Re: Win Update
Napsal: 26 led 2011 20:27
Má pocit že jsem něco pokazil.Během Combofix se spustil zálohovací program.Okamžitě jsem ho vypl.Mám akci opakovat?Jinak žádná změna.
Zde je log.
ComboFix 11-01-25.03 - pc 26.01.2011 20:15:30.2.1 - x86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.420.1029.18.1022.724 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\pc\Plocha\CFScript.txt.txt
.
/wow section - STAGE 10
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system\winspool.drv
.
--------------- FCopy ---------------
c:\documents and settings\pc\plocha\comres.dll --> c:\winnt\System32\comres.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-26 do 2011-01-26 )))))))))))))))))))))))))))))))
.
2011-01-25 18:28 . 2011-01-25 18:28 -------- d-----w- c:\program files\trend micro
2011-01-25 18:28 . 2011-01-25 18:28 -------- d-----w- C:\rsit
2011-01-24 20:00 . 2011-01-24 20:01 -------- d-----w- c:\program files\Cobian Backup 8
2011-01-24 19:42 . 2011-01-24 19:42 -------- d-----w- c:\winnt\system32\wbem\Repository\Export
2011-01-24 17:50 . 2011-01-24 17:51 -------- d-----w- c:\program files\The KMPlayer
2011-01-23 20:37 . 2011-01-23 20:37 -------- d-----w- c:\program files\Virtual DJ
2011-01-17 20:12 . 2011-01-17 20:12 -------- d-----w- c:\documents and settings\pc\Data aplikací\OpenOffice.org2
2011-01-14 16:37 . 2011-01-14 16:37 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Help
2011-01-10 20:51 . 2011-01-10 20:51 -------- d-----w- c:\documents and settings\pc\Data aplikací\AnvSoft
2011-01-10 20:51 . 2011-01-10 20:51 -------- d-----w- c:\program files\AnvSoft
2011-01-10 20:32 . 2011-01-10 20:34 -------- d-----w- c:\program files\FreeTime
2011-01-10 18:59 . 2003-01-13 13:11 155648 ------w- c:\winnt\system32\igfxres.dll
2011-01-09 16:43 . 2011-01-09 16:43 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-09 16:38 . 2011-01-09 16:38 717296 ------w- c:\winnt\system32\drivers\sptd.sys
2011-01-09 16:38 . 2011-01-09 16:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\DAEMON Tools
2011-01-08 19:17 . 2011-01-08 19:17 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Yahoo
2011-01-08 19:17 . 2011-01-08 19:17 -------- d-----w- c:\program files\Yahoo!
2011-01-08 18:43 . 2011-01-08 18:43 -------- d-----w- c:\documents and settings\pc\Data aplikací\VirtuaWin
2011-01-08 18:43 . 2011-01-08 18:44 -------- d-----w- c:\program files\VirtuaWin
2011-01-08 18:29 . 2011-01-24 15:17 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Adobe
2011-01-08 18:16 . 2011-01-08 18:26 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\johnsadventures.com
2011-01-08 18:15 . 2011-01-08 18:15 -------- d-----w- c:\documents and settings\pc\Data aplikací\johnsadventures.com
2011-01-08 18:07 . 2011-01-09 12:33 -------- d-----w- c:\documents and settings\pc\Data aplikací\Dexpot
2011-01-08 16:40 . 2011-01-24 15:22 -------- d-----w- c:\program files\Common Files\Adobe
2011-01-08 16:22 . 2011-01-08 20:31 -------- d-----w- c:\program files\Google
2011-01-08 16:20 . 2011-01-09 12:59 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Google
2011-01-08 15:57 . 2011-01-08 15:57 -------- d-----w- c:\documents and settings\pc\Data aplikací\ESET
2011-01-08 15:56 . 2011-01-25 14:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-01-01 19:24 . 2011-01-01 19:39 -------- d-----w- c:\program files\Kaspersky Lab
2011-01-01 19:24 . 2011-01-01 19:24 -------- d-----w- C:\kav
2011-01-01 19:11 . 2011-01-01 19:11 -------- d-----w- c:\documents and settings\pc\Data aplikací\SoftPerfect Personal Firewall
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg6n.sys
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg5n.sys
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg4n.sys
2011-01-01 18:54 . 2011-01-01 18:54 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-01-01 18:37 . 2011-01-01 18:37 -------- d-----w- c:\winnt\Internet Logs
2010-12-31 14:36 . 2010-12-31 14:36 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-12-31 13:00 . 2010-12-31 13:00 -------- d-----w- c:\program files\Common Files\Skype
2010-12-31 13:00 . 2010-12-31 13:00 -------- d-----r- c:\program files\Skype
2010-12-30 21:01 . 2011-01-23 18:55 -------- d-----w- c:\documents and settings\pc\Data aplikací\skypePM
2010-12-30 21:00 . 2011-01-24 20:04 -------- d-----w- c:\documents and settings\pc\Data aplikací\Skype
2010-12-30 20:39 . 2010-12-31 13:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-31 14:35 . 2010-12-19 10:36 737280 ------w- c:\winnt\iun6002.exe
2010-12-17 11:51 . 2010-12-17 11:51 73216 ------w- c:\winnt\ST6UNST.EXE
2010-12-17 11:12 . 2010-12-17 11:12 58000 ------w- c:\winnt\system32\drivers\cdr4_2K.sys
2010-12-17 11:12 . 2010-12-17 11:12 57344 ------w- c:\winnt\uneng.exe
2010-12-17 11:12 . 2010-12-17 11:12 49152 ------w- c:\winnt\system32\cdrtc.dll
2010-12-17 11:12 . 2010-12-17 11:12 45056 ------w- c:\winnt\system32\cdral.dll
2010-12-17 11:12 . 2010-12-17 11:12 23420 ------w- c:\winnt\system32\drivers\cdralw2k.sys
.
------- Sigcheck -------
[-] 2004-05-13 23:19 . 1F51839ECCF908FD86558198909262E4 . 792064 . . [ERROR: 0x0] . . c:\winnt\system32\comres.dll
[-] 2003-02-01 11:09 . 9E1381B2DE2A23F8E4C22E814D55F475 . 52224 . . [ERROR: 0x0] . . c:\winnt\system32\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-01-26_12.47.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-26 19:14 . 2011-01-26 19:14 16384 c:\winnt\system32\Perflib_Perfdata_280.dat
+ 2011-01-26 15:36 . 2011-01-26 15:36 16384 c:\winnt\system32\Perflib_Perfdata_20c.dat
- 2011-01-26 12:36 . 2011-01-26 12:36 16384 c:\winnt\system32\Perflib_Perfdata_20c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2003-06-19 111888]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2005-06-21 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Cobian Backup 8"="c:\program files\Cobian Backup 8\Cobian.exe" [2007-09-27 501248]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 188688]
c:\documents and settings\pc\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2006-6-26 610304]
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.1.lnk]
path=c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\OpenOffice.org 2.1.lnk
backup=c:\winnt\pss\OpenOffice.org 2.1.lnkStartup
R0 sptd;sptd;c:\winnt\system32\drivers\sptd.sys [9.1.2011 17:38 717296]
R2 Active@ Disk Monitor;Active@ Disk Monitor;c:\program files\LSoft Technologies Inc\Active@ Hard Disk Monitor\DiskMonitorService.exe [23.12.2010 12:22 1464328]
R3 usbhub20;Podpora kořenového rozbočovač rozbočovače sběrnice USB 2.0;c:\winnt\system32\drivers\usbhub20.sys [16.12.2010 17:44 49776]
R3 ZD1211BU(Atheros);Atheros ZD1211B IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\winnt\system32\drivers\ZD1211BU.sys [11.4.2008 20:51 720896]
.
.
------- Doplňkový sken -------
.
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\fwegmscf.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-26 20:18
Windows 5.0.2195 Service Pack 4 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\winnt\system32\Perflib_Perfdata_274.dat 16384 bytes
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\pc\LOCALS~1\Temp\ASFWHide"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(216)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Celkový čas: 2011-01-26 20:20:25
ComboFix-quarantined-files.txt 2011-01-26 19:20
ComboFix2.txt 2011-01-26 12:49
Před spuštěním: Volných bajtů: 136 624 132 096
Po spuštění: Volných bajtů: 136 588 488 704
- - End Of File - - 99199A9A7C41A4FF74DE0BE9AE0C05C4
Zde je log.
ComboFix 11-01-25.03 - pc 26.01.2011 20:15:30.2.1 - x86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.420.1029.18.1022.724 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\pc\Plocha\CFScript.txt.txt
.
/wow section - STAGE 10
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\system\winspool.drv
.
--------------- FCopy ---------------
c:\documents and settings\pc\plocha\comres.dll --> c:\winnt\System32\comres.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-26 do 2011-01-26 )))))))))))))))))))))))))))))))
.
2011-01-25 18:28 . 2011-01-25 18:28 -------- d-----w- c:\program files\trend micro
2011-01-25 18:28 . 2011-01-25 18:28 -------- d-----w- C:\rsit
2011-01-24 20:00 . 2011-01-24 20:01 -------- d-----w- c:\program files\Cobian Backup 8
2011-01-24 19:42 . 2011-01-24 19:42 -------- d-----w- c:\winnt\system32\wbem\Repository\Export
2011-01-24 17:50 . 2011-01-24 17:51 -------- d-----w- c:\program files\The KMPlayer
2011-01-23 20:37 . 2011-01-23 20:37 -------- d-----w- c:\program files\Virtual DJ
2011-01-17 20:12 . 2011-01-17 20:12 -------- d-----w- c:\documents and settings\pc\Data aplikací\OpenOffice.org2
2011-01-14 16:37 . 2011-01-14 16:37 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Help
2011-01-10 20:51 . 2011-01-10 20:51 -------- d-----w- c:\documents and settings\pc\Data aplikací\AnvSoft
2011-01-10 20:51 . 2011-01-10 20:51 -------- d-----w- c:\program files\AnvSoft
2011-01-10 20:32 . 2011-01-10 20:34 -------- d-----w- c:\program files\FreeTime
2011-01-10 18:59 . 2003-01-13 13:11 155648 ------w- c:\winnt\system32\igfxres.dll
2011-01-09 16:43 . 2011-01-09 16:43 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-09 16:38 . 2011-01-09 16:38 717296 ------w- c:\winnt\system32\drivers\sptd.sys
2011-01-09 16:38 . 2011-01-09 16:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\DAEMON Tools
2011-01-08 19:17 . 2011-01-08 19:17 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Yahoo
2011-01-08 19:17 . 2011-01-08 19:17 -------- d-----w- c:\program files\Yahoo!
2011-01-08 18:43 . 2011-01-08 18:43 -------- d-----w- c:\documents and settings\pc\Data aplikací\VirtuaWin
2011-01-08 18:43 . 2011-01-08 18:44 -------- d-----w- c:\program files\VirtuaWin
2011-01-08 18:29 . 2011-01-24 15:17 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Adobe
2011-01-08 18:16 . 2011-01-08 18:26 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\johnsadventures.com
2011-01-08 18:15 . 2011-01-08 18:15 -------- d-----w- c:\documents and settings\pc\Data aplikací\johnsadventures.com
2011-01-08 18:07 . 2011-01-09 12:33 -------- d-----w- c:\documents and settings\pc\Data aplikací\Dexpot
2011-01-08 16:40 . 2011-01-24 15:22 -------- d-----w- c:\program files\Common Files\Adobe
2011-01-08 16:22 . 2011-01-08 20:31 -------- d-----w- c:\program files\Google
2011-01-08 16:20 . 2011-01-09 12:59 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Google
2011-01-08 15:57 . 2011-01-08 15:57 -------- d-----w- c:\documents and settings\pc\Data aplikací\ESET
2011-01-08 15:56 . 2011-01-25 14:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-01-01 19:24 . 2011-01-01 19:39 -------- d-----w- c:\program files\Kaspersky Lab
2011-01-01 19:24 . 2011-01-01 19:24 -------- d-----w- C:\kav
2011-01-01 19:11 . 2011-01-01 19:11 -------- d-----w- c:\documents and settings\pc\Data aplikací\SoftPerfect Personal Firewall
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg6n.sys
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg5n.sys
2011-01-01 18:55 . 2005-09-27 11:16 14944 ------w- c:\winnt\system32\drivers\wg4n.sys
2011-01-01 18:54 . 2011-01-01 18:54 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-01-01 18:37 . 2011-01-01 18:37 -------- d-----w- c:\winnt\Internet Logs
