Rkill:
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 01/17/2014 01:53:06 PM in x86 mode.
Windows Version: Windows 7 Ultimate
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 01/17/2014 01:53:32 PM
Execution time: 0 hours(s), 0 minute(s), and 26 seconds(s)
CF:
ComboFix 14-01-16.03 - Do iT 17.01.2014 13:55:26.5.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3037.1921 [GMT 1:00]
Spuštěný z: e:\users\Do iT\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
e:\program files\Internet Explorer\dmlconf.dat
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-17 do 2014-01-17 )))))))))))))))))))))))))))))))
.
.
2014-01-17 12:59 . 2014-01-17 12:59 -------- d-----w- e:\users\Default\AppData\Local\temp
2014-01-15 17:14 . 2014-01-16 14:08 108544 ------w- e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ftvbpxtt.exe
2014-01-14 19:45 . 2014-01-16 14:03 -------- d-----w- e:\program files\trend micro
2014-01-14 15:48 . 2014-01-14 15:48 -------- d-----w- e:\users\Do iT\AppData\Roaming\Malwarebytes
2014-01-14 15:48 . 2014-01-14 15:48 -------- d-----w- e:\programdata\Malwarebytes
2014-01-13 16:56 . 2014-01-13 17:07 -------- d-----w- e:\users\Do iT\AppData\Roaming\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\program files\Audacity
2014-01-13 16:56 . 2014-01-13 16:56 -------- d-----w- e:\users\Do iT\AppData\Local\Programs
2014-01-13 16:55 . 2014-01-13 16:55 -------- d-----w- e:\users\Do iT\AppData\Roaming\rmi
2013-12-22 08:22 . 2014-01-15 15:45 -------- d-----w- e:\users\Do iT\AppData\Roaming\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----w- e:\program files\Common Files\Skype
2013-12-22 08:21 . 2013-12-22 08:21 -------- d-----r- e:\program files\Skype
2013-12-22 08:21 . 2013-12-22 08:22 -------- d-----w- e:\programdata\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-25 17:27 . 2013-11-25 17:27 119808 ----a-r- e:\users\Do iT\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2013-11-18 00:28 . 2013-11-25 17:15 7772552 ----a-w- e:\programdata\Microsoft\Windows Defender\Definition Updates\{92829D96-68DD-41B5-92B5-7A5F2A843F1B}\mpengine.dll
2013-11-11 04:50 . 2013-11-25 17:14 230048 ------w- e:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"="e:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"Infium"="e:\program files\QIP 2012\qip.exe" [2013-01-10 8378408]
.
e:\users\Do iT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ftvbpxtt.exe [2014-1-16 108544]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - e:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
R2 SkypeUpdate;Skype Updater;e:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 CFcatchme;CFcatchme;e:\users\DOIT~1\AppData\Local\Temp\CFcatchme.sys [x]
R3 mvusbews;USB EWS Device;e:\windows\system32\Drivers\mvusbews.sys [2012-08-21 17408]
S2 HPSIService;HP SI Service;e:\windows\system32\HPSIsvc.exe [2012-08-31 100256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-16 08:59 1211672 ----a-w- e:\program files\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
.
Celkový čas: 2014-01-17 14:00:32
ComboFix-quarantined-files.txt 2014-01-17 13:00
.
Před spuštěním: Volných bajtů: 234 061 512 704
Po spuštění: Volných bajtů: 233 973 329 920
.
- - End Of File - - 96162D4EFEB06EB5CF0413476B2DC4E5
A36C5E4F47E84449FF07ED3517B43A31