Prosím o kontrolu logu. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu.

Příspěvekod Orcus » 26 črc 2011 08:08

čau, pokud by někdo byl tak hodnej, ocenil bych kdyby juknul na log. Mám podezření na nějaký nepodchycenou infekci. Na místo š mi občas kompl píše šč, což je jedinej projev (a né nemám tlustý prsty že bych mačkal dva čudlíky najednou:D). Jak skončí test MBAM tak přihodím i log z něj. AVG 2011 nic nenašlo. Moc děkuju :listen:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:03:07, on 26.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\AVG\AVG10\avgui.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
O4 - HKCU\..\Run: [Shutdown_Manager] C:\Program Files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9247 bytes
===========================
Přihazuju log z MBAM:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7279

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

26.7.2011 9:15:52
mbam-log-2011-07-26 (09-15-46).txt

Scan type: Full scan (C:\|E:\|F:\|)
Objects scanned: 569815
Time elapsed: 55 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod memphisto » 26 črc 2011 10:41

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštìní se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynù, bìhem aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by mìl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 26 črc 2011 11:01

ComboFix 11-07-26.02 - Orc 26.07.2011 10:49:19.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4094.2285 [GMT 2:00]
Spuštěný z: c:\users\Orc\Downloads\ComboFix.exe
AV: AVG Internet Security Business Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\facemoods.com
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoods.crx
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoods.png
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsApp.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsEng.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\uninstall.exe
c:\program files (x86)\facemoods.com\sqlite3.dll
c:\windows\SysWow64\Dvbpws.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 08:55 . 2011-07-26 08:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-26 08:47 . 2011-07-26 08:47 -------- d-----w- C:\32788R22FWJFW
2011-07-26 06:06 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 06:06 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-26 06:02 . 2011-07-26 06:02 -------- d-----w- c:\program files (x86)\Trend Micro
2011-07-26 05:41 . 2011-07-26 05:41 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\windows\PCHEALTH
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-07-26 05:39 . 2011-07-26 05:39 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-07-26 05:37 . 2011-07-26 05:44 -------- d-----w- c:\programdata\Microsoft Help
2011-07-26 05:37 . 2011-07-26 05:37 -------- d-----r- C:\MSOCache
2011-07-25 14:04 . 2011-07-25 14:04 -------- d-----w- c:\program files (x86)\Webteh
2011-07-24 22:11 . 2011-03-30 11:05 35112 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2011-07-24 22:11 . 2011-01-12 09:42 16376 ----a-w- c:\windows\system32\drivers\TVMonitor.sys
2011-07-24 22:11 . 2011-07-24 22:11 -------- d-----w- c:\program files (x86)\TeamViewer
2011-07-24 20:43 . 2011-07-24 20:43 -------- d-----w- C:\$AVG
2011-07-24 20:27 . 2011-07-24 20:27 -------- d-----w- c:\program files (x86)\MozBackup
2011-07-24 11:23 . 2011-07-26 05:34 -------- d-----w- C:\Instalačky
2011-07-24 11:20 . 2011-07-24 11:22 -------- d-----w- c:\program files (x86)\coolpro2
2011-07-24 10:20 . 2011-07-24 10:20 -------- d-----w- C:\found.000
2011-07-23 22:33 . 2011-07-23 22:33 -------- d-----w- c:\program files (x86)\DNsoft.be
2011-07-23 22:09 . 2011-07-23 22:11 -------- d-----w- c:\program files (x86)\JDownloader
2011-07-23 21:38 . 2007-10-22 01:37 17928 ----a-w- c:\windows\SysWow64\X3DAudio1_2.dll
2011-07-23 21:28 . 2011-07-23 21:28 -------- d-----w- C:\Games
2011-07-23 20:50 . 2011-07-23 20:50 -------- d-----w- c:\program files (x86)\BitTorrent
2011-07-23 18:57 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-23 18:57 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-23 10:42 . 2011-07-23 10:42 -------- d-----w- C:\WinFast WorkArea
2011-07-23 10:34 . 2011-07-23 10:35 -------- d-----w- c:\programdata\ArcSoft
2011-07-23 10:34 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems
2011-07-23 10:33 . 2008-08-13 07:35 20480 ----a-w- c:\program files\Windows Sidebar\Gadgets\PVR2Remote.Gadget\ClassLibrary1.dll
2011-07-23 10:33 . 2011-07-23 10:33 -------- d-----w- c:\program files\WinFast
2011-07-23 10:07 . 2007-07-13 10:28 116768 ----a-w- c:\windows\system32\NXPMV64.dll
2011-07-23 10:07 . 2011-07-23 10:07 -------- d-----w- c:\windows\SysWow64\WinFast
