nejde mi nastavit pozadie na prac ploche

Problematika virů a antivirů, zabezpečení PC - firewall, spyware, atd.
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

NOD je na 30 dni a co ste myslel , ze budete mat aspon akeho takeho ochrancu zadarmo? U FREE je to ine ako u nodu .
Ak chcete mat FREE antivirus , tak mozete pouzit AOL- Kaspersky antivirus , ale ten odosiela vase udaje do firmy kaspersky a vsetko , co na pocitaci robite.


Pocitac precistite s ccleanerom : http://www.viry.cz/forum/viewtopic.php?t=7478/

Start --> Spustit --> services.msc . Vyhladajte tieto sluzby : wampmysqld . Poklikajte a zakazte ju vo vsetkych moznostiah , alebo zastavte .

Toto pouzivate? D:\Programy\wamp\apache2\bin\httpd.exe
Mne sa to zda , ze je to BAD. Ak to nepouzivate , tak v sluzbach ako u predchodzej vyhladajte toto : wampapache - Apache Software Foundation . Aj tuto zakazte a zastavte. Pokial ju pouzivate , tak do avengeru nevkladajte toto : D:\Programy\wamp\apache2\bin\httpd.exe !
Nasledne restartuje pocitac

Do Avengeru vlozte toto :
Drivers to unload:
noskrnl.sys

Files to delete:
C:\WINDOWS\System32\noskrnl.sys
C:\Program Files\Video Add-on
D:\Programy\wamp\mysql\bin\mysqld-nt.exe
D:\Programy\wamp\apache2\bin\httpd.exe
Ako sme uz mazali pomocou ComboFixu , zmazneme este raz .
Do poznamkoveho bloku skopirujte toto :
File::
C:\gseiejlf.bat

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ejnoyihm]
Ulozte blok na plochu ako CFScript.txt , s mysou ho chytte a presunte nad ComboFix.

Obrázek

Potom tu dajte oba logy z ComboFix a Avenger.

Nainstalujte SP2 ! Ten , ktory mate vy , nie je dostatocny !
Na stranke si vyberte slovencinu (podla vaseho win , stiahnite a nainstalujte . Instalacia trva cca 30 minut. Tu urobte az po tom , ked budu vsetky logy ciste :-)
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

tie weci okolo wamp-u sa tykaju php...nemozem ich zmazat lebo by mi na pc nebezal php server...to avengeru som uz vlozil tie prikazy co tu boli predtym a po restarte pc a prihlaseny mi vybehol prikazovy riadok a nespustila sa plocha...tak som ju spustil rucne cez spravcu uloh ale avenger nenechal ziaden log...
chcem este upozornit ze nemam legalnu verziu windows...ked nainstalujem sp2 tak pojdu vsetky aplikacie uplne v pohode?

o chvilu tu pridam loh z combofixu a potom este zaverecny z hijacku...mozno ten z avengeru nebude potrebny
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

Log z avengeru mate v C:\avenger.txt To ak nenabehne plocha je niekedy bezny jav . Ten log z avengeru je pomerne dost dolezity ako informacia otom , ci prebehlo mazanie korektne.

Ak pouzivatie tie programy ktore som oznacil na zastavenie a zmazanie , tak potom ok . Mne to google dalo ako zbytocnost a ak to poznate tak je vsetko ok .

Ak nemate legalny win , neviem ci vam to pojde , za pokus nic nedate a ak vam to nainstaluje , tak vam vsetko pojde ok a lepsie , pretoze niektore programy sa vam nemusia ani dat spustit z dovodu dier vo win .
Ak to budete instalovat , tak na pc nerobte nic .
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

log z combofix

ComboFix 07-11-08.1 - prodigy 2007-11-10 21:57:03.5 - NTFSx86
Running from: D:\Programy\Ochrana\ComboFix.exe
Command switches used :: D:\Programy\Ochrana\CFScript.txt
* Created a new restore point

FILE
C:\gseiejlf.bat
.

((((((((((((((((((((((((( Files Created from 2007-10-10 to 2007-11-10 )))))))))))))))))))))))))))))))
.