2010-12-31 14:36 . 2010-12-31 14:36 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-12-31 13:00 . 2010-12-31 13:00 -------- d-----w- c:\program files\Common Files\Skype
2010-12-31 13:00 . 2010-12-31 13:00 -------- d-----r- c:\program files\Skype
2010-12-30 21:01 . 2011-01-23 18:55 -------- d-----w- c:\documents and settings\pc\Data aplikací\skypePM
2010-12-30 21:00 . 2011-01-24 20:04 -------- d-----w- c:\documents and settings\pc\Data aplikací\Skype
2010-12-30 20:39 . 2010-12-31 13:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-31 14:35 . 2010-12-19 10:36 737280 ------w- c:\winnt\iun6002.exe
2010-12-17 11:51 . 2010-12-17 11:51 73216 ------w- c:\winnt\ST6UNST.EXE
2010-12-17 11:12 . 2010-12-17 11:12 58000 ------w- c:\winnt\system32\drivers\cdr4_2K.sys
2010-12-17 11:12 . 2010-12-17 11:12 57344 ------w- c:\winnt\uneng.exe
2010-12-17 11:12 . 2010-12-17 11:12 49152 ------w- c:\winnt\system32\cdrtc.dll
2010-12-17 11:12 . 2010-12-17 11:12 45056 ------w- c:\winnt\system32\cdral.dll
2010-12-17 11:12 . 2010-12-17 11:12 23420 ------w- c:\winnt\system32\drivers\cdralw2k.sys
.
------- Sigcheck -------
[-] 2004-05-13 23:19 . 1F51839ECCF908FD86558198909262E4 . 792064 . . [ERROR: 0x0] . . c:\winnt\system32\comres.dll
[-] 2003-02-01 11:09 . 9E1381B2DE2A23F8E4C22E814D55F475 . 52224 . . [ERROR: 0x0] . . c:\winnt\system32\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-01-26_12.47.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-26 19:14 . 2011-01-26 19:14 16384 c:\winnt\system32\Perflib_Perfdata_280.dat
+ 2011-01-26 15:36 . 2011-01-26 15:36 16384 c:\winnt\system32\Perflib_Perfdata_20c.dat
- 2011-01-26 12:36 . 2011-01-26 12:36 16384 c:\winnt\system32\Perflib_Perfdata_20c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2003-06-19 111888]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2005-06-21 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Cobian Backup 8"="c:\program files\Cobian Backup 8\Cobian.exe" [2007-09-27 501248]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 188688]
c:\documents and settings\pc\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2006-6-26 610304]
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.1.lnk]
path=c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\OpenOffice.org 2.1.lnk
backup=c:\winnt\pss\OpenOffice.org 2.1.lnkStartup
R0 sptd;sptd;c:\winnt\system32\drivers\sptd.sys [9.1.2011 17:38 717296]
R2 Active@ Disk Monitor;Active@ Disk Monitor;c:\program files\LSoft Technologies Inc\Active@ Hard Disk Monitor\DiskMonitorService.exe [23.12.2010 12:22 1464328]
R3 usbhub20;Podpora kořenového rozbočovač rozbočovače sběrnice USB 2.0;c:\winnt\system32\drivers\usbhub20.sys [16.12.2010 17:44 49776]
R3 ZD1211BU(Atheros);Atheros ZD1211B IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\winnt\system32\drivers\ZD1211BU.sys [11.4.2008 20:51 720896]
.
.
------- Doplňkový sken -------
.
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\fwegmscf.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-26 20:18
Windows 5.0.2195 Service Pack 4 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\winnt\system32\Perflib_Perfdata_274.dat 16384 bytes
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\pc\LOCALS~1\Temp\ASFWHide"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(216)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Celkový čas: 2011-01-26 20:20:25
ComboFix-quarantined-files.txt 2011-01-26 19:20
ComboFix2.txt 2011-01-26 12:49
Před spuštěním: Volných bajtů: 136 624 132 096
Po spuštění: Volných bajtů: 136 588 488 704
- - End Of File - - 99199A9A7C41A4FF74DE0BE9AE0C05C4