Zdravím, mrkněte mi prosím na log.Norton mi našel trojana.Díky
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:52:41, on 22.2.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Plánovač automatické aktualizace LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Služba Google Update (gupdate1c991e82e17cf0) (gupdate1c991e82e17cf0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\STacSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
--
End of file - 14860 bytes
Prosím o kontrolu "Trojan hors"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Především máš dva antiviry..Norton/Symantec a Avast, jeden odinstaluj....
Poté:
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Toto otestuj na Virustotal
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
Vlož sem pak odkaz výsledku.
Poté:
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Toto otestuj na Virustotal
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
Vlož sem pak odkaz výsledku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu "Trojan hors"
Odkaz VirusTotal: http://www.virustotal.com/cs/analisis/7 ... a4965ac2bf a mbam log. v příloze.
Edit: tak příloha se asi napovedla, tak to zkopčím
Malwarebytes' Anti-Malware 1.34
Verze databáze: 1792
Windows 6.0.6001 Service Pack 1
22.2.2009 17:39:59
mbam-log-2009-02-22 (17-39-59).txt
Typ skenu: Rychlý sken
Objektu skenováno: 65069
Uplynulý cas: 5 minute(s), 43 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
(Žádné zákerné položky nebyly zjišteny)
Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)
Edit: tak příloha se asi napovedla, tak to zkopčím
Malwarebytes' Anti-Malware 1.34
Verze databáze: 1792
Windows 6.0.6001 Service Pack 1
22.2.2009 17:39:59
mbam-log-2009-02-22 (17-39-59).txt
Typ skenu: Rychlý sken
Objektu skenováno: 65069
Uplynulý cas: 5 minute(s), 43 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
(Žádné zákerné položky nebyly zjišteny)
Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Vypni rez. ochranu u antiviru.
Pokud máš 32 bitovou verzi win, postupuj takto:
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud máš 32 bitovou verzi win, postupuj takto:
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu "Trojan hors"
Tak tady je log z ComboFix:
ComboFix 09-02-21.01 - Zdendys 2009-02-22 18:29:20.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1029.18.2045.981 [GMT 1:00]
Spuštěný z: c:\users\Zdendys\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Zdendys\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-01-22 do 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-22 18:21 . 2009-02-22 18:21 6,736 --a------ c:\windows\System32\drivers\PROCEXP90.SYS
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-22 17:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-22 17:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-22 16:51 . 2009-02-22 16:51 <DIR> d-------- c:\program files\Trend Micro
2009-02-21 15:05 . 2009-02-21 15:42 <DIR> d-------- c:\program files\Cyklotrasy
2009-02-19 15:15 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\System32\D3DX9_37.dll
2009-02-19 15:15 . 2008-03-05 15:56 1,420,824 --a------ c:\windows\System32\D3DCompiler_37.dll
2009-02-19 15:15 . 2008-02-05 23:07 462,864 --a------ c:\windows\System32\d3dx10_37.dll
2009-02-19 15:15 . 2007-04-04 18:53 81,768 --a------ c:\windows\System32\xinput1_3.dll
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\windows\System32\xlive
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\users\All Users\Google Updater
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\programdata\Google Updater
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\users\All Users\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\programdata\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 14:38 . 2009-02-17 14:39 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\users\All Users\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\users\All Users\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\programdata\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\programdata\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2009-02-16 12:39 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-16 12:39 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-16 12:39 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-16 12:39 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-16 12:39 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\users\All Users\HPSSUPPLY
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\programdata\HPSSUPPLY
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\users\All Users\WEBREG
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\programdata\WEBREG
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\users\All Users\HP Product Assistant
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\programdata\HP Product Assistant
2009-02-11 14:24 . 2009-02-11 14:24 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-02-11 14:22 . 2009-02-11 14:22 <DIR> d-------- c:\program files\Common Files\HP
2009-02-11 14:20 . 2007-10-30 10:11 729,088 --a------ c:\windows\System32\hpowiax7.dll
2009-02-11 14:20 . 2007-10-30 10:11 581,632 --a------ c:\windows\System32\hpotscl6.dll
2009-02-11 14:20 . 2007-10-30 10:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-02-11 14:20 . 2007-10-30 10:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-02-11 14:20 . 2007-10-30 10:11 303,104 --a------ c:\windows\System32\hpovst15.dll
2009-02-11 14:20 . 2007-11-08 15:52 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-02-11 14:20 . 2007-10-20 18:25 117,760 --a------ c:\windows\System32\hpzll5mu.dll
2009-02-11 14:15 . 2009-02-11 14:41 175,829 --a------ c:\windows\hpoins27.dat
2009-02-11 14:10 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 14:10 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 16:09 . 2009-02-10 16:09 <DIR> d-------- c:\program files\CCleaner
2009-02-09 20:52 . 2009-02-09 20:52 <DIR> d-------- c:\program files\Resco
2009-02-09 20:52 . 2007-10-10 19:38 90,112 --a------ c:\windows\RSetupCE.exe
2009-02-09 20:51 . 2009-02-09 20:51 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-07 16:56 . 2009-02-07 16:56 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-06 22:57 . 2009-02-06 22:57 <DIR> d-------- c:\users\Monika\AppData\Roaming\CyberLink
2009-02-03 23:33 . 2009-02-03 23:33 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\users\All Users\Google
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\program files\Google
2009-01-31 15:47 . 2009-01-31 15:53 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\COWON
2009-01-31 15:45 . 2009-01-31 16:49 <DIR> d-------- c:\program files\JetAudio
2009-01-31 15:40 . 2009-01-31 15:40 <DIR> d-------- c:\program files\FlashPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 17:43 --------- d-----w c:\users\Zdendys\AppData\Roaming\Skype
2009-02-22 17:42 --------- d-----w c:\users\Zdendys\AppData\Roaming\skypePM
2009-02-19 14:25 --------- d-----w c:\programdata\Downloaded Installations
