nákaza v PC, prosím o kontrolu logu
Napsal: 25 led 2015 10:01
Ahoj,
MBAM diagnostikoval virovou nákazu. Posílám log a prosím i o kontrolu logu HJT. Děkuji. J*
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 25.1.2015
Čas skenování: 9:07:50
Protokol: Malwarebytes Anti-Malware nálezy.txt
Správce: Ano
Verze: 2.00.4.1028
Databáze malwaru: v2015.01.25.06
Databáze rootkitů: v2015.01.14.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: Jirka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 295198
Uplynulý čas: 26 min, 46 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Varovat
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 0
(Žádné zákerné zjištěny položek)
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 2
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\bitstreams, , [bedc2ecd9eebc1758255dc6611f2b947],
Soubory: 14
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\diablo130302.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\diakgcn121016.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libcurl-4.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libeay32.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libidn-11.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\librtmp.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libssh2.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\mncxwvmeo.exe, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\phatk121016.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\poclbm130302.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\scrypt130511.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\ssleay32.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\zlib1.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, , [bedc2ecd9eebc1758255dc6611f2b947],
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
HJT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:52:36, on 25.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
--
End of file - 5008 bytes
MBAM diagnostikoval virovou nákazu. Posílám log a prosím i o kontrolu logu HJT. Děkuji. J*
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 25.1.2015
Čas skenování: 9:07:50
Protokol: Malwarebytes Anti-Malware nálezy.txt
Správce: Ano
Verze: 2.00.4.1028
Databáze malwaru: v2015.01.25.06
Databáze rootkitů: v2015.01.14.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: Jirka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 295198
Uplynulý čas: 26 min, 46 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Varovat
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 0
(Žádné zákerné zjištěny položek)
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 2
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\bitstreams, , [bedc2ecd9eebc1758255dc6611f2b947],
Soubory: 14
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\diablo130302.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\diakgcn121016.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libcurl-4.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libeay32.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libidn-11.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\librtmp.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\libssh2.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\mncxwvmeo.exe, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\phatk121016.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\poclbm130302.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\scrypt130511.cl, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\ssleay32.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\zlib1.dll, , [bedc2ecd9eebc1758255dc6611f2b947],
Trojan.Agent.BCM, C:\Windows\inf\mncxwvmeo\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, , [bedc2ecd9eebc1758255dc6611f2b947],
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
HJT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:52:36, on 25.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVG\AVG2015\avgui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
--
End of file - 5008 bytes