Trojan v SVI Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Trojan v SVI  Vyřešeno

Příspěvekod Pic » 05 úno 2010 20:57

Viz nález z Mwav.exe :
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000356.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000360.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000361.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000362.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000363.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000364.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000365.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000367.ocx je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000368.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000369.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000370.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000371.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000372.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000373.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000374.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!

Přikládám log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:56:17, on 5.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
D:\DU Meter\DUMeter.exe
C:\ZoneAlarm\zlclient.exe
C:\Avast4\ashDisp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Avast4\aswUpdSv.exe
C:\Avast4\ashServ.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Avast4\ashMaiSv.exe
C:\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
E:\STAH\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dumeter.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DU Meter] D:\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\WINDOWS\TEMP\E_S54.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{24197EB0-FA9F-4AE0-BE39-C770E873404B}: NameServer = 84.16.96.139,84.16.96.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F09F727-F0ED-4FE9-8454-66C5D8E56F13}: NameServer = 84.16.96.139,84.16.96.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Avast4\ashWebSv.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Google Update Service (gupdate1c986cfc8d23e46) (gupdate1c986cfc8d23e46) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5930 bytes

Díky za kontrolu a radu.
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod jaro3 » 05 úno 2010 21:30

Zkoušel si vypnout bod obnovy -restart PC-a znovu zapnout obnovu?

V logu můžeš fixnout zbytečnosti:

Kód: Vybrat vše

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab


Vypni si rez. ochranu u Avastu
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 05 úno 2010 21:49

Ano to jsem zkoušel, ale nevedlo to k odstranění. V logu fixnuto a zde je log z combofixu:

ComboFix 10-02-05.01 - Petr 05.02.2010 21:42:53.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1604 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100204-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Pro Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Petr\Dokumenty\cc_20090121_225405.reg
c:\documents and settings\Petr\Dokumenty\cc_20090124_131853.reg
c:\documents and settings\Petr\Dokumenty\cc_20090206_171749.reg
c:\documents and settings\Petr\Dokumenty\cc_20090327_171701.reg
c:\recycler\S-1-5-21-1547161642-1647877149-682003330-1005
c:\windows\EventSystem.log
c:\windows\regedit.com
c:\windows\system32\Cache
c:\windows\system32\ieuinit.inf
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-05 do 2010-02-05 )))))))))))))))))))))))))))))))
.

2010-02-04 17:27 . 2010-02-04 17:27 -------- d---a-w- c:\windows\rundll16.exe
2010-02-04 17:27 . 2010-02-04 17:27 -------- d---a-w- c:\windows\logo1_.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 12:26 . 2008-09-14 12:26 16608 ----a-w- c:\windows\gdrv.sys
2010-02-04 23:50 . 2010-02-05 12:25 3701248 ----a-w- c:\windows\Internet Logs\xDB34E.tmp
2010-02-04 23:50 . 2010-02-05 12:25 64000 ----a-w- c:\windows\Internet Logs\xDB34F.tmp
2010-02-02 23:43 . 2010-02-03 13:05 3701248 ----a-w- c:\windows\Internet Logs\xDB34C.tmp
2010-02-02 23:43 . 2010-02-03 13:05 59904 ----a-w- c:\windows\Internet Logs\xDB34D.tmp
2010-01-29 23:44 . 2010-01-30 10:47 47104 ----a-w- c:\windows\Internet Logs\xDB34B.tmp
2010-01-29 23:44 . 2010-01-30 10:47 3701248 ----a-w- c:\windows\Internet Logs\xDB34A.tmp
2010-01-27 23:35 . 2010-01-28 15:23 3699712 ----a-w- c:\windows\Internet Logs\xDB349.tmp
2010-01-26 17:38 . 2010-01-27 16:53 22016 ----a-w- c:\windows\Internet Logs\xDB348.tmp
2010-01-26 17:28 . 2010-01-27 16:53 3700736 ----a-w- c:\windows\Internet Logs\xDB347.tmp
2010-01-25 23:25 . 2010-01-26 16:22 3699712 ----a-w- c:\windows\Internet Logs\xDB345.tmp
2010-01-25 23:25 . 2010-01-26 16:22 31232 ----a-w- c:\windows\Internet Logs\xDB346.tmp
2010-01-24 23:04 . 2010-01-25 10:04 32256 ----a-w- c:\windows\Internet Logs\xDB344.tmp
2010-01-24 23:04 . 2010-01-25 10:04 3699712 ----a-w- c:\windows\Internet Logs\xDB343.tmp
2010-01-24 00:43 . 2010-01-24 08:39 3698176 ----a-w- c:\windows\Internet Logs\xDB341.tmp
2010-01-24 00:43 . 2010-01-24 08:39 35328 ----a-w- c:\windows\Internet Logs\xDB342.tmp
2010-01-22 19:30 . 2010-01-22 19:32 3699712 ----a-w- c:\windows\Internet Logs\xDB33F.tmp
2010-01-22 19:30 . 2010-01-22 19:32 88064 ----a-w- c:\windows\Internet Logs\xDB340.tmp
2010-01-17 00:02 . 2010-01-17 11:59 54784 ----a-w- c:\windows\Internet Logs\xDB33E.tmp
2010-01-17 00:02 . 2010-01-17 11:59 3693568 ----a-w- c:\windows\Internet Logs\xDB33D.tmp
2010-01-14 11:17 . 2010-01-14 17:15 39936 ----a-w- c:\windows\Internet Logs\xDB33C.tmp
2010-01-14 11:17 . 2010-01-14 17:15 3692032 ----a-w- c:\windows\Internet Logs\xDB33B.tmp
2010-01-12 23:05 . 2010-01-13 12:24 3698176 ----a-w- c:\windows\Internet Logs\xDB339.tmp
2010-01-12 23:05 . 2010-01-13 12:24 31744 ----a-w- c:\windows\Internet Logs\xDB33A.tmp
2010-01-12 00:00 . 2010-01-12 12:00 34816 ----a-w- c:\windows\Internet Logs\xDB338.tmp
2010-01-12 00:00 . 2010-01-12 12:00 3692032 ----a-w- c:\windows\Internet Logs\xDB337.tmp
2010-01-10 17:41 . 2010-01-10 20:41 20992 ----a-w- c:\windows\Internet Logs\xDB336.tmp
2010-01-10 15:59 . 2010-01-10 20:41 3695616 ----a-w- c:\windows\Internet Logs\xDB335.tmp
2010-01-09 23:54 . 2010-01-10 11:30 28160 ----a-w- c:\windows\Internet Logs\xDB334.tmp
2010-01-09 23:54 . 2010-01-10 11:30 3692032 ----a-w- c:\windows\Internet Logs\xDB333.tmp
2010-01-08 23:41 . 2010-01-09 12:27 3692032 ----a-w- c:\windows\Internet Logs\xDB331.tmp
2010-01-08 23:41 . 2010-01-09 12:27 25088 ----a-w- c:\windows\Internet Logs\xDB332.tmp
2010-01-08 16:40 . 2010-01-08 16:42 3692032 ----a-w- c:\windows\Internet Logs\xDB32F.tmp
2010-01-08 16:40 . 2010-01-08 16:42 33280 ----a-w- c:\windows\Internet Logs\xDB330.tmp
2010-01-08 00:20 . 2010-01-08 16:09 3692032 ----a-w- c:\windows\Internet Logs\xDB32E.tmp
2010-01-07 14:55 . 2010-01-07 17:48 19456 ----a-w- c:\windows\Internet Logs\xDB32D.tmp
2010-01-07 14:55 . 2010-01-07 17:48 3692032 ----a-w- c:\windows\Internet Logs\xDB32C.tmp
2010-01-07 00:15 . 2010-01-07 14:49 3693568 ----a-w- c:\windows\Internet Logs\xDB32A.tmp
2010-01-07 00:15 . 2010-01-07 14:49 38400 ----a-w- c:\windows\Internet Logs\xDB32B.tmp
2010-01-05 12:03 . 2010-01-05 12:05 3688960 ----a-w- c:\windows\Internet Logs\xDB328.tmp
2010-01-05 12:03 . 2010-01-05 12:05 38400 ----a-w- c:\windows\Internet Logs\xDB329.tmp
2010-01-03 23:31 . 2010-01-04 11:45 27136 ----a-w- c:\windows\Internet Logs\xDB327.tmp
2010-01-03 23:31 . 2010-01-04 11:45 3688960 ----a-w- c:\windows\Internet Logs\xDB326.tmp
2010-01-03 11:07 . 2010-01-03 20:09 33280 ----a-w- c:\windows\Internet Logs\xDB325.tmp
2010-01-03 11:07 . 2010-01-03 20:09 3688960 ----a-w- c:\windows\Internet Logs\xDB324.tmp
2010-01-01 22:50 . 2010-01-02 12:27 28672 ----a-w- c:\windows\Internet Logs\xDB323.tmp
2010-01-01 22:50 . 2010-01-02 12:27 3693056 ----a-w- c:\windows\Internet Logs\xDB322.tmp
2009-12-31 17:50 . 2010-01-01 17:40 3691520 ----a-w- c:\windows\Internet Logs\xDB320.tmp
2009-12-31 17:50 . 2010-01-01 17:40 33280 ----a-w- c:\windows\Internet Logs\xDB321.tmp
2009-12-30 22:44 . 2009-12-30 22:45 3688960 ----a-w- c:\windows\Internet Logs\xDB31E.tmp
2009-12-30 22:44 . 2009-12-30 22:45 29696 ----a-w- c:\windows\Internet Logs\xDB31F.tmp
2009-12-29 23:24 . 2009-12-30 11:52 3690496 ----a-w- c:\windows\Internet Logs\xDB31C.tmp
2009-12-29 23:24 . 2009-12-30 11:52 27648 ----a-w- c:\windows\Internet Logs\xDB31D.tmp
2009-12-29 00:06 . 2009-12-29 09:07 35840 ----a-w- c:\windows\Internet Logs\xDB31B.tmp
2009-12-29 00:06 . 2009-12-29 09:07 3688960 ----a-w- c:\windows\Internet Logs\xDB31A.tmp
2009-12-26 23:32 . 2009-12-27 10:33 3688960 ----a-w- c:\windows\Internet Logs\xDB318.tmp
2009-12-26 23:32 . 2009-12-27 10:33 38912 ----a-w- c:\windows\Internet Logs\xDB319.tmp
2009-12-24 10:35 . 2009-12-25 12:07 34816 ----a-w- c:\windows\Internet Logs\xDB317.tmp
2009-12-24 10:35 . 2009-12-25 12:07 3688960 ----a-w- c:\windows\Internet Logs\xDB316.tmp
2009-12-23 00:10 . 2009-12-23 15:42 3695104 ----a-w- c:\windows\Internet Logs\xDB314.tmp
2009-12-23 00:10 . 2009-12-23 15:42 47616 ----a-w- c:\windows\Internet Logs\xDB315.tmp
2009-12-22 14:45 . 2008-11-11 19:34 -------- d-----w- c:\program files\Google
2009-12-22 05:09 . 2008-04-14 06:52 668160 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2008-04-14 06:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-20 00:18 . 2009-12-20 10:05 44544 ----a-w- c:\windows\Internet Logs\xDB313.tmp
2009-12-20 00:18 . 2009-12-20 10:05 3687424 ----a-w- c:\windows\Internet Logs\xDB312.tmp
2009-12-18 10:47 . 2009-12-18 14:52 3687424 ----a-w- c:\windows\Internet Logs\xDB310.tmp
2009-12-18 10:47 . 2009-12-18 14:52 58368 ----a-w- c:\windows\Internet Logs\xDB311.tmp
2009-12-15 00:35 . 2009-12-15 11:46 30720 ----a-w- c:\windows\Internet Logs\xDB30F.tmp
2009-12-15 00:35 . 2009-12-15 11:46 3681280 ----a-w- c:\windows\Internet Logs\xDB30E.tmp
2009-12-13 23:23 . 2009-12-14 11:07 3681280 ----a-w- c:\windows\Internet Logs\xDB30C.tmp
2009-12-13 23:23 . 2009-12-14 11:07 37888 ----a-w- c:\windows\Internet Logs\xDB30D.tmp
2009-12-12 00:11 . 2009-12-12 10:57 3681280 ----a-w- c:\windows\Internet Logs\xDB30A.tmp
2009-12-12 00:11 . 2009-12-12 10:57 43520 ----a-w- c:\windows\Internet Logs\xDB30B.tmp
2009-12-10 00:06 . 2009-12-10 12:28 46080 ----a-w- c:\windows\Internet Logs\xDB309.tmp
2009-12-10 00:06 . 2009-12-10 12:28 3678208 ----a-w- c:\windows\Internet Logs\xDB308.tmp
2009-12-06 23:30 . 2009-12-07 10:25 36864 ----a-w- c:\windows\Internet Logs\xDB307.tmp
2009-12-06 23:30 . 2009-12-07 10:25 3670528 ----a-w- c:\windows\Internet Logs\xDB306.tmp
2009-12-05 10:15 . 2009-12-05 15:25 85504 ----a-w- c:\windows\Internet Logs\xDB305.tmp
2009-12-05 10:15 . 2009-12-05 15:25 3670528 ----a-w- c:\windows\Internet Logs\xDB304.tmp
2009-11-29 23:31 . 2009-11-30 09:52 3666944 ----a-w- c:\windows\Internet Logs\xDB302.tmp
2009-11-29 23:31 . 2009-11-30 09:52 48640 ----a-w- c:\windows\Internet Logs\xDB303.tmp
2009-11-27 15:13 . 2009-11-27 17:13 32768 ----a-w- c:\windows\Internet Logs\xDB301.tmp
2009-11-27 15:13 . 2009-11-27 17:12 3662336 ----a-w- c:\windows\Internet Logs\xDB300.tmp
2009-11-26 15:38 . 2009-11-26 15:39 23040 ----a-w- c:\windows\Internet Logs\xDB2FF.tmp
2009-11-26 15:38 . 2009-11-26 15:39 3651072 ----a-w- c:\windows\Internet Logs\xDB2FE.tmp
2009-11-25 23:14 . 2009-11-26 15:35 24064 ----a-w- c:\windows\Internet Logs\xDB2FD.tmp
2009-11-25 23:13 . 2009-11-26 15:35 3648000 ----a-w- c:\windows\Internet Logs\xDB2FC.tmp
2009-11-25 14:31 . 2009-11-25 14:32 3648000 ----a-w- c:\windows\Internet Logs\xDB2FA.tmp
2009-11-25 14:31 . 2009-11-25 14:32 40960 ----a-w- c:\windows\Internet Logs\xDB2FB.tmp
2009-11-24 23:54 . 2008-09-15 12:07 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2008-09-15 12:07 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:49 . 2008-09-15 12:07 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-09-15 12:07 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-09-15 12:07 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2008-09-15 12:07 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-24 14:21 . 2009-11-24 14:22 3643904 ----a-w- c:\windows\Internet Logs\xDB2F8.tmp
2009-11-24 14:21 . 2009-11-24 14:22 30208 ----a-w- c:\windows\Internet Logs\xDB2F9.tmp
2009-11-23 23:03 . 2009-11-24 11:52 41984 ----a-w- c:\windows\Internet Logs\xDB2F7.tmp
2009-11-23 23:03 . 2009-11-24 11:52 3646976 ----a-w- c:\windows\Internet Logs\xDB2F6.tmp
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-10 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"DU Meter"="d:\du meter\DUMeter.exe" [2003-06-22 1297920]
"Zone Labs Client"="c:\zonealarm\zlclient.exe" [2004-11-28 902432]
"avast!"="c:\avast4\ashDisp.exe" [2009-11-24 81000]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-13 16862720]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - d:\adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
Adobe Reader Speed Launch.lnk.disabled [2008-9-18 1528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DAEMON Tools-1033"="d:\d-tools\daemon.exe" -lang 1033
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [26.11.2008 12:56 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [26.11.2008 12:56 5248]
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [15.10.2008 15:39 38448]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [15.9.2008 13:07 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.9.2008 13:07 20560]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [14.9.2008 13:29 80392]
S2 gupdate1c986cfc8d23e46;Google Update Service (gupdate1c986cfc8d23e46);c:\program files\Google\Update\GoogleUpdate.exe [4.2.2009 14:52 133104]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [6.11.2008 22:46 40060]
.
Obsah adresáře 'Naplánované úlohy'