2007-11-10 20:26 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-10 18:57 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\Comodo
2007-11-10 15:40 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2007-11-10 15:39 <DIR> d-------- C:\WINDOWS\Noslip
2007-11-10 13:22 <DIR> d-------- C:\Documents and Settings\prodigy\Data aplikací\Comodo
2007-11-10 13:21 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Comodo
2007-11-10 00:21 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-09 23:59 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Prevx
2007-11-09 23:56 <DIR> d-------- C:\Temp
2007-11-09 17:03 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-11-06 16:40 952 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-05 18:15 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\AdobeUM
2007-11-04 13:07 <DIR> d-------- C:\Documents and Settings\prodigy\Data aplikací\InstallShield
2007-11-01 14:21 <DIR> d-------- C:\Program Files\Common Files\ChaosGroup
2007-11-01 13:05 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-11-01 13:01 797,184 --a--c--- C:\WINDOWS\system32\dllcache\d3dim700.dll
2007-11-01 13:01 797,184 --a------ C:\WINDOWS\system32\d3dim700.dll
2007-11-01 13:01 24,064 --a--c--- C:\WINDOWS\system32\dllcache\ddrawex.dll
2007-11-01 13:01 24,064 --a------ C:\WINDOWS\system32\ddrawex.dll
2007-10-30 09:51 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-10-30 09:51 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Adobe Systems
2007-10-28 21:41 <DIR> d-------- C:\www
2007-10-27 15:42 <DIR> d-------- C:\Program Files\DCPFLICS
2007-10-27 14:45 <DIR> d-------- C:\Program Files\Autodesk
2007-10-26 19:41 36,224 --a------ C:\WINDOWS\system32\drivers\an983.sys
2007-10-26 19:41 36,224 --a--c--- C:\WINDOWS\system32\dllcache\an983.sys
2007-10-20 16:10 <DIR> d-------- C:\Documents and Settings\Luk1\Data aplikací\MEGAUPLOADTOOLBAR
2007-10-20 16:10 <DIR> d-------- C:\Documents and Settings\Luk1\Data aplikací\ICQ
2007-10-20 16:09 <DIR> d-------- C:\Documents and Settings\Luk1\Data aplikací\AVG7
2007-10-20 14:04 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\ICQ
2007-10-20 10:52 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\MEGAUPLOADTOOLBAR
2007-10-20 10:50 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\Share-to-Web Upload Folder
2007-10-20 10:50 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací\AVG7
2007-10-20 10:49 <DIR> d-------- C:\Documents and Settings\Vladimir Malik.MALIK\Plocha
2007-10-20 10:49 <DIR> d--h----- C:\Documents and Settings\Vladimir Malik.MALIK\Okolní tiskárny
2007-10-20 10:49 <DIR> d--h----- C:\Documents and Settings\Vladimir Malik.MALIK\Okolní síť
2007-10-20 10:49 <DIR> dr------- C:\Documents and Settings\Vladimir Malik.MALIK\Oblíbené položky
2007-10-20 10:49 <DIR> d--h----- C:\Documents and Settings\Vladimir Malik.MALIK\Šablony
2007-10-20 10:49 <DIR> dr------- C:\Documents and Settings\Vladimir Malik.MALIK\Nabídka Start
2007-10-20 10:49 <DIR> dr------- C:\Documents and Settings\Vladimir Malik.MALIK\Dokumenty
2007-10-20 10:49 <DIR> dr-h----- C:\Documents and Settings\Vladimir Malik.MALIK\Data aplikací
2007-10-18 15:08 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2007-10-18 15:08 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2007-10-18 15:08 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2007-10-18 15:08 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2007-10-18 15:08 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2007-10-18 15:08 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2007-10-18 15:08 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2007-10-18 15:08 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2007-10-18 15:04 <DIR> d-------- C:\Program Files\Video Add-on
2007-10-17 19:51 <DIR> d-------- C:\Documents and Settings\prodigy\Data aplikací\RapidGet
2007-10-17 19:47 50,048 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-10-17 19:46 <DIR> d-------- C:\Documents and Settings\prodigy\Data aplikací\PC Tools
2007-10-17 14:21 <DIR> d-------- C:\Documents and Settings\prodigy\Data aplikací\AVG7
2007-10-17 14:19 <DIR> d-------- C:\Documents and Settings\LocalService\Data aplikací\AVG7
2007-10-17 13:32 9,488 --a------ C:\WINDOWS\system32\sporder.dll
2007-10-17 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Avg7
2007-10-17 13:22 <DIR> d-------- C:\Program Files\Common Files\Panda Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2020-10-21 10:14 223,128 ----a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2020-10-21 10:09 611,064 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-11-10 14:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-09 16:25 --------- d-----w C:\Program Files\ICQToolbar
2007-11-09 16:25 --------- d-----w C:\Program Files\HP Travel Idea CD
2007-11-09 10:14 12,800 ----a-w C:\WINDOWS\system32\svchost.exe
2007-11-06 17:29 --------- d-----w C:\Program Files\ReadIris
2007-11-01 13:22 --------- d-----w C:\Program Files\Common Files\ChaosGroup
2007-11-01 13:03 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-10-30 08:52 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-18 14:05 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2007-10-17 13:19 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Grisoft
2007-10-15 12:44 --------- d-----w C:\Program Files\Common Files\Macromedia
2007-10-12 17:18 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\ICQ
2007-10-11 20:17 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\DVD Shrink
2007-10-10 15:12 --------- d-----w C:\Program Files\MegauploadToolbar
2007-10-09 08:58 --------- d-----w C:\Program Files\Google
2007-10-07 11:27 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\MegauploadToolbar
2007-10-06 16:05 --------- d-----w C:\Program Files\TV JOJ Media Player
2007-10-03 16:51 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\vlc
2007-10-01 17:19 --------- d-----w C:\Program Files\Best of My WaterWorks
2007-10-01 17:10 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\SUPERAntiSpyware.com
2007-10-01 17:10 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2007-10-01 17:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-30 11:38 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\Sony
2007-09-28 15:57 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\FlashFXP
2007-09-28 15:54 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Macrovision
2007-09-23 16:19 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\MSN6
2007-09-20 12:35 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
2007-09-18 13:28 --------- d-----w C:\Documents and Settings\prodigy\Data aplikací\CyberLink
2007-09-15 15:07 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-09-14 17:26 --------- d-----w C:\Program Files\ROUTE66
.

((((((((((((((((((((((((((((( snapshot@2007-11-10_ 1.16.36.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-03-13 17:58:20 7,272 ------w C:\WINDOWS\Noslip\Nbupinfo.dat
- 2007-11-09 23:33:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-10 19:15:11 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-09 23:33:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-10 19:15:11 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-09 23:35:00 81,920 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-10 19:15:11 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-10 12:18:04 75,520 ----a-w C:\WINDOWS\system32\drivers\cmdmon.sys
+ 2007-11-10 12:18:04 51,328 ----a-w C:\WINDOWS\system32\drivers\inspect.sys
- 2007-11-04 18:02:45 696,048 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-11-10 15:22:48 696,848 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 1997-07-24 16:41:52 48,640 ------w C:\WINDOWS\system32\INETWH32.DLL
+ 1999-01-28 14:44:20 49,152 ----a-w C:\WINDOWS\system32\INETWH32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="atiptaxx.exe" []
"AVG7_CC"="D:\Programy\AVGANT~1\avgcc.exe" [2007-10-27 16:07]
"COMODO Firewall Pro"="D:\Programy\Ochrana\Comodo\Firewall\CPF.exe" [2007-11-10 13:18]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-20 19:05]
"ICQ"="D:\Programy\ICQ\ICQ6\ICQ.exe" [2007-08-08 16:03]
"Spyware Doctor"="D:\Programy\Ochrana\Spyware Doctor\swdoctor.exe" [2006-01-10 18:31]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"=D:\Programy\AVGANT~1\avgw.exe /RUNONCE
"Spyware Doctor"="D:\Programy\Ochrana\Spyware Doctor\swdoctor.exe" /Q

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp instant support.lnk - C:\Program Files\Hewlett-Packard\HP Instant Support DI\bin\matcli.exe [2007-08-09 09:18:53]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-05-29 13:57:06]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-05-29 13:57:28]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)
"NoFavoritesMenu"=0 (0x0)
"NoSMMyPictures"=0 (0x0)
"NoStartMenuMyMusic"=0 (0x0)
"NoRecentDocsHistory"=0 (0x0)
"NoRecentDocsNetHood"=0 (0x0)
"NoInstrumentation"=0 (0x0)
"NoSimpleStartMenu"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)
"NoFavoritesMenu"=0 (0x0)
"NoSMMyPictures"=0 (0x0)
"NoStartMenuMyMusic"=0 (0x0)
"NoRecentDocsHistory"=0 (0x0)
"NoRecentDocsNetHood"=0 (0x0)
"NoUserNameInStartMenu"=0 (0x0)
"NoInstrumentation"=0 (0x0)
"NoStartMenuPinnedList"=0 (0x0)
"ForceStartMenuLogoff"=0 (0x0)
"NoSharedDocuments"=01000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Programy\Ochrana\AntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Programy\Ochrana\AntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 D:\Programy\Ochrana\AntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^prodigy^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
path=C:\Documents and Settings\prodigy\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
"C:\Program Files\ATI Multimedia\main\LaunchPd.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
mHotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"D:\Programy\Deamon Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
D:\Programy\Nero 7\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Antispyware]
C:\DOCUME~1\prodigy\LOCALS~1\Temp\3.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
D:\Programy\Power DVD 5\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
"D:\Programy\SE PC Suite\Application Launcher\Application Launcher.exe" /startoptions

