Re: Havěť - pravděpodbně vir z FB
Napsal: 19 srp 2011 22:38
ComboFix 11-08-19.02 - Martina Dreslerová 19.08.2011 23:16:51.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1014.504 [GMT 2:00]
Spuštěný z: c:\documents and settings\Martina Dreslerová\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Martina Dreslerová\Plocha\CFScript.txt
AV: Eset NOD32 Antivirus 2.70 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\program files\GOMPLAYERENSETUP.EXE"
"c:\program files\SoftonicDownloader_for_vlc-media-player.exe"
"c:\windows\l1rezerv.exe"
"c:\windows\systemup.exe"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ConduitEngine
c:\program files\ConduitEngine\appContextMenu.xml
c:\program files\ConduitEngine\ConduitEngine.dll
c:\program files\ConduitEngine\ConduitEngineHelper.exe
c:\program files\ConduitEngine\ConduitEngineUninstall.exe
c:\program files\ConduitEngine\engineContextMenu.xml
c:\program files\ConduitEngine\EngineSettings.json
c:\program files\ConduitEngine\INSTALL.LOG
c:\program files\ConduitEngine\toolbar.cfg
c:\windows\update.7.1
c:\windows\update.7.1\svchostdriver.exe
c:\windows\update.tray-3-0
c:\windows\update.tray-3-0\svchost.exe
E:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DDSERVICE
-------\Service_ddservice
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-19 do 2011-08-19 )))))))))))))))))))))))))))))))
.
.
2011-08-19 20:09 . 2011-08-19 20:09 -------- d-----w- c:\documents and settings\Administrator
2011-08-19 19:55 . 2011-08-19 19:55 -------- d-----w- C:\_OTL
2011-08-19 19:30 . 2011-08-19 19:30 512 ----a-w- C:\PhysicalMBR.bin
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\documents and settings\Martina Dreslerová\Data aplikací\Malwarebytes
2011-08-19 16:43 . 2010-11-29 15:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-08-19 16:43 . 2010-11-29 15:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-19 14:03 . 2011-08-19 14:04 -------- d-----w- c:\program files\trend micro
2011-08-19 14:03 . 2011-08-19 14:04 -------- d-----w- C:\rsit
2011-08-19 12:09 . 2011-08-19 12:09 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-08-04 07:53 . 2011-08-04 07:53 -------- d-----w- c:\program files\SHARP
2011-08-04 07:52 . 2008-10-29 12:18 98304 ----a-w- c:\windows\system32\SN0ELMON.dll
2011-08-04 07:52 . 2007-04-17 14:11 45056 ----a-w- c:\windows\system32\SN0EMTNT.dll
2011-08-04 07:52 . 2009-05-22 09:35 159836 ----a-w- c:\windows\_isusr32.dll
2011-08-04 07:52 . 2004-04-12 14:17 45056 ------w- c:\windows\system32\_isusr2k.dll
2011-08-04 07:52 . 2009-01-29 14:36 77492 ----a-w- c:\windows\system32\SCN2PM.dll
2011-08-04 07:52 . 2007-05-31 15:00 51855 ----a-w- c:\windows\system32\SCN2PMUI.dll
2011-08-04 07:52 . 2006-02-06 09:24 53248 ----a-w- c:\windows\system32\SCN2PMR.dll
2011-08-04 07:51 . 2011-08-04 07:52 -------- d-----w- c:\windows\system32\SCDRV
2011-08-04 07:51 . 2011-08-04 07:51 -------- d-----w- C:\Drivers
2011-07-24 08:10 . 2011-07-24 08:10 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-22 09:32 . 2011-07-22 09:32 -------- d-----w- c:\documents and settings\Martina Dreslerová\Data aplikací\HypoKalk
2011-07-22 09:31 . 2011-07-22 09:31 -------- d-----w- c:\program files\Komerční Banka
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 08:39 . 2011-07-19 08:12 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-19 08:31 . 2011-07-19 07:59 246272 ----a-w- c:\windows\unrar.exe
2011-07-19 08:12 . 2011-07-19 08:12 114176 ----a-w- c:\windows\systemup.exe
2011-07-15 13:29 . 2009-12-23 18:07 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2009-12-23 18:07 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2009-12-24 02:16 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2009-12-23 18:07 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2009-12-23 18:07 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2009-12-23 18:07 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2009-12-23 18:07 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2009-12-23 18:07 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2009-12-23 18:07 1858944 ----a-w- c:\windows\system32\win32k.sys