2009-02-19 14:25 --------- d-----w c:\program files\Nokia
2009-02-19 14:25 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-18 21:00 --------- d-----w c:\users\Monika\AppData\Roaming\Skype
2009-02-18 19:00 --------- d-----w c:\users\Monika\AppData\Roaming\skypePM
2009-02-18 17:00 --------- d-----w c:\users\Zdendys\AppData\Roaming\uTorrent
2009-02-14 13:28 --------- d-----w c:\users\Zdendys\AppData\Roaming\Ahead
2009-02-11 16:10 --------- d-----w c:\program files\Windows Mail
2009-02-11 14:05 --------- d-----w c:\users\Zdendys\AppData\Roaming\HP
2009-02-11 13:42 --------- d-----w c:\programdata\HP
2009-02-11 13:40 --------- d-----w c:\programdata\Hewlett-Packard
2009-02-11 13:18 --------- d-----w c:\program files\HP
2009-02-03 11:14 --------- d-----w c:\users\Zdendys\AppData\Roaming\dvdcss
2009-02-03 10:54 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nokia
2009-01-31 14:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-27 17:52 --------- d-----w c:\programdata\Symantec
2009-01-16 22:45 --------- d-----w c:\program files\Common Files\Ahead
2009-01-16 22:42 --------- d-----w c:\programdata\Nero
2009-01-16 22:42 --------- d-----w c:\program files\Nero
2009-01-15 20:13 --------- d-----w c:\program files\Common Files\Nero
2009-01-15 02:02 --------- d-----w c:\program files\Microsoft Works
2009-01-14 16:38 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-09 09:07 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 09:07 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 09:07 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 09:07 --------- d-----w c:\program files\Symantec
2009-01-08 18:36 --------- d-----w c:\users\Zdendys\AppData\Roaming\Vso
2009-01-07 21:59 --------- d-----w c:\users\Zdendys\AppData\Roaming\vlc
2009-01-07 21:55 --------- d-----w c:\program files\VideoLAN
2009-01-03 21:08 --------- d-----w c:\program files\MSECache
2008-12-31 13:22 --------- d-----w c:\program files\MediaInfo
2008-12-30 22:12 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nero
2008-12-27 17:13 --------- d-----w c:\users\Zdendys\AppData\Roaming\CyberLink
2008-12-24 12:37 --------- d-----w c:\programdata\vsosdk
2008-12-23 22:26 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-23 22:26 47,360 ----a-w c:\users\Zdendys\AppData\Roaming\pcouffin.sys
2008-12-23 22:26 --------- d-----w c:\program files\VSO
2008-12-22 21:27 --------- d-----w c:\program files\Webteh
2008-12-15 20:20 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-11-14 15:22 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-11-14 15:22 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2008-06-30 12:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-11-15 12:48 22 --sha-w c:\windows\SMINST\HPCD.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
"ICQ"="c:\program files\ICQ6\ICQ.exe" [2008-09-01 173304]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-17 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-16 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-05-14 468264]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-01-16 727592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1346C59F-C7C4-4E6A-AE37-B11D86E2A71F}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{9D4F55D8-FB3A-4DE5-85D1-26F1850F4F95}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{91466F9D-5388-4574-A29E-FC826CF13688}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{C0945923-124B-4BC5-A732-3808CFCEC48F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{D6A6996C-6F1E-4009-B774-5C0AA80DCD33}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{27F64D1B-D3F4-46BA-8FA9-C64C8A9C17CD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3210A871-1AED-42B0-84C2-89803DE27826}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4DAEDE10-6A47-4647-9527-39FE66D60B92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{29DB70D6-832D-47A1-BB5B-95A5B93A2090}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{FC730066-E500-4C03-AF64-F9BCFFF14326}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0398D392-65A0-4780-8EC3-BA36BFB585EE}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0168C6FB-E12B-4381-A662-6F291AA7426A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{68133144-9356-451B-B838-8D321F8F8328}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DED75DB0-EF08-48D3-9B6F-2255FC04FF56}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{00725283-8EA1-40C0-9D51-E9C38B1D4A84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{2EAB20FB-BA46-4CB4-8672-160341EE8BD8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{A20FA3B2-7082-4F68-B45C-7BB74A37EAC4}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\System32\drivers\Amddfltr.sys [2008-09-20 15416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090217.004\IDSvix86.sys [2009-02-20 270384]
R1 PSched;Plánovač paketů technologie QoS;c:\windows\System32\drivers\pacer.sys [2008-11-14 72192]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\AEstSrv.exe [2008-09-20 73728]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [2008-03-18 19456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-07 149352]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-06-11 341328]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2008-03-26 595248]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-06-11 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [2008-01-23 52736]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-14 99376]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-04-01 81296]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2008-03-26 40752]
S2 gupdate1c991e82e17cf0;Služba Google Update (gupdate1c991e82e17cf0);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-13 23888]
S3 EC168BDA;TVGo DVB-T02PRO;c:\windows\System32\drivers\EC168BDA.sys [2008-11-15 67968]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f35f857d-b262-11dd-84a2-002186b39ad7}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Obsah adresáře 'Naplánované úlohy'
2009-02-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-18 17:39]
2009-02-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 17:42]
2009-02-17 c:\windows\Tasks\NeroLiveEpgUpdate-Zdendys-PC_Zdendys.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe []
2009-02-09 c:\windows\Tasks\Norton Internet Security - Prověřit tento počítač - Zdendys.job
- c:\program files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe [2008-02-07 13:05]
2009-02-22 c:\windows\Tasks\User_Feed_Synchronization-{36514A6C-BCFF-4A44-8A1D-555ECF717C8F}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-22 18:44:35
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(668)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(5588)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
c:\users\Zdendys\AppData\Local\Temp\catchme.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\conime.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\combofix\hidec.exe
c:\combofix\Catchme.tmp
