Stránka 1 z 2

Jeste jeden log z HiJackThis

Napsal: 09 led 2008 08:43
od Dvori
Dekuji za kontrolu.
JD

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:41, on 9.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\TEMP\ZLBC91.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Novell\GroupWise\notify.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\DOCUME~1\dvorak\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Novell\GroupWise\grpwise.exe
C:\Novell\GroupWise\GWSync.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\dvorak\Plocha\Viry\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = devetsil.vse.cz:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ntiMUI] "C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe"
O4 - HKLM\..\Run: [AzMixerSel] "C:\Program Files\Realtek\InstallShield\AzMixerSel.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [eRecoveryService] "C:\Acer\Empowering Technology\eRecovery\Monitor.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [gemstrmw] "C:\WINDOWS\system32\gemstrmw.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - HKCU\..\Run: [CM] "C:\PROGRA~1\VCM\cm.exe" 212.150.243.4
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: VCM.lnk = C:\Program Files\VCM\cm.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Notify.lnk = C:\Novell\GroupWise\notify.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe

Napsal: 09 led 2008 12:50
od Baron Prášil
v pořádku.Trend Micro Client-je kompletní ochrana?(FW,Antispy)

fixni zbytečnosti
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

aktualizuj javu
- Stáhni si poslení verzi Java Runtime Environment (JRE) 6 Update 3
- Posuň se dolů kde je napsáno Java Runtime Environment (JRE) 6 Update 3 a klikni na tlačítko Download
- Zatrhni možnost kde je napsáno: Accept License Agreement
- Stránka se ti znovu načte.
- Klikni na odkaz pro stažení: Windows Offline Installation, Multi-language a ulož si ho na disk
- Ukonči běžící programy které máš spuštěné, hlavě webový prohlížeč
- Jdi přes Start -> Ovládací panely -> Přidat nebo odebrat programy a odinstaluj všechny staré verze Javy
- Podívej se po položkách s názvem Java Runtime Environment (JRE or J2SE)
* příklady starých verzí v Přidat nebo odebrat programy:
    J2SE Runtime Environment 5.0
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2
- Odinstaluj je přes tlačítko Změnit nebo odebrat nebo Odebrat
- Odinstaluj postupně po sobě případné všechny staré verze Javy
- Po skončení odinstalovaní restartuj Pc.
- Pak už jen spusť instalaci poslední verze ze souboru jre-6u3-windows-i586-p.exe, který sis stáhl na začátku.

Napsal: 09 led 2008 22:22
od Dvori
Udelal jsem to co jsi psal...

Pro jistotu jsem jeste projel PC pomoci MWAV a ten nasel tohle:

ue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\snd.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (snd.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\sub.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (sub.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\sze.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (sze.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\ath.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (ath.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\frb.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (frb.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata3.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata3.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata2.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata2.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata1.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata1.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesfactors.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesfactors.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\anticipator.dll
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (anticipator.dll)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\mcact.dll
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (mcact.dll)! Action taken: Nic nebylo provedeno.

Wed Jan 09 22:06:18 2008 => Testovaných objektů: 30547
Wed Jan 09 22:06:18 2008 => Kritických objektů: 12
Wed Jan 09 22:06:18 2008 => Celkem vyléčených objektů: 0
Wed Jan 09 22:06:18 2008 => Celkem přejmenováno: 0
Wed Jan 09 22:06:18 2008 => Smazaných objektů: 0
Wed Jan 09 22:06:18 2008 => Celkem chyb: 2
Wed Jan 09 22:06:18 2008 => Uplynulý čas: 00:02:12
Wed Jan 09 22:06:18 2008 => Datum vydání databáze: 6/4/2007
Wed Jan 09 22:06:18 2008 => Verze virové databáze: 336875

Napsal: 09 led 2008 22:32
od Dvori
tenhle pocitac mam pripojenej na kolejni sit a od te me odpojili, pac z meho notase odchazelo prilis mnoho dat... tak proto delam kontrolu, co se deje...

