Kontrola logu, pls...

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Kontrola logu, pls...

Příspěvekod colorado44 » 27 črc 2008 13:07

Prosim o kontrolu, nejak mi blbne internet... :o



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:02:21, on 27.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\WINDOWS\system32\oodtray.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\oodag.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [] Rundll32.exe "C:\WINDOWS\system32\xeyacjaw.dll",s
O4 - HKLM\..\Run: [BM4f4fbdd3] Rundll32.exe "C:\WINDOWS\system32\xeyacjaw.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\WINDOWS\System32\appdrvrem01.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySQL5 - Unknown owner - C:\web\prog\mySQL\bin\mysqld-nt (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 7061 bytes

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu, pls...

Příspěvekod fredik » 27 črc 2008 13:47

Před použitím Combofix udělej následující krok:

Vypni rezidentní štít ve Spyware Terminátoru:
Spusť Spywater Terminátora, nahoře klikni na ikonu Rezidentní štít
- program se přepne do okna Natavení rezidentního štítu
- tam na záložce Nastavení štítu zruš zatržení u položky: Aktivovat Rezidentní štít
- klikni dole na tlačítko: Uložit změny
- zavři program

Pak si stáhni ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 27 črc 2008 14:10

Tak jsem udelal, jak si rekl.



ComboFix 08-07-26.1 - Colorado 2008-07-27 14:00:36.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.466 [GMT 2:00]
Running from: C:\Documents and Settings\Colorado\Plocha\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aqoyfalq.dll
C:\WINDOWS\system32\awtuurOG.dll
C:\WINDOWS\system32\bcgiigfc.dll
C:\WINDOWS\system32\bhrhyamn.ini
C:\WINDOWS\system32\cbXRKCSI.dll
C:\WINDOWS\system32\cfgiigcb.ini
C:\WINDOWS\system32\geBrsRKd.dll
C:\WINDOWS\system32\hgGyyxVL.dll
C:\WINDOWS\system32\iticpich.dll
C:\WINDOWS\system32\krvwfmju.dll
C:\WINDOWS\system32\LVxyyGgh.ini
C:\WINDOWS\system32\LVxyyGgh.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nmayhrhb.dll
C:\WINDOWS\system32\tuvVPgFU.dll
C:\WINDOWS\system32\ujmfwvrk.ini
C:\WINDOWS\system32\xeyacjaw.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.

