Ahoj, posílám logy ze dvou PC.
První PC: vymazaný adresář z c:\Program Files konkrétně Adobe Reader. Dále z původně nainstalovaného skeneru F2710 c:\Program Files\HP kde zbyla pouze složka HP Software Update a v ní soubor hpwuSchd2.exe.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:35:38, on 18.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Microsoft Activation Assistant\FGUPM.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Micos\SpravceClient\mcsspravcesrv.exe
C:\Program Files\Micos\SpravceClient\mcsspravce.exe
C:\Program Files\OA10\rcClient.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\OA10\oaServerNt.exe
C:\Program Files\OA10\oaServerNt.exe
C:\Program Files\OA10\WorkSpApUia.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\MsiExec.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: Re§im ECHO je zapnut.
O1 - Hosts: 127.0.0.2 http://www.facebook.com
O1 - Hosts: 127.0.0.2 facebook.com
O1 - Hosts: 127.0.0.2 static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 login.facebook.com
O1 - Hosts: 127.0.0.2 http://www.login.facebook.com
O1 - Hosts: 127.0.0.2 fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.fbcdn.net
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 http://www.static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://www.cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 https://cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://www.seznam.cz# Block Facebook
O1 - Hosts: 127.0.0.2 http://www.facebook.com
O1 - Hosts: 127.0.0.2 facebook.com
O1 - Hosts: 127.0.0.2 static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 login.facebook.com
O1 - Hosts: 127.0.0.2 http://www.login.facebook.com
O1 - Hosts: 127.0.0.2 fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.fbcdn.net
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 http://www.static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 https://www.torproject.org
O1 - Hosts: 127.0.0.2 http://www.torproject.org
O1 - Hosts: 127.0.0.2 http://www.torproject.org
O1 - Hosts: 127.0.0.2 torproject.org
O1 - Hosts: 127.0.0.2 https://www.hry.cz
O1 - Hosts: 127.0.0.2 http://www.hry.cz
O1 - Hosts: 127.0.0.2 http://www.hry.cz
O1 - Hosts: 127.0.0.2 hry.cz
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WorkSpIE - {D0035573-5C85-40A7-9B17-ED6B89A21C40} - C:\Program Files\OA10\WorkSpIe.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.intranet.pld
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pld.local
O17 - HKLM\Software\..\Telephony: DomainName = pld.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pld.local
O20 - Winlogon Notify: oaKel - oaKelNt.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: MicosClientSpr - MiCoS Software s.r.o. - C:\Program Files\Micos\SpravceClient\mcsspravcesrv.exe
O23 - Service: oaServerNT - SODATSW - C:\Program Files\OA10\oaServerNt.exe
O23 - Service: rcClient - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
--
End of file - 7869 bytes
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Druhé PC: - Po restartu chybely soubory v c:\windows\fonts začínajicí souborem VGA852.fon
- vymazaný adresář z c:\Program Files konkrétně Firefox
- po přihlášení uživatele se přidaly do složky po spuštění (Media Player, Outlook express, IE 8, vzdálená pomoc).
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:42:17, on 18.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Micos\SpravceClient\mcsspravcesrv.exe
C:\Program Files\Micos\SpravceClient\mcsspravce.exe
C:\Program files\OA10\rcClient.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program files\OA10\oaServerNt.exe
C:\Program files\OA10\oaServerNt.exe
C:\windows\system32\svchost.exe
C:\Program files\OA10\WorkSpApUia.exe
C:\windows\Explorer.EXE
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ClientRS\csend.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: Re§im ECHO je zapnut.
O1 - Hosts: 127.0.0.2 http://www.facebook.com
O1 - Hosts: 127.0.0.2 facebook.com
O1 - Hosts: 127.0.0.2 static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 login.facebook.com
O1 - Hosts: 127.0.0.2 http://www.login.facebook.com
O1 - Hosts: 127.0.0.2 fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.fbcdn.net
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 http://www.static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://www.cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 https://cs-cz.facebook.com
O1 - Hosts: 127.0.0.2 http://www.seznam.cz# Block Facebook
O1 - Hosts: 127.0.0.2 http://www.facebook.com
O1 - Hosts: 127.0.0.2 facebook.com
O1 - Hosts: 127.0.0.2 static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.static.ak.fbcdn.net
O1 - Hosts: 127.0.0.2 login.facebook.com
O1 - Hosts: 127.0.0.2 http://www.login.facebook.com
O1 - Hosts: 127.0.0.2 fbcdn.net
O1 - Hosts: 127.0.0.2 http://www.fbcdn.net
O1 - Hosts: 127.0.0.2 fbcdn.com
O1 - Hosts: 127.0.0.2 http://www.fbcdn.com
O1 - Hosts: 127.0.0.2 static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 http://www.static.ak.connect.facebook.com
O1 - Hosts: 127.0.0.2 https://www.torproject.org
O1 - Hosts: 127.0.0.2 http://www.torproject.org
O1 - Hosts: 127.0.0.2 http://www.torproject.org
O1 - Hosts: 127.0.0.2 torproject.org
O1 - Hosts: 127.0.0.2 https://www.hry.cz
O1 - Hosts: 127.0.0.2 http://www.hry.cz
O1 - Hosts: 127.0.0.2 http://www.hry.cz
O1 - Hosts: 127.0.0.2 hry.cz
O2 - BHO: WorkSpIE - {D0035573-5C85-40A7-9B17-ED6B89A21C40} - C:\Program files\OA10\WorkSpIe.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [csend] "C:\Program Files\ClientRS\csend.exe" "" "769"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pld.local
O17 - HKLM\Software\..\Telephony: DomainName = pld.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pld.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = pld.local
O20 - Winlogon Notify: oaKel - oaKelNt.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: MicosClientSpr - MiCoS Software s.r.o. - C:\Program Files\Micos\SpravceClient\mcsspravcesrv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Unknown owner - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (file missing)
O23 - Service: oaServerNT - SODATSW - C:\Program files\OA10\oaServerNt.exe
O23 - Service: rcClient - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
--
End of file - 7613 bytes