Malwarebytes mi našel root kit gyqdeaip.sys, který nejde odstranit, prosím o pomoc s tímto neřádem..
Předem děkuju.
ComboFix 10-04-28.08 - merlp 29.04.2010 16:43:21.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.1306 [GMT 2:00]
Spuštěný z: d:\!!!!!!!!! martinova slozka !!!!!!!!!!!!!!\PROGRAMY !!\!! ničitel Trojáků a virů\ComboFix.exe
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-220523388-1644491937-839522115-1003
c:\users\merlp\AppData\Local\Microsoft\Windows\Temporary Internet Files\-hyFBlFlU3b-hl
c:\users\merlp\AppData\Local\Microsoft\Windows\Temporary Internet Files\8aU4koGz_RXxcf
c:\users\merlp\AppData\Local\Microsoft\Windows\Temporary Internet Files\AJ1w9EC5_
c:\windows\system32\%appdata%
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-28 do 2010-04-29 )))))))))))))))))))))))))))))))
.
2010-04-29 14:31 . 2009-12-11 07:38 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-29 14:31 . 2009-12-11 07:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-27 13:59 . 2010-04-27 13:59 -------- d-----w- c:\program files\Imagenomic
2010-04-27 13:01 . 2010-04-27 13:01 -------- d-----w- c:\windows\MSSecurityNS
2010-04-27 13:01 . 2010-04-27 13:01 -------- d-----w- c:\windows\MSSecurityNi
2010-04-23 19:18 . 2010-04-23 19:18 -------- d-----w- c:\users\merlp\AppData\Roaming\Malwarebytes
2010-04-23 19:16 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-23 19:16 . 2010-04-23 19:16 -------- d-----w- c:\programdata\Malwarebytes
2010-04-23 19:16 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 19:16 . 2010-04-23 19:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-23 18:53 . 2010-01-10 17:40 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-04-23 12:34 . 2010-04-23 12:34 -------- d-----w- c:\windows\Sun
2010-04-23 12:32 . 2010-04-23 12:38 -------- d-----w- c:\program files\Common Files\Java
2010-04-23 12:32 . 2010-04-23 12:32 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-23 12:32 . 2010-04-23 12:39 -------- d-----w- c:\program files\Java
2010-04-21 18:40 . 1998-06-17 22:00 102912 ----a-w- c:\windows\system32\Vb6stkit.dll
2010-04-21 18:40 . 1997-02-24 15:44 70656 ----a-w- c:\windows\system32\vspell32.dll
2010-04-21 18:40 . 1998-11-22 12:23 84992 ----a-w- c:\windows\system32\Ledit32.dll
2010-04-21 18:40 . 2008-09-12 12:55 1245184 ----a-w- c:\windows\system32\ChilkatCert.dll
2010-04-21 18:40 . 2008-09-12 12:50 1105920 ----a-w- c:\windows\system32\ChilkatFtp2.dll
2010-04-21 14:42 . 2010-04-21 14:42 -------- d-----w- c:\program files\Advanced Port Scanner
2010-04-20 16:01 . 2010-04-20 16:02 -------- d-----w- c:\programdata\Sticky Notes TB Hider
2010-04-20 16:01 . 2010-04-20 16:01 -------- d-----w- c:\program files\StickyNotes
2010-04-20 15:37 . 2010-04-20 15:37 53319 ----a-w- c:\programdata\TEMP\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2010-04-20 15:04 . 2010-04-20 15:04 -------- d-----w- c:\users\merlp\AppData\Local\PowerDVDCox
2010-04-20 15:04 . 2010-04-20 15:04 -------- d-----w- c:\users\merlp\AppData\Local\PowerDVDCinema
2010-04-20 15:04 . 2010-04-20 15:04 -------- d-----w- c:\users\Public\CyberLink
2010-04-20 15:04 . 2010-04-20 15:04 -------- d-----w- c:\programdata\CyberLink
2010-04-20 15:02 . 2010-04-20 15:12 53319 ----a-w- c:\programdata\TEMP\{2B55AF83-017A-4C81-9324-D9D3255642A6}\PostBuild.exe
2010-04-20 14:59 . 2010-04-20 15:13 -------- d-----w- c:\program files\InstallShield Installation Information
2010-04-20 14:59 . 2010-04-20 14:59 -------- d-----w- c:\program files\Common Files\CyberLink
2010-04-20 14:58 . 2010-04-20 14:58 -------- d-----w- c:\program files\CyberLink
2010-04-20 14:58 . 2010-04-20 15:12 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-04-20 14:58 . 2010-04-20 15:12 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-20 14:58 . 2010-04-20 15:12 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-04-20 14:58 . 2010-04-20 14:57 53319 ----a-w- c:\programdata\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2010-04-19 11:13 . 2010-04-19 11:13 -------- d-----w- c:\users\merlp\AppData\Local\PunkBuster
2010-04-19 11:12 . 2010-04-21 12:30 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-19 11:12 . 2010-04-19 11:12 138056 ----a-w- c:\users\merlp\AppData\Roaming\PnkBstrK.sys
2010-04-19 11:11 . 2010-04-21 12:30 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-04-19 11:11 . 2010-04-19 11:11 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-04-19 11:11 . 2010-04-19 11:11 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-04-19 10:37 . 2010-04-19 10:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-04-19 10:00 . 2010-04-19 11:55 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-04-16 19:35 . 2010-04-16 19:35 -------- d-----w- C:\Local Publish
2010-04-16 19:25 . 2010-04-16 19:24 737280 ----a-w- c:\windows\iun6002.exe
2010-04-16 19:24 . 2010-04-19 11:55 -------- d-----w- c:\program files\WYSIWYG Web Builder 6
2010-04-16 18:11 . 2010-04-19 11:55 -------- d-----w- c:\users\merlp\AppData\Local\Totalidea_Software
2010-04-16 18:10 . 2010-04-19 11:55 -------- d-----w- c:\windows\Tweak-7
2010-04-16 18:10 . 2010-04-19 11:55 -------- d-----w- c:\program files\Tweak-7
2010-04-16 18:08 . 2010-04-19 11:55 -------- d-----w- c:\program files\Změna MAC adresy
2010-04-13 19:08 . 2010-04-19 11:47 -------- d-----w- c:\users\merlp\AppData\Roaming\Tweak-7
2010-04-13 18:54 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-13 18:54 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-04-13 18:29 . 2010-02-27 12:07 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-13 18:29 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-04-13 18:29 . 2010-02-27 12:07 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-13 18:29 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-13 18:29 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 18:29 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-13 17:34 . 2010-04-13 17:34 -------- d-----w- c:\programdata\Adobe Systems
2010-04-13 17:28 . 2010-04-13 17:28 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-04-13 13:29 . 2010-04-13 13:29 -------- d-----w- c:\program files\Xvid
2010-04-13 13:28 . 2010-04-13 13:28 -------- d-----w- c:\program files\VDGPRS Client NetMeter
2010-04-13 13:28 . 2010-04-13 13:28 -------- d-----w- c:\program files\VDGPRS NetMeter
2010-04-13 13:28 . 2001-08-31 10:00 24626 ----a-w- c:\windows\system32\ScrrnIT.dll
2010-04-13 13:28 . 2010-04-13 13:28 -------- d-----w- c:\program files\VDGPRS Client Manager
2010-04-13 13:27 . 2010-04-13 13:29 -------- d-----w- c:\program files\VDGPRS CLIENT 2°
2010-04-10 15:48 . 2010-04-10 15:48 714752 ----a-w- c:\windows\is-MADLI.exe
2010-04-10 15:48 . 2009-08-24 19:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2010-04-10 15:46 . 2009-01-09 09:46 39776 ----a-w- c:\windows\system32\DfSdkBt64.exe
2010-04-10 15:46 . 2010-04-24 06:18 -------- d-----w- c:\program files\Ashampoo WinOptimizer 6
2010-04-10 15:44 . 2010-04-10 15:44 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-04-10 15:44 . 2010-04-20 18:34 -------- d-----w- c:\program files\Hewlett-Packard
2010-04-10 08:31 . 2010-04-10 08:31 -------- d-----w- c:\program files\Common Files\Borland Shared
2010-04-10 08:31 . 2010-04-10 08:31 -------- d-----w- C:\Avaris
2010-04-10 08:31 . 1999-03-23 07:12 299520 ----a-w- c:\windows\uninst.exe
2010-04-10 08:29 . 2010-04-10 08:29 -------- d-----w- c:\users\merlp\AppData\Roaming\TrueCrypt
2010-04-09 16:21 . 2010-04-09 16:21 -------- d-----w- c:\program files\ESET
2010-04-09 16:18 . 2010-04-13 17:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-09 15:51 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-04-09 15:51 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-04-09 15:51 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
2010-04-09 15:51 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-04-09 15:51 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-04-09 15:51 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-04-09 15:51 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-04-09 15:51 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-04-09 15:51 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-04-09 15:51 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-04-09 15:51 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-04-09 15:02 . 2010-04-19 14:22 -------- d-----w- c:\program files\Classic Menu for Office
2010-04-09 15:01 . 2010-04-09 15:01 -------- d-----w- c:\program files\MSECache
2010-04-09 15:00 . 2010-04-09 15:00 -------- d-----w- c:\windows\PCHEALTH
2010-04-09 15:00 . 2010-04-09 15:00 -------- d-----w- c:\program files\Microsoft.NET
2010-04-09 14:59 . 2010-04-09 14:59 -------- d-----w- c:\users\merlp\AppData\Local\Microsoft Help
2010-04-09 14:59 . 2010-04-09 15:01 -------- d-----w- c:\programdata\Microsoft Help
2010-04-09 14:57 . 2010-04-09 14:57 -------- d-----r- C:\MSOCache
2010-04-09 14:36 . 2010-04-09 14:36 4 ----a-w- c:\program files\1522086.dat
2010-04-09 14:22 . 2010-04-09 14:22 -------- d-----w- c:\users\merlp\AppData\Roaming\Nero
2010-04-09 14:09 . 2010-04-09 14:09 -------- d-----w- c:\programdata\Nero
2010-04-09 14:09 . 2010-04-09 14:09 -------- d-----w- c:\program files\Common Files\Nero
2010-04-09 14:09 . 2010-04-09 14:09 -------- d-----w- c:\program files\Nero
2010-04-09 13:51 . 2010-04-09 13:51 53248 ----a-w- c:\users\merlp\AppData\Roaming\Thinstall\Microsoft Office Enterprise 2007\300000005700002h\WINWORD.EXE
2010-04-09 13:44 . 2010-04-20 14:52 -------- d-----w- c:\program files\AusLogics Registry Defrag
2010-04-09 13:43 . 2010-04-09 13:43 -------- d-----w- c:\program files\PoiEdit2007
2010-04-09 13:43 . 2010-04-09 13:43 -------- d-----w- c:\program files\TomTom HOME 2
2010-04-09 13:42 . 2010-04-09 13:42 -------- d-----w- c:\program files\Regino v5.0
2010-04-09 13:42 . 2010-04-09 13:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-09 13:41 . 2010-04-09 13:41 -------- d-----w- c:\program files\ConvertX
2010-04-09 13:41 . 2010-04-09 13:41 -------- d-----w- c:\program files\DVD Shrink
2010-04-09 13:40 . 2010-04-09 13:40 -------- d-----w- c:\program files\MP3Gain
2010-04-09 12:56 . 2010-04-09 13:51 -------- d-----w- c:\users\merlp\AppData\Roaming\Thinstall
2010-04-09 12:56 . 2010-04-09 12:56 -------- d-----w- c:\users\merlp\AppData\Local\Thinstall
2010-04-09 12:50 . 2010-04-09 12:50 4 ----a-w- c:\program files\513648.dat
2010-04-09 12:49 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-04-09 12:48 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-09 12:45 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-09 12:45 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-04-08 18:46 . 2010-04-29 15:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-08 18:44 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-04-08 18:44 . 2008-04-27 08:35 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-04-08 18:44 . 2008-04-27 08:33 765952 ----a-w- c:\windows\system32\xvidcore.dll