2011-07-23 10:07 . 2010-10-13 10:08 1345664 ----a-w- c:\windows\system32\drivers\3xHybr64.sys
2011-07-23 10:00 . 2011-07-23 10:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-23 09:59 . 2011-07-23 09:58 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-23 09:58 . 2011-07-23 09:58 -------- d-----w- c:\program files (x86)\Java
2011-07-23 09:46 . 2011-07-22 23:56 -------- d-----w- c:\windows\Panther
2011-07-23 09:46 . 2011-07-23 09:46 -------- d-----w- C:\Boot
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\system32\Wat
2011-07-23 01:50 . 2011-07-23 01:50 -------- d--h--w- c:\programdata\Common Files
2011-07-23 01:50 . 2011-07-23 01:51 -------- d-----w- c:\programdata\AVG Security Toolbar
2011-07-23 01:49 . 2011-07-23 01:49 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-07-23 01:48 . 2011-07-25 23:53 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-23 01:48 . 2011-07-23 01:50 -------- d-----w- c:\programdata\AVG10
2011-07-23 01:47 . 2011-07-23 01:47 -------- d-----w- c:\program files (x86)\AVG
2011-07-23 01:40 . 2011-07-23 01:51 -------- d-----w- c:\programdata\MFAData
2011-07-23 01:25 . 2011-07-23 01:25 -------- d-----w- c:\program files\Defraggler
2011-07-23 01:24 . 2011-07-23 01:24 -------- d-----w- c:\program files\CCleaner
2011-07-23 01:23 . 2011-07-23 01:24 -------- d-----w- c:\program files (x86)\Google
2011-07-23 01:22 . 2011-07-26 06:02 -------- d-sh--w- c:\windows\Installer
2011-07-23 01:20 . 2011-05-25 07:25 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-07-23 01:15 . 2011-06-01 03:16 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-07-23 01:15 . 2011-06-01 03:16 535656 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-07-23 01:15 . 2011-06-01 03:16 107624 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\program files\Realtek
2011-07-23 01:12 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-07-23 01:12 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-07-23 01:12 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-23 01:08 . 2011-07-23 02:16 -------- d-----w- C:\Cinema
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- c:\program files (x86)\Intel
2011-07-23 01:06 . 2010-03-02 08:04 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- C:\Intel
2011-07-23 01:00 . 2011-07-23 01:00 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2011-07-23 00:52 . 2011-07-23 02:24 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-23 00:52 . 2011-07-23 00:52 -------- d-----w- c:\windows\SysWow64\Macromed
2011-07-23 00:21 . 2011-04-29 05:47 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-23 00:10 . 2009-12-29 08:03 220672 ----a-w- c:\windows\system32\wintrust.dll
2011-07-23 00:10 . 2009-12-29 06:55 172032 ----a-w- c:\windows\SysWow64\wintrust.dll
2011-07-23 00:09 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2011-07-23 00:09 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2011-07-23 00:06 . 2011-07-20 07:44 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E9B8650-EF5E-458F-BC37-C50C57A74E58}\mpengine.dll
2011-07-23 00:06 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-07-22 23:56 . 2011-07-22 23:57 -------- d-----w- c:\users\Orc
2011-07-22 23:56 . 2011-07-22 23:56 -------- d-----w- C:\Recovery
2011-07-22 15:02 . 2011-07-23 02:17 -------- d-----w- C:\Moje
2011-07-22 14:40 . 2011-07-23 21:28 -------- d-----w- C:\Hry
2011-07-20 08:11 . 2011-07-23 00:39 -------- d-----w- C:\Music
2011-07-20 08:00 . 2011-07-23 02:17 -------- d-----w- C:\Fotky
2011-07-20 07:58 . 2011-07-25 17:52 -------- d-----w- C:\Bramboráček
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-14 06:34 . 2011-07-23 00:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 09:33 2495816 ----a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Shutdown_Manager"="c:\program files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe" [2007-03-23 1081344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 136176]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S3 3xHybr64;WinFast DTV1000 S;c:\windows\system32\DRIVERS\3xHybr64.sys [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 01:23]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 01:23]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 88.146.189.14 88.146.189.10
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Orc\AppData\Roaming\Mozilla\Firefox\Profiles\6u95ym7x.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-26 10:59:55
ComboFix-quarantined-files.txt 2011-07-26 08:59
.
Před spuštěním: 566 672 543 744 bytes free
Po spuštění: 568 311 582 720 bytes free
.
- - End Of File - - 8B193E8AF7BE55089F61628F9188A5DB
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod memphisto » 26 črc 2011 11:42

