vir -system32.trojan.BHO

Problematika virů a antivirů, zabezpečení PC - firewall, spyware, atd.
Odpovědět
mirgir
Nováček
Nováček
Registrován: 11. črc 2008

vir -system32.trojan.BHO

Příspěvek od mirgir »

Může mi někdo poradit? Avast hlásí torjského koně ale odstranit nejde. Nemůžu odesílat e-maily ale neustále to něco odesílá, PC je pomalý a kouše se. Přidávám log z hijaktisu. Dík. Mirek
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:00:04, on 11.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Josef\Plocha\SPC\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: myiebho - {CAEF67AA-2E7F-444C-A7D6-E552DEF460DE} - C:\WINDOWS\SYSTEM32\TWAIN16.dll
O4 - HKLM\..\Run: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe
O4 - HKLM\..\RunServices: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe
O4 - HKLM\..\RunServicesOnce: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] C:\WINDOWS\SYSTEM32\twunk_16.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [MS Windows State Monitor] C:\WINDOWS\SYSTEM32\twunk_16.exe (User 'Default user')
O4 - S-1-5-18 User Startup: twunk_16.exe (User 'SYSTEM')
O4 - .DEFAULT User Startup: twunk_16.exe (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: TWAIN16.dll
O20 - Winlogon Notify: winrzf32 - winrzf32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 4713 bytes
hypnotic666
Mírně pokročilý
Mírně pokročilý
Uživatelský avatar
Registrován: 15. kvě 2006
Bydliště: Praha

Příspěvek od hypnotic666 »

PC: Intel i7-7700K | ASUS PRIME Z270-K | Kingston 16GB KIT DDR4 2400MHz CL15 HyperX Fury Black Series | MSI GTX 1070 GAMING X 8G | Corsair RM650x | AOC 24", 144Hz | Windows 10 64bit

Arguing on the Internet is like running at the Olympic Games for mentally challenged.Even if you win, you stay retarded.
Odpovědět

Zpět na „Viry, antiviry a bezpečnost“