2010-02-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-10 15:31]

2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 13:52]

2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 13:52]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.dumeter.com/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {24197EB0-FA9F-4AE0-BE39-C770E873404B} = 84.16.96.139,84.16.96.2
TCP: {7F09F727-F0ED-4FE9-8454-66C5D8E56F13} = 84.16.96.139,84.16.96.2
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\progra~1\GetRight\xx2gr.dll
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\progra~1\GetRight\xx2gr.dll
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\34ba03i3.default\
FF - prefs.js: browser.startup.homepage - http:/www.seznam.cz
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\34ba03i3.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: d:\adobe\Acrobat 7.0\Reader\browser\nppdf32.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 21:45
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

? [51676]
? [55328]
? [54564]
? [56124]
? [55476]
? [56972]
skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A5BE348]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba90cf28
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a5be348
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
Celkový čas: 2010-02-05 21:46:04
ComboFix-quarantined-files.txt 2010-02-05 20:46

Před spuštěním: Volných bajtů: 34 504 781 824
Po spuštění: Volných bajtů: 34 562 494 464

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.1="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - CA69FF5298788BB354F283F402950B64

Díky za pomoc!
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod jaro3 » 05 úno 2010 22:03

Nejprve ještě toto:
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 05 úno 2010 22:22

Zde je:
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3694
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

5.2.2010 22:20:48
mbam-log-2010-02-05 (22-20-48).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 150907
Uplynulý čas: 2 minute(s), 0 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod jaro3 » 05 úno 2010 23:14

Stáhni si program OTM (by OldTimer)
http://www.edisk.cz/stahni/07995/OTMove ... .39KB.html
a ulož si ho na disk C a spusť ho.
- Do levého sloupce (Paste Instructions for Items to be Moved) zkopíruj tyto cesty:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

:Processes
explorer.exe

:Services

:Reg

:Files
c:\windows\Internet Logs\*.tmp

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď.

******************************************************
Jdi přes Start -> Spustit... a napiš do okna tento příkaz označený modře:
C:\mbr.exe -f
a dej Ok.mezi mbr.exe a -f je mezera
- pokud by tě bezpečnostní software upozornil na přepsání MBR tak to povol
- počkej až program proběhne a pak restartuj Pc
******************************************************
Stáhni si MBR Rootkit Detektor
- ulož si ho přímo na disk C a spusť ho
- za chvíli se ti vytvoří jeho log (mbr.log) vlož sem celý jeho obsah.
*********************************************************************************
Poté vypni obnovu--restartuj PC--obnovu si zapni.
Udělej nový sken MWAV.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 05 úno 2010 23:31

Zde je log
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\windows\Internet Logs\xDB1.tmp moved successfully.
c:\windows\Internet Logs\xDB10.tmp moved successfully.
c:\windows\Internet Logs\xDB100.tmp moved successfully.
c:\windows\Internet Logs\xDB101.tmp moved successfully.
c:\windows\Internet Logs\xDB102.tmp moved successfully.
c:\windows\Internet Logs\xDB103.tmp moved successfully.
c:\windows\Internet Logs\xDB104.tmp moved successfully.
c:\windows\Internet Logs\xDB105.tmp moved successfully.
c:\windows\Internet Logs\xDB106.tmp moved successfully.
c:\windows\Internet Logs\xDB107.tmp moved successfully.
c:\windows\Internet Logs\xDB108.tmp moved successfully.
c:\windows\Internet Logs\xDB109.tmp moved successfully.
c:\windows\Internet Logs\xDB10A.tmp moved successfully.
c:\windows\Internet Logs\xDB10B.tmp moved successfully.
c:\windows\Internet Logs\xDB10C.tmp moved successfully.
c:\windows\Internet Logs\xDB10D.tmp moved successfully.
c:\windows\Internet Logs\xDB10E.tmp moved successfully.
c:\windows\Internet Logs\xDB10F.tmp moved successfully.
c:\windows\Internet Logs\xDB11.tmp moved successfully.
c:\windows\Internet Logs\xDB110.tmp moved successfully.
c:\windows\Internet Logs\xDB111.tmp moved successfully.
c:\windows\Internet Logs\xDB112.tmp moved successfully.
c:\windows\Internet Logs\xDB113.tmp moved successfully.
c:\windows\Internet Logs\xDB114.tmp moved successfully.
c:\windows\Internet Logs\xDB115.tmp moved successfully.
c:\windows\Internet Logs\xDB116.tmp moved successfully.
c:\windows\Internet Logs\xDB117.tmp moved successfully.
c:\windows\Internet Logs\xDB118.tmp moved successfully.
c:\windows\Internet Logs\xDB119.tmp moved successfully.
c:\windows\Internet Logs\xDB11A.tmp moved successfully.
c:\windows\Internet Logs\xDB11B.tmp moved successfully.
c:\windows\Internet Logs\xDB11C.tmp moved successfully.
c:\windows\Internet Logs\xDB11D.tmp moved successfully.
c:\windows\Internet Logs\xDB11E.tmp moved successfully.
c:\windows\Internet Logs\xDB11F.tmp moved successfully.
c:\windows\Internet Logs\xDB12.tmp moved successfully.
c:\windows\Internet Logs\xDB120.tmp moved successfully.
c:\windows\Internet Logs\xDB121.tmp moved successfully.
c:\windows\Internet Logs\xDB122.tmp moved successfully.
c:\windows\Internet Logs\xDB123.tmp moved successfully.
c:\windows\Internet Logs\xDB124.tmp moved successfully.
c:\windows\Internet Logs\xDB125.tmp moved successfully.
c:\windows\Internet Logs\xDB126.tmp moved successfully.
c:\windows\Internet Logs\xDB127.tmp moved successfully.
c:\windows\Internet Logs\xDB128.tmp moved successfully.
c:\windows\Internet Logs\xDB129.tmp moved successfully.
c:\windows\Internet Logs\xDB12A.tmp moved successfully.
c:\windows\Internet Logs\xDB12B.tmp moved successfully.
c:\windows\Internet Logs\xDB12C.tmp moved successfully.
c:\windows\Internet Logs\xDB12D.tmp moved successfully.
c:\windows\Internet Logs\xDB12E.tmp moved successfully.
c:\windows\Internet Logs\xDB12F.tmp moved successfully.
c:\windows\Internet Logs\xDB13.tmp moved successfully.
c:\windows\Internet Logs\xDB130.tmp moved successfully.
c:\windows\Internet Logs\xDB131.tmp moved successfully.
c:\windows\Internet Logs\xDB132.tmp moved successfully.
c:\windows\Internet Logs\xDB133.tmp moved successfully.
c:\windows\Internet Logs\xDB134.tmp moved successfully.
c:\windows\Internet Logs\xDB135.tmp moved successfully.
c:\windows\Internet Logs\xDB136.tmp moved successfully.
c:\windows\Internet Logs\xDB137.tmp moved successfully.
c:\windows\Internet Logs\xDB138.tmp moved successfully.
c:\windows\Internet Logs\xDB139.tmp moved successfully.
c:\windows\Internet Logs\xDB13A.tmp moved successfully.
c:\windows\Internet Logs\xDB13B.tmp moved successfully.
c:\windows\Internet Logs\xDB13C.tmp moved successfully.
c:\windows\Internet Logs\xDB13D.tmp moved successfully.
c:\windows\Internet Logs\xDB13E.tmp moved successfully.
c:\windows\Internet Logs\xDB13F.tmp moved successfully.
c:\windows\Internet Logs\xDB14.tmp moved successfully.
c:\windows\Internet Logs\xDB140.tmp moved successfully.
c:\windows\Internet Logs\xDB141.tmp moved successfully.
c:\windows\Internet Logs\xDB142.tmp moved successfully.
c:\windows\Internet Logs\xDB143.tmp moved successfully.
c:\windows\Internet Logs\xDB144.tmp moved successfully.
c:\windows\Internet Logs\xDB145.tmp moved successfully.
c:\windows\Internet Logs\xDB146.tmp moved successfully.
c:\windows\Internet Logs\xDB147.tmp moved successfully.
c:\windows\Internet Logs\xDB148.tmp moved successfully.
c:\windows\Internet Logs\xDB149.tmp moved successfully.
c:\windows\Internet Logs\xDB14A.tmp moved successfully.
c:\windows\Internet Logs\xDB14B.tmp moved successfully.
c:\windows\Internet Logs\xDB14C.tmp moved successfully.
c:\windows\Internet Logs\xDB14D.tmp moved successfully.
c:\windows\Internet Logs\xDB14E.tmp moved successfully.
c:\windows\Internet Logs\xDB14F.tmp moved successfully.
c:\windows\Internet Logs\xDB15.tmp moved successfully.
c:\windows\Internet Logs\xDB150.tmp moved successfully.
c:\windows\Internet Logs\xDB151.tmp moved successfully.
c:\windows\Internet Logs\xDB152.tmp moved successfully.
c:\windows\Internet Logs\xDB153.tmp moved successfully.
c:\windows\Internet Logs\xDB154.tmp moved successfully.
c:\windows\Internet Logs\xDB155.tmp moved successfully.
c:\windows\Internet Logs\xDB156.tmp moved successfully.
c:\windows\Internet Logs\xDB157.tmp moved successfully.
c:\windows\Internet Logs\xDB158.tmp moved successfully.
c:\windows\Internet Logs\xDB159.tmp moved successfully.
c:\windows\Internet Logs\xDB15A.tmp moved successfully.
c:\windows\Internet Logs\xDB15B.tmp moved successfully.
c:\windows\Internet Logs\xDB15C.tmp moved successfully.
c:\windows\Internet Logs\xDB15D.tmp moved successfully.
c:\windows\Internet Logs\xDB15E.tmp moved successfully.
c:\windows\Internet Logs\xDB15F.tmp moved successfully.
c:\windows\Internet Logs\xDB16.tmp moved successfully.
c:\windows\Internet Logs\xDB160.tmp moved successfully.
c:\windows\Internet Logs\xDB161.tmp moved successfully.
c:\windows\Internet Logs\xDB162.tmp moved successfully.
c:\windows\Internet Logs\xDB163.tmp moved successfully.
c:\windows\Internet Logs\xDB164.tmp moved successfully.
c:\windows\Internet Logs\xDB165.tmp moved successfully.
c:\windows\Internet Logs\xDB166.tmp moved successfully.
c:\windows\Internet Logs\xDB167.tmp moved successfully.
c:\windows\Internet Logs\xDB168.tmp moved successfully.
c:\windows\Internet Logs\xDB169.tmp moved successfully.
c:\windows\Internet Logs\xDB16A.tmp moved successfully.
c:\windows\Internet Logs\xDB16B.tmp moved successfully.
c:\windows\Internet Logs\xDB16C.tmp moved successfully.
c:\windows\Internet Logs\xDB16D.tmp moved successfully.
c:\windows\Internet Logs\xDB16E.tmp moved successfully.
c:\windows\Internet Logs\xDB16F.tmp moved successfully.
c:\windows\Internet Logs\xDB17.tmp moved successfully.
c:\windows\Internet Logs\xDB170.tmp moved successfully.
c:\windows\Internet Logs\xDB171.tmp moved successfully.
c:\windows\Internet Logs\xDB172.tmp moved successfully.
c:\windows\Internet Logs\xDB173.tmp moved successfully.
c:\windows\Internet Logs\xDB174.tmp moved successfully.
c:\windows\Internet Logs\xDB175.tmp moved successfully.
c:\windows\Internet Logs\xDB176.tmp moved successfully.
c:\windows\Internet Logs\xDB177.tmp moved successfully.
c:\windows\Internet Logs\xDB178.tmp moved successfully.
c:\windows\Internet Logs\xDB179.tmp moved successfully.
c:\windows\Internet Logs\xDB17A.tmp moved successfully.
c:\windows\Internet Logs\xDB17B.tmp moved successfully.
c:\windows\Internet Logs\xDB17C.tmp moved successfully.
c:\windows\Internet Logs\xDB17D.tmp moved successfully.
c:\windows\Internet Logs\xDB17E.tmp moved successfully.
c:\windows\Internet Logs\xDB17F.tmp moved successfully.
c:\windows\Internet Logs\xDB18.tmp moved successfully.
c:\windows\Internet Logs\xDB180.tmp moved successfully.
c:\windows\Internet Logs\xDB181.tmp moved successfully.
c:\windows\Internet Logs\xDB182.tmp moved successfully.
c:\windows\Internet Logs\xDB183.tmp moved successfully.
c:\windows\Internet Logs\xDB184.tmp moved successfully.
c:\windows\Internet Logs\xDB185.tmp moved successfully.
c:\windows\Internet Logs\xDB186.tmp moved successfully.
c:\windows\Internet Logs\xDB187.tmp moved successfully.
c:\windows\Internet Logs\xDB188.tmp moved successfully.
c:\windows\Internet Logs\xDB189.tmp moved successfully.
c:\windows\Internet Logs\xDB18A.tmp moved successfully.
c:\windows\Internet Logs\xDB18B.tmp moved successfully.
c:\windows\Internet Logs\xDB18C.tmp moved successfully.
c:\windows\Internet Logs\xDB18D.tmp moved successfully.
c:\windows\Internet Logs\xDB18E.tmp moved successfully.
c:\windows\Internet Logs\xDB18F.tmp moved successfully.
c:\windows\Internet Logs\xDB19.tmp moved successfully.
c:\windows\Internet Logs\xDB190.tmp moved successfully.
c:\windows\Internet Logs\xDB191.tmp moved successfully.
c:\windows\Internet Logs\xDB192.tmp moved successfully.
c:\windows\Internet Logs\xDB193.tmp moved successfully.
c:\windows\Internet Logs\xDB194.tmp moved successfully.
c:\windows\Internet Logs\xDB195.tmp moved successfully.
c:\windows\Internet Logs\xDB196.tmp moved successfully.
c:\windows\Internet Logs\xDB197.tmp moved successfully.
c:\windows\Internet Logs\xDB198.tmp moved successfully.
c:\windows\Internet Logs\xDB199.tmp moved successfully.
c:\windows\Internet Logs\xDB19A.tmp moved successfully.
c:\windows\Internet Logs\xDB19B.tmp moved successfully.
c:\windows\Internet Logs\xDB19C.tmp moved successfully.
c:\windows\Internet Logs\xDB19D.tmp moved successfully.
c:\windows\Internet Logs\xDB19E.tmp moved successfully.
c:\windows\Internet Logs\xDB19F.tmp moved successfully.
c:\windows\Internet Logs\xDB1A.tmp moved successfully.
c:\windows\Internet Logs\xDB1A0.tmp moved successfully.
c:\windows\Internet Logs\xDB1A1.tmp moved successfully.
c:\windows\Internet Logs\xDB1A2.tmp moved successfully.
c:\windows\Internet Logs\xDB1A3.tmp moved successfully.
c:\windows\Internet Logs\xDB1A4.tmp moved successfully.
c:\windows\Internet Logs\xDB1A5.tmp moved successfully.
c:\windows\Internet Logs\xDB1A6.tmp moved successfully.
c:\windows\Internet Logs\xDB1A7.tmp moved successfully.
c:\windows\Internet Logs\xDB1A8.tmp moved successfully.
c:\windows\Internet Logs\xDB1A9.tmp moved successfully.
c:\windows\Internet Logs\xDB1AA.tmp moved successfully.
c:\windows\Internet Logs\xDB1AB.tmp moved successfully.
c:\windows\Internet Logs\xDB1AC.tmp moved successfully.
c:\windows\Internet Logs\xDB1AD.tmp moved successfully.
c:\windows\Internet Logs\xDB1AE.tmp moved successfully.
c:\windows\Internet Logs\xDB1AF.tmp moved successfully.
c:\windows\Internet Logs\xDB1B.tmp moved successfully.
c:\windows\Internet Logs\xDB1B0.tmp moved successfully.
c:\windows\Internet Logs\xDB1B1.tmp moved successfully.
c:\windows\Internet Logs\xDB1B2.tmp moved successfully.
c:\windows\Internet Logs\xDB1B3.tmp moved successfully.
c:\windows\Internet Logs\xDB1B4.tmp moved successfully.
c:\windows\Internet Logs\xDB1B5.tmp moved successfully.
c:\windows\Internet Logs\xDB1B6.tmp moved successfully.
c:\windows\Internet Logs\xDB1B7.tmp moved successfully.
c:\windows\Internet Logs\xDB1B8.tmp moved successfully.
c:\windows\Internet Logs\xDB1B9.tmp moved successfully.
c:\windows\Internet Logs\xDB1BA.tmp moved successfully.
c:\windows\Internet Logs\xDB1BB.tmp moved successfully.
c:\windows\Internet Logs\xDB1BC.tmp moved successfully.
c:\windows\Internet Logs\xDB1BD.tmp moved successfully.
c:\windows\Internet Logs\xDB1BE.tmp moved successfully.
c:\windows\Internet Logs\xDB1BF.tmp moved successfully.
c:\windows\Internet Logs\xDB1C.tmp moved successfully.
c:\windows\Internet Logs\xDB1C0.tmp moved successfully.
c:\windows\Internet Logs\xDB1C1.tmp moved successfully.
c:\windows\Internet Logs\xDB1C2.tmp moved successfully.
c:\windows\Internet Logs\xDB1C3.tmp moved successfully.
c:\windows\Internet Logs\xDB1C4.tmp moved successfully.
c:\windows\Internet Logs\xDB1C5.tmp moved successfully.
c:\windows\Internet Logs\xDB1C6.tmp moved successfully.
c:\windows\Internet Logs\xDB1C7.tmp moved successfully.
c:\windows\Internet Logs\xDB1C8.tmp moved successfully.
c:\windows\Internet Logs\xDB1C9.tmp moved successfully.
c:\windows\Internet Logs\xDB1CA.tmp moved successfully.
c:\windows\Internet Logs\xDB1CB.tmp moved successfully.
c:\windows\Internet Logs\xDB1CC.tmp moved successfully.
c:\windows\Internet Logs\xDB1CD.tmp moved successfully.
c:\windows\Internet Logs\xDB1CE.tmp moved successfully.
c:\windows\Internet Logs\xDB1CF.tmp moved successfully.
c:\windows\Internet Logs\xDB1D.tmp moved successfully.
c:\windows\Internet Logs\xDB1D0.tmp moved successfully.
c:\windows\Internet Logs\xDB1D1.tmp moved successfully.
c:\windows\Internet Logs\xDB1D2.tmp moved successfully.
c:\windows\Internet Logs\xDB1D3.tmp moved successfully.
c:\windows\Internet Logs\xDB1D4.tmp moved successfully.
c:\windows\Internet Logs\xDB1D5.tmp moved successfully.
c:\windows\Internet Logs\xDB1D6.tmp moved successfully.
c:\windows\Internet Logs\xDB1D7.tmp moved successfully.
c:\windows\Internet Logs\xDB1D8.tmp moved successfully.
c:\windows\Internet Logs\xDB1D9.tmp moved successfully.
c:\windows\Internet Logs\xDB1DA.tmp moved successfully.
c:\windows\Internet Logs\xDB1DB.tmp moved successfully.
c:\windows\Internet Logs\xDB1DC.tmp moved successfully.
c:\windows\Internet Logs\xDB1DD.tmp moved successfully.
c:\windows\Internet Logs\xDB1DE.tmp moved successfully.
c:\windows\Internet Logs\xDB1DF.tmp moved successfully.
c:\windows\Internet Logs\xDB1E.tmp moved successfully.
c:\windows\Internet Logs\xDB1E0.tmp moved successfully.
c:\windows\Internet Logs\xDB1E1.tmp moved successfully.
c:\windows\Internet Logs\xDB1E2.tmp moved successfully.
c:\windows\Internet Logs\xDB1E3.tmp moved successfully.
c:\windows\Internet Logs\xDB1E4.tmp moved successfully.
c:\windows\Internet Logs\xDB1E5.tmp moved successfully.
c:\windows\Internet Logs\xDB1E6.tmp moved successfully.
c:\windows\Internet Logs\xDB1E7.tmp moved successfully.
c:\windows\Internet Logs\xDB1E8.tmp moved successfully.
c:\windows\Internet Logs\xDB1E9.tmp moved successfully.
c:\windows\Internet Logs\xDB1EA.tmp moved successfully.
c:\windows\Internet Logs\xDB1EB.tmp moved successfully.
c:\windows\Internet Logs\xDB1EC.tmp moved successfully.
c:\windows\Internet Logs\xDB1ED.tmp moved successfully.
c:\windows\Internet Logs\xDB1EE.tmp moved successfully.
c:\windows\Internet Logs\xDB1EF.tmp moved successfully.
c:\windows\Internet Logs\xDB1F.tmp moved successfully.
c:\windows\Internet Logs\xDB1F0.tmp moved successfully.
c:\windows\Internet Logs\xDB1F1.tmp moved successfully.
c:\windows\Internet Logs\xDB1F2.tmp moved successfully.
c:\windows\Internet Logs\xDB1F3.tmp moved successfully.
c:\windows\Internet Logs\xDB1F4.tmp moved successfully.
c:\windows\Internet Logs\xDB1F5.tmp moved successfully.
c:\windows\Internet Logs\xDB1F6.tmp moved successfully.
c:\windows\Internet Logs\xDB1F7.tmp moved successfully.
c:\windows\Internet Logs\xDB1F8.tmp moved successfully.
c:\windows\Internet Logs\xDB1F9.tmp moved successfully.
c:\windows\Internet Logs\xDB1FA.tmp moved successfully.
c:\windows\Internet Logs\xDB1FB.tmp moved successfully.
c:\windows\Internet Logs\xDB1FC.tmp moved successfully.
c:\windows\Internet Logs\xDB1FD.tmp moved successfully.
c:\windows\Internet Logs\xDB1FE.tmp moved successfully.
c:\windows\Internet Logs\xDB1FF.tmp moved successfully.
c:\windows\Internet Logs\xDB2.tmp moved successfully.
c:\windows\Internet Logs\xDB20.tmp moved successfully.
c:\windows\Internet Logs\xDB200.tmp moved successfully.
c:\windows\Internet Logs\xDB201.tmp moved successfully.
c:\windows\Internet Logs\xDB202.tmp moved successfully.
c:\windows\Internet Logs\xDB203.tmp moved successfully.
c:\windows\Internet Logs\xDB204.tmp moved successfully.
c:\windows\Internet Logs\xDB205.tmp moved successfully.
c:\windows\Internet Logs\xDB206.tmp moved successfully.
c:\windows\Internet Logs\xDB207.tmp moved successfully.
c:\windows\Internet Logs\xDB208.tmp moved successfully.
c:\windows\Internet Logs\xDB209.tmp moved successfully.
c:\windows\Internet Logs\xDB20A.tmp moved successfully.
c:\windows\Internet Logs\xDB20B.tmp moved successfully.
c:\windows\Internet Logs\xDB20C.tmp moved successfully.
c:\windows\Internet Logs\xDB20D.tmp moved successfully.
c:\windows\Internet Logs\xDB20E.tmp moved successfully.
c:\windows\Internet Logs\xDB20F.tmp moved successfully.
c:\windows\Internet Logs\xDB21.tmp moved successfully.
c:\windows\Internet Logs\xDB210.tmp moved successfully.
c:\windows\Internet Logs\xDB211.tmp moved successfully.
c:\windows\Internet Logs\xDB212.tmp moved successfully.
c:\windows\Internet Logs\xDB213.tmp moved successfully.
c:\windows\Internet Logs\xDB214.tmp moved successfully.
c:\windows\Internet Logs\xDB215.tmp moved successfully.
c:\windows\Internet Logs\xDB216.tmp moved successfully.
c:\windows\Internet Logs\xDB217.tmp moved successfully.
c:\windows\Internet Logs\xDB218.tmp moved successfully.
c:\windows\Internet Logs\xDB219.tmp moved successfully.
c:\windows\Internet Logs\xDB21A.tmp moved successfully.
c:\windows\Internet Logs\xDB21B.tmp moved successfully.
c:\windows\Internet Logs\xDB21C.tmp moved successfully.
c:\windows\Internet Logs\xDB21D.tmp moved successfully.
c:\windows\Internet Logs\xDB21E.tmp moved successfully.
c:\windows\Internet Logs\xDB21F.tmp moved successfully.
c:\windows\Internet Logs\xDB22.tmp moved successfully.
c:\windows\Internet Logs\xDB220.tmp moved successfully.
c:\windows\Internet Logs\xDB221.tmp moved successfully.
c:\windows\Internet Logs\xDB222.tmp moved successfully.
c:\windows\Internet Logs\xDB223.tmp moved successfully.
c:\windows\Internet Logs\xDB224.tmp moved successfully.
c:\windows\Internet Logs\xDB225.tmp moved successfully.
c:\windows\Internet Logs\xDB226.tmp moved successfully.
c:\windows\Internet Logs\xDB227.tmp moved successfully.
c:\windows\Internet Logs\xDB228.tmp moved successfully.
c:\windows\Internet Logs\xDB229.tmp moved successfully.
c:\windows\Internet Logs\xDB22A.tmp moved successfully.
c:\windows\Internet Logs\xDB22B.tmp moved successfully.
c:\windows\Internet Logs\xDB22C.tmp moved successfully.
c:\windows\Internet Logs\xDB22D.tmp moved successfully.
c:\windows\Internet Logs\xDB22E.tmp moved successfully.
c:\windows\Internet Logs\xDB22F.tmp moved successfully.
c:\windows\Internet Logs\xDB23.tmp moved successfully.
c:\windows\Internet Logs\xDB230.tmp moved successfully.
c:\windows\Internet Logs\xDB231.tmp moved successfully.
c:\windows\Internet Logs\xDB232.tmp moved successfully.
c:\windows\Internet Logs\xDB233.tmp moved successfully.
c:\windows\Internet Logs\xDB234.tmp moved successfully.
c:\windows\Internet Logs\xDB235.tmp moved successfully.
c:\windows\Internet Logs\xDB236.tmp moved successfully.
c:\windows\Internet Logs\xDB237.tmp moved successfully.
c:\windows\Internet Logs\xDB238.tmp moved successfully.
c:\windows\Internet Logs\xDB239.tmp moved successfully.
c:\windows\Internet Logs\xDB23A.tmp moved successfully.