2008-07-27 13:02 . 2008-07-27 13:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-27 12:38 . 2008-07-27 13:55 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-07-27 12:38 . 2008-07-27 12:38 <DIR> d---s---- C:\Documents and Settings\Colorado\UserData
2008-07-27 12:34 . 2008-07-27 12:34 <DIR> d-------- C:\Program Files\Panda Security
2008-07-24 14:54 . 2008-07-27 13:28 110,484 --a------ C:\WINDOWS\BM4f4fbdd3.xml
2008-07-24 13:59 . 2008-07-24 13:59 <DIR> d-------- C:\WINDOWS\Sun
2008-07-24 13:58 . 2008-07-24 13:58 <DIR> d-------- C:\WINDOWS\system32\tenarchlib
2008-07-20 18:59 . 2008-05-02 18:07 4,874,301 --a------ C:\WINDOWS\system32\php5ts.dll
2008-07-20 18:59 . 2008-07-20 18:59 49,961 --a------ C:\WINDOWS\php.ini
2008-07-20 18:55 . 2008-05-02 18:07 278,800 --a------ C:\WINDOWS\system32\ntwdblib.dll
2008-07-20 16:40 . 2008-07-20 16:41 <DIR> d-------- C:\totalcmd
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\UC.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\RAR.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\LHA.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\ARJ.PIF
2008-07-20 16:40 . 2008-07-20 19:14 498 --a------ C:\WINDOWS\wincmd.ini
2008-07-20 16:32 . 2008-07-20 16:39 46,359 --a------ C:\WINDOWS\php.ini-dist
2008-07-20 16:24 . 2008-05-02 18:07 2,076,672 --a------ C:\WINDOWS\system32\libmysql.dll
2008-07-20 16:24 . 2008-05-02 18:07 1,097,728 --a------ C:\WINDOWS\system32\libeay32.dll
2008-07-20 16:24 . 2008-05-02 18:07 417,792 --a------ C:\WINDOWS\system32\fdftk.dll
2008-07-20 16:24 . 2008-05-02 18:07 346,624 --a------ C:\WINDOWS\system32\gds32.dll
2008-07-20 16:24 . 2008-05-02 18:07 166,912 --a------ C:\WINDOWS\system32\libmcrypt.dll
2008-07-20 16:24 . 2008-05-02 18:07 165,643 --a------ C:\WINDOWS\system32\libmhash.dll
2008-07-20 16:24 . 2008-05-02 18:07 57,344 --a------ C:\WINDOWS\system32\msql.dll
2008-07-20 14:59 . 2008-07-20 14:59 2,915,944 --a------ C:\WINDOWS\system32\drivers\appdrv01.sys
2008-07-20 14:59 . 2008-07-20 14:59 304,528 --a------ C:\WINDOWS\system32\appdrvrem01.exe
2008-07-20 13:42 . 2008-07-20 19:15 <DIR> d-------- C:\web
2008-07-20 13:29 . 2008-07-20 13:36 <DIR> d-------- C:\Program Files\PHP
2008-07-20 13:28 . 2008-07-20 13:28 <DIR> d-------- C:\Program Files\MySQL
2008-07-19 17:15 . 2008-07-19 17:16 <DIR> d-------- C:\Program Files\BitComet
2008-07-18 20:38 . 2008-07-18 20:38 <DIR> d-------- C:\Program Files\SmartSound Software
2008-07-18 20:38 . 2008-07-18 20:38 <DIR> d-------- C:\Program Files\DivX
2008-07-18 20:38 . 2007-03-01 23:45 118,520 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-18 20:38 . 2007-03-01 23:45 116,472 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-18 20:36 . 2008-07-18 20:40 <DIR> d-------- C:\Program Files\CyberLink
2008-07-18 20:36 . 2008-07-18 20:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-18 20:36 . 2008-07-18 20:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-18 20:35 . 2008-07-18 20:36 <DIR> d-------- C:\Program Files\QuickTime
2008-07-18 20:34 . 2008-07-24 16:57 <DIR> d-------- C:\MyWorks
2008-07-18 16:49 . 2008-07-19 09:08 <DIR> d-------- C:\Program Files\Buyertools Reminder
2008-07-17 15:55 . 2008-07-17 15:55 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-15 20:36 . 2008-07-20 09:15 <DIR> d-------- C:\Program Files\Cyanide
2008-07-15 18:48 . 2008-07-15 18:48 <DIR> d-------- C:\Program Files\Canon
2008-07-15 18:46 . 2005-04-15 06:00 140,288 --a------ C:\WINDOWS\system32\CNMLM78.DLL
2008-07-15 18:46 . 2005-03-08 19:17 90,112 --a------ C:\WINDOWS\system32\CNMCP78.exe
2008-07-15 18:46 . 2005-04-15 06:00 8,704 --a------ C:\WINDOWS\system32\CNMVS78.DLL
2008-07-12 14:14 . 2008-07-12 14:14 <DIR> d-------- C:\Program Files\Infogrames
2008-07-10 20:07 . 2004-08-17 15:49 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-10 20:07 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-10 20:07 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-10 20:07 . 2001-10-24 12:25 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-09 15:24 . 2008-07-09 15:24 <DIR> d-------- C:\Program Files\Mio Technology
2008-07-09 15:23 . 2008-07-09 15:23 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-09 15:23 . 2005-10-21 03:47 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-07-09 15:23 . 2005-10-21 03:47 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2008-07-06 12:55 . 2008-07-06 12:55 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-03 17:55 . 2008-07-03 17:55 390 --a------ C:\WINDOWS\ODBC.INI
2008-07-01 12:38 . 2008-07-01 12:38 <DIR> d-------- C:\Program Files\Java
2008-07-01 12:38 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-01 12:37 . 2008-07-01 12:37 <DIR> d-------- C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 09:55 --------- d-----w C:\Program Files\Spyware Terminator
2008-07-20 06:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-20 06:50 --------- d-----w C:\Program Files\QIP
2008-07-19 15:15 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2008-07-18 18:33 --------- d-----w C:\Program Files\SpeedFan
2008-07-06 10:55 --------- d-----w C:\Program Files\Sports Interactive
2008-07-03 15:54 --------- d-----w C:\Program Files\Microsoft Works
2008-06-15 14:49 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-06-15 14:49 --------- d-----w C:\Program Files\AutoCAD 2008
2008-06-15 14:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-15 14:46 --------- d-----w C:\Program Files\Autodesk
2008-06-14 07:33 --------- d-----w C:\Program Files\Sweet Home 3D
2008-06-14 07:16 --------- d--h--w C:\Program Files\Zero G Registry
2008-06-12 20:05 --------- d-----w C:\Program Files\LS
2008-06-09 14:37 2,426 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2008-06-09 14:36 8,972 ----a-w C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2008-06-09 12:25 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-09 12:10 --------- d-----w C:\Program Files\EA Sports
2008-06-08 17:47 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-06-08 17:44 --------- d-----w C:\Program Files\Sega
2008-06-08 17:25 --------- d-----w C:\Program Files\MSBuild
2008-06-08 17:24 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-08 17:23 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-08 16:58 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-08 16:28 --------- d-----w C:\Program Files\Nero
2008-06-08 16:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-08 16:06 --------- d-----w C:\Program Files\Bonjour
2008-06-08 16:02 --------- d-----w C:\Program Files\StrongDC
2008-06-08 15:56 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-08 15:53 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-06-08 15:51 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-06-08 15:47 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-06-08 15:47 --------- d-----w C:\Program Files\Realtek
2008-06-08 15:36 --------- d-----w C:\Program Files\Smart PC Solutions
2008-06-08 15:22 --------- d-----w C:\Program Files\Google
2008-06-08 12:59 --------- d-----w C:\Program Files\ATI Technologies
2008-06-08 12:58 --------- d-----w C:\Program Files\Alwil Software
2008-06-08 12:57 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-08 12:53 --------- d-----w C:\Program Files\RegCleaner
2008-06-08 12:53 --------- d-----w C:\Program Files\CCleaner
2008-06-08 12:52 --------- d-----w C:\Program Files\Winamp
2008-06-08 12:51 --------- d-----w C:\Program Files\Webteh
2008-06-08 12:51 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-06-08 12:50 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-06-08 12:49 --------- d-----w C:\Program Files\OO Software
2008-06-08 12:48 --------- d-----w C:\Program Files\Skype
2008-06-08 12:48 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-08 12:47 --------- d-----w C:\Program Files\ICQ6
2008-06-08 10:28 --------- d-----w C:\Program Files\A4Tech
2008-06-08 10:10 --------- d-----w C:\Program Files\GIGABYTE
2008-06-08 09:57 --------- d-----w C:\Program Files\Intel
2008-06-08 09:36 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:09 47,104 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 19,968 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 08:49 593,920 ----a-w C:\WINDOWS\system32\ati2sgag.exe
2008-05-07 13:39 16,862,208 ----a-w C:\WINDOWS\RTHDCPL.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 17:49 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2007-05-15 17:33 204800]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 14:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-11-19 11:28 1966080]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-06-08 14:57 1817600]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 15:39 16862208 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 17:49 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\StrongDC\\StrongDC.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"=
"C:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\PCM.exe"=
"C:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\Autorun\\Exe\\Autorun.exe"=
"C:\\WINDOWS\\system32\\winver.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"15312:TCP"= 15312:TCP:BitComet 15312 TCP
"15312:UDP"= 15312:UDP:BitComet 15312 UDP
"9186:TCP"= 9186:TCP:BitComet 9186 TCP
"9186:UDP"= 9186:UDP:BitComet 9186 UDP

