NTB uz zase neni moc ve forme Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: NTB uz zase neni moc ve forme  Vyřešeno

Příspěvekod Žbeky » 03 srp 2012 09:26

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::

Folder::
c:\program files\Google\Update

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\system32\drivers\ehdrv.sys
c:\windows\system32\drivers\epfwtdir.sys

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2221:TCP"=-
"2222:TCP"=-
"2223:TCP"=-
"2224:TCP"=-
"2846:TCP"=-

Driver::
ehdrv
epfwtdir

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Reklama
pechytce
Level 2
Level 2
Příspěvky: 182
Registrován: květen 09
Pohlaví: Muž
Stav:
Offline

Re: NTB uz zase neni moc ve forme

Příspěvekod pechytce » 03 srp 2012 19:34

ComboFix 12-07-31.03 - pechy 03.08.2012 19:09:28.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.502.275 [GMT 2:00]
Spuštěný z: c:\documents and settings\pechy\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\pechy\Plocha\CFScript.txt
AV: Eset NOD32 Antivirus 2.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\windows\system32\drivers\ehdrv.sys"
"c:\windows\system32\drivers\epfwtdir.sys"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.115\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.115\goopdate.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.115\psmachine.dll
c:\program files\Google\Update\1.3.21.115\psuser.dll
c:\program files\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\0.0.0.0\gsync.msi
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EHDRV
-------\Legacy_EPFWTDIR
-------\Service_ehdrv
-------\Service_epfwtdir
-------\Legacy_gupdate
-------\Legacy_gupdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-03 do 2012-08-03 )))))))))))))))))))))))))))))))
.
.
2012-08-02 19:51 . 2012-08-02 19:51 9827016 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-08-01 05:00 . 2012-08-01 05:00 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-07-31 22:02 . 2012-07-31 22:02 -------- d-----w- c:\documents and settings\pechy\Data aplikací\Malwarebytes
2012-07-31 22:01 . 2012-07-31 22:01 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-07-31 18:43 . 2012-07-31 18:43 388096 ----a-r- c:\documents and settings\pechy\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-31 18:43 . 2012-07-31 18:43 -------- d-----w- c:\program files\Trend Micro
2012-07-27 17:51 . 2001-08-17 19:51 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2012-07-27 17:51 . 2001-08-17 19:51 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2012-07-27 17:51 . 2008-04-14 03:22 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2012-07-27 17:51 . 2008-04-14 03:22 152064 ----a-w- c:\windows\system32\irftp.exe
2012-07-27 17:51 . 2008-04-14 03:22 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2012-07-27 17:51 . 2008-04-14 03:22 8192 ----a-w- c:\windows\system32\wshirda.dll
2012-07-27 17:51 . 2008-04-14 03:21 27648 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2012-07-27 17:51 . 2008-04-14 03:21 27648 ----a-w- c:\windows\system32\irmon.dll
2012-07-27 17:51 . 2008-04-13 18:54 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2012-07-27 17:51 . 2008-04-13 18:54 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2012-07-27 17:50 . 2001-08-17 19:49 26624 -c--a-w- c:\windows\system32\dllcache\irstusb.sys
2012-07-27 17:50 . 2001-08-17 19:49 26624 ----a-w- c:\windows\system32\drivers\irstusb.sys
2012-07-27 17:43 . 2006-10-25 15:05 640000 ----a-w- c:\windows\system32\Calculate.dll
2012-07-27 17:43 . 2004-07-05 11:18 430592 ----a-w- c:\windows\system32\Old.dll
2012-07-27 17:43 . 2004-07-05 08:52 15259 ----a-w- c:\windows\system32\compress.exe
2012-07-27 17:42 . 2012-07-27 17:43 -------- d-----w- c:\program files\SmartTRAK
2012-07-24 08:18 . 2012-07-24 14:12 -------- d-----w- c:\documents and settings\pechy\Data aplikací\GeoSetter
2012-07-24 07:08 . 2012-07-24 07:08 -------- d-----r- c:\program files\Skype
2012-07-24 07:08 . 2012-07-24 07:08 -------- d-----w- c:\program files\Common Files\Skype
2012-07-06 14:49 . 2012-07-06 15:34 -------- d-----w- C:\j
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 19:51 . 2012-04-09 17:22 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-02 19:51 . 2011-10-21 16:43 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:55 . 2001-10-25 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2009-08-19 15:07 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2001-10-25 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2001-10-25 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-08-06 17:24 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2011-10-21 16:01 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2011-10-21 16:01 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2011-10-21 16:01 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2011-10-21 16:01 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2011-10-21 12:54 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2001-10-25 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2011-10-21 16:01 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2011-10-21 12:54 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2011-12-16 18:34 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2011-12-16 18:34 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2009-08-06 18:23 214256 ----a-w- c:\windows\system32\muweb.dll