c:\windows\Internet Logs\xDB23B.tmp moved successfully.
c:\windows\Internet Logs\xDB23C.tmp moved successfully.
c:\windows\Internet Logs\xDB23D.tmp moved successfully.
c:\windows\Internet Logs\xDB23E.tmp moved successfully.
c:\windows\Internet Logs\xDB23F.tmp moved successfully.
c:\windows\Internet Logs\xDB24.tmp moved successfully.
c:\windows\Internet Logs\xDB240.tmp moved successfully.
c:\windows\Internet Logs\xDB241.tmp moved successfully.
c:\windows\Internet Logs\xDB242.tmp moved successfully.
c:\windows\Internet Logs\xDB243.tmp moved successfully.
c:\windows\Internet Logs\xDB244.tmp moved successfully.
c:\windows\Internet Logs\xDB245.tmp moved successfully.
c:\windows\Internet Logs\xDB246.tmp moved successfully.
c:\windows\Internet Logs\xDB247.tmp moved successfully.
c:\windows\Internet Logs\xDB248.tmp moved successfully.
c:\windows\Internet Logs\xDB249.tmp moved successfully.
c:\windows\Internet Logs\xDB24A.tmp moved successfully.
c:\windows\Internet Logs\xDB24B.tmp moved successfully.
c:\windows\Internet Logs\xDB24C.tmp moved successfully.
c:\windows\Internet Logs\xDB24D.tmp moved successfully.
c:\windows\Internet Logs\xDB24E.tmp moved successfully.
c:\windows\Internet Logs\xDB24F.tmp moved successfully.
c:\windows\Internet Logs\xDB25.tmp moved successfully.
c:\windows\Internet Logs\xDB250.tmp moved successfully.
c:\windows\Internet Logs\xDB251.tmp moved successfully.
c:\windows\Internet Logs\xDB252.tmp moved successfully.
c:\windows\Internet Logs\xDB253.tmp moved successfully.
c:\windows\Internet Logs\xDB254.tmp moved successfully.
c:\windows\Internet Logs\xDB255.tmp moved successfully.
c:\windows\Internet Logs\xDB256.tmp moved successfully.
c:\windows\Internet Logs\xDB257.tmp moved successfully.
c:\windows\Internet Logs\xDB258.tmp moved successfully.
c:\windows\Internet Logs\xDB259.tmp moved successfully.
c:\windows\Internet Logs\xDB25A.tmp moved successfully.
c:\windows\Internet Logs\xDB25B.tmp moved successfully.
c:\windows\Internet Logs\xDB25C.tmp moved successfully.
c:\windows\Internet Logs\xDB25D.tmp moved successfully.
c:\windows\Internet Logs\xDB25E.tmp moved successfully.
c:\windows\Internet Logs\xDB25F.tmp moved successfully.
c:\windows\Internet Logs\xDB26.tmp moved successfully.
c:\windows\Internet Logs\xDB260.tmp moved successfully.
c:\windows\Internet Logs\xDB261.tmp moved successfully.
c:\windows\Internet Logs\xDB262.tmp moved successfully.
c:\windows\Internet Logs\xDB263.tmp moved successfully.
c:\windows\Internet Logs\xDB264.tmp moved successfully.
c:\windows\Internet Logs\xDB265.tmp moved successfully.
c:\windows\Internet Logs\xDB266.tmp moved successfully.
c:\windows\Internet Logs\xDB267.tmp moved successfully.
c:\windows\Internet Logs\xDB268.tmp moved successfully.
c:\windows\Internet Logs\xDB269.tmp moved successfully.
c:\windows\Internet Logs\xDB26A.tmp moved successfully.
c:\windows\Internet Logs\xDB26B.tmp moved successfully.
c:\windows\Internet Logs\xDB26C.tmp moved successfully.
c:\windows\Internet Logs\xDB26D.tmp moved successfully.
c:\windows\Internet Logs\xDB26E.tmp moved successfully.
c:\windows\Internet Logs\xDB26F.tmp moved successfully.
c:\windows\Internet Logs\xDB27.tmp moved successfully.
c:\windows\Internet Logs\xDB270.tmp moved successfully.
c:\windows\Internet Logs\xDB271.tmp moved successfully.
c:\windows\Internet Logs\xDB272.tmp moved successfully.
c:\windows\Internet Logs\xDB273.tmp moved successfully.
c:\windows\Internet Logs\xDB274.tmp moved successfully.
c:\windows\Internet Logs\xDB275.tmp moved successfully.
c:\windows\Internet Logs\xDB276.tmp moved successfully.
c:\windows\Internet Logs\xDB277.tmp moved successfully.
c:\windows\Internet Logs\xDB278.tmp moved successfully.
c:\windows\Internet Logs\xDB279.tmp moved successfully.
c:\windows\Internet Logs\xDB27A.tmp moved successfully.
c:\windows\Internet Logs\xDB27B.tmp moved successfully.
c:\windows\Internet Logs\xDB27C.tmp moved successfully.
c:\windows\Internet Logs\xDB27D.tmp moved successfully.
c:\windows\Internet Logs\xDB27E.tmp moved successfully.
c:\windows\Internet Logs\xDB27F.tmp moved successfully.
c:\windows\Internet Logs\xDB28.tmp moved successfully.
c:\windows\Internet Logs\xDB280.tmp moved successfully.
c:\windows\Internet Logs\xDB281.tmp moved successfully.
c:\windows\Internet Logs\xDB282.tmp moved successfully.
c:\windows\Internet Logs\xDB283.tmp moved successfully.
c:\windows\Internet Logs\xDB284.tmp moved successfully.
c:\windows\Internet Logs\xDB285.tmp moved successfully.
c:\windows\Internet Logs\xDB286.tmp moved successfully.
c:\windows\Internet Logs\xDB287.tmp moved successfully.
c:\windows\Internet Logs\xDB288.tmp moved successfully.
c:\windows\Internet Logs\xDB289.tmp moved successfully.
c:\windows\Internet Logs\xDB28A.tmp moved successfully.
c:\windows\Internet Logs\xDB28B.tmp moved successfully.
c:\windows\Internet Logs\xDB28C.tmp moved successfully.
c:\windows\Internet Logs\xDB28D.tmp moved successfully.
c:\windows\Internet Logs\xDB28E.tmp moved successfully.
c:\windows\Internet Logs\xDB28F.tmp moved successfully.
c:\windows\Internet Logs\xDB29.tmp moved successfully.
c:\windows\Internet Logs\xDB290.tmp moved successfully.
c:\windows\Internet Logs\xDB291.tmp moved successfully.
c:\windows\Internet Logs\xDB292.tmp moved successfully.
c:\windows\Internet Logs\xDB293.tmp moved successfully.
c:\windows\Internet Logs\xDB294.tmp moved successfully.
c:\windows\Internet Logs\xDB295.tmp moved successfully.
c:\windows\Internet Logs\xDB296.tmp moved successfully.
c:\windows\Internet Logs\xDB297.tmp moved successfully.
c:\windows\Internet Logs\xDB298.tmp moved successfully.
c:\windows\Internet Logs\xDB299.tmp moved successfully.
c:\windows\Internet Logs\xDB29A.tmp moved successfully.
c:\windows\Internet Logs\xDB29B.tmp moved successfully.
c:\windows\Internet Logs\xDB29C.tmp moved successfully.
c:\windows\Internet Logs\xDB29D.tmp moved successfully.
c:\windows\Internet Logs\xDB29E.tmp moved successfully.
c:\windows\Internet Logs\xDB29F.tmp moved successfully.
c:\windows\Internet Logs\xDB2A.tmp moved successfully.
c:\windows\Internet Logs\xDB2A0.tmp moved successfully.
c:\windows\Internet Logs\xDB2A1.tmp moved successfully.
c:\windows\Internet Logs\xDB2A2.tmp moved successfully.
c:\windows\Internet Logs\xDB2A3.tmp moved successfully.
c:\windows\Internet Logs\xDB2A4.tmp moved successfully.
c:\windows\Internet Logs\xDB2A5.tmp moved successfully.
c:\windows\Internet Logs\xDB2A6.tmp moved successfully.
c:\windows\Internet Logs\xDB2A7.tmp moved successfully.
c:\windows\Internet Logs\xDB2A8.tmp moved successfully.
c:\windows\Internet Logs\xDB2A9.tmp moved successfully.
c:\windows\Internet Logs\xDB2AA.tmp moved successfully.
c:\windows\Internet Logs\xDB2AB.tmp moved successfully.
c:\windows\Internet Logs\xDB2AC.tmp moved successfully.
c:\windows\Internet Logs\xDB2AD.tmp moved successfully.
c:\windows\Internet Logs\xDB2AE.tmp moved successfully.
c:\windows\Internet Logs\xDB2AF.tmp moved successfully.
c:\windows\Internet Logs\xDB2B.tmp moved successfully.
c:\windows\Internet Logs\xDB2B0.tmp moved successfully.
c:\windows\Internet Logs\xDB2B1.tmp moved successfully.
c:\windows\Internet Logs\xDB2B2.tmp moved successfully.
c:\windows\Internet Logs\xDB2B3.tmp moved successfully.
c:\windows\Internet Logs\xDB2B4.tmp moved successfully.
c:\windows\Internet Logs\xDB2B5.tmp moved successfully.
c:\windows\Internet Logs\xDB2B6.tmp moved successfully.
c:\windows\Internet Logs\xDB2B7.tmp moved successfully.
c:\windows\Internet Logs\xDB2B8.tmp moved successfully.
c:\windows\Internet Logs\xDB2B9.tmp moved successfully.
c:\windows\Internet Logs\xDB2BA.tmp moved successfully.
c:\windows\Internet Logs\xDB2BB.tmp moved successfully.
c:\windows\Internet Logs\xDB2BC.tmp moved successfully.
c:\windows\Internet Logs\xDB2BD.tmp moved successfully.
c:\windows\Internet Logs\xDB2BE.tmp moved successfully.
c:\windows\Internet Logs\xDB2BF.tmp moved successfully.
c:\windows\Internet Logs\xDB2C.tmp moved successfully.
c:\windows\Internet Logs\xDB2C0.tmp moved successfully.
c:\windows\Internet Logs\xDB2C1.tmp moved successfully.
c:\windows\Internet Logs\xDB2C2.tmp moved successfully.
c:\windows\Internet Logs\xDB2C3.tmp moved successfully.
c:\windows\Internet Logs\xDB2C4.tmp moved successfully.
c:\windows\Internet Logs\xDB2C5.tmp moved successfully.
c:\windows\Internet Logs\xDB2C6.tmp moved successfully.
c:\windows\Internet Logs\xDB2C7.tmp moved successfully.
c:\windows\Internet Logs\xDB2C8.tmp moved successfully.
c:\windows\Internet Logs\xDB2C9.tmp moved successfully.
c:\windows\Internet Logs\xDB2CA.tmp moved successfully.
c:\windows\Internet Logs\xDB2CB.tmp moved successfully.
c:\windows\Internet Logs\xDB2CC.tmp moved successfully.
c:\windows\Internet Logs\xDB2CD.tmp moved successfully.
c:\windows\Internet Logs\xDB2CE.tmp moved successfully.
c:\windows\Internet Logs\xDB2CF.tmp moved successfully.
c:\windows\Internet Logs\xDB2D.tmp moved successfully.
c:\windows\Internet Logs\xDB2D0.tmp moved successfully.
c:\windows\Internet Logs\xDB2D1.tmp moved successfully.
c:\windows\Internet Logs\xDB2D2.tmp moved successfully.
c:\windows\Internet Logs\xDB2D3.tmp moved successfully.
c:\windows\Internet Logs\xDB2D4.tmp moved successfully.
c:\windows\Internet Logs\xDB2D5.tmp moved successfully.
c:\windows\Internet Logs\xDB2D6.tmp moved successfully.
c:\windows\Internet Logs\xDB2D7.tmp moved successfully.
c:\windows\Internet Logs\xDB2D8.tmp moved successfully.
c:\windows\Internet Logs\xDB2D9.tmp moved successfully.