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Celkový čas: 2009-02-22 18:49:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-02-22 17:47:54
Před spuštěním: Volných bajtů: 210 485 522 432
Po spuštění: Volných bajtů: 210,636,996,608
308 --- E O F --- 2009-02-20 13:42:24
ComboFix 09-02-21.01 - Zdendys 2009-02-22 18:29:20.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1029.18.2045.981 [GMT 1:00]
Spuštěný z: c:\users\Zdendys\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Zdendys\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-01-22 do 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-22 18:21 . 2009-02-22 18:21 6,736 --a------ c:\windows\System32\drivers\PROCEXP90.SYS
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-22 17:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-22 17:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-22 16:51 . 2009-02-22 16:51 <DIR> d-------- c:\program files\Trend Micro
2009-02-21 15:05 . 2009-02-21 15:42 <DIR> d-------- c:\program files\Cyklotrasy
2009-02-19 15:15 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\System32\D3DX9_37.dll
2009-02-19 15:15 . 2008-03-05 15:56 1,420,824 --a------ c:\windows\System32\D3DCompiler_37.dll
2009-02-19 15:15 . 2008-02-05 23:07 462,864 --a------ c:\windows\System32\d3dx10_37.dll
2009-02-19 15:15 . 2007-04-04 18:53 81,768 --a------ c:\windows\System32\xinput1_3.dll
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\windows\System32\xlive
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\users\All Users\Google Updater
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\programdata\Google Updater
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\users\All Users\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\programdata\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 14:38 . 2009-02-17 14:39 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\users\All Users\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\users\All Users\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\programdata\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\programdata\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2009-02-16 12:39 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-16 12:39 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-16 12:39 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-16 12:39 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-16 12:39 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\users\All Users\HPSSUPPLY
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\programdata\HPSSUPPLY
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\users\All Users\WEBREG
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\programdata\WEBREG
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\users\All Users\HP Product Assistant
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\programdata\HP Product Assistant
2009-02-11 14:24 . 2009-02-11 14:24 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-02-11 14:22 . 2009-02-11 14:22 <DIR> d-------- c:\program files\Common Files\HP
2009-02-11 14:20 . 2007-10-30 10:11 729,088 --a------ c:\windows\System32\hpowiax7.dll
2009-02-11 14:20 . 2007-10-30 10:11 581,632 --a------ c:\windows\System32\hpotscl6.dll
2009-02-11 14:20 . 2007-10-30 10:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-02-11 14:20 . 2007-10-30 10:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-02-11 14:20 . 2007-10-30 10:11 303,104 --a------ c:\windows\System32\hpovst15.dll
2009-02-11 14:20 . 2007-11-08 15:52 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-02-11 14:20 . 2007-10-20 18:25 117,760 --a------ c:\windows\System32\hpzll5mu.dll
2009-02-11 14:15 . 2009-02-11 14:41 175,829 --a------ c:\windows\hpoins27.dat
2009-02-11 14:10 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 14:10 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 16:09 . 2009-02-10 16:09 <DIR> d-------- c:\program files\CCleaner
2009-02-09 20:52 . 2009-02-09 20:52 <DIR> d-------- c:\program files\Resco
2009-02-09 20:52 . 2007-10-10 19:38 90,112 --a------ c:\windows\RSetupCE.exe
2009-02-09 20:51 . 2009-02-09 20:51 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-07 16:56 . 2009-02-07 16:56 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-06 22:57 . 2009-02-06 22:57 <DIR> d-------- c:\users\Monika\AppData\Roaming\CyberLink
2009-02-03 23:33 . 2009-02-03 23:33 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\users\All Users\Google
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\program files\Google
2009-01-31 15:47 . 2009-01-31 15:53 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\COWON
2009-01-31 15:45 . 2009-01-31 16:49 <DIR> d-------- c:\program files\JetAudio
2009-01-31 15:40 . 2009-01-31 15:40 <DIR> d-------- c:\program files\FlashPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 17:43 --------- d-----w c:\users\Zdendys\AppData\Roaming\Skype
2009-02-22 17:42 --------- d-----w c:\users\Zdendys\AppData\Roaming\skypePM
2009-02-19 14:25 --------- d-----w c:\programdata\Downloaded Installations
2009-02-19 14:25 --------- d-----w c:\program files\Nokia
2009-02-19 14:25 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-18 21:00 --------- d-----w c:\users\Monika\AppData\Roaming\Skype
2009-02-18 19:00 --------- d-----w c:\users\Monika\AppData\Roaming\skypePM
2009-02-18 17:00 --------- d-----w c:\users\Zdendys\AppData\Roaming\uTorrent
2009-02-14 13:28 --------- d-----w c:\users\Zdendys\AppData\Roaming\Ahead
2009-02-11 16:10 --------- d-----w c:\program files\Windows Mail
2009-02-11 14:05 --------- d-----w c:\users\Zdendys\AppData\Roaming\HP
2009-02-11 13:42 --------- d-----w c:\programdata\HP
2009-02-11 13:40 --------- d-----w c:\programdata\Hewlett-Packard
2009-02-11 13:18 --------- d-----w c:\program files\HP
2009-02-03 11:14 --------- d-----w c:\users\Zdendys\AppData\Roaming\dvdcss
2009-02-03 10:54 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nokia
2009-01-31 14:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-27 17:52 --------- d-----w c:\programdata\Symantec
2009-01-16 22:45 --------- d-----w c:\program files\Common Files\Ahead
2009-01-16 22:42 --------- d-----w c:\programdata\Nero
2009-01-16 22:42 --------- d-----w c:\program files\Nero
2009-01-15 20:13 --------- d-----w c:\program files\Common Files\Nero
2009-01-15 02:02 --------- d-----w c:\program files\Microsoft Works
2009-01-14 16:38 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-09 09:07 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 09:07 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 09:07 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 09:07 --------- d-----w c:\program files\Symantec
2009-01-08 18:36 --------- d-----w c:\users\Zdendys\AppData\Roaming\Vso
2009-01-07 21:59 --------- d-----w c:\users\Zdendys\AppData\Roaming\vlc
2009-01-07 21:55 --------- d-----w c:\program files\VideoLAN
2009-01-03 21:08 --------- d-----w c:\program files\MSECache
2008-12-31 13:22 --------- d-----w c:\program files\MediaInfo