Napsal: 09 led 2008 22:34
od Baron Prášil
ale já sem se taky tázal je-li trend micro client,kterej vlastníš,kompletní ochranou či ne :|
(nechce se mi všechno gůglit)

takže nainstaluj Superantispyware a vyčisti systém.

a ještě k tomu mwavu-je poněkud staršího data Wed Jan 09 22:06:18 2008 => Datum vydání databáze: 6/4/2007
a jestli sken trval dvě a půl minuty,tak je to taky špatně. :roll:
(pokud teda nezačíná minutama-už sem ho dlouho nepoužil)

Napsal: 09 led 2008 23:44
od Dvori
Pocítac jsem projel SuperAntiSpywarem, ale mylim ze neodstranil vic nez nejake cookies...

Tady prikladam novy log z MWAV (aktualizovaneho :D )
diky

Tue Jan 08 23:33:12 2008 => ***** Testování registrů a souborů na přítomnost Adware/Spyware *****
Tue Jan 08 23:33:12 2008 => Loading Spyware Signatures from new External Database [Name: C:\DOCUME~1\dvorak\LOCALS~1\Temp\spydb.avs, Size: 229744].
Tue Jan 08 23:33:14 2008 => Indexed Spyware Databases Successfully Created...

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\snd.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (snd.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\sub.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (sub.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\sze.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (sze.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\ath.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (ath.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\frb.mgf
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (frb.mgf)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata3.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata3.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata2.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata2.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesdata1.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesdata1.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\rulesfactors.xml
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (rulesfactors.xml)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\anticipator.dll
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (anticipator.dll)! Action taken: Nic nebylo provedeno.

Tue Jan 08 23:33:27 2008 => Offending file found: C:\WINDOWS\system32\mcact.dll
Tue Jan 08 23:33:27 2008 => System found infected with vcatch Spyware/Adware (mcact.dll)! Action taken: Nic nebylo provedeno.

2008 => Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".mgf". Provedené akce: Nic nebylo provedeno.

23:33:38 2008 => Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".std". Provedené akce: Nic nebylo provedeno.


23:35:44 2008 => Testovaných objektů: 40106
Wed Jan 09 23:35:44 2008 => Kritických objektů: 13
Wed Jan 09 23:35:44 2008 => Celkem vyléčených objektů: 0
Wed Jan 09 23:35:44 2008 => Celkem přejmenováno: 0
Wed Jan 09 23:35:44 2008 => Smazaných objektů: 0
Wed Jan 09 23:35:44 2008 => Celkem chyb: 3
Wed Jan 09 23:35:44 2008 => Uplynulý čas: 00:03:18
Wed Jan 09 23:35:44 2008 => Datum vydání databáze: 1/9/2008
Wed Jan 09 23:35:44 2008 => Verze virové databáze: 505619

Napsal: 09 led 2008 23:45
od Dvori
nebo bych mel udelat jiny test...

Napsal: 09 led 2008 23:49
od Baron Prášil
toto smaž
C:\WINDOWS\system32\anticipator.dll
C:\WINDOWS\system32\mcact.dll

jsou s tim kompem nějaký potíže?

Napsal: 09 led 2008 23:52
od Dvori
Kromně toho, ze me vcera odpojili od site, tak ne :D Dneska uz bezim a nikdo me neodpojil, ale bezi tu testy jenou za cas tak to neni uplne jisty....
co je to ten vcatch 3.0? je to nejaky zmetek? ja jsme nic takove neinstaloval?
diky

Napsal: 10 led 2008 00:13
od Dvori
tak jsem smazal anticipator.dll, ale ten druhej soubor se mi ani nepodarilo najit... po smazani jsem restartoval pocitac a anticipator.dll je zase zpet...
no tak nevim :?

Napsal: 12 led 2008 13:14
od Dvori
muze mi prosim nekdo odpovedet...
diky moc

Napsal: 12 led 2008 16:01
od Baron Prášil
je to spyware http://logiguard.com/spyware/v/vcatch.htm
udělej
COMBOFIX
Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem klávesy 1
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log, který se ti zobrazí, jinak ho najdeš zde: C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah