Stránka 1 z 1

Prosím o kontrolu PC "blbne"

Napsal: 30 čer 2008 10:57
od Fox8
Zdarec, tak jsem zase zde a prosím o kontrolu. S PC mam problémy ráno se automaticky nezapne, přitov v biosu to nastavené je, strašně pomalé a spouští se programy, které mám při stratu zakázané. Někdy se mi i program spustí jen tak když odejdu. Avast nic nenašel a Ad aware ano a to trojana, dal jsem ho do karantény, tedy alespoň doufám. Dík za rady




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:52, on 30.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aktualne.cz/?ms=ae
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\ETcall.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ\ICQ6\ICQ.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 7025 bytes

Re: Prosím o kontrolu PC "blbne"

Napsal: 30 čer 2008 12:19
od Fox8
Ještě combofix, snad je to dobře udělané ;-) a jen dotaz, jestli po combofixu ma naskočit zakázaná ikona internet jen dotaz, mam ji schovanou a po doděláni comba sem musel restartovat a pak byla ta ikona na ploše




ComboFix 08-06-20.4 - LordFox 2008-06-30 12:02:05.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.606 [GMT 2:00]
Running from: C:\Documents and Settings\LordFox\Plocha\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\MSINET.oca

.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.

2008-06-16 18:12 . 2008-06-16 18:12 <DIR> d-------- C:\totalcmd
2008-06-16 18:12 . 2008-06-25 13:42 687 --a------ C:\WINDOWS\wincmd.ini
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\UC.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\RAR.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\LHA.PIF
2008-06-16 18:12 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\ARJ.PIF
2008-06-15 11:09 . 2008-06-15 11:09 <DIR> d-------- C:\Documents and Settings\LordFox\Data aplikací\Ubisoft
2008-06-15 11:07 . 2008-06-15 11:07 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
2008-06-13 21:41 . 2008-06-13 21:41 <DIR> d-------- C:\Program Files\LitexMedia
2008-06-10 20:01 . 2003-12-15 12:43 1,871,872 --a------ C:\WINDOWS\system32\NCTAudioFile2.dll
2008-06-10 20:01 . 2003-12-08 12:19 425,984 --a------ C:\WINDOWS\system32\NCTAudioTransform2.dll
2008-06-10 20:01 . 2002-01-05 14:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-06-10 20:01 . 2004-12-01 14:43 315,392 --a------ C:\WINDOWS\system32\NCTAudioPlayer2.dll
2008-06-10 20:01 . 2003-08-07 14:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-06-10 20:01 . 2008-06-10 20:03 121 --a------ C:\WINDOWS\mp3wavcon.ini
2008-06-10 20:01 . 2008-06-10 20:03 5 --a------ C:\WINDOWS\system32\SySMP3OC.dat
2008-06-10 13:47 . 2008-06-10 13:47 1,244,214 --a------ C:\WINDOWS\KMPBitmap.bmp
2008-06-09 07:41 . 2008-06-10 20:20 <DIR> d-------- C:\Program Files\MediaCoder
2008-06-05 20:51 . 2008-06-05 20:51 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-05 20:51 . 2008-06-05 20:51 <DIR> d-------- C:\Program Files\D-Tools
2008-06-05 20:51 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-06-05 20:51 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-06-05 12:07 . 2008-06-05 12:07 <DIR> d-------- C:\Documents and Settings\LordFox\Data aplikací\Ahead
2008-06-04 15:15 . 2008-06-04 15:15 <DIR> d-------- C:\Program Files\QIP
2008-06-03 20:41 . 2008-06-03 20:41 <DIR> d-------- C:\Program Files\miranda
2008-06-02 16:30 . 2008-06-02 16:30 <DIR> d-------- C:\Documents and Settings\LordFox\Data aplikací\InstallShield Installation Information
2008-06-02 16:22 . 2008-06-02 16:22 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-06-02 16:22 . 2008-06-02 16:22 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-05-30 06:57 . 2008-05-30 06:57 <DIR> d-------- C:\Program Files\YouTube Video Downloader
2008-05-29 17:21 . 2008-05-29 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Test Drive Unlimited
2008-05-25 20:28 . 2008-05-25 20:28 <DIR> d-------- C:\Program Files\Crystal Player
2008-05-23 15:15 . 2008-05-29 17:17 811 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-05-22 20:54 . 2008-05-22 20:54 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-22 20:24 . 2008-05-22 20:24 <DIR> dr-h----- C:\Documents and Settings\LordFox\Data aplikací\SecuROM
2008-05-22 20:24 . 2008-05-22 20:24 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-05-22 20:02 . 2008-05-22 20:54 22,328 --a------ C:\Documents and Settings\LordFox\Data aplikací\PnkBstrK.sys
2008-05-22 19:58 . 2008-05-22 19:58 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-05-22 19:58 . 2008-05-22 20:54 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-05-22 19:58 . 2008-05-22 20:54 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-22 19:58 . 2008-05-22 19:58 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-18 22:20 . 2008-05-18 22:20 <DIR> d-------- C:\Documents and Settings\LordFox\vypinac