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
D:\Programy\Ochrana\AntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LightScribeService"=2 (0x2)
"InCDsrv"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"DCPFLICS"=2 (0x2)

R2 Dnscache;Klient DNS;C:\WINDOWS\System32\svchost.exe -k NetworkService
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\System32\DRIVERS\AN983.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\System32\DRIVERS\psched.sys
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM);C:\WINDOWS\System32\DRIVERS\zebrceb.sys
S0 blwgvjgf;blwgvjgf;C:\WINDOWS\System32\drivers\hltfjvhg.sys
S3 ATICDSDr;ATICDSDr;\??\C:\DOCUME~1\prodigy\LOCALS~1\Temp\ATICDSDr.sys
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\System32\DRIVERS\k510bus.sys
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\System32\DRIVERS\k510mdfl.sys
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\System32\DRIVERS\k510mdm.sys
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\System32\DRIVERS\k510mgmt.sys
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\System32\DRIVERS\k510obex.sys
S3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\System32\PavSRK.sys
S3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\System32\PavTPK.sys
S3 wampapache;wampapache;"D:\Programy\wamp\apache2\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;D:\Programy\wamp\mysql\bin\mysqld-nt.exe --defaults-file=D:\Programy\wamp\mysql\my.ini wampmysqld

.
Contents of the 'Scheduled Tasks' folder
"2007-10-31 09:21:15 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1186647607.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-10 22:01:28
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-10 22:03:17
.
--- E O F ---
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

tu je z hijacku a o chvilu tu dam aj ten avenger

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:07:04, on 10.11.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
D:\Programy\AVGANT~1\avgamsvr.exe
D:\Programy\AVGANT~1\avgupsvc.exe
D:\Programy\AVGANT~1\avgemc.exe
D:\Programy\Ochrana\Comodo\Firewall\cmdagent.exe
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\atiptaxx.exe
D:\Programy\3dsmax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\System32\locator.exe
D:\Programy\Ochrana\Spyware Doctor\sdhelp.exe
D:\Programy\AVGANT~1\avgcc.exe
D:\Programy\Ochrana\Comodo\Firewall\CPF.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Programy\ICQ\ICQ6\ICQ.exe
D:\Programy\Ochrana\Spyware Doctor\swdoctor.exe
D:\Programy\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\tlntsvr.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\explorer.exe
D:\Programy\Opera\Opera.exe
D:\Programy\Hijack\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
D:\Programy\Ochrana\avenger.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\Programy\Ochrana\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\Programy\Ochrana\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\Programy\AVGANT~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Programy\Ochrana\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "D:\Programy\ICQ\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Programy\Ochrana\Spyware Doctor\swdoctor.exe" /Q
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\Programy\AVGANT~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\HP Instant Support DI\bin\matcli.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\Programy\Ochrana\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programy\MSOFFI~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programy\ICQ\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programy\ICQ\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CE40C3F1-3DF5-4461-A521-810923235628} (JOJ_Explorer_Player Control) - http://www.joj.sk/fileadmin/joj_player/ ... Player.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Programy\Ochrana\AntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\Programy\AVGANT~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\Programy\AVGANT~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\Programy\AVGANT~1\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Programy\Ochrana\Comodo\Firewall\cmdagent.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - D:\Programy\3dsmax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Programy\Ochrana\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Programy\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: wampapache - Apache Software Foundation - D:\Programy\wamp\apache2\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - D:\Programy\wamp\mysql\bin\mysqld-nt.exe

--
End of file - 7288 bytes
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

opat sa stalo to s plochou...avenger vytvoril subot txt ale ten bol prazdny...mam uz cd s winxp sp2 takze ked si zalohujem veci tak asi preinstalujem windows...ale cital som niekde ze po preinstalovani na sp2 mali problemy so spustanim internetu...
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

Avenger nechajte avengerom a urobte nasledovne :

Oznacte (povolte) zobrazenie skrytych suborov: V priecinkuNASTROJE --> MOZNOSTI PRIECINKA --> ZOBRAZENIE --> ZOBRAZIT SKRYTE SUBORY A PRIECINKY.

Na plochu vlozte novy textovy dokument hladam.txt Do neho vlozte tento text :
cd\
dir "c:\Program Files" >> mam.txt
echo ------------------>> mam.txt
dir "C:\Program Files\Video Add-on" >> mam.txt
echo ------------------>> mam.txt
notepad mam.txt
Dajtete ho ulozit ako , ounacte vsechny programy a ulozte ho pod nazvom hladam.bat Na subor poklikajte a log sem skopirujte .

Ak nepouzivate Megaupload toolbar , google toolbar a Yahoo toolbar , tak ich odinstalujte.
Naposledy upravil(a) BUBINO dne sob 10. lis 2007, 22:39, celkem upraveno 1 x.
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

Svazek v jednotce C nemá žádnou jmenovku.
Sériové číslo svazku je 7418-B782.

Výpis adresáře c:\Program Files

10.11.2007 20:26 <DIR> .
10.11.2007 20:26 <DIR> ..
30.10.2007 09:55 <DIR> Adobe
08.08.2007 10:09 <DIR> ATI
07.08.2007 15:45 <DIR> ATI Multimedia
07.08.2007 15:47 <DIR> ATI Technologies
27.10.2007 14:57 <DIR> Autodesk
07.08.2007 16:18 <DIR> Avance Sound Manager
07.08.2007 16:18 <DIR> AvRack
01.10.2007 18:19 <DIR> Best of My WaterWorks
01.11.2007 14:21 <DIR> Common Files
07.08.2007 15:31 <DIR> ComPlus Applications
02.09.2007 12:14 <DIR> CyberLink
01.11.2007 14:27 <DIR> DCPFLICS
09.10.2007 09:58 <DIR> Google
17.10.2007 14:19 <DIR> Grisoft
09.08.2007 09:14 <DIR> Hewlett-Packard
09.11.2007 17:25 <DIR> HP Travel Idea CD
09.11.2007 17:25 <DIR> ICQToolbar
20.08.2007 09:02 <DIR> Internet Explorer
09.08.2007 15:41 <DIR> Media Player Classic
10.10.2007 16:12 <DIR> MegauploadToolbar
07.08.2007 15:30 <DIR> Messenger
07.08.2007 15:35 <DIR> microsoft frontpage
10.08.2007 17:51 <DIR> Microsoft SQL Server
02.09.2007 12:29 <DIR> Microsoft.NET
07.08.2007 15:33 <DIR> Movie Maker
07.08.2007 15:30 <DIR> MSN
07.08.2007 15:30 <DIR> MSN Gaming Zone
07.08.2007 15:32 <DIR> NetMeeting
07.08.2007 15:33 <DIR> Online Services
07.08.2007 15:32 <DIR> Outlook Express
02.09.2007 12:36 <DIR> psconvert
06.11.2007 18:29 <DIR> ReadIris
14.09.2007 18:26 <DIR> ROUTE66
22.08.2007 09:43 <DIR> SEMC
02.09.2007 12:35 <DIR> Teslain Crypto
06.10.2007 17:05 <DIR> TV JOJ Media Player
09.11.2007 17:25 <DIR> Video Add-on
25.08.2007 12:56 <DIR> Vstplugins
09.11.2007 17:25 <DIR> Windows Media Player
07.08.2007 15:30 <DIR> Windows NT
07.08.2007 15:35 <DIR> xerox
10.11.2007 20:26 <DIR> Yahoo!
0 souborů, 0 bajtů
Adresářů: 44, Volných bajtů: 4 054 102 016
------------------
Svazek v jednotce C nemá žádnou jmenovku.
Sériové číslo svazku je 7418-B782.

Výpis adresáře C:\Program Files\Video Add-on

09.11.2007 17:25 <DIR> .
09.11.2007 17:25 <DIR> ..
18.10.2007 15:04 4 286 ot.ico
18.10.2007 15:04 4 286 ts.ico
18.10.2007 15:04 37 292 uninst.exe
3 souborů, 45 864 bajtů
Adresářů: 2, Volných bajtů: 4 054 102 016
------------------
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

ale ten video addon ide normalne vymazat...respektive odinstalovat
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

Zmaste ho , je to trojan.
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

zmazal som ho...v LocalSetting/Temp mam viac suborov ktore mi vyhadzuje AVG a viry...takto vyzeraju a nejdu zmazat
Obrázek
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

Otestuje ich na virustotal a podajte mi presnu cestu
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

C:\Documents and Settings\prodigy\Local Settings\Temp
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

tie subory este testujem...prvy je v pohode...a ake viry mam este v pc?
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

V logu nic nevidno . Vypada to cisto . Ak mate v C:\ zlozky avenger a combogix , tak ich zmazte a vysipte kos .
fonseka
Nováček
Nováček
Registrován: 09. lis 2007

Příspěvek od fonseka »

ok...vrela vdaka za pomoc...
BUBINO
Začátečník
Začátečník
Registrován: 12. čer 2007
Bydliště: Mám

Příspěvek od BUBINO »

Rado sa stalo . Aj na buduce :-) :wink:
Odpovědět

Zpět na „Viry, antiviry a bezpečnost“