R1 appdrv01;Application Driver (01);C:\WINDOWS\system32\Drivers\appdrv01.sys [2008-07-20 14:59]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-06-08 14:57]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 01:04]
S2 appdrvrem01;Application Driver Auto Removal Service (01);C:\WINDOWS\System32\appdrvrem01.exe svc []
S2 MySQL5;MySQL5;C:\web\prog\mySQL\bin\mysqld-nt --defaults-file=C:\web\prog\mySQL\my.ini MySQL5 []
S3 tap0901_2gm;VPN Anonymizer Adapter;C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 17:21]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{944c85d4-354c-11dd-91e2-806d6172696f}]
\Shell\AutoRun\command - E:\Run.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BM4f4fbdd3 - C:\WINDOWS\system32\xeyacjaw.dll
Notify-winrkp32 - winrkp32.dll


.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyOverride = <local>
R1 -: HKCU-Internet Settings,ProxyServer = <local>
O8 -: Download all links using BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 -: Download all videos using BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: Download link using &BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 14:04:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL5]
"ImagePath"="\"C:\web\prog\mySQL\bin\mysqld-nt\" --defaults-file=\"C:\web\prog\mySQL\my.ini\" MySQL5"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\oodag.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2008-07-27 14:07:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-27 12:07:02

Pre-Run: Volných bajtů: 55,343,411,200
Post-Run: Volněch bajt…: 56,032,628,736

275

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu, pls...

Příspěvekod fredik » 27 črc 2008 18:33

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

File::
C:\WINDOWS\BM4f4fbdd3.xml

DirLook::
C:\WINDOWS\system32\tenarchlib

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť
Obrázek
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 27 črc 2008 19:12

COMBOFIX

ComboFix 08-07-26.1 - Colorado 2008-07-27 18:51:19.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.453 [GMT 2:00]
Running from: C:\Documents and Settings\Colorado\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Colorado\Plocha\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM4f4fbdd3.xml
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM4f4fbdd3.xml

.
((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.

2008-07-27 13:02 . 2008-07-27 13:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-27 12:38 . 2008-07-27 13:55 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-07-27 12:38 . 2008-07-27 12:38 <DIR> d---s---- C:\Documents and Settings\Colorado\UserData
2008-07-27 12:34 . 2008-07-27 12:34 <DIR> d-------- C:\Program Files\Panda Security
2008-07-24 13:59 . 2008-07-24 13:59 <DIR> d-------- C:\WINDOWS\Sun
2008-07-24 13:58 . 2008-07-24 13:58 <DIR> d-------- C:\WINDOWS\system32\tenarchlib
2008-07-24 13:58 . 2008-07-24 13:58 <DIR> d-------- C:\Documents and Settings\Colorado\Data aplikací\Tenebril
2008-07-21 21:19 . 2008-07-21 21:19 <DIR> d-------- C:\Documents and Settings\LocalService\Data aplikací\CyberLink
2008-07-20 18:59 . 2008-05-02 18:07 4,874,301 --a------ C:\WINDOWS\system32\php5ts.dll
2008-07-20 18:59 . 2008-07-20 18:59 49,961 --a------ C:\WINDOWS\php.ini
2008-07-20 18:55 . 2008-05-02 18:07 278,800 --a------ C:\WINDOWS\system32\ntwdblib.dll
2008-07-20 16:40 . 2008-07-20 16:41 <DIR> d-------- C:\totalcmd
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\UC.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\RAR.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\LHA.PIF
2008-07-20 16:40 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\ARJ.PIF
2008-07-20 16:40 . 2008-07-20 19:14 498 --a------ C:\WINDOWS\wincmd.ini
2008-07-20 16:32 . 2008-07-20 16:39 46,359 --a------ C:\WINDOWS\php.ini-dist
2008-07-20 16:24 . 2008-05-02 18:07 2,076,672 --a------ C:\WINDOWS\system32\libmysql.dll
2008-07-20 16:24 . 2008-05-02 18:07 1,097,728 --a------ C:\WINDOWS\system32\libeay32.dll
2008-07-20 16:24 . 2008-05-02 18:07 417,792 --a------ C:\WINDOWS\system32\fdftk.dll
2008-07-20 16:24 . 2008-05-02 18:07 346,624 --a------ C:\WINDOWS\system32\gds32.dll
2008-07-20 16:24 . 2008-05-02 18:07 166,912 --a------ C:\WINDOWS\system32\libmcrypt.dll
2008-07-20 16:24 . 2008-05-02 18:07 165,643 --a------ C:\WINDOWS\system32\libmhash.dll
2008-07-20 16:24 . 2008-05-02 18:07 57,344 --a------ C:\WINDOWS\system32\msql.dll
2008-07-20 14:59 . 2008-07-20 14:59 2,915,944 --a------ C:\WINDOWS\system32\drivers\appdrv01.sys
2008-07-20 14:59 . 2008-07-20 14:59 304,528 --a------ C:\WINDOWS\system32\appdrvrem01.exe
2008-07-20 13:42 . 2008-07-20 19:15 <DIR> d-------- C:\web
2008-07-20 13:29 . 2008-07-20 13:36 <DIR> d-------- C:\Program Files\PHP
2008-07-20 13:28 . 2008-07-20 13:28 <DIR> d-------- C:\Program Files\MySQL
2008-07-20 13:07 . 2008-07-20 19:51 <DIR> d-------- C:\Documents and Settings\Colorado\Data aplikací\Pro Cycling Manager 2008
2008-07-19 17:15 . 2008-07-19 17:16 <DIR> d-------- C:\Program Files\BitComet
2008-07-19 09:19 . 2008-07-19 09:19 <DIR> d-------- C:\Documents and Settings\Colorado\Data aplikací\DivX
2008-07-19 09:19 . 2008-07-19 09:19 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2008-07-19 09:18 . 2008-07-19 09:18 <DIR> d-------- C:\Documents and Settings\Colorado\Data aplikací\CyberLink
2008-07-18 20:38 . 2008-07-18 20:38 <DIR> d-------- C:\Program Files\SmartSound Software
2008-07-18 20:38 . 2008-07-18 20:38 <DIR> d-------- C:\Program Files\DivX
2008-07-18 20:38 . 2008-07-18 20:39 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SmartSound Software Inc
2008-07-18 20:38 . 2007-03-01 23:45 118,520 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-18 20:38 . 2007-03-01 23:45 116,472 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-18 20:36 . 2008-07-18 20:40 <DIR> d-------- C:\Program Files\CyberLink
2008-07-18 20:36 . 2008-07-18 20:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-18 20:36 . 2008-07-18 20:36 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-18 20:35 . 2008-07-18 20:36 <DIR> d-------- C:\Program Files\QuickTime
2008-07-18 20:35 . 2008-07-18 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-07-18 20:34 . 2008-07-24 16:57 <DIR> d-------- C:\MyWorks
2008-07-18 16:49 . 2008-07-19 09:08 <DIR> d-------- C:\Program Files\Buyertools Reminder
2008-07-17 15:55 . 2008-07-17 15:55 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-16 15:50 . 2008-07-19 21:54 <DIR> d-------- C:\Documents and Settings\Colorado\Data aplikací\Pro Cycling Manager 2007
2008-07-15 20:36 . 2008-07-20 09:15 <DIR> d-------- C:\Program Files\Cyanide
2008-07-15 18:48 . 2008-07-15 18:48 <DIR> d-------- C:\Program Files\Canon
2008-07-15 18:46 . 2008-07-15 18:46 <DIR> d--h----- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
2008-07-15 18:46 . 2005-04-15 06:00 140,288 --a------ C:\WINDOWS\system32\CNMLM78.DLL
2008-07-15 18:46 . 2005-03-08 19:17 90,112 --a------ C:\WINDOWS\system32\CNMCP78.exe
2008-07-15 18:46 . 2005-04-15 06:00 8,704 --a------ C:\WINDOWS\system32\CNMVS78.DLL
2008-07-12 14:14 . 2008-07-12 14:14 <DIR> d-------- C:\Program Files\Infogrames
2008-07-10 20:07 . 2004-08-17 15:49 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-10 20:07 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-10 20:07 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-10 20:07 . 2001-10-24 12:25 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-09 15:24 . 2008-07-09 15:24 <DIR> d-------- C:\Program Files\Mio Technology
2008-07-09 15:23 . 2008-07-09 15:23 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-09 15:23 . 2005-10-21 03:47 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-07-09 15:23 . 2005-10-21 03:47 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2008-07-06 12:55 . 2008-07-06 12:55 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-03 17:55 . 2008-07-03 17:55 390 --a------ C:\WINDOWS\ODBC.INI
2008-07-01 12:38 . 2008-07-01 12:38 <DIR> d-------- C:\Program Files\Java
2008-07-01 12:38 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-01 12:37 . 2008-07-01 12:37 <DIR> d-------- C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 12:10 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Spyware Terminator
2008-07-27 09:55 --------- d-----w C:\Program Files\Spyware Terminator
2008-07-27 09:54 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-07-20 06:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-20 06:50 --------- d-----w C:\Program Files\QIP
2008-07-19 15:15 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2008-07-18 18:33 --------- d-----w C:\Program Files\SpeedFan
2008-07-06 10:59 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Sports Interactive
2008-07-06 10:55 --------- d-----w C:\Program Files\Sports Interactive
2008-07-05 20:55 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Ahead
2008-07-03 15:54 --------- d-----w C:\Program Files\Microsoft Works
2008-07-02 17:07 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-06-15 14:49 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-06-15 14:49 --------- d-----w C:\Program Files\AutoCAD 2008
2008-06-15 14:47 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Autodesk
2008-06-15 14:47 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Autodesk
2008-06-15 14:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-15 14:46 --------- d-----w C:\Program Files\Autodesk
2008-06-14 07:33 --------- d-----w C:\Program Files\Sweet Home 3D
2008-06-14 07:16 --------- d--h--w C:\Program Files\Zero G Registry
2008-06-12 20:05 --------- d-----w C:\Program Files\LS
2008-06-09 14:37 2,426 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2008-06-09 14:36 8,972 ----a-w C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2008-06-09 12:25 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-09 12:10 --------- d-----w C:\Program Files\EA Sports
2008-06-08 17:47 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-06-08 17:44 --------- d-----w C:\Program Files\Sega
2008-06-08 17:37 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2008-06-08 17:25 --------- d-----w C:\Program Files\MSBuild
2008-06-08 17:24 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-08 17:23 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-08 16:58 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-08 16:28 --------- d-----w C:\Program Files\Nero
2008-06-08 16:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-08 16:06 --------- d-----w C:\Program Files\Bonjour
2008-06-08 16:02 --------- d-----w C:\Program Files\StrongDC
2008-06-08 15:56 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-08 15:53 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-06-08 15:51 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-06-08 15:51 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\DAEMON Tools
2008-06-08 15:47 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-06-08 15:47 --------- d-----w C:\Program Files\Realtek
2008-06-08 15:36 --------- d-----w C:\Program Files\Smart PC Solutions
2008-06-08 15:36 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Smart PC Solutions
2008-06-08 15:22 --------- d-----w C:\Program Files\Google
2008-06-08 15:20 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Winamp
2008-06-08 14:59 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\ATI
2008-06-08 14:59 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ATI
2008-06-08 12:59 --------- d-----w C:\Program Files\ATI Technologies
2008-06-08 12:58 --------- d-----w C:\Program Files\Alwil Software
2008-06-08 12:57 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-08 12:53 --------- d-----w C:\Program Files\RegCleaner
2008-06-08 12:53 --------- d-----w C:\Program Files\CCleaner
2008-06-08 12:52 --------- d-----w C:\Program Files\Winamp
2008-06-08 12:51 --------- d-----w C:\Program Files\Webteh
2008-06-08 12:51 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-06-08 12:50 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-06-08 12:49 --------- d-----w C:\Program Files\OO Software
2008-06-08 12:49 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\skypePM
2008-06-08 12:49 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Skype
2008-06-08 12:48 --------- d-----w C:\Program Files\Skype
2008-06-08 12:48 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-08 12:48 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Skype
2008-06-08 12:47 --------- d-----w C:\Program Files\ICQ6
2008-06-08 12:47 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\ICQ
2008-06-08 10:28 --------- d-----w C:\Program Files\A4Tech
2008-06-08 10:16 --------- d-----w C:\Documents and Settings\Colorado\Data aplikací\Talkback
2008-06-08 10:10 --------- d-----w C:\Program Files\GIGABYTE
2008-06-08 09:57 --------- d-----w C:\Program Files\Intel
2008-06-08 09:36 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:09 47,104 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 19,968 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 08:49 593,920 ----a-w C:\WINDOWS\system32\ati2sgag.exe
2008-05-07 13:39 16,862,208 ----a-w C:\WINDOWS\RTHDCPL.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\WINDOWS\system32\tenarchlib ----

2005-01-27 23:13 1134592 --a-s---- C:\WINDOWS\system32\tenarchlib\uilib.dll
2004-12-23 21:50 327680 --a-s---- C:\WINDOWS\system32\tenarchlib\syslib.dll
2004-05-01 23:42 98304 --a-s---- C:\WINDOWS\system32\tenarchlib\datalib.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 17:49 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2007-05-15 17:33 204800]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 14:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-11-19 11:28 1966080]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-06-08 14:57 1817600]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 15:39 16862208 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 17:49 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\StrongDC\\StrongDC.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"=
"C:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\PCM.exe"=
"C:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\Autorun\\Exe\\Autorun.exe"=
"C:\\WINDOWS\\system32\\winver.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"15312:TCP"= 15312:TCP:BitComet 15312 TCP
"15312:UDP"= 15312:UDP:BitComet 15312 UDP
"9186:TCP"= 9186:TCP:BitComet 9186 TCP
"9186:UDP"= 9186:UDP:BitComet 9186 UDP

R1 appdrv01;Application Driver (01);C:\WINDOWS\system32\Drivers\appdrv01.sys [2008-07-20 14:59]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-06-08 14:57]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 01:04]
S2 appdrvrem01;Application Driver Auto Removal Service (01);C:\WINDOWS\System32\appdrvrem01.exe svc []
S2 MySQL5;MySQL5;C:\web\prog\mySQL\bin\mysqld-nt --defaults-file=C:\web\prog\mySQL\my.ini MySQL5 []
S3 tap0901_2gm;VPN Anonymizer Adapter;C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 17:21]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{944c85d4-354c-11dd-91e2-806d6172696f}]
\Shell\AutoRun\command - E:\Run.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 18:52:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL5]
"ImagePath"="\"C:\web\prog\mySQL\bin\mysqld-nt\" --defaults-file=\"C:\web\prog\mySQL\my.ini\" MySQL5"
.
Completion time: 2008-07-27 18:53:20
ComboFix-quarantined-files.txt 2008-07-27 16:53:10
ComboFix2.txt 2008-07-27 12:07:06

Pre-Run: Volných bajtů: 56,010,502,144
Post-Run: Volných bajtů: 55,997,968,384

262

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 27 črc 2008 19:13

HIJACKTHIS


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:11:37, on 27.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\oodtray.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\oodag.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\WINDOWS\System32\appdrvrem01.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySQL5 - Unknown owner - C:\web\prog\mySQL\bin\mysqld-nt (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 7535 bytes

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu, pls...

Příspěvekod fredik » 27 črc 2008 20:18

Doporučil bych ti aktualizovat Javu:
- Stáhni si poslední verzi Java Runtime Environment (JRE) 6 Update 7
- Posuň se dolů kde je napsáno Java Runtime Environment (JRE) 6 Update 7 a klikni na tlačítko Download
- Načte se ti nová stránka
- Pod nadpisem Select Platform and Language for your download:
* u položky Platform: vyber OS který používáš
* zatrhni možnost kde je napsáno: I agree to the Java SE Runtime Environment 6 License Agreement
* klikni na tlačítko Continue >>
- Načte se ti nová stránka
- Klikni na odkaz pro stažení pod položkou: Windows Offline Installation
Obrázek
a ulož si ho na disk

- Ukonči běžící programy které máš spuštěné, hlavě webový prohlížeč
- Jdi přes Start -> Ovládací panely -> Přidat nebo odebrat programy a odinstaluj všechny staré verze Javy
- Podívej se po položkách s názvem Java Runtime Environment (JRE or J2SE)
* příklady starých verzí v Přidat nebo odebrat programy:
    J2SE Runtime Environment 5.0
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2
- Odinstaluj je přes tlačítko Změnit nebo odebrat nebo Odebrat
- Odinstaluj postupně po sobě případné všechny staré verze Javy
- Po skončení odinstalovaní restartuj Pc.
- Pak už jen spusť instalaci poslední verze ze souboru jre-6u7-windows-i586-p.exe, který sis stáhl na začátku

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Pro lepší zabezpečení bych ti doporučil doinstalovat firewall, můžeš si vybrat některý zde uvedený nebo některý jiný z odkazu: Přehled osobních firewallů
Firewally zdarma:
Kerio - přehledný, větší možnosti nastavení, náročnější na systémové prostředky, v češtině
ZoneAlarm - jednoduchý, kompatibilní, nenáročný na systémové prostředky, málo možností nastavení, v angličtině + návod
Comodo - kvalitní, pokročilý, s mnoha funkcemi, originálně v angličtině (nepoužít jeho malware scaner, nebo přes něj odstranit co najde)

Máš ještě nějaké problémy?
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 27 črc 2008 20:50

moc diky :bigups:
ten rezidentni stit u spyware terminator mam nechat vyplej?

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu, pls...

Příspěvekod fredik » 27 črc 2008 20:59

Když nejsou žádné problémy tak udělej toto:

Jdi přes Start -> Spustit... a napiš do okna tento příkaz označený modře ComboFix /u a dej Ok.
- mezi ComboFix a /u musí být mezera
- počkej až proběhne, bude tě o tom informovat.

Podle logu je aktivní, jinak si ho můžeš zapnout zpět.

Nemáš za co Obrázek, kdyby byl nějaký problém tak dej vědět.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logu, pls...

Příspěvekod fredik » 27 črc 2008 21:27

Ještě jsem zapomněl, udělej pak ještě toto:

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující text označený zeleně:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe"

Pak dej Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: fix.reg
Uložit jako typ: tak tam vyber Všechny soubory
Ulož si daný soubor na plochu
Na ploše by se měl objevit soubor Obrázek fix.reg
- spusť ho vyskočí hláška kde odklikni Ano poté je další hláška kde odklikni OK
Pokud by ti na podruhé vyhodil chybovou hlášku tak udělej toto:

Spusť Avast a až se ti objeví okno aplikace tak vlevo nahoře klikni na ikonu šipky směřující nahoru (Menu) tam zvol Nastavení...
- v nově otevřeném okně zvol poslední možnost dole Řešení problémů tam zatrhni možnost: Vypnout sebeobranné mechanismy programu Avast! a potvrď přes Ok
- ukáže se ti hláška Avastu tak zvol Ano
- zavři Avast
Pak použij znovu ten soubor fix.reg a mělo by to proběhnout všechno v pořádku. Restartuj Pc a po najetí zpět do Win. si opačným postupem zapni sebeobranu v Avastu.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 01 srp 2008 23:47

Tak se me pocitac upe po.... :) neslo vubec nic, hlasilo, ze nemam na nic prava, kdyz jsem chtel cokoliv otevrit. Tak jsem to musel preinstalovat, ale po nainstalovani windows mi jde pc strasne pomalu. Posilam log z HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:43:11, on 1.8.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\oodtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mexe.com
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 5161 bytes

colorado44
Level 1
Level 1
Příspěvky: 51
Registrován: červenec 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola logu, pls...