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::
Folder::
C:\32788R22FWJFW

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=-
"ConsentPromptBehaviorUser"=-
"EnableLUA"=-
"EnableUIADesktopToggle"=-
"PromptOnSecureDesktop"=-

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 26 črc 2011 19:30

ComboFix 11-07-26.02 - Orc 26.07.2011 19:14:47.2.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4094.2783 [GMT 2:00]
Spuštěný z: c:\users\Orc\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Orc\Desktop\CFScript.txt.txt
AV: AVG Internet Security Business Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\Dvbpws.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 17:21 . 2011-07-26 17:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-26 16:56 . 2011-07-26 16:56 -------- d-----w- c:\program files (x86)\FreeTime
2011-07-26 06:06 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 06:06 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-26 06:02 . 2011-07-26 06:02 -------- d-----w- c:\program files (x86)\Trend Micro
2011-07-26 05:41 . 2011-07-26 05:41 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\windows\PCHEALTH
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-07-26 05:39 . 2011-07-26 05:39 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-07-26 05:37 . 2011-07-26 05:44 -------- d-----w- c:\programdata\Microsoft Help
2011-07-26 05:37 . 2011-07-26 05:37 -------- d-----r- C:\MSOCache
2011-07-25 14:04 . 2011-07-25 14:04 -------- d-----w- c:\program files (x86)\Webteh
2011-07-24 22:11 . 2011-03-30 11:05 35112 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2011-07-24 22:11 . 2011-01-12 09:42 16376 ----a-w- c:\windows\system32\drivers\TVMonitor.sys
2011-07-24 22:11 . 2011-07-24 22:11 -------- d-----w- c:\program files (x86)\TeamViewer
2011-07-24 20:43 . 2011-07-24 20:43 -------- d-----w- C:\$AVG
2011-07-24 20:27 . 2011-07-24 20:27 -------- d-----w- c:\program files (x86)\MozBackup
2011-07-24 11:23 . 2011-07-26 05:34 -------- d-----w- C:\Instalačky
2011-07-24 11:20 . 2011-07-24 11:22 -------- d-----w- c:\program files (x86)\coolpro2
2011-07-24 10:20 . 2011-07-24 10:20 -------- d-----w- C:\found.000
2011-07-23 22:33 . 2011-07-23 22:33 -------- d-----w- c:\program files (x86)\DNsoft.be
2011-07-23 22:09 . 2011-07-23 22:11 -------- d-----w- c:\program files (x86)\JDownloader
2011-07-23 21:38 . 2007-10-22 01:37 17928 ----a-w- c:\windows\SysWow64\X3DAudio1_2.dll
2011-07-23 21:28 . 2011-07-23 21:28 -------- d-----w- C:\Games
2011-07-23 20:50 . 2011-07-23 20:50 -------- d-----w- c:\program files (x86)\BitTorrent
2011-07-23 18:57 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-23 18:57 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-23 10:42 . 2011-07-26 14:49 -------- d-----w- C:\WinFast WorkArea
2011-07-23 10:34 . 2011-07-23 10:35 -------- d-----w- c:\programdata\ArcSoft
2011-07-23 10:34 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems
2011-07-23 10:33 . 2008-08-13 07:35 20480 ----a-w- c:\program files\Windows Sidebar\Gadgets\PVR2Remote.Gadget\ClassLibrary1.dll
2011-07-23 10:33 . 2011-07-23 10:33 -------- d-----w- c:\program files\WinFast
2011-07-23 10:07 . 2007-07-13 10:28 116768 ----a-w- c:\windows\system32\NXPMV64.dll
2011-07-23 10:07 . 2011-07-23 10:07 -------- d-----w- c:\windows\SysWow64\WinFast
2011-07-23 10:07 . 2010-10-13 10:08 1345664 ----a-w- c:\windows\system32\drivers\3xHybr64.sys
2011-07-23 10:00 . 2011-07-23 10:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-23 09:59 . 2011-07-23 09:58 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-23 09:58 . 2011-07-23 09:58 -------- d-----w- c:\program files (x86)\Java
2011-07-23 09:46 . 2011-07-22 23:56 -------- d-----w- c:\windows\Panther
2011-07-23 09:46 . 2011-07-23 09:46 -------- d-----w- C:\Boot
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\system32\Wat
2011-07-23 01:50 . 2011-07-23 01:50 -------- d--h--w- c:\programdata\Common Files
2011-07-23 01:50 . 2011-07-23 01:51 -------- d-----w- c:\programdata\AVG Security Toolbar
2011-07-23 01:49 . 2011-07-23 01:49 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-07-23 01:48 . 2011-07-26 11:54 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-23 01:48 . 2011-07-23 01:50 -------- d-----w- c:\programdata\AVG10
2011-07-23 01:47 . 2011-07-23 01:47 -------- d-----w- c:\program files (x86)\AVG
2011-07-23 01:40 . 2011-07-23 01:51 -------- d-----w- c:\programdata\MFAData
2011-07-23 01:25 . 2011-07-23 01:25 -------- d-----w- c:\program files\Defraggler
2011-07-23 01:24 . 2011-07-23 01:24 -------- d-----w- c:\program files\CCleaner
2011-07-23 01:23 . 2011-07-23 01:24 -------- d-----w- c:\program files (x86)\Google
2011-07-23 01:22 . 2011-07-26 17:14 -------- d-sh--w- c:\windows\Installer
2011-07-23 01:20 . 2011-05-25 07:25 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-07-23 01:15 . 2011-06-01 03:16 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-07-23 01:15 . 2011-06-01 03:16 535656 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-07-23 01:15 . 2011-06-01 03:16 107624 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\program files\Realtek
