Virus- ako ho odstranit? (Vyriesene)

Všetko o antivírových programoch, firewalloch, víroch, spyware, ostatných aktuálnych hrozbách, názoroch a skúsenostiach, ako sa im vyvarovať...
POZOR: žiadny WAREZ
Používateľov profilový obrázok
lacika
Pokročilý používateľ
Pokročilý používateľ
Príspevky: 4278
Dátum registrácie: Pi 11. Jan, 2008, 14:00
Bydlisko: KE

Virus- ako ho odstranit? (Vyriesene)

Príspevok od používateľa lacika »

Logfile of HijackThis v1.99.1
Scan saved at 15:53:24, on 27. 10. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\qip8050\MusicToQIP.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\FRAPS\FRAPS.EXE
D:\Core Temp.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\JetAudio\JetAudio.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: (no name) - {DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ddcDvwxu.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AMD_Display] C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [MusicToQIP] "C:\qip8050\MusicToQIP.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RivaTuner] "C:\Program Files\RivaTuner v2.08\RivaTuner.exe" /T
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - Startup: Core Temp.lnk = D:\Core Temp.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: ddcDvwxu - C:\WINDOWS\SYSTEM32\ddcDvwxu.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
To cervenym je virus, resp. trojan. NOD32 ho nedokaze odstanit, ani SB S&D, ani HJT.
Skusal som aj v nudzovom rezime, ale system ho pouziva. Vypol som aj procesor explorer.exe a aj tak nesiel odstanit.
Skusil som aj v nudzovom rezime cez MS-DOS, tiez bez uspechu.
Ten hnup sa pripaja na net asi cez IE. IE mam v KPF blokovane.
Len neviem ako ho odstranit.
Spustit nejaky DOS z CD a tak odstanit? Poradte, prosim.

edit:// uprany nazov temy na "Virus- ako ho odstranit? (Vyriesene)".
Naposledy upravil/-a lacika v Po 27. Okt, 2008, 22:31, upravené celkom 1 krát.
Lopik
Používateľ
Používateľ
Príspevky: 413
Dátum registrácie: Ut 17. Apr, 2007, 08:00
Bydlisko: Žilina

Re: Virus- ako ho odstranit?

Príspevok od používateľa Lopik »

hmm sila ... google mi nenasial ani jeden udaj o tomto vire :hmmm: ... akoby ten virus sam sebe generoval nazov tohto suboru. :?
oskenuj tento virus NODom a ked ti vyhodi NOD alarmove okno, urob screen a supni sem. Ak bude viac okien, nahod kazde jedno sem.

// btw ... o subore UTSCSI.EXE vies ? ... nejavi sa ako doverihodny
Naposledy upravil/-a Lopik v Po 27. Okt, 2008, 21:28, upravené celkom 1 krát.
Používateľov profilový obrázok
Snake
VIP
VIP
Príspevky: 13677
Dátum registrácie: Ne 23. Júl, 2006, 02:00
Bydlisko: Bratislava/Galanta

Re: Virus- ako ho odstranit?

Príspevok od používateľa Snake »

skus unregnut v safe mode cez CMD (regsvr32 /u "subor") alebo ho zmaz externe, popr ho sem supni ze co to je zac :-)





.
Používateľov profilový obrázok
lacika
Pokročilý používateľ
Pokročilý používateľ
Príspevky: 4278
Dátum registrácie: Pi 11. Jan, 2008, 14:00
Bydlisko: KE

Re: Virus- ako ho odstranit?

Príspevok od používateľa lacika »

Obrázok
Obrázok
mam supnut len dll-ko?
Ako zmazat externe? ked je v operacnej pamati?
Na bootovat linux, abo nieco podobne?
Používateľov profilový obrázok
Snake
VIP
VIP
Príspevky: 13677
Dátum registrácie: Ne 23. Júl, 2006, 02:00
Bydlisko: Bratislava/Galanta

Re: Virus- ako ho odstranit?

Príspevok od používateľa Snake »

http://www.viry.cz/forum/viewtopic.php? ... &sk=t&sd=a" onclick="window.open(this.href);return false;

skus toto...





.
Lopik
Používateľ
Používateľ
Príspevky: 413
Dátum registrácie: Ut 17. Apr, 2007, 08:00
Bydlisko: Žilina

Re: Virus- ako ho odstranit?

Príspevok od používateľa Lopik »

alebo potom skus pouzit program Malwarebytes' Anti-Malware
http://www.viry.cz/forum/viewtopic.php?f=29&t=67229" onclick="window.open(this.href);return false;
ale bacha na to , co mazes ! musis si byt isty.
Používateľov profilový obrázok
lacika
Pokročilý používateľ
Pokročilý používateľ
Príspevky: 4278
Dátum registrácie: Pi 11. Jan, 2008, 14:00
Bydlisko: KE

Re: Virus- ako ho odstranit?

Príspevok od používateľa lacika »

Diki hosi.. Zvlast tebe Snake.. Combofix to zvladol.. :dance:

ak chcete tu mate nejake citanie :D
Combofix
Spoiler: ukázať
ComboFix 08-10-27.01 - lacko 2008-10-27 20:59:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.703 [GMT 1:00]
Použité ovládací přepínače :: C:\Documents and Settings\lacko\Plocha\CFScript.txt.txt
* Vytvořen nový Bod Obnovení
* Resident AV is active


VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!

FILE ::
C:\WINDOWS\system32\ddcDvwxu.dll
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\cbXPGWqQ.dll
C:\WINDOWS\system32\ddcDvwxu.dll

----- BITS: Možné infikované stránky -----

hxxp://www.thematurevideo.net" onclick="window.open(this.href);return false;
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-09-27 do 2008-10-27 )))))))))))))))))))))))))))))))
.

2009-04-29 16:50 . 2008-05-04 22:20 <DIR> d-------- C:\Program Files\HD Tune Pro
2008-10-27 18:57 . 2008-10-27 18:57 398,802 --a------ C:\WINDOWS\system32\prfh0405.dat
2008-10-27 18:57 . 2008-10-27 18:57 73,440 --a------ C:\WINDOWS\system32\prfc0405.dat
2008-10-27 14:08 . 2008-04-19 12:41 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-10-27 14:08 . 2008-04-19 12:34 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-10-27 14:08 . 2008-10-27 14:08 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-27 14:06 . 2008-10-27 14:06 28,061 --a------ C:\WINDOWS\system32\ddcDvwxu.zip
2008-10-24 16:31 . 2008-04-28 14:53 805,400 -ra------ C:\WINDOWS\system32\tmp2F2.tmp
2008-10-24 15:10 . 2008-10-24 15:10 0 --a------ C:\as.dat
2008-10-23 14:18 . 2008-10-23 14:18 <DIR> d-------- C:\Program Files\Deep Silver
2008-10-21 13:20 . 2008-10-21 13:26 <DIR> d-------- C:\WINDOWS\NKCCDViewerSetting
2008-10-18 18:21 . 2008-10-18 20:59 <DIR> dr------- C:\AUTOŠKOLA
2008-10-17 17:21 . 2008-10-17 17:21 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Last.fm
2008-10-17 17:18 . 2008-10-17 17:18 <DIR> d-------- C:\Program Files\Last.fm
2008-10-07 14:04 . 2008-10-14 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\TrackMania
2008-10-07 13:58 . 2008-10-07 16:33 <DIR> d-------- C:\Program Files\TmNationsForever
2008-10-04 14:51 . 2008-10-04 14:51 <DIR> d-------- C:\Program Files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 20:06 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-10-27 19:40 --------- d-----w C:\Program Files\Mozilla Firefox3
2008-10-27 19:32 38,498 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-10-27 19:14 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\uTorrent
2008-10-26 15:53 --------- d-----w C:\Program Files\AIMP2
2008-10-23 13:30 279,712 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-10-23 13:30 25,888 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-10-19 15:42 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\dvdcss
2008-10-18 16:28 --------- d-----w C:\Program Files\Flash FLV to Video Audio Converter
2008-09-24 12:47 --------- d-----w C:\Program Files\Gothic III
2008-09-24 12:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-14 23:45 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\LimeWire
2008-09-09 20:45 --------- d-----w C:\Program Files\SpeedFan
2008-09-09 13:45 --------- d-----w C:\Program Files\Euro Truck Simulator
2008-09-09 13:38 --------- d-----w C:\Program Files\18 Wheels of Steel Haulin
2008-09-09 13:32 --------- d-----w C:\Program Files\phenomedia
2008-09-08 14:44 --------- d-----w C:\Program Files\GameShadow
2008-09-08 14:36 --------- d-----w C:\Program Files\Eidos
2008-08-31 16:56 --------- d-----w C:\Program Files\GameTop.com
2008-08-31 16:12 167,317 ----a-w C:\WINDOWS\San Andreas Tools Uninstaller.exe
2008-08-31 16:12 --------- d-----w C:\Program Files\San Andreas Tools
2008-08-30 15:55 --------- d-----w C:\Program Files\Sanny Builder 3
2008-08-28 17:45 --------- d-----w C:\Program Files\Common Files\Futuremark Shared
2008-08-11 14:21 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-08-06 09:21 45,056 ----a-w C:\WINDOWS\system32\UTSCSI.EXE
.

------- Sigcheck -------

2005-09-03 00:55 661504 5e7263b2ee473b8edbab9a7d578018f0 C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
2006-01-09 19:04 663040 fd4554fa8c83594a63325d2d827c3712 C:\WINDOWS\$hf_mig$\KB912945\SP2QFE\wininet.dll
2006-01-09 19:08 659456 1b28e6c7a9034a7e798d79d035de3de1 C:\WINDOWS\$NtUninstallKB912945$\wininet.dll
2006-01-09 19:04 663040 fd4554fa8c83594a63325d2d827c3712 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 12:26 1225216 a886e193e41188dca0dacc3aa2960c17 C:\WINDOWS\system32\wininet.dll
2006-06-23 12:26 1225216 a886e193e41188dca0dacc3aa2960c17 C:\WINDOWS\system32\dllcache\wininet.dll

2005-04-07 19:48 1881088 6df495956bdab96dbec93a2135174910 C:\WINDOWS\explorer.exe
2004-08-18 13:00 1032704 53114d57ab73a406ac7f602227781a99 C:\WINDOWS\$NtUninstallKB884883$\explorer.exe
2005-04-07 19:48 1881088 6df495956bdab96dbec93a2135174910 C:\WINDOWS\system32\dllcache\explorer.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 15360]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2008-01-14 3182248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD_Display"="C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe" [2007-12-17 1445888]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 196608]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
"MusicToQIP"="C:\qip8050\MusicToQIP.exe" [2007-04-10 359936]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-19 949376]
"RivaTuner"="C:\Program Files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2007-12-05 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\lacko\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Core Temp.lnk - D:\Core Temp.exe [2008-04-19 223760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll

[HKLM\~\startupfolder\C:^Documents and Settings^lacko^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^lacko^Nabídka Start^Programy^Po spuštění^RivaTuner.lnk]
backup=C:\WINDOWS\pss\RivaTuner.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 00:41 8523776 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 12:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
-ra------ 2006-01-20 12:34 544768 C:\WINDOWS\sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrA"=2 (0x2)
"NMIndexingService"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"UxTuneUp"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Crypkey License"=2 (0x2)
"bgsvcgen"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"OM_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"OM_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

R1 atitray;atitray;C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2008-04-14 17952]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2006-07-18 284184]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2006-07-18 91672]
R1 SysTool;SysTool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 24064]
R1 VBoxDrv;VirtualBox Service;C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2008-05-31 55520]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2008-05-31 42048]
R3 ALSysIO;ALSysIO;C:\DOCUME~1\lacko\LOCALS~1\Temp\ALSysIO.sys [ ]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 69120]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbhub;Ovladač standardního rozbočovače USB;C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-09-01 59264]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2006-04-19 17152]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-18 26496]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2007-10-16 22640]
S3 RTCore32;RTCore32;D:\RightMark Memory Analyzer\RTCore32.sys [2005-05-25 4608]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-05-01 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-05-01 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-05-01 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-05-01 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-05-01 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-05-01 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-05-01 90800]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-29 306432]
S4 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40fd7ca8-810e-11dd-a6a1-0015f2f2be15}]
\Shell\AutoRun\command - setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f63e4c5-3253-11dd-a64b-0015f2f2be15}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa717787-268c-11dd-a632-0015f2f2be15}]
\Shell\AutoRun\command - M:\USBNB.exe

*Newly Created Service* - ALSYSIO
.
Obsah adresáře 'Naplánované úlohy'

2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-28 13:49]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ddcDvwxu.dll
ShellExecuteHooks-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ddcDvwxu.dll
Notify-ddcDvwxu - ddcDvwxu.dll
MSConfigStartUp-Google Update - C:\Documents and Settings\lacko\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net" onclick="window.open(this.href);return false;
Rootkit scan 2008-10-27 21:06:26
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

PROCES: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2008-10-27 21:09:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2008-10-27 20:09:49

Před spuštěním: Volných bajtů: 72,069,988,352
Po spuštění: Volných bajtů: 72,124,907,520

240
HJT
Spoiler: ukázať
Logfile of HijackThis v1.99.1
Scan saved at 21:15:34, on 27. 10. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\qip8050\MusicToQIP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\FRAPS\FRAPS.EXE
D:\Core Temp.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Zadako\Communicator\Communicator.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox3\firefox.exe
C:\PROGRA~1\PSPADE~1\PSPad.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157" onclick="window.open(this.href);return false;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896" onclick="window.open(this.href);return false;
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896" onclick="window.open(this.href);return false;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AMD_Display] C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [MusicToQIP] "C:\qip8050\MusicToQIP.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RivaTuner] "C:\Program Files\RivaTuner v2.08\RivaTuner.exe" /T
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - Startup: Core Temp.lnk = D:\Core Temp.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{337B38F6-BC91-457B-8833-6B7BA7A8775D}: NameServer = 213.151.200.30 213.151.208.161
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

Návrat na "Bezpečnost a zabezpečenie PC"