2010-12-04 22:01 . 2010-12-04 22:01 293160 ----a-w- c:\program files\SoftonicDownloader_for_vlc-media-player.exe
2010-10-15 13:04 . 2010-10-15 13:04 7271080 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-19_20.43.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-19 21:24 . 2011-08-19 21:24 16384 c:\windows\Temp\Perflib_Perfdata_604.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"ICQ"="c:\program files\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2010-03-25 402096]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-28 173592]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2010-01-29 751592]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-11-19 83240]
"ASUSPRP"="c:\program files\ASUS\APRP\APRP.EXE" [2010-05-12 2018032]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"CapsHook"="c:\program files\EeePC\CapsHook\CapsHook.exe" [2010-05-28 445344]
"RTHDCPL"="RTHDCPL.EXE" [2010-04-27 19523616]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-06-26 118784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-05-08 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-11-19 1594664]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-28 141336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2010-05-17 1246632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Martina Dreslerov \Nabˇdka Start\Programy\Po spuçtŘnˇ\
Lingea Update Center.lnk - c:\program files\Common Files\Lingea Shared\luc.exe [2010-11-14 275736]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2010-3-18 385024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Martina Dreslerová^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Martina Dreslerová\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
"24654:TCP"= 24654:TCP:BitComet 24654 TCP
"24654:UDP"= 24654:UDP:BitComet 24654 UDP
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [18.3.2010 1:51 11520]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [26.9.2010 22:15 15424]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [3.11.2009 10:34 44032]
R3 rtsuvc;Realtek USB2.0 PC Camera;c:\windows\system32\drivers\rtsuvc.sys [31.8.2010 0:29 73088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [31.8.2010 0:28 1691480]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [23.12.2009 20:07 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-conduitEngine - c:\progra~1\CONDUI~1\ConduitEngineUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-19 23:25
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3776)
c:\windows\system32\webcheck.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Celkový čas: 2011-08-19 23:28:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-19 21:28
ComboFix2.txt 2011-08-19 20:48
.
Před spuštěním: Volných bajtů: 43 360 657 408
Po spuštění: Volných bajtů: 43 329 122 304
.
- - End Of File - - 81E0384C8E77F8957BEA7EAF1F65E73D
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1014.504 [GMT 2:00]
Spuštěný z: c:\documents and settings\Martina Dreslerová\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Martina Dreslerová\Plocha\CFScript.txt
AV: Eset NOD32 Antivirus 2.70 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\program files\GOMPLAYERENSETUP.EXE"
"c:\program files\SoftonicDownloader_for_vlc-media-player.exe"
"c:\windows\l1rezerv.exe"
"c:\windows\systemup.exe"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ConduitEngine
c:\program files\ConduitEngine\appContextMenu.xml
c:\program files\ConduitEngine\ConduitEngine.dll
c:\program files\ConduitEngine\ConduitEngineHelper.exe
c:\program files\ConduitEngine\ConduitEngineUninstall.exe
c:\program files\ConduitEngine\engineContextMenu.xml
c:\program files\ConduitEngine\EngineSettings.json
c:\program files\ConduitEngine\INSTALL.LOG
c:\program files\ConduitEngine\toolbar.cfg
c:\windows\update.7.1
c:\windows\update.7.1\svchostdriver.exe
c:\windows\update.tray-3-0
c:\windows\update.tray-3-0\svchost.exe
E:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DDSERVICE
-------\Service_ddservice
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-19 do 2011-08-19 )))))))))))))))))))))))))))))))
.
.