2008-12-30 22:12 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nero
2008-12-27 17:13 --------- d-----w c:\users\Zdendys\AppData\Roaming\CyberLink
2008-12-24 12:37 --------- d-----w c:\programdata\vsosdk
2008-12-23 22:26 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-23 22:26 47,360 ----a-w c:\users\Zdendys\AppData\Roaming\pcouffin.sys
2008-12-23 22:26 --------- d-----w c:\program files\VSO
2008-12-22 21:27 --------- d-----w c:\program files\Webteh
2008-12-15 20:20 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-11-14 15:22 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-11-14 15:22 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2008-06-30 12:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-11-15 12:48 22 --sha-w c:\windows\SMINST\HPCD.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
"ICQ"="c:\program files\ICQ6\ICQ.exe" [2008-09-01 173304]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-17 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-16 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-05-14 468264]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-01-16 727592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1346C59F-C7C4-4E6A-AE37-B11D86E2A71F}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{9D4F55D8-FB3A-4DE5-85D1-26F1850F4F95}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{91466F9D-5388-4574-A29E-FC826CF13688}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{C0945923-124B-4BC5-A732-3808CFCEC48F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{D6A6996C-6F1E-4009-B774-5C0AA80DCD33}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{27F64D1B-D3F4-46BA-8FA9-C64C8A9C17CD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3210A871-1AED-42B0-84C2-89803DE27826}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4DAEDE10-6A47-4647-9527-39FE66D60B92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{29DB70D6-832D-47A1-BB5B-95A5B93A2090}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{FC730066-E500-4C03-AF64-F9BCFFF14326}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0398D392-65A0-4780-8EC3-BA36BFB585EE}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0168C6FB-E12B-4381-A662-6F291AA7426A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{68133144-9356-451B-B838-8D321F8F8328}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DED75DB0-EF08-48D3-9B6F-2255FC04FF56}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{00725283-8EA1-40C0-9D51-E9C38B1D4A84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{2EAB20FB-BA46-4CB4-8672-160341EE8BD8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{A20FA3B2-7082-4F68-B45C-7BB74A37EAC4}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\System32\drivers\Amddfltr.sys [2008-09-20 15416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090217.004\IDSvix86.sys [2009-02-20 270384]
R1 PSched;Plánovač paketů technologie QoS;c:\windows\System32\drivers\pacer.sys [2008-11-14 72192]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\AEstSrv.exe [2008-09-20 73728]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [2008-03-18 19456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-07 149352]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-06-11 341328]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2008-03-26 595248]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-06-11 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [2008-01-23 52736]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-14 99376]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-04-01 81296]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2008-03-26 40752]
S2 gupdate1c991e82e17cf0;Služba Google Update (gupdate1c991e82e17cf0);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-13 23888]
S3 EC168BDA;TVGo DVB-T02PRO;c:\windows\System32\drivers\EC168BDA.sys [2008-11-15 67968]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f35f857d-b262-11dd-84a2-002186b39ad7}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Obsah adresáře 'Naplánované úlohy'
2009-02-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-18 17:39]
2009-02-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 17:42]
2009-02-17 c:\windows\Tasks\NeroLiveEpgUpdate-Zdendys-PC_Zdendys.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe []
2009-02-09 c:\windows\Tasks\Norton Internet Security - Prověřit tento počítač - Zdendys.job
- c:\program files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe [2008-02-07 13:05]
2009-02-22 c:\windows\Tasks\User_Feed_Synchronization-{36514A6C-BCFF-4A44-8A1D-555ECF717C8F}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-22 18:44:35
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(668)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(5588)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
c:\users\Zdendys\AppData\Local\Temp\catchme.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\conime.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\combofix\hidec.exe
c:\combofix\Catchme.tmp
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Celkový čas: 2009-02-22 18:49:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-02-22 17:47:54
Před spuštěním: Volných bajtů: 210 485 522 432
Po spuštění: Volných bajtů: 210,636,996,608
308 --- E O F --- 2009-02-20 13:42:24
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Jeden trojan to smazalo, snad je to on.jinak tam nic nevidím.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
Registry::
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu "Trojan hors"
Combo log:
ComboFix 09-02-21.01 - Zdendys 2009-02-22 20:03:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1029.18.2045.1210 [GMT 1:00]
Spuštěný z: c:\users\Zdendys\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Zdendys\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-01-22 do 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-22 17:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-22 17:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-22 16:51 . 2009-02-22 16:51 <DIR> d-------- c:\program files\Trend Micro
2009-02-21 15:05 . 2009-02-21 15:42 <DIR> d-------- c:\program files\Cyklotrasy
2009-02-19 15:15 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\System32\D3DX9_37.dll
2009-02-19 15:15 . 2008-03-05 15:56 1,420,824 --a------ c:\windows\System32\D3DCompiler_37.dll
2009-02-19 15:15 . 2008-02-05 23:07 462,864 --a------ c:\windows\System32\d3dx10_37.dll
2009-02-19 15:15 . 2007-04-04 18:53 81,768 --a------ c:\windows\System32\xinput1_3.dll
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\windows\System32\xlive
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\users\All Users\Google Updater
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\programdata\Google Updater
