Trojan
Napsal: 10 srp 2006 23:10
Zdravím všechny
Prosím o kontrolu logu.AVG hlásí trojany a nevím co s nima.Předem díky
> Scan saved at 20:06:16, on 10.8.2006
> Platform: Windows XP SP1 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\Explorer.EXE
> C:\WINDOWS\system32\spoolsv.exe
> C:\WINDOWS\System32\igfxtray.exe
> C:\WINDOWS\System32\hkcmd.exe
> C:\WINDOWS\SOUNDMAN.EXE
> C:\WINDOWS\AGRSMMSG.exe
> C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
> C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
> C:\Program Files\Apoint2K\Apoint.exe
> C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe C:\Program
> Files\Common Files\Nokia\NCLTools\NclTray.exe
> C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
> C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
> C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
> C:\WINDOWS\System\csrss.exe
> C:\WINDOWS\System32\ctfmon.exe
> C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
> C:\Program Files\Messenger\msmsgs.exe
> C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
> C:\Program Files\Apoint2K\Apntex.exe
> C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
> C:\WINDOWS\System32\svchost.exe C:\Program Files\Access
> Manager\AccessManager.exe C:\Program Files\Mozilla Firefox\firefox.exe
> C:\Documents and Settings\D\Local
> Settings\Temp\hijackthis\HijackThis.exe
> >
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://web.volny.cz/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
> > = http://global.acer.com
> R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
> http://windowsupdate.microsoft.com/
> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
> > = Odkazy
> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
> > - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
> > O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467}
> -
> C:\WINDOWS\System32\msdxm.ocx
> O4 - HKLM\..\Run: [LaunchApp] Alaunch
> O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
> O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
> O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
> O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
> O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
> O4 - HKLM\..\Run: [RemoteControl] C:\Program
> Files\CyberLink\PowerDVD\PDVDServ.exe
> O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
> O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite
> 5\DataLayer.exe
> O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common
> Files\Nokia\NCLTools\NclTray.exe
> O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
> /STARTUP
> O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
> O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
> > O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
> Files\Java\j2re1.4.2_02\bin\jusched.exe
> O4 - HKLM\..\Run: [CsRss] C:\WINDOWS\System\csrss.exe
> O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
> O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
> /background
> O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel
> - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
> O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office
> Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
> O8 - Extra context menu item: Stáhnout pomocí Download &Expressu -
> C:\Program Files\Download Express\Add_Url.htm
> O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
> > - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
> O9 - Extra 'Tools' menuitem: Sun Java Console -
> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
> - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
> O9 - Extra button: Zdroje informací -
> {92780B25-18CC-41C8-B9BE-3C9C571A8263}
> > - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
> O17 -
> HKLM\System\CCS\Services\Tcpip\..\{FD19C0AF-D6A3-43FD-91EF-FDB89651DBC9}:
> > NameServer = 160.218.10.200 160.218.43.200
> O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
> O23 - Service: AVG7 Alert Manager Server (Avg7Alrt)
> - GRISOFT, s.r.o.
> - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
> O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
> C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
>
Prosím o kontrolu logu.AVG hlásí trojany a nevím co s nima.Předem díky
> Scan saved at 20:06:16, on 10.8.2006
> Platform: Windows XP SP1 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\Explorer.EXE
> C:\WINDOWS\system32\spoolsv.exe
> C:\WINDOWS\System32\igfxtray.exe
> C:\WINDOWS\System32\hkcmd.exe
> C:\WINDOWS\SOUNDMAN.EXE
> C:\WINDOWS\AGRSMMSG.exe
> C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
> C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
> C:\Program Files\Apoint2K\Apoint.exe
> C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe C:\Program
> Files\Common Files\Nokia\NCLTools\NclTray.exe
> C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
> C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
> C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
> C:\WINDOWS\System\csrss.exe
> C:\WINDOWS\System32\ctfmon.exe
> C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
> C:\Program Files\Messenger\msmsgs.exe
> C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
> C:\Program Files\Apoint2K\Apntex.exe
> C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
> C:\WINDOWS\System32\svchost.exe C:\Program Files\Access
> Manager\AccessManager.exe C:\Program Files\Mozilla Firefox\firefox.exe
> C:\Documents and Settings\D\Local
> Settings\Temp\hijackthis\HijackThis.exe
> >
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://web.volny.cz/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
> > = http://global.acer.com
> R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
> http://windowsupdate.microsoft.com/
> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
> > = Odkazy
> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
> > - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
> > O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467}
> -
> C:\WINDOWS\System32\msdxm.ocx
> O4 - HKLM\..\Run: [LaunchApp] Alaunch
> O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
> O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
> O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
> O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
> O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
> O4 - HKLM\..\Run: [RemoteControl] C:\Program
> Files\CyberLink\PowerDVD\PDVDServ.exe
> O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
> O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite
> 5\DataLayer.exe
> O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common
> Files\Nokia\NCLTools\NclTray.exe
> O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
> /STARTUP
> O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
> O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
> > O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
> Files\Java\j2re1.4.2_02\bin\jusched.exe
> O4 - HKLM\..\Run: [CsRss] C:\WINDOWS\System\csrss.exe
> O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
> O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
> /background
> O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel
> - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
> O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office
> Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
> O8 - Extra context menu item: Stáhnout pomocí Download &Expressu -
> C:\Program Files\Download Express\Add_Url.htm
> O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
> > - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
> O9 - Extra 'Tools' menuitem: Sun Java Console -
> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
> - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
> O9 - Extra button: Zdroje informací -
> {92780B25-18CC-41C8-B9BE-3C9C571A8263}
> > - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
> O17 -
> HKLM\System\CCS\Services\Tcpip\..\{FD19C0AF-D6A3-43FD-91EF-FDB89651DBC9}:
> > NameServer = 160.218.10.200 160.218.43.200
> O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
> O23 - Service: AVG7 Alert Manager Server (Avg7Alrt)
> - GRISOFT, s.r.o.
> - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
> O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
> C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
>