL
Panda 9.0.0.4 2008.08.06 -
PCTools 4.4.2.0 2008.08.06 -
Prevx1 V2 2008.08.06 -
Rising 20.56.22.00 2008.08.06 -
Sophos 4.31.0 2008.08.06 -
Sunbelt 3.1.1537.1 2008.08.06 -
Symantec 10 2008.08.06 -
TheHacker 6.2.96.393 2008.08.04 -
TrendMicro 8.700.0.1004 2008.08.06 PAK_Generic.001
VBA32 3.12.8.2 2008.08.05 -
ViRobot 2008.8.6.1326 2008.08.06 -
VirusBuster 4.5.11.0 2008.08.05 -
Webwasher-Gateway 6.6.2 2008.08.06 -
Rozšiřující informace
File size: 47104 bytes
MD5...: 5458c618bf7c23c52614b6c751870730
SHA1..: 011f0eb01b83b6b7ac0d82ced9e54f6319db22d0
SHA256: e8cd9b1f917fd26ee66113a32ad9f767085a16076e4f5106fd9d2e8b95ed42a1
SHA512: cbdaf90fce3731d819e8ba3fc567c6a487ed1d0f34b7c9b710bd0c1061712656
c721136ac64091465b01c7d6321f945ac4fc987e7d16390b1e28c1794f38d98a
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x416a00
timedatestamp.....: 0x4872844e (Mon Jul 07 21:02:06 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x11000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x12000 0x5000 0x4c00 7.86 1c467324c7b9d1ee64d1b3ce0c448b78
.rsrc 0x17000 0x7000 0x6800 5.28 ff12745a5527489167878fa64c60102e
( 5 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: RegCloseKey
> ntdll.dll: ZwSystemDebugControl
> SHELL32.dll: ShellExecuteA
> USER32.dll: LoadIconA
( 0 exports )
ThreatExpert info: http://www.threatexpert.com/report.aspx ... c751870730
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX, embedded
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:50:55, on 6.8.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6512 bytes
- fredik
- člen Security týmu
-
Master Level 7
- Příspěvky: 4680
- Registrován: červenec 06
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
Stáhni si program OTMoveIt2 (by OldTimer) a ulož si ho na disk C a spusť ho.
- zatrhni možnost Zip Files After Move
- Do levého sloupce (Paste List Of Files/Folders to Move) zkopíruj tuto cestu:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď
V tomoto adresáři C:\_OTMoveIt\MovedFiles\ se ti vytvoří archiv ve formátu 08062008_201235.zip (datum_čas.zip) Pošli tento archiv přes SZ jako přílohu dík, případně ji vlož jako přílohu do dalšího příspěvku. Zkus ale spíš tu první možnost.
- zatrhni možnost Zip Files After Move
- Do levého sloupce (Paste List Of Files/Folders to Move) zkopíruj tuto cestu:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
C:\WINDOWS\destrub.exe
EmptyTemp
- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď
V tomoto adresáři C:\_OTMoveIt\MovedFiles\ se ti vytvoří archiv ve formátu 08062008_201235.zip (datum_čas.zip) Pošli tento archiv přes SZ jako přílohu dík, případně ji vlož jako přílohu do dalšího příspěvku. Zkus ale spíš tu první možnost.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
-
- nováček
- Příspěvky: 5
- Registrován: červenec 08
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
C:\WINDOWS\destrub.exe moved successfully.
< EmptyTemp >
Temp folders emptied.
IE temp folders emptied.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09022008_185010
< EmptyTemp >
Temp folders emptied.
IE temp folders emptied.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09022008_185010
-
- nováček
- Příspěvky: 5
- Registrován: červenec 08
- Pohlaví:
- Stav:
Offline
Re: malware nebo co
bohuzel se mi zadnej .zip nevytvořil,ale snad už to bude ok
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 121 hostů