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\users\All Users\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\programdata\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 14:38 . 2009-02-17 14:39 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\users\All Users\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\users\All Users\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\programdata\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\programdata\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2009-02-16 12:39 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-16 12:39 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-16 12:39 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-16 12:39 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-16 12:39 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\users\All Users\HPSSUPPLY
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\programdata\HPSSUPPLY
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\users\All Users\WEBREG
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\programdata\WEBREG
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\users\All Users\HP Product Assistant
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\programdata\HP Product Assistant
2009-02-11 14:24 . 2009-02-11 14:24 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-02-11 14:22 . 2009-02-11 14:22 <DIR> d-------- c:\program files\Common Files\HP
2009-02-11 14:20 . 2007-10-30 10:11 729,088 --a------ c:\windows\System32\hpowiax7.dll
2009-02-11 14:20 . 2007-10-30 10:11 581,632 --a------ c:\windows\System32\hpotscl6.dll
2009-02-11 14:20 . 2007-10-30 10:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-02-11 14:20 . 2007-10-30 10:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-02-11 14:20 . 2007-10-30 10:11 303,104 --a------ c:\windows\System32\hpovst15.dll
2009-02-11 14:20 . 2007-11-08 15:52 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-02-11 14:20 . 2007-10-20 18:25 117,760 --a------ c:\windows\System32\hpzll5mu.dll
2009-02-11 14:15 . 2009-02-11 14:41 175,829 --a------ c:\windows\hpoins27.dat
2009-02-11 14:10 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 14:10 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 16:09 . 2009-02-10 16:09 <DIR> d-------- c:\program files\CCleaner
2009-02-09 20:52 . 2009-02-09 20:52 <DIR> d-------- c:\program files\Resco
2009-02-09 20:52 . 2007-10-10 19:38 90,112 --a------ c:\windows\RSetupCE.exe
2009-02-09 20:51 . 2009-02-09 20:51 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-07 16:56 . 2009-02-07 16:56 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-06 22:57 . 2009-02-06 22:57 <DIR> d-------- c:\users\Monika\AppData\Roaming\CyberLink
2009-02-03 23:33 . 2009-02-03 23:33 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\users\All Users\Google
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\program files\Google
2009-01-31 15:47 . 2009-01-31 15:53 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\COWON
2009-01-31 15:45 . 2009-01-31 16:49 <DIR> d-------- c:\program files\JetAudio
2009-01-31 15:40 . 2009-01-31 15:40 <DIR> d-------- c:\program files\FlashPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 17:43 --------- d-----w c:\users\Zdendys\AppData\Roaming\Skype
2009-02-22 17:42 --------- d-----w c:\users\Zdendys\AppData\Roaming\skypePM
2009-02-19 14:25 --------- d-----w c:\programdata\Downloaded Installations
2009-02-19 14:25 --------- d-----w c:\program files\Nokia
2009-02-19 14:25 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-18 21:00 --------- d-----w c:\users\Monika\AppData\Roaming\Skype
2009-02-18 19:00 --------- d-----w c:\users\Monika\AppData\Roaming\skypePM
2009-02-18 17:00 --------- d-----w c:\users\Zdendys\AppData\Roaming\uTorrent
2009-02-14 13:28 --------- d-----w c:\users\Zdendys\AppData\Roaming\Ahead
2009-02-11 16:10 --------- d-----w c:\program files\Windows Mail
2009-02-11 14:05 --------- d-----w c:\users\Zdendys\AppData\Roaming\HP
2009-02-11 13:42 --------- d-----w c:\programdata\HP
2009-02-11 13:40 --------- d-----w c:\programdata\Hewlett-Packard
2009-02-11 13:18 --------- d-----w c:\program files\HP
2009-02-03 11:14 --------- d-----w c:\users\Zdendys\AppData\Roaming\dvdcss
2009-02-03 10:54 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nokia
2009-01-31 14:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-27 17:52 --------- d-----w c:\programdata\Symantec
2009-01-16 22:45 --------- d-----w c:\program files\Common Files\Ahead
2009-01-16 22:42 --------- d-----w c:\programdata\Nero
2009-01-16 22:42 --------- d-----w c:\program files\Nero
2009-01-15 20:13 --------- d-----w c:\program files\Common Files\Nero
2009-01-15 02:02 --------- d-----w c:\program files\Microsoft Works
2009-01-14 16:38 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-09 09:07 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 09:07 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 09:07 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 09:07 --------- d-----w c:\program files\Symantec
2009-01-08 18:36 --------- d-----w c:\users\Zdendys\AppData\Roaming\Vso
2009-01-07 21:59 --------- d-----w c:\users\Zdendys\AppData\Roaming\vlc
2009-01-07 21:55 --------- d-----w c:\program files\VideoLAN
2009-01-03 21:08 --------- d-----w c:\program files\MSECache
2008-12-31 13:22 --------- d-----w c:\program files\MediaInfo
2008-12-30 22:12 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nero
2008-12-27 17:13 --------- d-----w c:\users\Zdendys\AppData\Roaming\CyberLink
2008-12-24 12:37 --------- d-----w c:\programdata\vsosdk
2008-12-23 22:26 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-23 22:26 47,360 ----a-w c:\users\Zdendys\AppData\Roaming\pcouffin.sys
2008-12-23 22:26 --------- d-----w c:\program files\VSO
2008-12-22 21:27 --------- d-----w c:\program files\Webteh
2008-12-15 20:20 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-11-14 15:22 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-11-14 15:22 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2008-06-30 12:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-11-15 12:48 22 --sha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-22_18.46.24.44 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-22 17:38:46 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-22 19:10:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-22 17:38:46 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-22 19:10:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-22 17:41:00 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-22 19:12:52 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-02-22 17:41:54 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-22 19:12:49 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-22 19:12:49 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-22 13:18:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-22 18:55:43 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-22 13:18:03 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-22 18:55:43 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-22 13:18:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-22 18:55:43 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-22 16:02:32 114,992 ----a-w c:\windows\System32\perfc005.dat