2008-05-18 22:19 . 2008-05-18 22:19 <DIR> d-------- C:\Program Files\AMP WinOFF
2008-05-13 16:34 . 2008-05-13 16:34 <DIR> d-------- C:\Program Files\RivaTuner v2.09
2008-05-12 17:18 . 2007-02-09 16:34 198,144 --------- C:\WINDOWS\system32\_psisdecd.dll
2008-05-11 21:47 . 2008-05-12 17:18 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2008-05-11 21:46 . 2007-02-09 16:34 1,233,920 --a------ C:\WINDOWS\system32\msxml4.dll
2008-05-11 21:46 . 2007-02-09 16:34 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-05-11 21:46 . 2007-02-09 16:34 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-05-11 21:37 . 2008-05-12 17:18 <DIR> d-------- C:\Program Files\CyberLink
2008-05-11 19:14 . 2008-05-11 19:14 921,654 --a------ C:\capt0002.bmp
2008-05-11 19:12 . 2008-05-11 19:13 <DIR> d-------- C:\CTV_TEMP
2008-05-09 15:27 . 2008-05-13 15:18 22,536 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2008-05-08 21:12 . 2008-06-22 10:57 1,082,880 --a------ C:\WINDOWS\system32\AutoPartNt.exe
2008-05-08 21:12 . 2008-06-22 10:58 1,024 --a------ C:\WINDOWS\system32\AutoPartNt.let
2008-05-08 21:01 . 2008-05-08 21:03 <DIR> d-------- C:\Documents and Settings\LordFox\Data aplikací\LangSoft
2008-05-08 21:01 . 2008-05-08 21:01 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\LangSoft
2008-05-08 20:39 . 2008-05-08 20:39 <DIR> d-------- C:\Program Files\Common Files\Acronis
2008-05-08 20:39 . 2008-05-08 20:39 <DIR> d-------- C:\Program Files\Acronis
2008-05-08 12:26 . 2008-05-08 12:26 <DIR> d-------- C:\Program Files\Sanny Builder 3
2008-05-08 09:35 . 2008-05-08 09:36 <DIR> d-------- C:\Program Files\Winamp
2008-05-08 09:32 . 2008-05-08 09:40 <DIR> d-------- C:\Documents and Settings\LordFox\Data aplikací\Winamp
2008-05-04 22:49 . 2008-05-04 22:49 <DIR> d-------- C:\Program Files\PowerQuest
2008-05-04 16:58 . 2007-03-19 18:05 13,840 --a------ C:\WINDOWS\system32\wnaspi32.dll
2008-05-04 15:15 . 2008-05-04 15:15 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Acronis
2008-05-04 14:27 . 2008-05-08 20:39 99,776 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2008-05-04 13:28 . 2008-05-04 13:30 <DIR> d-------- C:\Program Files\Infra Recorder
2008-05-03 19:25 . 2008-05-03 19:25 <DIR> d-------- C:\Program Files\BSPlayer
2008-05-03 19:08 . 2008-05-03 23:24 <DIR> d-------- C:\Program Files\Thoosje Sidebar V2.3
2008-05-01 14:54 . 2008-05-01 14:54 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-01 14:54 . 2008-05-01 14:55 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 09:00 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\Spyware Terminator
2008-06-29 22:04 --------- d-----w C:\Program Files\ChrisTV PVR
2008-06-27 13:12 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-06-21 19:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-21 19:35 --------- d-----w C:\Program Files\Common Files\Logitech
2008-06-19 18:50 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\Skype
2008-06-19 18:21 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\skypePM
2008-06-18 20:37 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\gtk-2.0
2008-06-18 12:50 --------- d-----w C:\Program Files\Spyware Terminator
2008-06-16 16:48 --------- d-----w C:\Program Files\Opera
2008-06-08 16:04 --------- d-----w C:\Program Files\SpeedFan
2008-06-07 14:21 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\ICQ
2008-06-05 07:37 --------- d-----w C:\Program Files\Evrsoft First Page 2006
2008-06-02 18:25 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\Hamachi
2008-06-02 14:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-01 16:43 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-05-01 12:41 --------- d-----w C:\Documents and Settings\LordFox\Data aplikací\Lavasoft
2008-04-29 04:37 --------- d-----w C:\Program Files\Google
2008-04-12 16:20 197,017 ----a-w C:\WINDOWS\San Andreas Tools Uninstaller.exe
2008-03-21 12:40 2,321,408 ----a-w C:\WINDOWS\system32\TUKernel.exe
2008-01-13 14:08 20,064 ----a-w C:\Documents and Settings\LordFox\Data aplikací\GDIPFONTCACHEV1.DAT
2007-12-28 12:10 32 ----a-w C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
.

Re: Prosím o kontrolu PC "blbne"

Napsal: 30 čer 2008 17:48
od Fox8
No ještě jsem zpoměl, když při přihlášení na PC-help zaškrtnu automatiku, proč při dalším zapnutí netu (PC-HELP-- hlavní strana) se mě to zase ptá na heslo, jako by se mi automat mazalo cookies

Re: Prosím o kontrolu PC "blbne"

Napsal: 30 čer 2008 20:06
od Fox8
Hážu se do top. Asi je tam opravdu vir, ale nic ho nechce najít.

Re: Prosím o kontrolu PC "blbne"

Napsal: 30 čer 2008 21:03
od zao
já v logu hjt nevidím

Re: Prosím o kontrolu PC "blbne"

Napsal: 01 črc 2008 16:10
od zlobyl
Log z CF není kompletní-zkus ho spustit znovu.

Log má na konci informaci E O F a velikost logu. :wink: