Tady je log z ComboFixu
ComboFix 10-05-20.A4 - LEO 21.05.2010 20:51:31.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1535.962 [GMT 2:00]
Spuštěný z: c:\documents and settings\LEO\Plocha\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LEO\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\LEO\Recent\Thumbs.db
c:\windows\Fonts\mlog
c:\windows\system32\_id.dat
c:\windows\system32\FInstall.sys
c:\windows\system32\Install.txt
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BTWSRV
-------\Service_BtwSrv
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-21 do 2010-05-21 )))))))))))))))))))))))))))))))
.
2010-05-21 17:16 . 2010-05-21 17:16 -------- d-----w- C:\_OTL
2010-05-21 17:05 . 2010-05-21 17:05 -------- d-----w- c:\documents and settings\All Users\Plocha
2010-05-21 16:10 . 2010-05-21 16:10 -------- d-----w- c:\program files\trend micro
2010-05-19 17:10 . 2004-03-16 06:35 49152 ----a-w- c:\windows\system32\OctaneARM.dll
2010-05-19 17:10 . 2010-05-19 17:12 -------- d-----w- c:\program files\eDATA Unerase
2010-05-19 16:28 . 2010-05-19 16:28 -------- d-----w- c:\windows\system32\wbem\Repository
2010-05-19 14:22 . 2010-05-19 15:16 -------- d-----w- c:\program files\HyperSnap 6
2010-05-17 08:37 . 2010-05-17 08:37 -------- d-----w- c:\program files\HDD Capacity Restore
2010-05-17 08:37 . 2007-04-12 19:02 5248 ----a-w- c:\windows\system32\affhdd.sys
2010-05-17 08:13 . 2010-05-17 16:19 -------- d-----w- c:\program files\Common Files\Acronis
2010-05-17 01:45 . 2010-05-17 01:45 -------- d-----w- c:\program files\HDDGURU LLF Tool
2010-05-17 00:58 . 2010-05-17 00:58 -------- d-----w- c:\program files\Western Digital Corporation
2010-05-17 00:02 . 2010-05-17 16:20 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-05-17 00:02 . 2010-05-17 16:20 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-05-17 00:02 . 2010-05-17 16:19 132480 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-05-17 00:01 . 2010-05-17 16:19 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2010-05-17 00:01 . 2010-05-17 08:14 -------- d-----w- c:\program files\Acronis
2010-05-16 16:42 . 2010-05-19 11:29 1885464 ----a-w- c:\windows\system32\AutoPartNt.exe
2010-05-16 12:13 . 2010-05-16 12:13 911680 ----a-w- c:\windows\system32\drivers\tdrpm258.sys
2010-05-14 14:26 . 2010-05-14 14:26 -------- d-----w- C:\$AVG
2010-05-10 17:12 . 2010-05-10 17:12 -------- d-----w- c:\program files\Saxo Bank
2010-05-08 11:00 . 2010-05-08 11:00 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-05-08 10:59 . 2010-05-08 10:59 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-05-08 10:59 . 2010-05-08 10:59 -------- d-----w- c:\documents and settings\All Users\Microsoft
2010-05-02 00:28 . 2010-05-02 00:28 -------- d-----w- C:\fc96e1c42e650b1f1d2f8a354e
2010-05-01 23:52 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-05-01 23:42 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-05-01 23:42 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-05-01 23:42 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-05-01 23:42 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-05-01 23:42 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-05-01 23:42 . 2010-05-01 23:42 -------- d-----w- C:\0a38966b82518c2c2db9c7
2010-05-01 21:34 . 2010-05-01 21:34 -------- d-----w- c:\program files\ViaVoiceTTS
2010-05-01 21:34 . 2010-05-01 21:34 -------- d-----w- c:\windows\lhsp
2010-05-01 21:33 . 2010-05-01 21:33 -------- d-----w- c:\windows\speech
2010-05-01 21:31 . 2010-05-01 21:31 -------- d-----w- c:\program files\Magnus
2010-04-29 07:58 . 2010-04-03 15:25 112056 ----a-w- c:\windows\system32\acaptuser32.dll
2010-04-28 22:01 . 2010-04-28 22:02 -------- d-----w- c:\program files\MT4 at easy-forex
2010-04-28 20:00 . 2010-04-28 20:00 -------- d-----w- c:\program files\Easy-Forex
2010-04-28 15:27 . 2010-04-28 15:27 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-21 18:58 . 2006-02-26 23:31 12 ----a-w- c:\windows\bthservsdp.dat
2010-05-20 11:58 . 2004-06-13 19:11 -------- d-----w- c:\program files\CDVPlayer
2010-05-20 11:56 . 2008-07-07 09:16 -------- d-----w- c:\program files\Brother's Keeper 6
2010-05-20 11:50 . 2009-06-08 08:57 -------- d-----w- c:\program files\BDE5Setup
2010-05-20 11:49 . 2003-06-19 07:27 -------- d-----w- c:\program files\AvRack
2010-05-20 11:48 . 2004-10-29 20:04 -------- d-----w- c:\program files\ASUS
2010-05-20 11:46 . 2007-11-24 20:20 -------- d-----w- c:\program files\Allok MPEG4 Converter
2010-05-17 00:51 . 2006-05-10 10:46 -------- d-----w- c:\program files\Google
2010-05-16 21:54 . 2009-01-14 13:23 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-05-05 07:31 . 2009-10-17 15:43 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 07:31 . 2009-10-17 15:43 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-02 00:27 . 1979-12-31 22:00 547106 ----a-w- c:\windows\system32\perfh005.dat
2010-05-02 00:27 . 1979-12-31 22:00 126070 ----a-w- c:\windows\system32\perfc005.dat
2010-04-19 22:02 . 2010-04-19 22:02 -------- d-----w- c:\program files\A-PDF Restrictions Remover
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-07 17:20 . 2010-04-07 17:20 -------- d-----w- c:\program files\TuneUpMedia
2010-04-07 16:56 . 2010-04-07 16:56 -------- d-----w- c:\program files\MediaCoder
2010-03-31 15:45 . 2010-03-31 15:45 -------- d-----w- c:\program files\iTunes
2010-03-31 15:38 . 2010-03-31 15:38 -------- d-----w- c:\program files\QuickTime
2010-03-30 19:19 . 2010-03-30 19:19 -------- d-----w- c:\program files\PartyGaming
2010-03-26 07:28 . 2010-03-26 07:28 -------- d-----w- c:\program files\ICQ7.1
2010-03-10 06:17 . 2002-09-23 10:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:18 . 2002-09-23 10:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-09-23 10:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-10-17 15:57 . 2009-10-17 15:49 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2010-02-28 00:20 561552 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-12 68856]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-03-26 133368]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SoundMan"="SOUNDMAN.EXE" [2010-02-10 46592]
"ATIModeChange"="Ati2mdxx.exe" [2003-03-20 28672]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2002-11-18 561152]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 315392]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2002-11-15 126976]
"QtZwLMng"="c:\program files\QBU\QtZwLMng.EXE" [2003-04-03 196608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-06-10 1326080]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-06-10 904840]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-06-10 136472]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2002-09-23 40960]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 77824]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 126976]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2003-10-5 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\program files\Symantec\WinFax\WfxSeh32.Dll" [1998-07-27 38400]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\dplaysvr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\TOTALCMD\\TOTALCMD.EXE"=
"c:\\Program Files\\PSPad\\PSPad.exe"=
"c:\\Program Files\\LCS International\\Helios IQ\\Helios.EXE"=
"c:\\Program Files\\Kodak Photo Voice\\Kodak Photo Voice.exe"=
"c:\\Program Files\\Huawei technologies\\Huawei E620 Data Card\\HUAWEI 3G Data Card.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"\\\\7f8b5e7a9bfa4c9\\C\\LCS International\\Helios IQ\\Helios.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Virtual Volumes\\vv_cmd.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15.12.2008 20:41 33808]
R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs_x32.sys [26.9.2009 22:31 146904]
R1 Ext2fs;Ext2fs;c:\windows\system32\drivers\ext2fs.sys [7.9.2009 21:00 181120]
R1 IfsMount;IfsMount;c:\windows\system32\drivers\ifsmount.sys [7.9.2009 21:00 51072]
R2 CommSBEP;CommSBEP;c:\windows\system32\drivers\COMMSBEP.sys [25.7.2006 15:56 36864]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [16.3.2009 11:24 222456]
R2 MSSQL$BANKKLIENT;SQL Server (BANKKLIENT);c:\program files\bkwin\MSSQL.1\MSSQL\Binn\sqlservr.exe [27.5.2009 3:27 29262680]
R3 AVMWAN;AVM NDIS WAN CAPI Driver;c:\windows\system32\drivers\avmwan.sys [10.2.2010 12:40 37568]
R3 FXPCBASE;ISDN@2lines (WinXP/2000);c:\windows\system32\drivers\fxpcbase.sys [4.9.2004 11:31 523248]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13.5.2009 17:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16.5.2009 20:59 19472]
S0 IFP900;iriver Internet Audio Player IFP-900;c:\windows\system32\drivers\IFP900.sys --> c:\windows\system32\drivers\IFP900.sys [?]