+ 2009-02-22 18:05:53 114,992 ----a-w c:\windows\System32\perfc005.dat
- 2009-02-22 16:02:32 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-22 18:05:53 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-22 16:02:32 598,832 ----a-w c:\windows\System32\perfh005.dat
+ 2009-02-22 18:05:53 598,832 ----a-w c:\windows\System32\perfh005.dat
- 2009-02-22 16:02:32 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-22 18:05:53 587,178 ----a-w c:\windows\System32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
"ICQ"="c:\program files\ICQ6\ICQ.exe" [2008-09-01 173304]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-17 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-16 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-05-14 468264]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-01-16 727592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1346C59F-C7C4-4E6A-AE37-B11D86E2A71F}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{9D4F55D8-FB3A-4DE5-85D1-26F1850F4F95}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{91466F9D-5388-4574-A29E-FC826CF13688}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{C0945923-124B-4BC5-A732-3808CFCEC48F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{D6A6996C-6F1E-4009-B774-5C0AA80DCD33}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{27F64D1B-D3F4-46BA-8FA9-C64C8A9C17CD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3210A871-1AED-42B0-84C2-89803DE27826}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4DAEDE10-6A47-4647-9527-39FE66D60B92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{29DB70D6-832D-47A1-BB5B-95A5B93A2090}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{FC730066-E500-4C03-AF64-F9BCFFF14326}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0398D392-65A0-4780-8EC3-BA36BFB585EE}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0168C6FB-E12B-4381-A662-6F291AA7426A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{68133144-9356-451B-B838-8D321F8F8328}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DED75DB0-EF08-48D3-9B6F-2255FC04FF56}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{00725283-8EA1-40C0-9D51-E9C38B1D4A84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{2EAB20FB-BA46-4CB4-8672-160341EE8BD8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{A20FA3B2-7082-4F68-B45C-7BB74A37EAC4}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\System32\drivers\Amddfltr.sys [2008-09-20 15416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090217.004\IDSvix86.sys [2009-02-20 270384]
R1 PSched;Plánovač paketů technologie QoS;c:\windows\System32\drivers\pacer.sys [2008-11-14 72192]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\AEstSrv.exe [2008-09-20 73728]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [2008-03-18 19456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-07 149352]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-06-11 341328]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2008-03-26 595248]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-06-11 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [2008-01-23 52736]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-14 99376]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-04-01 81296]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2008-03-26 40752]
S2 gupdate1c991e82e17cf0;Služba Google Update (gupdate1c991e82e17cf0);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-13 23888]
S3 EC168BDA;TVGo DVB-T02PRO;c:\windows\System32\drivers\EC168BDA.sys [2008-11-15 67968]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f35f857d-b262-11dd-84a2-002186b39ad7}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Obsah adresáře 'Naplánované úlohy'
2009-02-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-18 17:39]
2009-02-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 17:42]
2009-02-17 c:\windows\Tasks\NeroLiveEpgUpdate-Zdendys-PC_Zdendys.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe []
2009-02-09 c:\windows\Tasks\Norton Internet Security - Prověřit tento počítač - Zdendys.job
- c:\program files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe [2008-02-07 13:05]
2009-02-22 c:\windows\Tasks\User_Feed_Synchronization-{36514A6C-BCFF-4A44-8A1D-555ECF717C8F}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-22 20:12:57
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(684)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(4636)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Celkový čas: 2009-02-22 20:19:07 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-02-22 19:19:00
ComboFix2.txt 2009-02-22 17:49:19
Před spuštěním: Volných bajtů: 212 436 312 064
Po spuštění: Volných bajtů: 212,516,941,824
327 --- E O F --- 2009-02-20 13:42:24
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:52:41, on 22.2.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Plánovač automatické aktualizace LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Služba Google Update (gupdate1c991e82e17cf0) (gupdate1c991e82e17cf0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\STacSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
--
End of file - 14860 bytes
ComboFix 09-02-21.01 - Zdendys 2009-02-22 20:03:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1029.18.2045.1210 [GMT 1:00]
Spuštěný z: c:\users\Zdendys\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Zdendys\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-01-22 do 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-22 17:31 . 2009-02-22 17:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-22 17:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-22 17:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-22 16:51 . 2009-02-22 16:51 <DIR> d-------- c:\program files\Trend Micro
2009-02-21 15:05 . 2009-02-21 15:42 <DIR> d-------- c:\program files\Cyklotrasy
2009-02-19 15:15 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\System32\D3DX9_37.dll
2009-02-19 15:15 . 2008-03-05 15:56 1,420,824 --a------ c:\windows\System32\D3DCompiler_37.dll
2009-02-19 15:15 . 2008-02-05 23:07 462,864 --a------ c:\windows\System32\d3dx10_37.dll
2009-02-19 15:15 . 2007-04-04 18:53 81,768 --a------ c:\windows\System32\xinput1_3.dll
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\windows\System32\xlive
2009-02-19 15:14 . 2009-02-19 15:14 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\users\All Users\Google Updater
2009-02-18 17:39 . 2009-02-22 16:42 <DIR> d-------- c:\programdata\Google Updater
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\users\All Users\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 22:01 . 2009-02-17 22:01 <DIR> d----c--- c:\programdata\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-17 14:38 . 2009-02-17 14:39 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\users\All Users\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\users\All Users\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\programdata\ParetoLogic
