C:\Documents and Settings\Miroslava - Slamená\Plocha\HelpAsst_mebroot_fix.exe
čt 15.07.2010 at 17:22:21,60
Could not determine language ~ no action taken on account ~ please consult noahdfear
00000405
U§ivatelsk‚ jm‚no HelpAssistant
Jm‚no a pýˇjmenˇ éźet pomoci vzd len‚ plochy
Koment ý éźet pro poskytov nˇ vzd len‚ pomoci.
Koment ý u§ivatele
SmŘrov‚ źˇslo zemŘ 000 (Věchozˇ syst‚mov‚ nastavenˇ)
éźet je aktivnˇ Ne
éźet vyprçel Nikdy
Heslo bylo naposledy nastaveno 12/21/2006 8:57 AM
Heslo vyprçˇ Nikdy
Heslo lze mŘnit 12/21/2006 8:57 AM
Heslo je vy§adov no Ano
U§ivatel smˇ mŘnit heslo Ne
Pracovnˇ stanice byla povolena Vçe
Pýihlaçovacˇ skript
Profil u§ivatele
Domovskě adres ý
Naposledy pýihl çen Nikdy
Povolen‚ pýihlaçovacˇ hodiny Vçe
¬lenstvˇ v mˇstnˇch skupin ch
¬lenstvˇ v glob lnˇch skupin ch *None
Pýˇkaz byl ŁspŘçnŘ dokonźen.
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
~~ Checking firewall ports ~~
HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on čt 15.07.2010 at 17:22:49,93
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B2DCC0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b2dcc0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on źt 15.07.2010 at 17:35:43,95
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B5EC40]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b5ec40
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~