2010-04-08 18:44 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-04-08 18:44 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-29 14:47 . 2009-07-14 08:44 622422 ----a-w- c:\windows\system32\perfh005.dat
2010-04-29 14:47 . 2009-07-14 08:44 118604 ----a-w- c:\windows\system32\perfc005.dat
2010-04-19 11:55 . 2010-04-16 18:08 -------- d-----w- c:\program files\Změna MAC adresy
2010-04-08 18:37 . 2010-04-08 18:37 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\Leadertech
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\Imagenomic
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\DAEMON Tools Lite
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\DAEMON Tools
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\CyberLink
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\CD-LabelPrint
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\Auslogics
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\atitray
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\ATI
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\Ahead
2010-04-08 17:05 . 2010-04-08 17:05 -------- d-----w- c:\users\merlp\AppData\Roaming\AdobeUM
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Plocha
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Oblíbené položky
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Šablony
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Nabídka Start
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Dokumenty
2010-04-08 16:31 . 2010-04-08 16:31 -------- d-sh--we c:\programdata\Data aplikací
2010-03-26 13:48 . 2010-03-26 13:48 91816 ----a-w- c:\windows\system32\Tweak7SystemService.exe
2010-03-04 11:42 . 2010-03-04 11:42 277536 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2010-03-03 04:22 . 2010-03-03 04:22 5340160 ----a-w- c:\windows\system32\drivers\atipmdag.sys
2010-03-03 04:22 . 2010-03-03 04:22 5340160 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-03-03 04:16 . 2010-03-03 04:16 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-03-03 04:16 . 2010-03-03 04:16 446464 ----a-w- c:\windows\system32\aticfx32.dll
2010-03-03 04:13 . 2010-03-03 04:13 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-03-03 04:12 . 2010-03-03 04:12 372736 ----a-w- c:\windows\system32\atieclxx.exe
2010-03-03 04:11 . 2010-03-03 04:11 172032 ----a-w- c:\windows\system32\atiesrxx.exe
2010-03-03 04:10 . 2010-03-03 04:10 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-03-03 04:10 . 2010-03-03 04:10 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-03-03 04:09 . 2010-03-03 04:09 274432 ----a-w- c:\windows\system32\Oemdspif.dll
2010-03-03 04:09 . 2010-03-03 04:09 11776 ----a-w- c:\windows\system32\atimuixx.dll
2010-03-03 04:09 . 2010-03-03 04:09 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-03-03 04:06 . 2010-03-03 04:06 3131392 ----a-w- c:\windows\system32\atidxx32.dll
2010-03-03 03:46 . 2010-03-03 03:46 3703808 ----a-w- c:\windows\system32\atiumdag.dll
2010-03-03 03:45 . 2010-03-03 03:45 14226944 ----a-w- c:\windows\system32\atioglxx.dll
2010-03-03 03:24 . 2010-03-03 03:24 2993152 ----a-w- c:\windows\system32\atiumdva.dll
2010-03-03 03:23 . 2010-03-03 03:23 50176 ----a-w- c:\windows\system32\coinst.dll
2010-03-03 03:20 . 2010-03-03 03:20 53248 ----a-w- c:\windows\system32\aticalrt.dll
2010-03-03 03:20 . 2010-03-03 03:20 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-03-03 03:18 . 2010-03-03 03:18 3657728 ----a-w- c:\windows\system32\aticaldd.dll
2010-03-03 03:08 . 2010-03-03 03:08 52224 ----a-w- c:\windows\system32\atimpc32.dll
2010-03-03 03:08 . 2010-03-03 03:08 52224 ----a-w- c:\windows\system32\amdpcom32.dll
2010-03-03 03:08 . 2010-03-03 03:08 237568 ----a-w- c:\windows\system32\atiadlxx.dll
2010-03-03 03:07 . 2010-03-03 03:07 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-03-03 03:07 . 2010-03-03 03:07 15360 ----a-w- c:\windows\system32\atigktxx.dll
2010-03-03 03:07 . 2010-03-03 03:07 152064 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2010-03-03 03:06 . 2010-03-03 03:06 27648 ----a-w- c:\windows\system32\atiuxpag.dll
2010-03-03 03:06 . 2010-03-03 03:06 20480 ----a-w- c:\windows\system32\atiu9pag.dll
2010-03-03 03:05 . 2010-03-03 03:05 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-25 19:55 . 2010-02-25 19:55 201875 ----a-w- c:\windows\system32\atiicdxx.dat
2010-02-23 16:15 . 2010-02-23 16:15 1105 ----a-w- c:\windows\system32\atipblag.dat
2010-02-23 07:56 . 2010-04-09 12:47 977920 ----a-w- c:\windows\system32\wininet.dll
2010-02-08 17:46 . 2010-02-22 16:51 1695264 ----a-w- c:\windows\system32\RtkPgExt.dll
2010-02-08 17:46 . 2010-02-22 16:51 57376 ----a-w- c:\windows\system32\RtkCoInst.dll
2010-02-08 17:46 . 2010-02-22 16:51 371232 ----a-w- c:\windows\system32\RtkApoApi.dll
2010-02-08 17:46 . 2010-02-22 16:51 2624544 ----a-w- c:\windows\system32\RtkAPO.dll
2010-02-08 17:17 . 2010-02-22 16:51 3019232 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2010-02-03 10:24 . 2009-12-03 08:27 94208 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
Kód: Vybrat vše
<pre>
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI\ATICustomerCare\aticustomercare .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\Common Files\Nero\Lib\nerocheck .exe
c:\program files\Nero\Nero8\Nero BackItUp\nbkeyscan .exe
c:\program files\Realtek\Audio\HDA\rthdvcpl .exe
</pre>
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-08 8505888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
c:\users\merlp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sticky Notes Taskbar Hider.lnk - c:\program files\StickyNotes\SNTBHider.exe [2010-4-20 638976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
R1 zflxsbdwi9;zflxsbdwi9.sys;c:\windows\system32\drivers\zflxsbdwi9.sys [x]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-04-19 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 172032]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-05-14 38240]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-03-29 303952]
S2 Tweak7SystemService;Tweak7SystemService;c:\windows\system32\Tweak7SystemService.exe [2010-03-26 91816]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 5340160]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 152064]
S3 kxwdmdrv;kX WDM Driver Service;c:\windows\system32\drivers\kx.sys [2008-04-05 568320]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-03-29 20824]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - gyqdeaip
.
Obsah adresáře 'Naplánované úlohy'
2010-04-20 c:\windows\Tasks\PDVD9Serv.EXE_20100420_170148_0336.job
- c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-02-16 07:55]
2010-04-20 c:\windows\Tasks\PDVD9Serv.EXE_20100420_171404_0721.job
- c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-02-16 07:55]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x850721F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
SecurityProcedure -> 0x850c26f0
QueryNameProcedure -> 0x850c2880
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\gyqdeaip]
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\DAEMON Tools Lite\DTShellHlp.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2010-04-29 16:52:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-04-29 14:52
Před spuštěním: Volných bajtů: 15 736 967 168
Po spuštění: Volných bajtů: 15 647 850 496
- - End Of File - - C961E9109096A39EAA50D87AB229455E