2011-07-23 01:12 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-07-23 01:12 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-07-23 01:12 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-23 01:08 . 2011-07-23 02:16 -------- d-----w- C:\Cinema
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- c:\program files (x86)\Intel
2011-07-23 01:06 . 2010-03-02 08:04 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- C:\Intel
2011-07-23 01:00 . 2011-07-23 01:00 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2011-07-23 00:52 . 2011-07-23 02:24 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-23 00:52 . 2011-07-23 00:52 -------- d-----w- c:\windows\SysWow64\Macromed
2011-07-23 00:21 . 2011-04-29 05:47 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-23 00:10 . 2009-12-29 08:03 220672 ----a-w- c:\windows\system32\wintrust.dll
2011-07-23 00:10 . 2009-12-29 06:55 172032 ----a-w- c:\windows\SysWow64\wintrust.dll
2011-07-23 00:09 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2011-07-23 00:09 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2011-07-23 00:06 . 2011-07-20 07:44 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E9B8650-EF5E-458F-BC37-C50C57A74E58}\mpengine.dll
2011-07-23 00:06 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-07-22 23:56 . 2011-07-22 23:57 -------- d-----w- c:\users\Orc
2011-07-22 23:56 . 2011-07-22 23:56 -------- d-----w- C:\Recovery
2011-07-22 15:02 . 2011-07-23 02:17 -------- d-----w- C:\Moje
2011-07-22 14:40 . 2011-07-23 21:28 -------- d-----w- C:\Hry
2011-07-20 08:11 . 2011-07-23 00:39 -------- d-----w- C:\Music
2011-07-20 08:00 . 2011-07-23 02:17 -------- d-----w- C:\Fotky
2011-07-20 07:58 . 2011-07-25 17:52 -------- d-----w- C:\Bramboráček
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-14 06:34 . 2011-07-23 00:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_08.55.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-07-23 02:16 . 2011-07-26 17:26 20182 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-26 17:26 37362 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-07-26 11:41 83552 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-07-23 00:00 . 2011-07-26 04:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-07-23 00:00 . 2011-07-26 04:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-26 08:56 . 2011-07-26 08:56 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\01558bff07cd0456e5e5c96baab32109\stdole.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\95c38e066702d70c07858acbde86c07f\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\90dfce85a149f16578cbf64ef25e008c\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\80ea3b62aab874d48f46b5c67899caf7\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 89088 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\752b4e9d81e92fdc388b3d2fcc5b92ae\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 71680 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\73ef8ad5107d6e7b220fdaa592d29c19\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 84480 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4d70553d106d0d9ec17a93c03b04f7ef\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 93696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\16f2dec6422f65763f083feab13c5cbf\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 87040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\137c8f2489e83eb92230890ddb95e97e\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 44032 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\07afe14f79b0a1ffe3bda329992eed8f\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2011-07-23 00:00 . 2011-07-26 17:26 5720 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3097329092-3601139478-389757476-1001_UserData.bin
+ 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-26 04:42 . 2011-07-26 04:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-26 04:42 . 2011-07-26 04:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-26 16:57 . 2002-12-06 06:02 272896 c:\windows\SysWOW64\pncrt.dll
- 2009-07-14 02:36 . 2011-07-26 04:46 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-26 11:42 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-26 11:42 103370 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-07-26 04:46 103370 c:\windows\system32\perfc009.dat