2011-08-19 20:09 . 2011-08-19 20:09 -------- d-----w- c:\documents and settings\Administrator
2011-08-19 19:55 . 2011-08-19 19:55 -------- d-----w- C:\_OTL
2011-08-19 19:30 . 2011-08-19 19:30 512 ----a-w- C:\PhysicalMBR.bin
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\documents and settings\Martina Dreslerová\Data aplikací\Malwarebytes
2011-08-19 16:43 . 2010-11-29 15:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-08-19 16:43 . 2010-11-29 15:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-19 16:43 . 2011-08-19 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-19 14:03 . 2011-08-19 14:04 -------- d-----w- c:\program files\trend micro
2011-08-19 14:03 . 2011-08-19 14:04 -------- d-----w- C:\rsit
2011-08-19 12:09 . 2011-08-19 12:09 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-08-04 07:53 . 2011-08-04 07:53 -------- d-----w- c:\program files\SHARP
2011-08-04 07:52 . 2008-10-29 12:18 98304 ----a-w- c:\windows\system32\SN0ELMON.dll
2011-08-04 07:52 . 2007-04-17 14:11 45056 ----a-w- c:\windows\system32\SN0EMTNT.dll
2011-08-04 07:52 . 2009-05-22 09:35 159836 ----a-w- c:\windows\_isusr32.dll
2011-08-04 07:52 . 2004-04-12 14:17 45056 ------w- c:\windows\system32\_isusr2k.dll
2011-08-04 07:52 . 2009-01-29 14:36 77492 ----a-w- c:\windows\system32\SCN2PM.dll
2011-08-04 07:52 . 2007-05-31 15:00 51855 ----a-w- c:\windows\system32\SCN2PMUI.dll
2011-08-04 07:52 . 2006-02-06 09:24 53248 ----a-w- c:\windows\system32\SCN2PMR.dll
2011-08-04 07:51 . 2011-08-04 07:52 -------- d-----w- c:\windows\system32\SCDRV
2011-08-04 07:51 . 2011-08-04 07:51 -------- d-----w- C:\Drivers
2011-07-24 08:10 . 2011-07-24 08:10 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-22 09:32 . 2011-07-22 09:32 -------- d-----w- c:\documents and settings\Martina Dreslerová\Data aplikací\HypoKalk
2011-07-22 09:31 . 2011-07-22 09:31 -------- d-----w- c:\program files\Komerční Banka
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 08:39 . 2011-07-19 08:12 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-19 08:31 . 2011-07-19 07:59 246272 ----a-w- c:\windows\unrar.exe
2011-07-19 08:12 . 2011-07-19 08:12 114176 ----a-w- c:\windows\systemup.exe
2011-07-15 13:29 . 2009-12-23 18:07 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2009-12-23 18:07 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2009-12-24 02:16 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2009-12-23 18:07 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2009-12-23 18:07 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2009-12-23 18:07 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2009-12-23 18:07 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2009-12-23 18:07 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2009-12-23 18:07 1858944 ----a-w- c:\windows\system32\win32k.sys
2010-12-04 22:01 . 2010-12-04 22:01 293160 ----a-w- c:\program files\SoftonicDownloader_for_vlc-media-player.exe
2010-10-15 13:04 . 2010-10-15 13:04 7271080 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-19_20.43.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-19 21:24 . 2011-08-19 21:24 16384 c:\windows\Temp\Perflib_Perfdata_604.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"ICQ"="c:\program files\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2010-03-25 402096]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-28 173592]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2010-01-29 751592]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-11-19 83240]
"ASUSPRP"="c:\program files\ASUS\APRP\APRP.EXE" [2010-05-12 2018032]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"CapsHook"="c:\program files\EeePC\CapsHook\CapsHook.exe" [2010-05-28 445344]
"RTHDCPL"="RTHDCPL.EXE" [2010-04-27 19523616]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-06-26 118784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-05-08 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-11-19 1594664]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-28 141336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2010-05-17 1246632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Martina Dreslerov \Nabˇdka Start\Programy\Po spuçtŘnˇ\
Lingea Update Center.lnk - c:\program files\Common Files\Lingea Shared\luc.exe [2010-11-14 275736]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2010-3-18 385024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Martina Dreslerová^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Martina Dreslerová\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
"24654:TCP"= 24654:TCP:BitComet 24654 TCP
"24654:UDP"= 24654:UDP:BitComet 24654 UDP
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [18.3.2010 1:51 11520]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [26.9.2010 22:15 15424]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [3.11.2009 10:34 44032]
R3 rtsuvc;Realtek USB2.0 PC Camera;c:\windows\system32\drivers\rtsuvc.sys [31.8.2010 0:29 73088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [31.8.2010 0:28 1691480]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [23.12.2009 20:07 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-conduitEngine - c:\progra~1\CONDUI~1\ConduitEngineUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-19 23:25
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3776)
c:\windows\system32\webcheck.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Celkový čas: 2011-08-19 23:28:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-19 21:28
ComboFix2.txt 2011-08-19 20:48
.
Před spuštěním: Volných bajtů: 43 360 657 408
Po spuštění: Volných bajtů: 43 329 122 304
.
- - End Of File - - 81E0384C8E77F8957BEA7EAF1F65E73D