S2 gupdate1c9b86caad05c50;Služba Google Update (gupdate1c9b86caad05c50);c:\program files\Google\Update\GoogleUpdate.exe [8.4.2009 19:08 133104]
S3 gtcdcmdm;GTRAN USB CDC Driver (PID 3196);c:\windows\system32\DRIVERS\gtusbmdm_gpc6400.sys --> c:\windows\system32\DRIVERS\gtusbmdm_gpc6400.sys [?]
S3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [19.9.2006 17:05 65152]
S3 hwusbapp;HUAWEI Mobile Connect - 3G PC UI Interface;c:\windows\system32\drivers\ewusbapp.sys [19.9.2006 17:05 65152]
S3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [19.9.2006 17:05 65152]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 21:37 4640000]
S3 siusbmod;siusbmod;c:\windows\system32\DRIVERS\siusbmod.sys --> c:\windows\system32\DRIVERS\siusbmod.sys [?]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [3.1.2010 22:56 23600]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##7f8b5e7a9bfa4c9#FLASHDISK]
\Shell\AutoRun\command - Y:\setupSNK.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-05-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]
2010-05-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-15 17:07]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 17:08]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 17:08]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://neviditelnypes.zpravy.cz/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: {4ADC518E-B607-11D4-B395-0001020F4519} - hxxps://portal.ozp.cz/obj/Signer.cab
DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} - hxxps://
www.mojedatovaschranka.cz/static/pages/ ... b?3,14,8,0
DPF: {CF2BD3ED-F1CE-11D4-9B98-005004CA7085} - hxxps://portalp.cpzp.cz/dll/SignForm.dll
.
.
------- Asociace souborů -------
.
txtfile=%windir%\NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Borland Database Engine Setup - c:\progra~1\BDE5SE~1\UNWISE.EXE
AddRemove-EPSON Printer and Utilities - c:\windows\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE
AddRemove-HijackThis - c:\documents and settings\LEO\Plocha\hijackthis\HijackThis.exe
AddRemove-LiveAdvisor - c:\program files\Common Files\Symantec Shared\LiveAdvisor\VcSetup.exe
AddRemove-MediaNavigation.CDLabelPrint - c:\program files\Canon\CD-LabelPrint\Uninstal.exe
AddRemove-MiraplacidPublisher4 - c:\program files\Miraplacid Publisher 4.1\install\setup.exe
AddRemove-PacketVideo pvAuthor SDK - c:\progra~1\PACKET~1\TOOLKITS\PVAUTHOR\UNWISE.EXE
AddRemove-TopStyle (Version 3) - c:\progra~1\BRADBURY\TOPSTY~1\UNWISE.EXE
AddRemove-XviDDec - c:\windows\System32\UninstXviDDec.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-21 21:08
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\windows\TEMP\cch2A.tmp 32768 bytes
c:\windows\TEMP\cch2B.tmp 32768 bytes
sken byl úspešně dokončen
skryté soubory: 2
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,4b,0c,d1,b2,78,c7,4e,a0,c2,96,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,4b,0c,d1,b2,78,c7,4e,a0,c2,96,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(1724)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(3320)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\WFXSVC.EXE
c:\program files\Symantec\WinFax\WFXMOD32.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-05-21 21:14:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-05-21 19:14
ComboFix2.txt 2009-08-25 15:13
Před spuštěním: Volných bajtů: 14 412 656 640
Po spuštění: Volných bajtů: 14 396 485 632
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 0BDD431155C7ECE0DBC8AF119EC438D5