+ 2009-07-14 04:45 . 2011-07-26 11:38 414888 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 05:01 . 2011-07-26 17:21 396648 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-07-26 08:57 . 2011-07-26 08:57 777728 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\fcb9f8ec37aa8a7b38c603e4c4726e33\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 226816 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e6ac4afe01d7e6c7e7fbc5c7de6514c3\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 390656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\df600168d7df7fe49010548f88487bd7\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 494592 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d4ce81cec345d704c6a8dc52f9537f48\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 305664 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c27ffd40384598eb87d60592b3e55d13\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 225280 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9a46d28e25c8fe56d1e43996399b65d0\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 232448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7de97db945198aba3ece2dad79f52d0b\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 499200 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\753870602b09c109590a760737dbf386\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 230400 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\62e1319ee8ff2a56825e1cae8cebf3ce\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 125440 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\5caa4e0b3376c601cb7cb7faf9cbee53\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 202240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4e3265456dfbcc75df09155efba7c434\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 209920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4c4d35f877f44a06d354d7420f73d095\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\21627a41da150a7960abea518c5bbf88\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 277504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\11660caf1493cfc791dd08ee4946ab70\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 970240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\0db3936e114cc6eafb286257f8075912\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\0d67d47b364e629d0b701336442d6f38\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\d267bd30e38638b50aafd348b1510f9c\Microsoft.Office.Tools.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\25ca1c0d1c95549315495dc4ffa22818\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\7776f0878fd11bf3d82ca292f7f3338f\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\5ec72efeb5de80ecfded0ef5244e008a\ehiActivScp.ni.dll
+ 2009-07-14 04:45 . 2011-07-26 11:41 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2011-07-24 10:25 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2011-07-23 05:25 . 2011-07-26 17:21 8075352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097329092-3601139478-389757476-1001-12288.dat
+ 2011-07-26 08:57 . 2011-07-26 08:57 1877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\18ca39ae10109ad46c3082f82bd56812\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\73814ed343bc11f729af4038ea213559\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\52b581df7c2dce7a5daa3a0dcc8edead\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\32fdaa05af81a7d1cd7fc199d7203579\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\8a8c7d6eb6109efcdaf31427dba23cb8\ehiVidCtl.ni.dll
- 2009-07-14 02:34 . 2011-07-26 05:43 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-07-26 11:52 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll [BU]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 09:33 2495816 ----a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
"{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}"= "c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll" [BU]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CLASSES_ROOT\clsid\{db4e9724-f518-4dfd-9c7c-78b52103cab9}]
[HKEY_CLASSES_ROOT\facemoods.dskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\facemoods.dskBnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Shutdown_Manager"="c:\program files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe" [2007-03-23 1081344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 136176]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S3 3xHybr64;WinFast DTV1000 S;c:\windows\system32\DRIVERS\3xHybr64.sys [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 88.146.189.14 88.146.189.10
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Orc\AppData\Roaming\Mozilla\Firefox\Profiles\6u95ym7x.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com/?l=dis&o=14597
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
c:\program files (x86)\AVG\AVG10\avgam.exe
c:\program files (x86)\TeamViewer\Version6\tv_w32.exe
c:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 19:29:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 17:29
ComboFix2.txt 2011-07-26 08:59
.
Před spuštěním: 568 171 933 696 bytes free
Po spuštění: 567 887 503 360 bytes free
.
- - End Of File - - 5C39DE20C0EF62DC803E01B9BE338203
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Žbeky » 26 črc 2011 22:30