2009-02-17 14:38 . 2009-02-17 17:36 <DIR> d-------- c:\programdata\DriverCure
2009-02-17 14:38 . 2009-02-17 14:38 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2009-02-16 12:39 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-16 12:39 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-16 12:39 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-16 12:39 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-16 12:39 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\users\All Users\HPSSUPPLY
2009-02-11 15:25 . 2009-02-11 15:25 <DIR> d-------- c:\programdata\HPSSUPPLY
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\users\All Users\WEBREG
2009-02-11 14:42 . 2009-02-11 14:42 <DIR> d-------- c:\programdata\WEBREG
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\users\All Users\HP Product Assistant
2009-02-11 14:25 . 2009-02-11 14:25 <DIR> d-------- c:\programdata\HP Product Assistant
2009-02-11 14:24 . 2009-02-11 14:24 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-02-11 14:22 . 2009-02-11 14:22 <DIR> d-------- c:\program files\Common Files\HP
2009-02-11 14:20 . 2007-10-30 10:11 729,088 --a------ c:\windows\System32\hpowiax7.dll
2009-02-11 14:20 . 2007-10-30 10:11 581,632 --a------ c:\windows\System32\hpotscl6.dll
2009-02-11 14:20 . 2007-10-30 10:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-02-11 14:20 . 2007-10-30 10:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-02-11 14:20 . 2007-10-30 10:11 303,104 --a------ c:\windows\System32\hpovst15.dll
2009-02-11 14:20 . 2007-11-08 15:52 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-02-11 14:20 . 2007-10-20 18:25 117,760 --a------ c:\windows\System32\hpzll5mu.dll
2009-02-11 14:15 . 2009-02-11 14:41 175,829 --a------ c:\windows\hpoins27.dat
2009-02-11 14:10 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 14:10 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 16:09 . 2009-02-10 16:09 <DIR> d-------- c:\program files\CCleaner
2009-02-09 20:52 . 2009-02-09 20:52 <DIR> d-------- c:\program files\Resco
2009-02-09 20:52 . 2007-10-10 19:38 90,112 --a------ c:\windows\RSetupCE.exe
2009-02-09 20:51 . 2009-02-09 20:51 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-07 16:56 . 2009-02-07 16:56 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-06 22:57 . 2009-02-06 22:57 <DIR> d-------- c:\users\Monika\AppData\Roaming\CyberLink
2009-02-03 23:33 . 2009-02-03 23:33 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\users\All Users\Google
2009-02-03 23:15 . 2009-02-18 17:49 <DIR> d-------- c:\program files\Google
2009-01-31 15:47 . 2009-01-31 15:53 <DIR> d-------- c:\users\Zdendys\AppData\Roaming\COWON
2009-01-31 15:45 . 2009-01-31 16:49 <DIR> d-------- c:\program files\JetAudio
2009-01-31 15:40 . 2009-01-31 15:40 <DIR> d-------- c:\program files\FlashPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-22 17:43 --------- d-----w c:\users\Zdendys\AppData\Roaming\Skype
2009-02-22 17:42 --------- d-----w c:\users\Zdendys\AppData\Roaming\skypePM
2009-02-19 14:25 --------- d-----w c:\programdata\Downloaded Installations
2009-02-19 14:25 --------- d-----w c:\program files\Nokia
2009-02-19 14:25 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-18 21:00 --------- d-----w c:\users\Monika\AppData\Roaming\Skype
2009-02-18 19:00 --------- d-----w c:\users\Monika\AppData\Roaming\skypePM
2009-02-18 17:00 --------- d-----w c:\users\Zdendys\AppData\Roaming\uTorrent
2009-02-14 13:28 --------- d-----w c:\users\Zdendys\AppData\Roaming\Ahead
2009-02-11 16:10 --------- d-----w c:\program files\Windows Mail
2009-02-11 14:05 --------- d-----w c:\users\Zdendys\AppData\Roaming\HP
2009-02-11 13:42 --------- d-----w c:\programdata\HP
2009-02-11 13:40 --------- d-----w c:\programdata\Hewlett-Packard
2009-02-11 13:18 --------- d-----w c:\program files\HP
2009-02-03 11:14 --------- d-----w c:\users\Zdendys\AppData\Roaming\dvdcss
2009-02-03 10:54 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nokia
2009-01-31 14:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-27 17:52 --------- d-----w c:\programdata\Symantec
2009-01-16 22:45 --------- d-----w c:\program files\Common Files\Ahead
2009-01-16 22:42 --------- d-----w c:\programdata\Nero
2009-01-16 22:42 --------- d-----w c:\program files\Nero
2009-01-15 20:13 --------- d-----w c:\program files\Common Files\Nero
2009-01-15 02:02 --------- d-----w c:\program files\Microsoft Works
2009-01-14 16:38 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-09 09:07 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 09:07 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 09:07 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 09:07 --------- d-----w c:\program files\Symantec
2009-01-08 18:36 --------- d-----w c:\users\Zdendys\AppData\Roaming\Vso
2009-01-07 21:59 --------- d-----w c:\users\Zdendys\AppData\Roaming\vlc
2009-01-07 21:55 --------- d-----w c:\program files\VideoLAN
2009-01-03 21:08 --------- d-----w c:\program files\MSECache
2008-12-31 13:22 --------- d-----w c:\program files\MediaInfo
2008-12-30 22:12 --------- d-----w c:\users\Zdendys\AppData\Roaming\Nero
2008-12-27 17:13 --------- d-----w c:\users\Zdendys\AppData\Roaming\CyberLink
2008-12-24 12:37 --------- d-----w c:\programdata\vsosdk
2008-12-23 22:26 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-23 22:26 47,360 ----a-w c:\users\Zdendys\AppData\Roaming\pcouffin.sys
2008-12-23 22:26 --------- d-----w c:\program files\VSO
2008-12-22 21:27 --------- d-----w c:\program files\Webteh
2008-12-15 20:20 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-11-14 15:22 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-11-14 15:22 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2008-06-30 12:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-11-15 12:48 22 --sha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-22_18.46.24.44 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-22 17:38:46 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-22 19:10:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-22 17:38:46 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-22 19:10:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-22 17:41:00 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-22 19:12:52 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-02-22 17:41:54 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-22 19:12:49 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-22 19:12:49 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-22 13:18:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-22 18:55:43 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-22 13:18:03 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-22 18:55:43 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-22 13:18:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-22 18:55:43 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-22 16:02:32 114,992 ----a-w c:\windows\System32\perfc005.dat
+ 2009-02-22 18:05:53 114,992 ----a-w c:\windows\System32\perfc005.dat