Příspěvekod colorado44 » 02 srp 2008 00:51

Jeste z ComboFix

ComboFix 08-07-31.06 - Administrator 2008-08-02 0:44:56.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.626 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com

.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.

2008-08-02 00:22 . 2008-08-02 00:22 0 --a------ C:\23990098.$$$
2008-08-01 23:42 . 2008-08-01 23:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-08-01 22:14 . 2008-08-01 22:14 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-08-01 22:12 . 2008-08-01 22:14 50 --a------ C:\WINDOWS\Lic.xxx
2008-08-01 22:11 . 2004-08-17 17:49 147,968 --a------ C:\WINDOWS\R.COM
2008-08-01 22:11 . 2004-08-17 17:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-08-01 21:56 . 2008-08-01 21:56 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2008-08-01 21:18 . 2008-08-01 21:18 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-01 21:11 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-01 14:53 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-01 14:51 . 2008-08-01 14:53 <DIR> d-------- C:\Program Files\Java
2008-08-01 14:51 . 2008-08-01 14:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-01 07:17 . 2008-08-01 07:17 <DIR> d-------- C:\WINDOWS\system32\oodag
2008-08-01 07:06 . 2008-08-01 07:06 0 --a------ C:\WINDOWS\OODCNT.INI
2008-07-31 22:11 . 2008-07-31 22:11 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-31 22:07 . 2008-07-31 22:07 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-07-31 22:04 . 2008-07-31 22:04 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-31 22:01 . 2008-07-31 22:09 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-31 21:59 . 2008-07-31 22:12 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-07-31 21:58 . 2008-07-31 21:58 <DIR> dr-h----- C:\MSOCache
2008-07-31 21:49 . 2008-07-31 21:49 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-07-31 21:45 . 2008-07-31 21:45 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys.14684870
2008-07-31 21:44 . 2008-07-31 21:44 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools
2008-07-30 21:13 . 2008-07-31 22:32 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Apple Computer
2008-07-30 21:11 . 2008-07-30 21:11 <DIR> d-------- C:\Program Files\iTunes
2008-07-30 21:11 . 2008-07-30 21:11 <DIR> d-------- C:\Program Files\iPod
2008-07-30 21:10 . 2008-07-30 21:10 <DIR> d-------- C:\Program Files\Bonjour
2008-07-30 21:05 . 2008-07-30 21:10 <DIR> d-------- C:\Program Files\QuickTime
2008-07-30 21:05 . 2008-07-30 21:05 <DIR> d-------- C:\Program Files\Apple Software Update
2008-07-30 21:05 . 2008-07-30 21:11 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-07-30 21:03 . 2008-07-30 21:03 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-30 21:03 . 2008-07-30 21:03 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-07-30 21:03 . 2008-07-30 21:03 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple
2008-07-30 21:03 . 2008-07-10 09:35 32,000 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-30 20:58 . 2004-08-17 15:49 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-30 20:58 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-30 20:58 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-30 20:58 . 2001-10-24 12:25 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-30 20:43 . 2008-07-30 20:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-30 20:41 . 2008-07-30 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\ATI
2008-07-30 20:41 . 2008-07-30 20:41 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ATI
2008-07-30 20:40 . 2008-07-30 20:40 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2008-07-30 20:40 . 2008-07-30 20:40 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-30 20:38 . 2008-08-02 00:38 6,385 --a------ C:\WINDOWS\system32\oodbs.lor
2008-07-30 20:38 . 2008-07-30 20:38 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-07-30 20:34 . 2008-07-30 20:40 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Skype
2008-07-30 20:33 . 2008-07-30 20:33 <DIR> d-------- C:\Program Files\Skype
2008-07-30 20:33 . 2008-07-30 20:33 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-07-30 20:33 . 2008-07-30 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Skype
2008-07-30 20:31 . 2008-08-01 21:42 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-30 20:30 . 2008-07-30 20:30 <DIR> d-------- C:\Program Files\Webteh
2008-07-30 20:30 . 2008-07-30 20:30 <DIR> d-------- C:\Program Files\QIP
2008-07-30 20:27 . 2008-07-30 20:29 <DIR> d-------- C:\Program Files\Winamp
2008-07-30 20:27 . 2008-07-30 20:27 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Winamp
2008-07-30 20:26 . 2008-07-30 20:26 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2008-07-30 20:26 . 2008-07-30 20:25 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-07-30 20:25 . 2008-07-30 20:25 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-30 20:24 . 2008-07-30 20:48 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-07-30 20:24 . 2008-08-01 21:45 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-07-30 20:24 . 2008-07-30 21:05 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2008-07-30 20:24 . 2008-07-30 20:24 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-30 20:23 . 2008-07-30 20:23 <DIR> d-------- C:\Program Files\OO Software
2008-07-30 20:22 . 2008-07-30 20:22 <DIR> d-------- C:\Program Files\CCleaner
2008-07-30 20:09 . 2008-07-30 20:09 <DIR> d-------- C:\WINDOWS\system32\cs-CZ
2008-07-30 20:06 . 2008-07-31 22:10 <DIR> d-------- C:\Program Files\MSBuild
2008-07-30 20:01 . 2008-07-30 20:01 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-30 20:01 . 2008-07-30 20:01 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-30 20:00 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-07-30 19:58 . 2008-07-30 19:58 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-07-30 19:54 . 2008-07-30 20:40 <DIR> d-------- C:\Program Files\ATI
2008-07-30 19:54 . 2008-07-03 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-07-30 19:53 . 2008-07-30 19:54 <DIR> d-------- C:\Program Files\ATI Technologies
2008-07-30 17:39 . 2008-07-30 17:39 <DIR> d-------- C:\ATI
2008-07-30 17:34 . 2008-07-30 17:34 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-07-30 17:34 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-07-30 17:34 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-07-30 17:34 . 2004-08-03 23:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-07-30 17:34 . 2004-08-03 23:15 60,800 --a--c--- C:\WINDOWS\system32\dllcache\sysaudio.sys
2008-07-30 17:33 . 2004-08-03 22:58 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-07-30 17:33 . 2004-08-03 22:58 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-07-30 17:33 . 2004-08-03 22:58 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-07-30 17:32 . 2008-07-30 17:32 <DIR> d-------- C:\WINDOWS\JM
2008-07-30 17:32 . 2008-07-30 17:32 <DIR> d-------- C:\Program Files\GIGABYTE
2008-07-30 17:32 . 2006-06-02 10:46 385,024 -r------- C:\WINDOWS\system32\JMRaidTool.exe
2008-07-30 17:32 . 1998-10-02 19:00 327,168 --a------ C:\WINDOWS\IsUninst.exe
2008-07-30 17:32 . 2006-03-15 08:51 244,608 --a------ C:\WINDOWS\system32\drivers\yk51x86.sys
2008-07-30 17:32 . 2005-10-31 12:17 135,168 -r------- C:\WINDOWS\system32\RtlCPAPI.dll
2008-07-30 17:32 . 2006-06-02 13:49 43,264 -ra------ C:\WINDOWS\system32\drivers\jraid.sys
2008-07-30 17:32 . 2005-07-15 10:48 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-07-30 17:32 . 2006-02-07 13:52 6,912 -ra------ C:\WINDOWS\system32\drivers\JGOGO.sys
2008-07-30 17:31 . 2008-07-30 17:31 <DIR> d-------- C:\Program Files\Realtek
2008-07-30 17:31 . 2008-07-30 19:54 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-07-30 17:31 . 2008-07-30 17:39 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-07-30 17:30 . 2006-10-16 16:10 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-07-30 14:53 . 2008-07-30 14:53 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-07-30 14:53 . 2008-07-30 14:53 <DIR> d-------- C:\Documents and Settings\LocalService\Data aplikací
2008-07-30 14:53 . 2008-07-30 14:53 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-07-30 14:53 . 2008-08-02 00:43 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-07-30 14:53 . 2008-07-30 08:44 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-07-30 14:53 . 2008-07-30 08:44 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-07-30 14:53 . 2008-07-30 14:54 <DIR> dr------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-07-30 14:53 . 2008-08-01 21:44 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-07-30 14:53 . 2008-07-30 08:44 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-07-30 14:53 . 2008-08-01 22:11 <DIR> dr------- C:\Documents and Settings\Administrator\Dokumenty
2008-07-30 14:53 . 2008-08-01 22:05 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-07-30 14:53 . 2008-08-02 00:37 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-04 08:33 . 2008-07-04 08:33 3,230,720 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-07-04 08:33 . 2008-07-04 08:33 3,230,720 --a--c--- C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-07-04 05:48 . 2008-07-04 05:48 9,490,432 --a------ C:\WINDOWS\system32\atioglx2.dll
2008-07-04 05:25 . 2008-07-04 05:25 421,888 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 05:23 . 2008-07-04 05:23 309,248 --a--c--- C:\WINDOWS\system32\dllcache\ati2dvag.dll
2008-07-04 05:23 . 2008-07-04 05:23 309,248 --a------ C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 05:14 . 2008-07-04 05:14 184,320 --a------ C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 05:14 . 2008-07-04 05:14 143,360 --a------ C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 05:14 . 2008-07-04 05:14 26,112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 05:13 . 2008-07-04 05:13 139,264 --a------ C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 05:13 . 2008-07-04 05:13 43,520 --a------ C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 05:12 . 2008-07-04 05:12 561,152 --a------ C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 05:10 . 2008-07-04 05:10 53,248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 05:06 . 2008-07-04 05:06 253,952 --a------ C:\WINDOWS\system32\atiok3x2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-30 07:01 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 17:49 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 17:02 490952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 10:46 385024]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-07-30 20:24 1783808]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 04:47 16208384 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 17:49 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-07-30 20:24]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{906f7fec-5e01-11dd-830b-806d6172696f}]
\Shell\AutoRun\command - E:\Run.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\mth9nziz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://seznam.cz/
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-02 00:46:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-02 0:46:55
ComboFix-quarantined-files.txt 2008-08-01 22:46:45

Pre-Run: Volných bajtů: 102,050,308,096
Post-Run: Volných bajtů: 102,150,959,104

198









Strasne dlouho mi nabiha i Windows. Sileny...


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 2 hosti