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}"=-
[-HKEY_CLASSES_ROOT\clsid\{db4e9724-f518-4dfd-9c7c-78b52103cab9}]
[-HKEY_CLASSES_ROOT\facemoods.dskBnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[-HKEY_CLASSES_ROOT\facemoods.dskBnd]

DDS::
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597

Firefox::
FF - ProfilePath - c:\users\Orc\AppData\Roaming\Mozilla\Firefox\Profiles\6u95ym7x.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com/?l=dis&o=14597

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 26 črc 2011 22:34

Jojo, ten toolbar se mi tam omylem nacpal, když sem instaloval Format Factory. Zejtra udělám a hodím logu:) Každopádně zatím díky:))
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 27 črc 2011 07:39

Přihazuju log po provedeni CF skriptu.

ComboFix 11-07-26.03 - Orc 27.07.2011 7:29.3.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4094.2918 [GMT 2:00]
Spuštěný z: c:\users\Orc\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Orc\Desktop\CFScript.txt
AV: AVG Internet Security Business Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-27 do 2011-07-27 )))))))))))))))))))))))))))))))
.
.
2011-07-27 05:35 . 2011-07-27 05:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-26 16:56 . 2011-07-26 16:56 -------- d-----w- c:\program files (x86)\FreeTime
2011-07-26 06:06 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 06:06 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-26 06:02 . 2011-07-26 06:02 -------- d-----w- c:\program files (x86)\Trend Micro
2011-07-26 05:41 . 2011-07-26 05:41 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\windows\PCHEALTH
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-07-26 05:39 . 2011-07-26 05:39 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-07-26 05:37 . 2011-07-26 05:44 -------- d-----w- c:\programdata\Microsoft Help
2011-07-26 05:37 . 2011-07-26 05:37 -------- d-----r- C:\MSOCache
2011-07-25 14:04 . 2011-07-25 14:04 -------- d-----w- c:\program files (x86)\Webteh
2011-07-24 22:11 . 2011-03-30 11:05 35112 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2011-07-24 22:11 . 2011-01-12 09:42 16376 ----a-w- c:\windows\system32\drivers\TVMonitor.sys
2011-07-24 22:11 . 2011-07-24 22:11 -------- d-----w- c:\program files (x86)\TeamViewer
2011-07-24 20:43 . 2011-07-24 20:43 -------- d-----w- C:\$AVG
2011-07-24 20:27 . 2011-07-24 20:27 -------- d-----w- c:\program files (x86)\MozBackup
2011-07-24 11:23 . 2011-07-26 05:34 -------- d-----w- C:\Instalačky
2011-07-24 11:20 . 2011-07-24 11:22 -------- d-----w- c:\program files (x86)\coolpro2
2011-07-24 10:20 . 2011-07-24 10:20 -------- d-----w- C:\found.000
2011-07-23 22:33 . 2011-07-23 22:33 -------- d-----w- c:\program files (x86)\DNsoft.be
2011-07-23 22:09 . 2011-07-23 22:11 -------- d-----w- c:\program files (x86)\JDownloader
2011-07-23 21:38 . 2007-10-22 01:37 17928 ----a-w- c:\windows\SysWow64\X3DAudio1_2.dll
2011-07-23 21:28 . 2011-07-23 21:28 -------- d-----w- C:\Games
2011-07-23 20:50 . 2011-07-23 20:50 -------- d-----w- c:\program files (x86)\BitTorrent
2011-07-23 18:57 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-23 18:57 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-23 10:42 . 2011-07-27 01:03 -------- d-----w- C:\WinFast WorkArea
2011-07-23 10:34 . 2011-07-23 10:35 -------- d-----w- c:\programdata\ArcSoft
2011-07-23 10:34 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems
2011-07-23 10:33 . 2008-08-13 07:35 20480 ----a-w- c:\program files\Windows Sidebar\Gadgets\PVR2Remote.Gadget\ClassLibrary1.dll
2011-07-23 10:33 . 2011-07-23 10:33 -------- d-----w- c:\program files\WinFast
2011-07-23 10:07 . 2007-07-13 10:28 116768 ----a-w- c:\windows\system32\NXPMV64.dll
2011-07-23 10:07 . 2011-07-23 10:07 -------- d-----w- c:\windows\SysWow64\WinFast
2011-07-23 10:07 . 2010-10-13 10:08 1345664 ----a-w- c:\windows\system32\drivers\3xHybr64.sys
2011-07-23 10:00 . 2011-07-23 10:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-23 09:59 . 2011-07-23 09:58 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-23 09:58 . 2011-07-23 09:58 -------- d-----w- c:\program files (x86)\Java
2011-07-23 09:46 . 2011-07-22 23:56 -------- d-----w- c:\windows\Panther
2011-07-23 09:46 . 2011-07-23 09:46 -------- d-----w- C:\Boot
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\system32\Wat
2011-07-23 01:50 . 2011-07-23 01:50 -------- d--h--w- c:\programdata\Common Files
2011-07-23 01:50 . 2011-07-23 01:51 -------- d-----w- c:\programdata\AVG Security Toolbar
2011-07-23 01:49 . 2011-07-23 01:49 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-07-23 01:48 . 2011-07-27 00:17 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-23 01:48 . 2011-07-23 01:50 -------- d-----w- c:\programdata\AVG10
2011-07-23 01:47 . 2011-07-23 01:47 -------- d-----w- c:\program files (x86)\AVG
2011-07-23 01:40 . 2011-07-23 01:51 -------- d-----w- c:\programdata\MFAData
2011-07-23 01:25 . 2011-07-23 01:25 -------- d-----w- c:\program files\Defraggler
2011-07-23 01:24 . 2011-07-23 01:24 -------- d-----w- c:\program files\CCleaner
2011-07-23 01:23 . 2011-07-23 01:24 -------- d-----w- c:\program files (x86)\Google
2011-07-23 01:22 . 2011-07-27 04:22 -------- d-sh--w- c:\windows\Installer
2011-07-23 01:20 . 2011-05-25 07:25 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-07-23 01:15 . 2011-06-01 03:16 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-07-23 01:15 . 2011-06-01 03:16 535656 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-07-23 01:15 . 2011-06-01 03:16 107624 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\program files\Realtek
2011-07-23 01:12 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-07-23 01:12 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-07-23 01:12 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-23 01:08 . 2011-07-23 02:16 -------- d-----w- C:\Cinema
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- c:\program files (x86)\Intel
2011-07-23 01:06 . 2010-03-02 08:04 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- C:\Intel
2011-07-23 01:00 . 2011-07-23 01:00 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2011-07-23 00:52 . 2011-07-23 02:24 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-23 00:52 . 2011-07-23 00:52 -------- d-----w- c:\windows\SysWow64\Macromed
2011-07-23 00:21 . 2011-04-29 05:47 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-23 00:10 . 2009-12-29 08:03 220672 ----a-w- c:\windows\system32\wintrust.dll
2011-07-23 00:10 . 2009-12-29 06:55 172032 ----a-w- c:\windows\SysWow64\wintrust.dll
2011-07-23 00:09 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2011-07-23 00:09 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2011-07-23 00:06 . 2011-07-20 07:44 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E9B8650-EF5E-458F-BC37-C50C57A74E58}\mpengine.dll
2011-07-23 00:06 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-07-22 23:56 . 2011-07-22 23:57 -------- d-----w- c:\users\Orc
2011-07-22 23:56 . 2011-07-22 23:56 -------- d-----w- C:\Recovery
2011-07-22 15:02 . 2011-07-23 02:17 -------- d-----w- C:\Moje
2011-07-22 14:40 . 2011-07-23 21:28 -------- d-----w- C:\Hry
2011-07-20 08:11 . 2011-07-23 00:39 -------- d-----w- C:\Music
2011-07-20 08:00 . 2011-07-23 02:17 -------- d-----w- C:\Fotky
2011-07-20 07:58 . 2011-07-25 17:52 -------- d-----w- C:\Bramboráček
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-14 06:34 . 2011-07-23 00:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-07-26_17.24.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2011-07-27 04:22 37506 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-07-26 19:33 86032 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-07-23 00:00 . 2011-07-27 04:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-23 00:00 . 2011-07-27 04:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-27 04:22 . 2011-07-27 04:22 25088 c:\windows\Installer\2d08f.msi