2012-05-31 13:22 . 2001-10-25 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-24 21:18 . 2012-05-24 21:18 4472832 ----a-w- c:\windows\system32\GPhotos.scr
2012-05-16 15:09 . 2001-10-25 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:44 . 2001-10-25 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2001-10-25 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2011-10-21 16:01 385024 ------w- c:\windows\system32\html.iec
2011-08-11 11:18 . 2011-08-11 11:18 128960 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2011-08-10 22:16 . 2011-08-10 22:16 96192 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2011-08-11 11:18 . 2011-08-11 11:18 92096 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2011-08-11 11:18 . 2011-08-11 11:18 22976 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2011-08-11 11:18 . 2011-08-11 11:18 370624 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2011-08-11 11:18 . 2011-08-11 11:18 32192 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2011-08-11 11:18 . 2011-08-11 11:18 40896 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2011-08-10 22:18 . 2011-08-10 22:18 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2011-08-10 22:16 . 2011-08-10 22:16 24512 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-06-11 06:28 . 2012-01-07 22:13 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-01_11.46.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-03 17:22 . 2012-08-03 17:22 16384 c:\windows\temp\Perflib_Perfdata_7b8.dat
+ 2001-10-25 12:00 . 2012-08-02 18:59 68976 c:\windows\system32\perfc009.dat
- 2001-10-25 12:00 . 2012-07-31 21:40 68976 c:\windows\system32\perfc009.dat
+ 2001-10-25 12:00 . 2012-08-02 18:59 79926 c:\windows\system32\perfc005.dat
+ 2001-10-25 12:00 . 2012-08-02 18:59 436080 c:\windows\system32\perfh009.dat
- 2001-10-25 12:00 . 2012-07-31 21:40 436080 c:\windows\system32\perfh009.dat
+ 2001-10-25 12:00 . 2012-08-02 18:59 433002 c:\windows\system32\perfh005.dat
+ 2012-08-02 19:51 . 2012-08-02 19:51 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_270_Plugin.exe
+ 2012-08-02 18:53 . 2012-08-02 18:53 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_270_ActiveX.exe
+ 2012-08-02 18:53 . 2012-08-02 18:53 466632 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_270_ActiveX.dll
- 2012-04-09 17:22 . 2012-07-27 08:51 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-04-09 17:22 . 2012-08-02 19:51 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-08-02 19:51 . 2012-08-02 19:51 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-06-20 17:02 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-06-20 17:02 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-06-20 17:02 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-06-20 17:02 556056 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-06-20 12163848]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2007-03-30 138008]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2007-03-30 162584]
"Persistence"="c:\windows\System32\igfxpers.exe" [2007-03-30 138008]
"Broadcom Wireless Manager UI"="c:\windows\System32\WLTRAY.exe" [2007-10-09 2183168]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\redirector.exe" [2011-08-11 128960]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Citrix\ICACLI~1\RSHook.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:LocalSubNet,89.250.245.10/255.255.255.255:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet,89.250.245.10/255.255.255.255:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet,89.250.245.10/255.255.255.255:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet,89.250.245.10/255.255.255.255:Enabled:@xpsp2res.dll,-22002
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"RemoteAddresses"= LocalSubNet,89.250.245.10/255.255.255.255
"Enabled"= 1 (0x1)
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [25.4.2011 1:49 66776]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 13:28 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [9.4.2012 19:22 250056]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1.8.2012 7:00 40776]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [20.3.2012 21:57 113120]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 19:51]
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {9EF2BA47-C6A7-470D-9DD9-4323B0CB8353} - hxxp://vrchoslav.araxon.cz/WebClient.cab
FF - ProfilePath - c:\documents and settings\pechy\Data aplikací\Mozilla\Firefox\Profiles\nrah0ski.default\
FF - prefs.js: browser.startup.homepage - www.facebook.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-03 19:22
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1056)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(1252)
c:\program files\Google\Drive\googledrivesync32.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\System32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\System32\igfxsrvc.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2012-08-03 19:27:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-03 17:27
ComboFix2.txt 2012-08-01 12:00
.
Před spuštěním: 1 041 698 816
Po spuštění: 1 078 976 512
.
- - End Of File - - 3EB2EA579894B422D39973B084F297BF

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: NTB uz zase neni moc ve forme

Příspěvekod jaro3 » 04 srp 2012 11:55

Pořiď si nějaký free anitivir , Eset NOD32 Antivirus 2.0 , to je dost stará verze...

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj antivir a antispyware ,následně T-Cleaner smaž a zapni si znovu antivir a antispyware.


Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.

Vlož nový log z HJT + info o NB.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

pechytce
Level 2
Level 2
Příspěvky: 182
Registrován: květen 09
Pohlaví: Muž
Stav:
Offline

Re: NTB uz zase neni moc ve forme

Příspěvekod pechytce » 04 srp 2012 14:28

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-04 14:20:27
-----------------------------
14:20:27.515 OS Version: Windows 5.1.2600 Service Pack 3
14:20:27.515 Number of processors: 2 586 0xE0C
14:20:27.515 ComputerName: SITEL UserName: pechy
14:20:29.015 Initialize success
14:21:51.984 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
14:21:51.984 Disk 0 Vendor: Hitachi_HTS541660J9SA00 SBBOC7KP Size: 57231MB BusType: 3
14:21:52.062 Disk 0 MBR read successfully
14:21:52.062 Disk 0 MBR scan
14:21:52.062 Disk 0 Windows XP default MBR code
14:21:52.109 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 57223 MB offset 63
14:21:52.140 Disk 0 scanning sectors +117194175
14:21:52.250 Disk 0 scanning C:\WINDOWS\system32\drivers
14:22:02.656 Service scanning
14:22:21.093 Modules scanning
14:22:34.843 Disk 0 trace - called modules:
14:22:34.843
14:22:34.843 Scan finished successfully
14:22:46.859 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\pechy\Plocha\MBR.dat"
14:22:46.859 The log file has been saved successfully to "C:\Documents and Settings\pechy\Plocha\aswMBR.txt"


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:23:28, on 4.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Citrix\ICA Client\redirector.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Citrix\ICA Client\Receiver\Receiver.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\pechy\Plocha\aswMBR.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CtxIEInterceptorBHO - {2C4631FF-5CC8-4EBC-A0DF-34C92291759E} - C:\Program Files\Citrix\ICA Client\IEInterceptor.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\redirector.exe" /startup
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4536978515
O16 - DPF: {9EF2BA47-C6A7-470D-9DD9-4323B0CB8353} (WebClient Control) - http://vrchoslav.araxon.cz/WebClient.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Citrix\ICACLI~1\RSHook.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9540 bytes



ntb zatim slape...ale to uz slapal vcera... jeste pohledam nejaky ten free antivir

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: NTB uz zase neni moc ve forme

Příspěvekod Žbeky » 04 srp 2012 17:01

Fixni:

Kód: Vybrat vše

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4536978515
O16 - DPF: {9EF2BA47-C6A7-470D-9DD9-4323B0CB8353} (WebClient Control) - http://vrchoslav.araxon.cz/WebClient.cab

Pokud nejsou problémy, dej vyřešeno
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 62 hostů