- 2009-02-22 16:02:32 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-22 18:05:53 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-22 16:02:32 598,832 ----a-w c:\windows\System32\perfh005.dat
+ 2009-02-22 18:05:53 598,832 ----a-w c:\windows\System32\perfh005.dat
- 2009-02-22 16:02:32 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-22 18:05:53 587,178 ----a-w c:\windows\System32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
"ICQ"="c:\program files\ICQ6\ICQ.exe" [2008-09-01 173304]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-17 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-16 442433]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-05-14 468264]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-01-16 727592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1346C59F-C7C4-4E6A-AE37-B11D86E2A71F}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{9D4F55D8-FB3A-4DE5-85D1-26F1850F4F95}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{91466F9D-5388-4574-A29E-FC826CF13688}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{C0945923-124B-4BC5-A732-3808CFCEC48F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{D6A6996C-6F1E-4009-B774-5C0AA80DCD33}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{27F64D1B-D3F4-46BA-8FA9-C64C8A9C17CD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3210A871-1AED-42B0-84C2-89803DE27826}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4DAEDE10-6A47-4647-9527-39FE66D60B92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{29DB70D6-832D-47A1-BB5B-95A5B93A2090}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{FC730066-E500-4C03-AF64-F9BCFFF14326}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0398D392-65A0-4780-8EC3-BA36BFB585EE}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{0168C6FB-E12B-4381-A662-6F291AA7426A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{68133144-9356-451B-B838-8D321F8F8328}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DED75DB0-EF08-48D3-9B6F-2255FC04FF56}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{00725283-8EA1-40C0-9D51-E9C38B1D4A84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{2EAB20FB-BA46-4CB4-8672-160341EE8BD8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{A20FA3B2-7082-4F68-B45C-7BB74A37EAC4}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\System32\drivers\Amddfltr.sys [2008-09-20 15416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090217.004\IDSvix86.sys [2009-02-20 270384]
R1 PSched;Plánovač paketů technologie QoS;c:\windows\System32\drivers\pacer.sys [2008-11-14 72192]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\AEstSrv.exe [2008-09-20 73728]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [2008-03-18 19456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-07 149352]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-06-11 341328]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2008-03-26 595248]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-06-11 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [2008-01-23 52736]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-14 99376]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [2008-04-01 81296]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-06-13 41008]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2008-03-26 40752]
S2 gupdate1c991e82e17cf0;Služba Google Update (gupdate1c991e82e17cf0);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-13 23888]
S3 EC168BDA;TVGo DVB-T02PRO;c:\windows\System32\drivers\EC168BDA.sys [2008-11-15 67968]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f35f857d-b262-11dd-84a2-002186b39ad7}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Obsah adresáře 'Naplánované úlohy'
2009-02-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-18 17:39]
2009-02-22 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 17:42]
2009-02-17 c:\windows\Tasks\NeroLiveEpgUpdate-Zdendys-PC_Zdendys.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe []
2009-02-09 c:\windows\Tasks\Norton Internet Security - Prověřit tento počítač - Zdendys.job
- c:\program files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe [2008-02-07 13:05]
2009-02-22 c:\windows\Tasks\User_Feed_Synchronization-{36514A6C-BCFF-4A44-8A1D-555ECF717C8F}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-22 20:12:57
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(684)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(4636)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Celkový čas: 2009-02-22 20:19:07 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-02-22 19:19:00
ComboFix2.txt 2009-02-22 17:49:19
Před spuštěním: Volných bajtů: 212 436 312 064
Po spuštění: Volných bajtů: 212,516,941,824
327 --- E O F --- 2009-02-20 13:42:24
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:52:41, on 22.2.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Plánovač automatické aktualizace LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Služba Google Update (gupdate1c991e82e17cf0) (gupdate1c991e82e17cf0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\STacSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
--
End of file - 14860 bytes
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix[mezera]/u
takže jestli nejsou problémy,tak vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš>spustíš
máš tam zbytky ve službách Symantec/Norton:
Start- spustit- napiš services.msc- vpravo v okně vyhledej-pravým vyber vlastnosti- v okně typ spouštění dej na zakázáno.
Pokud nejsou problémy , je to vše.
Kód: Vybrat vše
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O13 - Gopher Prefix:
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix[mezera]/u
takže jestli nejsou problémy,tak vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš>spustíš
máš tam zbytky ve službách Symantec/Norton:
Start- spustit- napiš services.msc- vpravo v okně vyhledej-pravým vyber vlastnosti- v okně typ spouštění dej na zakázáno.
Pokud nejsou problémy , je to vše.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu "Trojan hors"
s tím Combofixem to má vypadat takhle ComboFix /u ?Když jsem to zadal, tak mě to zas vyzívá k odpojení rez. ochrany.je to ok? Pak jsem ještě nenašel v HJT k fixnutí tohle
Kód: Vybrat vše
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Když to vyzývá tak to proveď.
Ten fix zbytečností zkus znovu , nezapomeň vypnout všechny aplikace a net.
Když to tam bude znovu , musel bys odinstalovat HJT , stáhnout nový, ale není to nákaza , je to jen zbytečnost.
Ten fix zbytečností zkus znovu , nezapomeň vypnout všechny aplikace a net.
Když to tam bude znovu , musel bys odinstalovat HJT , stáhnout nový, ale není to nákaza , je to jen zbytečnost.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu "Trojan hors"
jj.Už jsem to dotáh ke konci.Teď to akorád projíždím Nortonem jestli ještě něco nenajde.Jinak ti moc díky chlape...Dobrá práce 

- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu "Trojan hors"
Nemáš zač 

Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 10 hostů