+ 2011-07-23 00:00 . 2011-07-27 04:22 6120 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3097329092-3601139478-389757476-1001_UserData.bin
- 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-27 04:19 . 2011-07-27 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-27 04:19 . 2011-07-27 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-07-26 11:42 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-27 04:24 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-27 04:24 103370 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-07-26 11:42 103370 c:\windows\system32\perfc009.dat
- 2009-07-14 05:01 . 2011-07-26 17:21 396648 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-27 01:24 396648 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-07-23 02:09 . 2011-07-27 01:24 2800485 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097329092-3601139478-389757476-1001-8192.dat
- 2009-07-14 02:34 . 2011-07-26 11:52 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-07-26 17:38 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 09:33 2495816 ----a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Shutdown_Manager"="c:\program files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe" [2007-03-23 1081344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 136176]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 136176]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S3 3xHybr64;WinFast DTV1000 S;c:\windows\system32\DRIVERS\3xHybr64.sys [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 01:23]
.
2011-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 01:23]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 88.146.189.14 88.146.189.10
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Orc\AppData\Roaming\Mozilla\Firefox\Profiles\6u95ym7x.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
Celkový čas: 2011-07-27 07:37:56
ComboFix-quarantined-files.txt 2011-07-27 05:37
ComboFix2.txt 2011-07-26 17:29
ComboFix3.txt 2011-07-26 08:59
.
Před spuštěním: 568 460 476 416 bytes free
Po spuštění: 568 175 742 976 bytes free
.
- - End Of File - - A3888C60C954F8078343189D2F054A34
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Žbeky » 27 črc 2011 09:40

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG , Avast,Avira či Microsoft Security Essentials následně T-Cleaner smaž a zapni si AVG , Avast, Avira či Microsoft Security Essentials

+ Nový log z HJT

Jak se chová PC?
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 28 črc 2011 07:10

Promazáno vyčištěno, ale je to pořád skoro stejný :roll: Teda s tím rozdílem, že občas to napíše samotný "š", ale občas i "šč" (tak 50:50)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:08:22, on 28.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [Shutdown_Manager] C:\Program Files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8377 bytes
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Orcus » 28 črc 2011 07:10

Promazáno vyčištěno, ale je to pořád skoro stejný :roll: Teda s tím rozdílem, že občas to napíše samotný "š", ale občas i "šč" (tak 50:50)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:08:22, on 28.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [Shutdown_Manager] C:\Program Files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3097329092-3601139478-389757476-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8377 bytes
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Žbeky » 28 črc 2011 09:52

Zkus jinou klávesnici - je možné, že to nemačkáš ty, ale přímo tlačítko dole na tišťáku
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 54 hostů