Prosím o kontrolu logu, Avast stále hlásí rootkit

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Prosím o kontrolu logu, Avast stále hlásí rootkit

#1 Příspěvek od carthman »

Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin at 2010-09-23 14:25:23
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (5%) free of 57 GB
Total RAM: 766 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:26:29, on 23. 9. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe
C:\WINDOWS\system32\DRIVERS\WtSrv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\EDIMAX\Common\RaUI.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Opera75\opera.exe
C:\RSIT.exe
C:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [EPSON Stylus D78 Series (kopie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE /FU "C:\WINDOWS\TEMP\E_SB.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [EPSON Stylus D78 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE /FU "C:\WINDOWS\TEMP\E_S84.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files\EDIMAX\Common\RaUI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webcamera Plus Service - Ateksoft Company Ltd. - C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv.exe

--
End of file - 10049 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1202660629-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1202660629-682003330-1003UA.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\RegCure.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-06-05 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-01-23 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-01-23 126976]
"EPSON Stylus D78 Series (kopie 1)"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE [2006-02-23 131072]
"EPSON Stylus D78 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE [2006-02-23 131072]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2008-06-12 37232]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2008-06-11 640376]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-11-15 135664]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Wireless Utility.lnk - C:\Program Files\EDIMAX\Common\RaUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2005-01-23 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-11 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispAppearancePage"=0
"NoDispScrSavPage"=0
"NoDispSettingsPage"=0
"NoDispCPL"=0
"DisableLockWorkstation"=0
"DisableChangePassword"=0
"NoVisualStyleChoice"=0
"NoColorChoice"=0
"NoSizeChoice"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0x91000000
"NoViewOnDrive"=0
"NoDrives"=0
"NoFavoritesMenu"=0
"NoCommonGroups"=0
"NoLogOff"=0
"StartMenuLogoff"=0
"NoFind"=0
"NoStartMenuSubFolders"=0
"NoSetFolders"=0
"NoDesktop"=0
"NoSetActiveDesktop"=0
"NoFolderOptions"=0
"NoActiveDesktopChanges"=0
"NoRun"=0
"NoClose"=0
"NoTrayContextMenu"=0
"NoViewContextMenu"=0
"NoWinKeys"=0
"NoThemesTab"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoChangeAnimation"=0
"NoDFSTab"=0
"NoToolbarCustomize"=0
"NoBandCustomize"=0
"NoFileAssociate"=0
"NoFileUrl"=0
"NoSMMyPictures"=0
"NoStartMenuMyMusic"=0
"LockTaskbar"=0
"HideClock"=0
"NoStartMenuMFUprogramsList"=0
"NoStartMenuPinnedList"=0
"NoStartMenuMorePrograms"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:LocalSubNet:Disabled:@xpsp2res.dll,-22019"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\Opera75\Opera.exe"="C:\Program Files\Opera75\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Windows Mobile 6 SDK\Tools\Cellular Emulator\Cellular Emulator.exe"="C:\Program Files\Windows Mobile 6 SDK\Tools\Cellular Emulator\Cellular Emulator.exe:*:Disabled:Cellular Emulator"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Disabled:Nero ProductSetup"
"C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"="C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe:*:Disabled:Sprite Backup PC Service"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe"="C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe:*:Enabled:WebCamera Plus Service"
"C:\Program Files\Ateksoft\WebCamera Plus\camviewer.exe"="C:\Program Files\Ateksoft\WebCamera Plus\camviewer.exe:*:Enabled:WebCamera Plus"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.js - open -

======List of files/folders created in the last 1 months======

2010-09-23 14:25:26 ----D---- C:\Program Files\trend micro
2010-09-23 14:25:23 ----DC---- C:\rsit
2010-09-23 14:22:59 ----AC---- C:\RSIT.exe
2010-09-23 14:18:45 ----A---- C:\WINDOWS\system32\RootkitReveal.txt
2010-09-23 13:41:03 ----A---- C:\RootkitRevealer.exe
2010-09-23 07:10:06 ----ASH---- C:\hiberfil.sys
2010-09-22 00:19:07 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-09-22 00:19:06 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-09-22 00:19:06 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-09-22 00:19:04 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-09-22 00:19:04 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-09-22 00:19:03 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-09-22 00:19:03 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-09-22 00:18:25 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-09-21 23:35:08 ----AC---- C:\setup_av_free.exe
2010-09-21 23:15:15 ----AC---- C:\aswclear5.exe
2010-09-21 22:30:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-09-21 13:18:59 ----A---- C:\WINDOWS\system32\drivers\nrqqwi.sys
2010-09-19 09:33:12 ----D---- C:\Program Files\Ateksoft
2010-09-15 14:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 14:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 14:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 14:51:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 14:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 14:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 14:41:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-09-15 12:53:19 ----D---- C:\Documents and Settings\Martin\Data aplikací\Malwarebytes
2010-09-15 12:52:53 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-09-15 12:52:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-09-15 12:51:20 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-09-15 12:51:19 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-09-14 19:37:17 ----D---- C:\Documents and Settings\Martin\Data aplikací\Uniblue
2010-09-14 16:56:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\RegCure
2010-09-14 16:56:42 ----D---- C:\Program Files\RegCure
2010-09-14 14:13:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\SecTaskMan
2010-09-14 14:12:30 ----D---- C:\Program Files\Security Task Manager
2010-09-14 10:00:23 ----A---- C:\WINDOWS\system32\drivers\lbrtfdc.sys
2010-09-14 10:00:20 ----A---- C:\WINDOWS\system32\drivers\i2omgmt.sys
2010-09-14 09:59:01 ----A---- C:\WINDOWS\system32\drivers\OLD23D.tmp
2010-09-14 09:57:16 ----A---- C:\WINDOWS\system32\drivers\changer.sys

======List of files/folders modified in the last 1 months======

2010-09-23 14:25:29 ----D---- C:\WINDOWS\Prefetch
2010-09-23 14:25:26 ----D---- C:\Program Files
2010-09-23 14:21:10 ----D---- C:\Documents and Settings\Martin\Data aplikací\Skype
2010-09-23 14:18:45 ----D---- C:\WINDOWS\system32
2010-09-23 13:50:22 ----D---- C:\WINDOWS\system32\drivers
2010-09-23 13:27:33 ----D---- C:\WINDOWS\Temp
2010-09-23 13:27:33 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-23 13:21:41 ----A---- C:\WINDOWS\WINCMD.INI
2010-09-23 13:21:33 ----D---- C:\Documents and Settings\Martin\Data aplikací\skypePM
2010-09-23 08:47:06 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-23 07:51:07 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-09-23 07:04:45 ----A---- C:\WINDOWS\ntbtlog.txt
2010-09-22 20:44:35 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-22 19:22:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-09-22 18:30:28 ----D---- C:\WINDOWS\system32\config
2010-09-22 18:29:53 ----D---- C:\WINDOWS\system32\wbem
2010-09-22 18:29:52 ----D---- C:\WINDOWS\Registration
2010-09-22 18:29:28 ----D---- C:\Documents and Settings\Martin\Data aplikací\gtk-2.0
2010-09-22 00:18:22 ----D---- C:\Program Files\Alwil Software
2010-09-21 23:45:15 ----D---- C:\WINDOWS
2010-09-21 23:37:50 ----DC---- C:\maja
2010-09-21 23:27:49 ----D---- C:\WINDOWS\WinSxS
2010-09-21 23:27:49 ----D---- C:\Config.Msi
2010-09-21 23:27:41 ----SHD---- C:\WINDOWS\Installer
2010-09-21 23:09:37 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-19 09:33:15 ----HD---- C:\WINDOWS\inf
2010-09-19 09:27:45 ----D---- C:\Program Files\Microsoft ActiveSync
2010-09-19 09:27:42 ----D---- C:\WINDOWS\Help
2010-09-17 17:26:26 ----A---- C:\WINDOWS\win.ini
2010-09-16 03:37:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-09-15 19:53:47 ----D---- C:\Program Files\Visual Zip Password Recovery Processor
2010-09-15 19:53:47 ----D---- C:\Program Files\Visual Zip Password Recovery
2010-09-15 19:53:47 ----D---- C:\Program Files\MonitorTest
2010-09-15 14:52:39 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-15 14:52:34 ----A---- C:\WINDOWS\imsins.BAK
2010-09-15 14:52:19 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-15 14:42:47 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-15 14:30:16 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2010-09-15 11:58:59 ----D---- C:\WINDOWS\SoftwareDistribution
2010-09-15 10:40:16 ----D---- C:\WINDOWS\system32\CatRoot
2010-09-14 20:00:28 ----SD---- C:\WINDOWS\Tasks
2010-09-14 14:41:09 ----D---- C:\Program Files\RegVac Registry Cleaner
2010-09-10 13:58:51 ----D---- C:\Program Files\Opera75

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 hwinterface;hwinterface; C:\WINDOWS\System32\Drivers\hwinterface.sys [2008-11-04 2996]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-05-01 21361]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
R2 SVKP;SVKP; \??\C:\WINDOWS\System32\SVKP.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-04-25 730092]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 AteksoftAudio;WebCamera Plus Audio; C:\WINDOWS\system32\drivers\ateksoftaudio.sys [2007-12-18 11776]
R3 AVHybrid;AVHybrid service; C:\WINDOWS\system32\DRIVERS\AVHybrid.sys [2005-08-26 660736]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-01-23 804317]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-01-15 47360]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RT61;Edimax RT61 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2008-03-05 491648]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 TClass2k;Tablet Class Driver; C:\WINDOWS\system32\DRIVERS\TClass2k.sys [2003-03-05 23202]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 UCTblHid;HID Tablet Port Driver; C:\WINDOWS\system32\DRIVERS\UCTblHid.sys [2003-03-05 11090]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 xpvcom;XPVCOM Port; C:\WINDOWS\system32\DRIVERS\XPVCOM.sys [2007-03-23 30032]
S0x02000000 OMSCAN;OMSCAN; \Sys []
S1 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2002-10-25 91774]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 P1C1394;Phase One 1394 Camera Driver; C:\WINDOWS\System32\Drivers\p1c1394.sys []
S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2002-10-25 71514]
S3 BtAudio;Bluetooth Audio; C:\WINDOWS\System32\DRIVERS\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\System32\DRIVERS\btport.sys []
S3 CEBDADTV;C&E DVB-T device; C:\WINDOWS\system32\DRIVERS\CEBDA150.sys []
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2003-02-17 15104]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys [2008-04-13 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2003-02-17 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2003-02-17 10112]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
S3 Ser2pl;SIEMENS Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2003-05-07 41472]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 Tablet2k;Serial Tablet Port Driver; C:\WINDOWS\System32\Drivers\Tablet2k.sys [2000-06-13 15370]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbsermpt;Motorola USB Modem Driver for MPT; C:\WINDOWS\system32\DRIVERS\usbsermpt.sys [2007-03-20 22768]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-04-10 104576]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-01-19 503144]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-06-05 153376]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 Webcamera Plus Service;Webcamera Plus Service; C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [2007-12-18 46592]
R2 WinTabService;WinTab Service; C:\WINDOWS\system32\DRIVERS\WtSrv.exe [2003-09-30 40960]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-11-15 135664]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2005-05-24 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Diskeeper;Diskeeper; C:\Program Files\Executive Software\Diskeeper\DkService.exe [2003-08-22 241664]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-06-07 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-01-15 266240]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 ATMsrvc;ATM Service; C:\WINDOWS\System32\ATMsrvc.exe [2000-05-24 15360]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#2 Příspěvek od JaRon »

Presun ComboFix
na plochu (ak tam este nie je)

otvor si Poznamkovy blok - notepad

do neho zkopiruj skript z nasledujiceho okna:

Kód: Vybrat vše

Driver::
SVKP

File::
C:\WINDOWS\System32\SVKP.sys 

uloz vytvoreny textovy soubor ako CFScript.txt na plochu

po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

Obrázek

po aplikacii by mal vzniknut dalsi log, ten vloz sem :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#3 Příspěvek od carthman »

ComboFix 10-09-22.06 - Martin . 09. 2010 15:23:22.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.766.442 [GMT 2:00]
Spuštěný z: c:\documents and settings\Martin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Martin\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100922-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Martin\Dokumenty\Readiris.DUS
c:\documents and settings\Martin\tt7_keygen.exe
c:\program files\INSTALL.LOG
c:\windows\secure32.html
c:\windows\system32\drivers\hwinterface.sys
c:\windows\system32\Thumbs.db
c:\windows\system32\wservice.exe

c:\windows\system32\drivers\asyncmac.sys chyběl.
Obnovena kopie z - c:\windows\system32\dllcache\asyncmac.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_HWINTERFACE
-------\Legacy_SVKP
-------\Service_hwinterface
-------\Service_SVKP


((((((((((((((((((((((((( Soubory vytvořené od 2010-08-23 do 2010-09-23 )))))))))))))))))))))))))))))))
.

2010-09-23 13:35 . 2008-04-13 18:57 14336 -c--a-w- c:\windows\system32\dllcache\asyncmac.sys
2010-09-23 13:35 . 2008-04-13 18:57 14336 ----a-w- c:\windows\system32\drivers\asyncmac.sys
2010-09-23 12:25 . 2010-09-23 12:26 -------- d-----w- c:\program files\trend micro
2010-09-23 12:25 . 2010-09-23 12:26 -------- dc----w- C:\rsit
2010-09-23 12:22 . 2010-09-23 12:21 339991 -c--a-w- C:\RSIT.exe
2010-09-23 11:41 . 2006-11-01 11:07 334720 ----a-w- C:\RootkitRevealer.exe
2010-09-22 16:29 . 2010-09-22 16:29 -------- d-----w- c:\windows\system32\wbem\Repository
2010-09-21 22:19 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-21 22:19 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-21 22:19 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-21 22:19 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-21 22:19 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-21 22:19 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-09-21 22:19 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-21 22:19 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-21 22:18 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-21 21:35 . 2010-09-21 20:08 55085336 -c--a-w- C:\setup_av_free.exe
2010-09-21 21:22 . 2010-09-21 21:22 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-09-21 21:15 . 2010-09-21 21:14 157232 -c--a-w- C:\aswclear5.exe
2010-09-21 20:38 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-21 11:18 . 2010-09-23 14:05 564800 ----a-w- c:\windows\system32\drivers\nrqqwi.sys
2010-09-19 07:33 . 2010-09-19 07:33 -------- d-----w- c:\program files\Ateksoft
2010-09-19 07:21 . 2010-09-19 07:22 7840768 -c--a-w- C:\setup.msi
2010-09-15 10:52 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 10:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-15 10:51 . 2010-09-15 10:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 18:23 . 2010-09-14 18:23 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-09-14 14:56 . 2010-09-14 15:04 -------- d-----w- c:\program files\RegCure
2010-09-14 12:12 . 2010-09-14 13:05 -------- d-----w- c:\program files\Security Task Manager
2010-09-14 08:00 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 22:18 . 2004-12-09 17:37 -------- d-----w- c:\program files\Alwil Software
2010-09-21 21:09 . 2001-10-25 12:00 433140 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 21:09 . 2001-10-25 12:00 80464 ----a-w- c:\windows\system32\perfc005.dat
2010-09-19 07:27 . 2008-01-25 18:04 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-09-15 17:53 . 2009-11-07 08:28 -------- d-----w- c:\program files\Visual Zip Password Recovery Processor
2010-09-15 17:53 . 2009-11-07 08:21 -------- d-----w- c:\program files\Visual Zip Password Recovery
2010-09-15 17:53 . 2004-11-19 08:34 -------- d-----w- c:\program files\MonitorTest
2010-09-14 12:41 . 2007-10-10 12:22 -------- d-----w- c:\program files\RegVac Registry Cleaner
2010-09-10 11:58 . 2004-07-11 12:46 -------- d-----w- c:\program files\Opera75
2010-08-17 13:17 . 2001-10-25 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 05:51 . 2004-05-22 07:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-15 05:46 . 2004-06-07 17:48 -------- d-----w- c:\program files\Lavasoft
2010-08-06 16:45 . 2010-08-06 16:43 -------- d-----w- c:\program files\QIP
2010-08-04 19:58 . 2004-09-22 07:32 -------- d-----w- c:\program files\GIMP-2.0
2010-07-22 15:46 . 2004-05-22 10:30 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 07:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-06-30 12:33 . 2001-10-25 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2007-09-01 16:46 . 2005-02-27 06:13 8628 -c-ha-w- c:\program files\readcz.GID
1999-09-13 10:15 . 2004-06-01 17:26 10900 -c--a-w- c:\program files\readcz.hlp
2007-11-25 17:10 . 2007-11-25 16:42 72 --sh--w- c:\windows\S8AD1EAD8.tmp
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\Adobe Photoshop CS2\Plug-Ins\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
c:\program files\Adobe\Photoshop 7.0 CE\Plug-Ins CZ\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
</pre>
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Google Update"="c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-11-15 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-5-1 716800]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCommonGroups"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\Opera75\\Opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Mobile 6 SDK\\Tools\\Cellular Emulator\\Cellular Emulator.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\WebCamPlusSrv.exe"=
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\camviewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1010:TCP"= 1010:TCP:192.168.100.0/255.255.255.0:Enabled:port
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [22. 9. 2010 0:19 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22. 9. 2010 0:19 20560]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [19. 9. 2010 9:33 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [15. 7. 2008 22:32 11776]
R3 AVHybrid;AVHybrid service;c:\windows\system32\drivers\AVHybrid.sys [22. 9. 2007 14:53 660736]
R3 xpvcom;XPVCOM Port;c:\windows\system32\drivers\XPVCOM.sys [23. 3. 2007 2:00 30032]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15. 11. 2009 16:20 135664]
S2 OMSCAN;OMSCAN;\Sysń --> \Sysń [?]
S2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\Drivers\p1c1394.sys --> c:\windows\system32\Drivers\p1c1394.sys [?]
S3 CEBDADTV;C&E DVB-T device;c:\windows\system32\DRIVERS\CEBDA150.sys --> c:\windows\system32\DRIVERS\CEBDA150.sys [?]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - nrqqwi
.
Obsah adresáře 'Naplánované úlohy'

2010-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-20 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]

2010-09-14 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\gihh5mfr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www3.iamwired.net/websearch.php?src=tops&search=
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://qip.ru
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Opera75\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\Opera75\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera75\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera75\program\plugins\NPSWF32_back.dll
FF - plugin: c:\program files\Opera75\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-23 16:04
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\OMSCAN]
"ImagePath"="\Sys"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\nrqqwi]

.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75784F4D-1FAD-959A-D7DE-EF1EE173E773}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"pacaadmgdgbpgpmbbliikeogdnpidnfm"=hex:6a,61,6c,66,6d,64,61,68,6d,61,61,6d,62,
70,6e,68,64,6c,66,68,00,00
"oaiaodjjpommpieobmeoknaejlfndh"=hex:6a,61,6f,66,64,66,6a,6f,70,70,69,6c,62,68,
6d,66,66,62,6f,66,00,00
"kaabkbkoddjfppgilogkil"=hex:62,61,6d,66,00,e5
"haopnfjnnmlgmjla"=hex:63,62,68,61,70,65,6c,6f,65,65,67,6a,6c,67,69,63,6e,68,
61,6b,65,6a,64,6c,69,6b,66,62,69,66,61,67,6e,6e,67,68,66,6e,00,00
"haopnfjncomfocbm"=hex:68,62,6e,66,69,6a,6e,62,69,6f,61,6d,67,70,66,6a,6f,69,
62,62,62,64,61,65,61,6d,70,61,67,67,66,6a,70,6d,66,70,6e,6c,63,67,64,68,63,\

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Param2"=""
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(2980)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\DRIVERS\WtSrv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-09-23 16:17:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-09-23 14:17

Před spuštěním: 2 671 415 296
Po spuštění: 4 361 265 152

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Current=3 Default=3 Failed=4 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 3C1C362B27277232A7788FE039304E58

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#4 Příspěvek od JaRon »

zopakuj akciu - novy CFS:

Kód: Vybrat vše

Driver::
OMSCAN

FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#5 Příspěvek od carthman »

ComboFix 10-09-22.06 - Martin . 09. 2010 7:53.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.766.488 [GMT 2:00]
Spuštěný z: c:\documents and settings\Martin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Martin\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100923-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_OMSCAN
-------\Service_OMSCAN


((((((((((((((((((((((((( Soubory vytvořené od 2010-08-24 do 2010-09-24 )))))))))))))))))))))))))))))))
.

2010-09-23 13:35 . 2008-04-13 18:57 14336 -c--a-w- c:\windows\system32\dllcache\asyncmac.sys
2010-09-23 13:35 . 2008-04-13 18:57 14336 ----a-w- c:\windows\system32\drivers\asyncmac.sys
2010-09-23 12:25 . 2010-09-23 12:26 -------- d-----w- c:\program files\trend micro
2010-09-23 12:25 . 2010-09-23 12:26 -------- dc----w- C:\rsit
2010-09-23 12:22 . 2010-09-23 12:21 339991 -c--a-w- C:\RSIT.exe
2010-09-23 11:41 . 2006-11-01 11:07 334720 ----a-w- C:\RootkitRevealer.exe
2010-09-22 16:29 . 2010-09-22 16:29 -------- d-----w- c:\windows\system32\wbem\Repository
2010-09-21 22:19 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-21 22:19 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-21 22:19 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-21 22:19 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-21 22:19 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-21 22:19 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-09-21 22:19 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-21 22:19 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-21 22:18 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-21 21:35 . 2010-09-21 20:08 55085336 -c--a-w- C:\setup_av_free.exe
2010-09-21 21:22 . 2010-09-21 21:22 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-09-21 21:15 . 2010-09-21 21:14 157232 -c--a-w- C:\aswclear5.exe
2010-09-21 20:38 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-21 11:18 . 2010-09-24 06:16 564800 ----a-w- c:\windows\system32\drivers\nrqqwi.sys
2010-09-19 07:33 . 2010-09-19 07:33 -------- d-----w- c:\program files\Ateksoft
2010-09-19 07:21 . 2010-09-19 07:22 7840768 -c--a-w- C:\setup.msi
2010-09-15 10:52 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 10:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-15 10:51 . 2010-09-15 10:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 18:23 . 2010-09-14 18:23 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-09-14 14:56 . 2010-09-14 15:04 -------- d-----w- c:\program files\RegCure
2010-09-14 12:12 . 2010-09-14 13:05 -------- d-----w- c:\program files\Security Task Manager
2010-09-14 08:00 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 22:18 . 2004-12-09 17:37 -------- d-----w- c:\program files\Alwil Software
2010-09-21 21:09 . 2001-10-25 12:00 433140 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 21:09 . 2001-10-25 12:00 80464 ----a-w- c:\windows\system32\perfc005.dat
2010-09-19 07:27 . 2008-01-25 18:04 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-09-15 17:53 . 2009-11-07 08:28 -------- d-----w- c:\program files\Visual Zip Password Recovery Processor
2010-09-15 17:53 . 2009-11-07 08:21 -------- d-----w- c:\program files\Visual Zip Password Recovery
2010-09-15 17:53 . 2004-11-19 08:34 -------- d-----w- c:\program files\MonitorTest
2010-09-14 12:41 . 2007-10-10 12:22 -------- d-----w- c:\program files\RegVac Registry Cleaner
2010-09-10 11:58 . 2004-07-11 12:46 -------- d-----w- c:\program files\Opera75
2010-08-17 13:17 . 2001-10-25 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 05:51 . 2004-05-22 07:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-15 05:46 . 2004-06-07 17:48 -------- d-----w- c:\program files\Lavasoft
2010-08-06 16:45 . 2010-08-06 16:43 -------- d-----w- c:\program files\QIP
2010-08-04 19:58 . 2004-09-22 07:32 -------- d-----w- c:\program files\GIMP-2.0
2010-07-22 15:46 . 2004-05-22 10:30 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 07:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-06-30 12:33 . 2001-10-25 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2007-09-01 16:46 . 2005-02-27 06:13 8628 -c-ha-w- c:\program files\readcz.GID
1999-09-13 10:15 . 2004-06-01 17:26 10900 -c--a-w- c:\program files\readcz.hlp
2007-11-25 17:10 . 2007-11-25 16:42 72 --sh--w- c:\windows\S8AD1EAD8.tmp
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\Adobe Photoshop CS2\Plug-Ins\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
c:\program files\Adobe\Photoshop 7.0 CE\Plug-Ins CZ\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
</pre>
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Google Update"="c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-11-15 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-02-27 77824]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-5-1 716800]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCommonGroups"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\Opera75\\Opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Mobile 6 SDK\\Tools\\Cellular Emulator\\Cellular Emulator.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\WebCamPlusSrv.exe"=
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\camviewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1010:TCP"= 1010:TCP:192.168.100.0/255.255.255.0:Enabled:port
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [22. 9. 2010 0:19 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22. 9. 2010 0:19 20560]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [19. 9. 2010 9:33 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [15. 7. 2008 22:32 11776]
R3 AVHybrid;AVHybrid service;c:\windows\system32\drivers\AVHybrid.sys [22. 9. 2007 14:53 660736]
R3 xpvcom;XPVCOM Port;c:\windows\system32\drivers\XPVCOM.sys [23. 3. 2007 2:00 30032]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15. 11. 2009 16:20 135664]
S2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\Drivers\p1c1394.sys --> c:\windows\system32\Drivers\p1c1394.sys [?]
S3 CEBDADTV;C&E DVB-T device;c:\windows\system32\DRIVERS\CEBDA150.sys --> c:\windows\system32\DRIVERS\CEBDA150.sys [?]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - nrqqwi
.
Obsah adresáře 'Naplánované úlohy'

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]

2010-09-14 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\gihh5mfr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www3.iamwired.net/websearch.php?src=tops&search=
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://qip.ru
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\gihh5mfr.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Opera75\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\Opera75\program\plugins\npdsplay.dll
FF - plugin: c:\program files\Opera75\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Opera75\program\plugins\NPSWF32_back.dll
FF - plugin: c:\program files\Opera75\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-24 08:15
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\nrqqwi]

.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75784F4D-1FAD-959A-D7DE-EF1EE173E773}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"pacaadmgdgbpgpmbbliikeogdnpidnfm"=hex:6a,61,6c,66,6d,64,61,68,6d,61,61,6d,62,
70,6e,68,64,6c,66,68,00,00
"oaiaodjjpommpieobmeoknaejlfndh"=hex:6a,61,6f,66,64,66,6a,6f,70,70,69,6c,62,68,
6d,66,66,62,6f,66,00,00
"kaabkbkoddjfppgilogkil"=hex:62,61,6d,66,00,e5
"haopnfjnnmlgmjla"=hex:63,62,68,61,70,65,6c,6f,65,65,67,6a,6c,67,69,63,6e,68,
61,6b,65,6a,64,6c,69,6b,66,62,69,66,61,67,6e,6e,67,68,66,6e,00,00
"haopnfjncomfocbm"=hex:68,62,6e,66,69,6a,6e,62,69,6f,61,6d,67,70,66,6a,6f,69,
62,62,62,64,61,65,61,6d,70,61,67,67,66,6a,70,6d,66,70,6e,6c,63,67,64,68,63,\

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Param2"=""
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(652)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\DRIVERS\WtSrv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-09-24 08:27:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-09-24 06:27
ComboFix2.txt 2010-09-23 14:17

Před spuštěním: 4 226 428 928
Po spuštění: 4 273 590 272

Current=3 Default=3 Failed=4 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - EE200EDAB4F2877E836D2EA35B9BD714

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#6 Příspěvek od JaRon »

OKi - prescanuj PC s MBAM a napis, ci este AVAST nieco hlasi :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#7 Příspěvek od carthman »

po restartu Avast stále hlásí c:\windows\system32\drivers\nrqqwi.sys Rootkit-GEN


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4680

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

24. 9. 2010 9:48:21
mbam-log-2010-09-24 (09-48-21).txt

Typ skenu: Rychlý sken
Skenované objekty: 174526
Uplynulý čas: 12 minuta(y), 5 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#8 Příspěvek od JaRon »

:) takze posledny CFS:

Kód: Vybrat vše

Driver::
nrqqwi

File::
c:\windows\system32\drivers\nrqqwi.sys 

FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#9 Příspěvek od carthman »

Zatím po restartu bez varování.

ComboFix 10-09-23.01 - Martin . 09. 2010 10:06:58.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.766.412 [GMT 2:00]
Spuštěný z: c:\documents and settings\Martin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Martin\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100923-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
"c:\windows\system32\drivers\nrqqwi.sys"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\nrqqwi.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NRQQWI
-------\Service_nrqqwi


((((((((((((((((((((((((( Soubory vytvořené od 2010-08-24 do 2010-09-24 )))))))))))))))))))))))))))))))
.

2010-09-23 13:35 . 2008-04-13 18:57 14336 -c--a-w- c:\windows\system32\dllcache\asyncmac.sys
2010-09-23 13:35 . 2008-04-13 18:57 14336 ----a-w- c:\windows\system32\drivers\asyncmac.sys
2010-09-23 12:25 . 2010-09-23 12:26 -------- d-----w- c:\program files\trend micro
2010-09-23 12:25 . 2010-09-23 12:26 -------- dc----w- C:\rsit
2010-09-23 12:22 . 2010-09-23 12:21 339991 -c--a-w- C:\RSIT.exe
2010-09-23 11:41 . 2006-11-01 11:07 334720 ----a-w- C:\RootkitRevealer.exe
2010-09-22 16:29 . 2010-09-22 16:29 -------- d-----w- c:\windows\system32\wbem\Repository
2010-09-21 22:19 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-21 22:19 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-21 22:19 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-21 22:19 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-21 22:19 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-21 22:19 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-09-21 22:19 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-21 22:19 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-21 22:18 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-21 21:35 . 2010-09-21 20:08 55085336 -c--a-w- C:\setup_av_free.exe
2010-09-21 21:22 . 2010-09-21 21:22 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-09-21 21:15 . 2010-09-21 21:14 157232 -c--a-w- C:\aswclear5.exe
2010-09-21 20:38 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-19 07:33 . 2010-09-19 07:33 -------- d-----w- c:\program files\Ateksoft
2010-09-19 07:21 . 2010-09-19 07:22 7840768 -c--a-w- C:\setup.msi
2010-09-15 10:52 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 10:51 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-15 10:51 . 2010-09-15 10:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 18:23 . 2010-09-14 18:23 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-09-14 14:56 . 2010-09-14 15:04 -------- d-----w- c:\program files\RegCure
2010-09-14 12:12 . 2010-09-14 13:05 -------- d-----w- c:\program files\Security Task Manager
2010-09-14 08:00 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-09-14 08:00 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-09-14 07:57 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 22:18 . 2004-12-09 17:37 -------- d-----w- c:\program files\Alwil Software
2010-09-21 21:09 . 2001-10-25 12:00 433140 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 21:09 . 2001-10-25 12:00 80464 ----a-w- c:\windows\system32\perfc005.dat
2010-09-19 07:27 . 2008-01-25 18:04 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-09-15 17:53 . 2009-11-07 08:28 -------- d-----w- c:\program files\Visual Zip Password Recovery Processor
2010-09-15 17:53 . 2009-11-07 08:21 -------- d-----w- c:\program files\Visual Zip Password Recovery
2010-09-15 17:53 . 2004-11-19 08:34 -------- d-----w- c:\program files\MonitorTest
2010-09-14 12:41 . 2007-10-10 12:22 -------- d-----w- c:\program files\RegVac Registry Cleaner
2010-09-10 11:58 . 2004-07-11 12:46 -------- d-----w- c:\program files\Opera75
2010-08-17 13:17 . 2001-10-25 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 05:51 . 2004-05-22 07:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-15 05:46 . 2004-06-07 17:48 -------- d-----w- c:\program files\Lavasoft
2010-08-06 16:45 . 2010-08-06 16:43 -------- d-----w- c:\program files\QIP
2010-08-04 19:58 . 2004-09-22 07:32 -------- d-----w- c:\program files\GIMP-2.0
2010-07-22 15:46 . 2004-05-22 10:30 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 07:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-06-30 12:33 . 2001-10-25 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2007-09-01 16:46 . 2005-02-27 06:13 8628 -c-ha-w- c:\program files\readcz.GID
1999-09-13 10:15 . 2004-06-01 17:26 10900 -c--a-w- c:\program files\readcz.hlp
2007-11-25 17:10 . 2007-11-25 16:42 72 --sh--w- c:\windows\S8AD1EAD8.tmp
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\Adobe Photoshop CS2\Plug-Ins\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
c:\program files\Adobe\Photoshop 7.0 CE\Plug-Ins CZ\Xenofex 2\LS_Alien_Skin_Xenofex_v2.0.0_Demo .exe
</pre>
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Google Update"="c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-11-15 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-02-27 77824]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-5-1 716800]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCommonGroups"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\Opera75\\Opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Mobile 6 SDK\\Tools\\Cellular Emulator\\Cellular Emulator.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\WebCamPlusSrv.exe"=
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\camviewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1010:TCP"= 1010:TCP:192.168.100.0/255.255.255.0:Enabled:port
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [22. 9. 2010 0:19 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22. 9. 2010 0:19 20560]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [19. 9. 2010 9:33 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [15. 7. 2008 22:32 11776]
R3 AVHybrid;AVHybrid service;c:\windows\system32\drivers\AVHybrid.sys [22. 9. 2007 14:53 660736]
R3 xpvcom;XPVCOM Port;c:\windows\system32\drivers\XPVCOM.sys [23. 3. 2007 2:00 30032]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15. 11. 2009 16:20 135664]
S2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\Drivers\p1c1394.sys --> c:\windows\system32\Drivers\p1c1394.sys [?]
S3 CEBDADTV;C&E DVB-T device;c:\windows\system32\DRIVERS\CEBDA150.sys --> c:\windows\system32\DRIVERS\CEBDA150.sys [?]
.
Obsah adresáře 'Naplánované úlohy'