c:\windows\Internet Logs\xDB2DA.tmp moved successfully.
c:\windows\Internet Logs\xDB2DB.tmp moved successfully.
c:\windows\Internet Logs\xDB2DC.tmp moved successfully.
c:\windows\Internet Logs\xDB2DD.tmp moved successfully.
c:\windows\Internet Logs\xDB2DE.tmp moved successfully.
c:\windows\Internet Logs\xDB2DF.tmp moved successfully.
c:\windows\Internet Logs\xDB2E.tmp moved successfully.
c:\windows\Internet Logs\xDB2E0.tmp moved successfully.
c:\windows\Internet Logs\xDB2E1.tmp moved successfully.
c:\windows\Internet Logs\xDB2E2.tmp moved successfully.
c:\windows\Internet Logs\xDB2E3.tmp moved successfully.
c:\windows\Internet Logs\xDB2E4.tmp moved successfully.
c:\windows\Internet Logs\xDB2E5.tmp moved successfully.
c:\windows\Internet Logs\xDB2E6.tmp moved successfully.
c:\windows\Internet Logs\xDB2E7.tmp moved successfully.
c:\windows\Internet Logs\xDB2E8.tmp moved successfully.
c:\windows\Internet Logs\xDB2E9.tmp moved successfully.
c:\windows\Internet Logs\xDB2EA.tmp moved successfully.
c:\windows\Internet Logs\xDB2EB.tmp moved successfully.
c:\windows\Internet Logs\xDB2EC.tmp moved successfully.
c:\windows\Internet Logs\xDB2ED.tmp moved successfully.
c:\windows\Internet Logs\xDB2EE.tmp moved successfully.
c:\windows\Internet Logs\xDB2EF.tmp moved successfully.
c:\windows\Internet Logs\xDB2F.tmp moved successfully.
c:\windows\Internet Logs\xDB2F0.tmp moved successfully.
c:\windows\Internet Logs\xDB2F1.tmp moved successfully.
c:\windows\Internet Logs\xDB2F2.tmp moved successfully.
c:\windows\Internet Logs\xDB2F3.tmp moved successfully.
c:\windows\Internet Logs\xDB2F4.tmp moved successfully.
c:\windows\Internet Logs\xDB2F5.tmp moved successfully.
c:\windows\Internet Logs\xDB2F6.tmp moved successfully.
c:\windows\Internet Logs\xDB2F7.tmp moved successfully.
c:\windows\Internet Logs\xDB2F8.tmp moved successfully.
c:\windows\Internet Logs\xDB2F9.tmp moved successfully.
c:\windows\Internet Logs\xDB2FA.tmp moved successfully.
c:\windows\Internet Logs\xDB2FB.tmp moved successfully.
c:\windows\Internet Logs\xDB2FC.tmp moved successfully.
c:\windows\Internet Logs\xDB2FD.tmp moved successfully.
c:\windows\Internet Logs\xDB2FE.tmp moved successfully.
c:\windows\Internet Logs\xDB2FF.tmp moved successfully.
c:\windows\Internet Logs\xDB3.tmp moved successfully.
c:\windows\Internet Logs\xDB30.tmp moved successfully.
c:\windows\Internet Logs\xDB300.tmp moved successfully.
c:\windows\Internet Logs\xDB301.tmp moved successfully.
c:\windows\Internet Logs\xDB302.tmp moved successfully.
c:\windows\Internet Logs\xDB303.tmp moved successfully.
c:\windows\Internet Logs\xDB304.tmp moved successfully.
c:\windows\Internet Logs\xDB305.tmp moved successfully.
c:\windows\Internet Logs\xDB306.tmp moved successfully.
c:\windows\Internet Logs\xDB307.tmp moved successfully.
c:\windows\Internet Logs\xDB308.tmp moved successfully.
c:\windows\Internet Logs\xDB309.tmp moved successfully.
c:\windows\Internet Logs\xDB30A.tmp moved successfully.
c:\windows\Internet Logs\xDB30B.tmp moved successfully.
c:\windows\Internet Logs\xDB30C.tmp moved successfully.
c:\windows\Internet Logs\xDB30D.tmp moved successfully.
c:\windows\Internet Logs\xDB30E.tmp moved successfully.
c:\windows\Internet Logs\xDB30F.tmp moved successfully.
c:\windows\Internet Logs\xDB31.tmp moved successfully.
c:\windows\Internet Logs\xDB310.tmp moved successfully.
c:\windows\Internet Logs\xDB311.tmp moved successfully.
c:\windows\Internet Logs\xDB312.tmp moved successfully.
c:\windows\Internet Logs\xDB313.tmp moved successfully.
c:\windows\Internet Logs\xDB314.tmp moved successfully.
c:\windows\Internet Logs\xDB315.tmp moved successfully.
c:\windows\Internet Logs\xDB316.tmp moved successfully.
c:\windows\Internet Logs\xDB317.tmp moved successfully.
c:\windows\Internet Logs\xDB318.tmp moved successfully.
c:\windows\Internet Logs\xDB319.tmp moved successfully.
c:\windows\Internet Logs\xDB31A.tmp moved successfully.
c:\windows\Internet Logs\xDB31B.tmp moved successfully.
c:\windows\Internet Logs\xDB31C.tmp moved successfully.
c:\windows\Internet Logs\xDB31D.tmp moved successfully.
c:\windows\Internet Logs\xDB31E.tmp moved successfully.
c:\windows\Internet Logs\xDB31F.tmp moved successfully.
c:\windows\Internet Logs\xDB32.tmp moved successfully.
c:\windows\Internet Logs\xDB320.tmp moved successfully.
c:\windows\Internet Logs\xDB321.tmp moved successfully.
c:\windows\Internet Logs\xDB322.tmp moved successfully.
c:\windows\Internet Logs\xDB323.tmp moved successfully.
c:\windows\Internet Logs\xDB324.tmp moved successfully.
c:\windows\Internet Logs\xDB325.tmp moved successfully.
c:\windows\Internet Logs\xDB326.tmp moved successfully.
c:\windows\Internet Logs\xDB327.tmp moved successfully.
c:\windows\Internet Logs\xDB328.tmp moved successfully.
c:\windows\Internet Logs\xDB329.tmp moved successfully.
c:\windows\Internet Logs\xDB32A.tmp moved successfully.
c:\windows\Internet Logs\xDB32B.tmp moved successfully.
c:\windows\Internet Logs\xDB32C.tmp moved successfully.
c:\windows\Internet Logs\xDB32D.tmp moved successfully.
c:\windows\Internet Logs\xDB32E.tmp moved successfully.
c:\windows\Internet Logs\xDB32F.tmp moved successfully.
c:\windows\Internet Logs\xDB33.tmp moved successfully.
c:\windows\Internet Logs\xDB330.tmp moved successfully.
c:\windows\Internet Logs\xDB331.tmp moved successfully.
c:\windows\Internet Logs\xDB332.tmp moved successfully.
c:\windows\Internet Logs\xDB333.tmp moved successfully.
c:\windows\Internet Logs\xDB334.tmp moved successfully.
c:\windows\Internet Logs\xDB335.tmp moved successfully.
c:\windows\Internet Logs\xDB336.tmp moved successfully.
c:\windows\Internet Logs\xDB337.tmp moved successfully.
c:\windows\Internet Logs\xDB338.tmp moved successfully.
c:\windows\Internet Logs\xDB339.tmp moved successfully.
c:\windows\Internet Logs\xDB33A.tmp moved successfully.
c:\windows\Internet Logs\xDB33B.tmp moved successfully.
c:\windows\Internet Logs\xDB33C.tmp moved successfully.
c:\windows\Internet Logs\xDB33D.tmp moved successfully.
c:\windows\Internet Logs\xDB33E.tmp moved successfully.
c:\windows\Internet Logs\xDB33F.tmp moved successfully.
c:\windows\Internet Logs\xDB34.tmp moved successfully.
c:\windows\Internet Logs\xDB340.tmp moved successfully.
c:\windows\Internet Logs\xDB341.tmp moved successfully.
c:\windows\Internet Logs\xDB342.tmp moved successfully.
c:\windows\Internet Logs\xDB343.tmp moved successfully.
c:\windows\Internet Logs\xDB344.tmp moved successfully.
c:\windows\Internet Logs\xDB345.tmp moved successfully.
c:\windows\Internet Logs\xDB346.tmp moved successfully.
c:\windows\Internet Logs\xDB347.tmp moved successfully.
c:\windows\Internet Logs\xDB348.tmp moved successfully.
c:\windows\Internet Logs\xDB349.tmp moved successfully.
c:\windows\Internet Logs\xDB34A.tmp moved successfully.
c:\windows\Internet Logs\xDB34B.tmp moved successfully.
c:\windows\Internet Logs\xDB34C.tmp moved successfully.
c:\windows\Internet Logs\xDB34D.tmp moved successfully.
c:\windows\Internet Logs\xDB34E.tmp moved successfully.
c:\windows\Internet Logs\xDB34F.tmp moved successfully.
c:\windows\Internet Logs\xDB35.tmp moved successfully.
c:\windows\Internet Logs\xDB36.tmp moved successfully.
c:\windows\Internet Logs\xDB37.tmp moved successfully.
c:\windows\Internet Logs\xDB38.tmp moved successfully.
c:\windows\Internet Logs\xDB39.tmp moved successfully.
c:\windows\Internet Logs\xDB3A.tmp moved successfully.
c:\windows\Internet Logs\xDB3B.tmp moved successfully.
c:\windows\Internet Logs\xDB3C.tmp moved successfully.
c:\windows\Internet Logs\xDB3D.tmp moved successfully.
c:\windows\Internet Logs\xDB3E.tmp moved successfully.
c:\windows\Internet Logs\xDB3F.tmp moved successfully.
c:\windows\Internet Logs\xDB4.tmp moved successfully.
c:\windows\Internet Logs\xDB40.tmp moved successfully.
c:\windows\Internet Logs\xDB41.tmp moved successfully.
c:\windows\Internet Logs\xDB42.tmp moved successfully.
c:\windows\Internet Logs\xDB43.tmp moved successfully.
c:\windows\Internet Logs\xDB44.tmp moved successfully.
c:\windows\Internet Logs\xDB45.tmp moved successfully.
c:\windows\Internet Logs\xDB46.tmp moved successfully.
c:\windows\Internet Logs\xDB47.tmp moved successfully.
c:\windows\Internet Logs\xDB48.tmp moved successfully.
c:\windows\Internet Logs\xDB49.tmp moved successfully.
c:\windows\Internet Logs\xDB4A.tmp moved successfully.
c:\windows\Internet Logs\xDB4B.tmp moved successfully.
c:\windows\Internet Logs\xDB4C.tmp moved successfully.
c:\windows\Internet Logs\xDB4D.tmp moved successfully.
c:\windows\Internet Logs\xDB4E.tmp moved successfully.
c:\windows\Internet Logs\xDB4F.tmp moved successfully.
c:\windows\Internet Logs\xDB5.tmp moved successfully.
c:\windows\Internet Logs\xDB50.tmp moved successfully.
c:\windows\Internet Logs\xDB51.tmp moved successfully.
c:\windows\Internet Logs\xDB52.tmp moved successfully.
c:\windows\Internet Logs\xDB53.tmp moved successfully.
c:\windows\Internet Logs\xDB54.tmp moved successfully.
c:\windows\Internet Logs\xDB55.tmp moved successfully.
c:\windows\Internet Logs\xDB56.tmp moved successfully.
c:\windows\Internet Logs\xDB57.tmp moved successfully.
c:\windows\Internet Logs\xDB58.tmp moved successfully.
c:\windows\Internet Logs\xDB59.tmp moved successfully.
c:\windows\Internet Logs\xDB5A.tmp moved successfully.
c:\windows\Internet Logs\xDB5B.tmp moved successfully.
c:\windows\Internet Logs\xDB5C.tmp moved successfully.
c:\windows\Internet Logs\xDB5D.tmp moved successfully.
c:\windows\Internet Logs\xDB5E.tmp moved successfully.
c:\windows\Internet Logs\xDB5F.tmp moved successfully.
c:\windows\Internet Logs\xDB6.tmp moved successfully.
c:\windows\Internet Logs\xDB60.tmp moved successfully.
c:\windows\Internet Logs\xDB61.tmp moved successfully.
c:\windows\Internet Logs\xDB62.tmp moved successfully.
c:\windows\Internet Logs\xDB63.tmp moved successfully.
c:\windows\Internet Logs\xDB64.tmp moved successfully.
c:\windows\Internet Logs\xDB65.tmp moved successfully.
c:\windows\Internet Logs\xDB66.tmp moved successfully.
c:\windows\Internet Logs\xDB67.tmp moved successfully.
c:\windows\Internet Logs\xDB68.tmp moved successfully.
c:\windows\Internet Logs\xDB69.tmp moved successfully.
c:\windows\Internet Logs\xDB6A.tmp moved successfully.
c:\windows\Internet Logs\xDB6B.tmp moved successfully.
c:\windows\Internet Logs\xDB6C.tmp moved successfully.
c:\windows\Internet Logs\xDB6D.tmp moved successfully.
c:\windows\Internet Logs\xDB6E.tmp moved successfully.
c:\windows\Internet Logs\xDB6F.tmp moved successfully.
c:\windows\Internet Logs\xDB7.tmp moved successfully.
c:\windows\Internet Logs\xDB70.tmp moved successfully.
c:\windows\Internet Logs\xDB71.tmp moved successfully.
c:\windows\Internet Logs\xDB72.tmp moved successfully.
c:\windows\Internet Logs\xDB73.tmp moved successfully.
c:\windows\Internet Logs\xDB74.tmp moved successfully.
c:\windows\Internet Logs\xDB75.tmp moved successfully.
c:\windows\Internet Logs\xDB76.tmp moved successfully.
c:\windows\Internet Logs\xDB77.tmp moved successfully.
c:\windows\Internet Logs\xDB78.tmp moved successfully.
c:\windows\Internet Logs\xDB79.tmp moved successfully.
c:\windows\Internet Logs\xDB7A.tmp moved successfully.
c:\windows\Internet Logs\xDB7B.tmp moved successfully.
c:\windows\Internet Logs\xDB7C.tmp moved successfully.
c:\windows\Internet Logs\xDB7D.tmp moved successfully.
c:\windows\Internet Logs\xDB7E.tmp moved successfully.
c:\windows\Internet Logs\xDB7F.tmp moved successfully.
c:\windows\Internet Logs\xDB8.tmp moved successfully.
c:\windows\Internet Logs\xDB80.tmp moved successfully.
c:\windows\Internet Logs\xDB81.tmp moved successfully.
c:\windows\Internet Logs\xDB82.tmp moved successfully.
c:\windows\Internet Logs\xDB83.tmp moved successfully.
c:\windows\Internet Logs\xDB84.tmp moved successfully.
c:\windows\Internet Logs\xDB85.tmp moved successfully.
c:\windows\Internet Logs\xDB86.tmp moved successfully.
c:\windows\Internet Logs\xDB87.tmp moved successfully.
c:\windows\Internet Logs\xDB88.tmp moved successfully.
c:\windows\Internet Logs\xDB89.tmp moved successfully.
c:\windows\Internet Logs\xDB8A.tmp moved successfully.
c:\windows\Internet Logs\xDB8B.tmp moved successfully.
c:\windows\Internet Logs\xDB8C.tmp moved successfully.
c:\windows\Internet Logs\xDB8D.tmp moved successfully.
c:\windows\Internet Logs\xDB8E.tmp moved successfully.
c:\windows\Internet Logs\xDB8F.tmp moved successfully.
c:\windows\Internet Logs\xDB9.tmp moved successfully.
c:\windows\Internet Logs\xDB90.tmp moved successfully.
c:\windows\Internet Logs\xDB91.tmp moved successfully.
c:\windows\Internet Logs\xDB92.tmp moved successfully.
c:\windows\Internet Logs\xDB93.tmp moved successfully.
c:\windows\Internet Logs\xDB94.tmp moved successfully.
c:\windows\Internet Logs\xDB95.tmp moved successfully.
c:\windows\Internet Logs\xDB96.tmp moved successfully.
c:\windows\Internet Logs\xDB97.tmp moved successfully.
c:\windows\Internet Logs\xDB98.tmp moved successfully.
c:\windows\Internet Logs\xDB99.tmp moved successfully.
c:\windows\Internet Logs\xDB9A.tmp moved successfully.
c:\windows\Internet Logs\xDB9B.tmp moved successfully.
c:\windows\Internet Logs\xDB9C.tmp moved successfully.
c:\windows\Internet Logs\xDB9D.tmp moved successfully.
c:\windows\Internet Logs\xDB9E.tmp moved successfully.
c:\windows\Internet Logs\xDB9F.tmp moved successfully.
c:\windows\Internet Logs\xDBA.tmp moved successfully.
c:\windows\Internet Logs\xDBA0.tmp moved successfully.
c:\windows\Internet Logs\xDBA1.tmp moved successfully.
c:\windows\Internet Logs\xDBA2.tmp moved successfully.
c:\windows\Internet Logs\xDBA3.tmp moved successfully.
c:\windows\Internet Logs\xDBA4.tmp moved successfully.
c:\windows\Internet Logs\xDBA5.tmp moved successfully.
c:\windows\Internet Logs\xDBA6.tmp moved successfully.
c:\windows\Internet Logs\xDBA7.tmp moved successfully.
c:\windows\Internet Logs\xDBA8.tmp moved successfully.
c:\windows\Internet Logs\xDBA9.tmp moved successfully.
c:\windows\Internet Logs\xDBAA.tmp moved successfully.
c:\windows\Internet Logs\xDBAB.tmp moved successfully.
c:\windows\Internet Logs\xDBAC.tmp moved successfully.
c:\windows\Internet Logs\xDBAD.tmp moved successfully.
c:\windows\Internet Logs\xDBAE.tmp moved successfully.
c:\windows\Internet Logs\xDBAF.tmp moved successfully.
c:\windows\Internet Logs\xDBB.tmp moved successfully.
c:\windows\Internet Logs\xDBB0.tmp moved successfully.
c:\windows\Internet Logs\xDBB1.tmp moved successfully.
c:\windows\Internet Logs\xDBB2.tmp moved successfully.
c:\windows\Internet Logs\xDBB3.tmp moved successfully.
c:\windows\Internet Logs\xDBB4.tmp moved successfully.
c:\windows\Internet Logs\xDBB5.tmp moved successfully.
c:\windows\Internet Logs\xDBB6.tmp moved successfully.
c:\windows\Internet Logs\xDBB7.tmp moved successfully.
c:\windows\Internet Logs\xDBB8.tmp moved successfully.
c:\windows\Internet Logs\xDBB9.tmp moved successfully.
c:\windows\Internet Logs\xDBBA.tmp moved successfully.
c:\windows\Internet Logs\xDBBB.tmp moved successfully.
c:\windows\Internet Logs\xDBBC.tmp moved successfully.
c:\windows\Internet Logs\xDBBD.tmp moved successfully.
c:\windows\Internet Logs\xDBBE.tmp moved successfully.
c:\windows\Internet Logs\xDBBF.tmp moved successfully.
c:\windows\Internet Logs\xDBC.tmp moved successfully.
c:\windows\Internet Logs\xDBC0.tmp moved successfully.
c:\windows\Internet Logs\xDBC1.tmp moved successfully.
c:\windows\Internet Logs\xDBC2.tmp moved successfully.
c:\windows\Internet Logs\xDBC3.tmp moved successfully.
c:\windows\Internet Logs\xDBC4.tmp moved successfully.
c:\windows\Internet Logs\xDBC5.tmp moved successfully.
c:\windows\Internet Logs\xDBC6.tmp moved successfully.
c:\windows\Internet Logs\xDBC7.tmp moved successfully.
c:\windows\Internet Logs\xDBC8.tmp moved successfully.
c:\windows\Internet Logs\xDBC9.tmp moved successfully.
c:\windows\Internet Logs\xDBCA.tmp moved successfully.
c:\windows\Internet Logs\xDBCB.tmp moved successfully.
c:\windows\Internet Logs\xDBCC.tmp moved successfully.
c:\windows\Internet Logs\xDBCD.tmp moved successfully.
c:\windows\Internet Logs\xDBCE.tmp moved successfully.
c:\windows\Internet Logs\xDBCF.tmp moved successfully.
c:\windows\Internet Logs\xDBD.tmp moved successfully.
c:\windows\Internet Logs\xDBD0.tmp moved successfully.
c:\windows\Internet Logs\xDBD1.tmp moved successfully.
c:\windows\Internet Logs\xDBD2.tmp moved successfully.
c:\windows\Internet Logs\xDBD3.tmp moved successfully.
c:\windows\Internet Logs\xDBD4.tmp moved successfully.
c:\windows\Internet Logs\xDBD5.tmp moved successfully.
c:\windows\Internet Logs\xDBD6.tmp moved successfully.
c:\windows\Internet Logs\xDBD7.tmp moved successfully.
c:\windows\Internet Logs\xDBD8.tmp moved successfully.
c:\windows\Internet Logs\xDBD9.tmp moved successfully.
c:\windows\Internet Logs\xDBDA.tmp moved successfully.
c:\windows\Internet Logs\xDBDB.tmp moved successfully.
c:\windows\Internet Logs\xDBDC.tmp moved successfully.
c:\windows\Internet Logs\xDBDD.tmp moved successfully.
c:\windows\Internet Logs\xDBDE.tmp moved successfully.
c:\windows\Internet Logs\xDBDF.tmp moved successfully.
c:\windows\Internet Logs\xDBE.tmp moved successfully.
c:\windows\Internet Logs\xDBE0.tmp moved successfully.
c:\windows\Internet Logs\xDBE1.tmp moved successfully.
c:\windows\Internet Logs\xDBE2.tmp moved successfully.
c:\windows\Internet Logs\xDBE3.tmp moved successfully.
c:\windows\Internet Logs\xDBE4.tmp moved successfully.
c:\windows\Internet Logs\xDBE5.tmp moved successfully.
c:\windows\Internet Logs\xDBE6.tmp moved successfully.
c:\windows\Internet Logs\xDBE7.tmp moved successfully.
c:\windows\Internet Logs\xDBE8.tmp moved successfully.
c:\windows\Internet Logs\xDBE9.tmp moved successfully.
c:\windows\Internet Logs\xDBEA.tmp moved successfully.
c:\windows\Internet Logs\xDBEB.tmp moved successfully.
c:\windows\Internet Logs\xDBEC.tmp moved successfully.
c:\windows\Internet Logs\xDBED.tmp moved successfully.
c:\windows\Internet Logs\xDBEE.tmp moved successfully.
c:\windows\Internet Logs\xDBEF.tmp moved successfully.
c:\windows\Internet Logs\xDBF.tmp moved successfully.
c:\windows\Internet Logs\xDBF0.tmp moved successfully.
c:\windows\Internet Logs\xDBF1.tmp moved successfully.
c:\windows\Internet Logs\xDBF2.tmp moved successfully.
c:\windows\Internet Logs\xDBF3.tmp moved successfully.
c:\windows\Internet Logs\xDBF4.tmp moved successfully.
c:\windows\Internet Logs\xDBF5.tmp moved successfully.
c:\windows\Internet Logs\xDBF6.tmp moved successfully.
c:\windows\Internet Logs\xDBF7.tmp moved successfully.
c:\windows\Internet Logs\xDBF8.tmp moved successfully.
c:\windows\Internet Logs\xDBF9.tmp moved successfully.
c:\windows\Internet Logs\xDBFA.tmp moved successfully.
c:\windows\Internet Logs\xDBFB.tmp moved successfully.
c:\windows\Internet Logs\xDBFC.tmp moved successfully.
c:\windows\Internet Logs\xDBFD.tmp moved successfully.
c:\windows\Internet Logs\xDBFE.tmp moved successfully.
c:\windows\Internet Logs\xDBFF.tmp moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 2919775 bytes

User: All Users

User: All Users.WINDOWS.1

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User.WINDOWS.1
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 3618044 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: Petr
->Temp folder emptied: 167930854 bytes
->Temporary Internet Files folder emptied: 4004825 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 113381499 bytes

User: Petr.KOCOUR-9A418690
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 8416483 bytes

User: PETR~1~KOC

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2830818 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33024 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 3775176 bytes

Total Files Cleaned = 293,00 mb


OTM by OldTimer - Version 3.1.8.0 log created on 02052010_232517

Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_704.dat not found!
File C:\WINDOWS\temp\ZLT005c8.TMP not found!

Registry entries deleted on Reboot...
Za chvíli zbytek.
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 05 úno 2010 23:42

Další log
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 06 úno 2010 00:03

Vše provedeno zde je výsledek. Jsou tam další potvory.
Objekt "Backdoor (IRCBot) Trojans Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Backdoor (IRCBot) Trojans Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "AntiSpyware Pro XP Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000356.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000360.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000361.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000362.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000363.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000364.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000365.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000367.ocx je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000368.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000369.exe je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000370.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000371.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000372.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000373.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\System Volume Information\_restore{DCEEB36B-6F4A-4F25-8A08-5A505F350A64}\RP5\A0000374.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.

Asi budu poprvé přeinstalovávat Windows.
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod jaro3 » 06 úno 2010 08:43

Reinstal je hloupost , žádná nebezpečná nákaza tam není (jen pár zbytků po vyléčených nákazách).

Pokud se jedná o SVI, zkus opravit:

Stáhni si Dial-a-fix
Klikni na kladívko-další možnosti:
Reinstall System Restore
- Reinstaluje službu zajišťující Nástroj Obnovení systému (případná potřeba instalačního media Windows).
Klikni na něj a potom na GO.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pic
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 23292
Registrován: září 06
Bydliště: Východní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod Pic » 06 úno 2010 16:24

Problém vyřešen. Způsoboval jej poškozený AVAST! Program mbam a combofix mám normálně odinstalovat, nebo je jiný postup odstranění z PC?

Edit: Programy použité k testování řádně odinstalovány a PC vyčištěn! Nainstalován Avast5 free. Díky za pomoc!
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Trojan v SVI

Příspěvekod jaro3 » 06 úno 2010 19:44

Nemáš zač.

ComboFix se odinstaluje takto:

Start-Spustit a zadej ComboFix /Uninstall

takže jestli nejsou problémy,tak vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG či Avast, následně T-Cleaner smaž a zapni si AVG či Avast.


MbAM můžeš ponechat , či odinstalovat.

Vše.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Majestic-12 [Bot] a 62 hostů