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 14:20]

2010-09-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]

2010-09-14 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 13:44]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\gihh5mfr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www3.iamwired.net/websearch.php?src=tops&search=
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://qip.ru
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\gihh5mfr.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-24 10:23
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75784F4D-1FAD-959A-D7DE-EF1EE173E773}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"pacaadmgdgbpgpmbbliikeogdnpidnfm"=hex:6a,61,6c,66,6d,64,61,68,6d,61,61,6d,62,
70,6e,68,64,6c,66,68,00,00
"oaiaodjjpommpieobmeoknaejlfndh"=hex:6a,61,6f,66,64,66,6a,6f,70,70,69,6c,62,68,
6d,66,66,62,6f,66,00,00
"kaabkbkoddjfppgilogkil"=hex:62,61,6d,66,00,e5
"haopnfjnnmlgmjla"=hex:63,62,68,61,70,65,6c,6f,65,65,67,6a,6c,67,69,63,6e,68,
61,6b,65,6a,64,6c,69,6b,66,62,69,66,61,67,6e,6e,67,68,66,6e,00,00
"haopnfjncomfocbm"=hex:68,62,6e,66,69,6a,6e,62,69,6f,61,6d,67,70,66,6a,6f,69,
62,62,62,64,61,65,61,6d,70,61,67,67,66,6a,70,6d,66,70,6e,6c,63,67,64,68,63,\

[HKEY_USERS\S-1-5-21-1708537768-1202660629-682003330-1003\Software\Microsoft\Windows Mobile Disc\W*i*n*d*o*w*s* *M*o*b*i*l*e*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Param2"=""
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(2640)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\DRIVERS\WtSrv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\documents and settings\Martin\Local Settings\Data aplikací\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-09-24 10:37:01 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-09-24 08:36
ComboFix2.txt 2010-09-24 06:27
ComboFix3.txt 2010-09-23 14:17

Před spuštěním: 4 249 145 344
Po spuštění: 4 245 778 432

Current=3 Default=3 Failed=4 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 6B3168A0F1F1CAA40D12C4BEAE9AADD2

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#10 Příspěvek od JaRon »

rodina rootkitov zlikvidovana :) je to OK - hotovo
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

carthman
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 23 Zář 2010 13:33

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#11 Příspěvek od carthman »

Díky moc za ochotu a rady. Vše naprosto seriózní a funkční.

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Prosím o kontrolu logu, Avast stále hlásí rootkit

#12 Příspěvek od JaRon »

rado sa stalo
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět