Re: fb virus
Napsal: 25 srp 2011 03:54
Combofix uz prebehol myslim v pohode, log:
ComboFix 11-08-24.06 - Renuska-mini . 08. 2011 4:31.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.726 [GMT 2:00]
Spuštěný z: c:\documents and settings\Renuska-mini\Dokumenty\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB4742$
c:\windows\$NtUninstallKB4742$\2132906584\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB4742$\2132906584\click.tlb
c:\windows\$NtUninstallKB4742$\2132906584\L\uxbbzgnt
c:\windows\$NtUninstallKB4742$\2132906584\loader.tlb
c:\windows\$NtUninstallKB4742$\2132906584\U\@00000001
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000c0
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000cb
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000cf
c:\windows\$NtUninstallKB4742$\2132906584\U\@80000000
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000c0
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000cb
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000cf
c:\windows\$NtUninstallKB4742$\860576131
c:\windows\system32\c_61613.nls
.
Nakažená kopie c:\windows\system32\drivers\redbook.sys byla nalezena a vyléčena.
Obnovena kopie z - The cat found it
Nakažená kopie c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067223.exe
.
Nakažená kopie c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067215.exe
.
Nakažená kopie c:\program files\iPod\bin\iPodService.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067214.exe
.
Nakažená kopie c:\windows\system32\wuauclt.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\wuauclt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DDSERVICE
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_WINRING0_1_0_1
-------\Service_7f219258
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-25 do 2011-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-11 22:14 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-08-11 22:13 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2013-08-11 22:13 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2013-08-11 22:13 . 2008-04-14 06:52 16384 ----a-w- c:\windows\system32\ipsink.ax
2013-08-11 22:13 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2013-08-11 22:12 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2013-08-11 22:12 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2013-08-11 22:12 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2013-08-11 22:12 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2013-08-11 22:12 . 2008-04-14 06:52 91648 ----a-w- c:\windows\system32\kswdmcap.ax
2013-08-11 22:12 . 2008-04-14 06:52 28672 ----a-w- c:\windows\system32\vidcap.ax
2013-08-11 22:12 . 2008-04-14 06:52 61952 ----a-w- c:\windows\system32\kstvtune.ax
2013-08-11 22:12 . 2008-04-14 06:52 20992 ----a-w- c:\windows\system32\dshowext.ax
2013-08-11 22:12 . 2008-04-14 06:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-13 22:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-08-11 22:12 . 2008-04-14 06:52 43008 ----a-w- c:\windows\system32\ksxbar.ax
2013-08-11 22:12 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-18 08:11 . 2008-08-19 20:16 47272 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-09-18 08:11 . 2008-07-24 15:37 156816 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-09-18 08:11 . 2007-09-20 09:59 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-09-18 08:10 . 2008-08-19 20:16 991656 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-09-18 08:10 . 2008-05-30 09:46 534568 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-09-18 08:10 . 2008-02-04 15:57 37160 ----a-w- c:\windows\system32\drivers\btport.sys
2012-09-18 08:10 . 2012-09-18 08:10 -------- d-----w- c:\program files\WIDCOMM
2011-09-11 15:59 . 2011-09-11 15:59 -------- d-----w- c:\program files\EeePC
2011-09-11 15:59 . 2008-04-08 13:59 10752 ----a-w- c:\windows\system32\drivers\ASUSACPI.SYS
2011-09-11 15:17 . 2011-09-11 15:17 -------- d-----w- c:\program files\Elantech
2011-08-25 02:11 . 2008-04-14 05:44 58496 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2011-08-25 02:11 . 2008-04-14 05:44 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-08-23 13:03 . 2011-08-23 13:03 -------- d-----w- C:\_OTM
2011-08-23 02:07 . 2011-08-23 02:07 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Malwarebytes
2011-08-23 02:07 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-23 02:07 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-23 01:57 . 2011-08-23 01:57 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\ICQ
2011-08-23 01:54 . 2011-08-23 01:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Opera
2011-08-23 01:50 . 2011-08-23 01:50 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\Malwarebytes
2011-08-23 01:50 . 2011-08-23 01:50 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-08-23 01:50 . 2011-08-23 02:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-23 01:45 . 2011-08-23 01:45 -------- d--h--w- c:\windows\PIF
2011-08-21 01:52 . 2011-08-21 01:52 -------- d-----w- c:\program files\trend micro
2011-08-21 01:52 . 2011-08-21 01:53 -------- d-----w- C:\rsit
2011-08-20 01:43 . 2011-08-23 01:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-20 01:43 . 2011-08-23 01:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-08-20 01:37 . 2011-08-20 01:37 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-08-20 01:16 . 2011-08-20 01:16 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
2011-08-19 12:36 . 2011-08-12 02:44 7152464 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5EECDACE-63CF-4C98-A50E-CD6E9A58C2FF}\mpengine.dll
2011-08-18 12:03 . 2011-08-18 12:03 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\skypePM
2011-08-09 13:22 . 2011-07-13 03:39 6881616 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-06 00:52 . 2011-08-06 00:52 -------- d-----w- c:\program files\Yontoo Layers Runtime
2011-08-06 00:52 . 2011-08-06 00:52 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2011-08-06 00:51 . 2011-08-06 00:51 -------- d-----w- c:\program files\FoxTabMP3Converter
2011-08-01 02:37 . 2011-08-01 02:37 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Apple Computer
2011-08-01 01:20 . 2011-08-01 02:38 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\Apple Computer
2011-08-01 01:19 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-01 01:19 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-08-01 01:18 . 2011-08-01 01:18 -------- d-----w- c:\program files\iPod
2011-08-01 01:18 . 2011-08-01 01:19 -------- d-----w- c:\program files\iTunes
2011-08-01 01:18 . 2011-08-01 01:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-08-01 01:16 . 2011-08-01 01:17 -------- d-----w- c:\program files\QuickTime
2011-08-01 01:16 . 2011-08-01 01:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple Computer
2011-08-01 01:15 . 2011-08-01 01:15 -------- d-----w- c:\documents and settings\Renuska-mini\Local Settings\Data aplikací\Apple
2011-08-01 01:15 . 2011-08-01 01:15 -------- d-----w- c:\program files\Apple Software Update
2011-08-01 01:15 . 2011-05-10 06:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-08-01 01:15 . 2011-05-10 06:06 42496 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-08-01 01:14 . 2011-08-01 01:14 -------- d-----w- c:\program files\Bonjour
2011-08-01 01:14 . 2011-08-01 02:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple
2011-08-01 01:14 . 2011-08-01 01:18 -------- d-----w- c:\program files\Common Files\Apple
2011-08-01 01:12 . 2011-08-01 01:20 -------- d-----w- c:\documents and settings\Renuska-mini\Local Settings\Data aplikací\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 12:52 . 2011-07-14 13:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-12 02:44 . 2010-01-01 21:27 7152464 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-15 13:29 . 2008-08-07 03:49 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2008-08-07 03:50 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 19:30 . 2011-07-05 19:30 38320 ----a-w- c:\windows\system32\f3PSSavr.scr
2011-06-24 14:10 . 2008-08-07 02:05 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2008-08-07 03:50 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2008-08-07 03:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2008-08-07 03:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2008-08-07 03:49 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2008-08-07 03:50 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2008-08-07 03:50 1858944 ----a-w- c:\windows\system32\win32k.sys
2008-05-07 14:34 . 2008-08-07 22:20 15523560 ----a-w- c:\program files\U1 Setup.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 ----a-w- c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-09-03 335872]
"ETDWareDetect"="c:\program files\Elantech\ETDDect.exe" [2008-08-22 204800]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-09-02 106496]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-09-02 593920]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 16806912]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2011-9-11 311296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17. 10. 2009 23:28 717296]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [7. 8. 2008 23:54 625024]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1 71.252.0.12
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-MSC - c:\program files\Microsoft Security Client\msseces.exe
AddRemove-Microsoft Security Client - c:\program files\Microsoft Security Client\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-25 04:46
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\btmmhook.dll
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\program files\eee storage\xpclient.dll
c:\program files\eee storage\logicnp.eznamespaceextensions.dll
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2011-08-25 04:51:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-25 02:51
.
Před spuštěním: Volných bajtů: 59 824 746 496
Po spuštění: Volných bajtů: 60 149 870 592
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - B4AEDF966E6F5333445F3678C9F7405A
ComboFix 11-08-24.06 - Renuska-mini . 08. 2011 4:31.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.726 [GMT 2:00]
Spuštěný z: c:\documents and settings\Renuska-mini\Dokumenty\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB4742$
c:\windows\$NtUninstallKB4742$\2132906584\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB4742$\2132906584\click.tlb
c:\windows\$NtUninstallKB4742$\2132906584\L\uxbbzgnt
c:\windows\$NtUninstallKB4742$\2132906584\loader.tlb
c:\windows\$NtUninstallKB4742$\2132906584\U\@00000001
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000c0
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000cb
c:\windows\$NtUninstallKB4742$\2132906584\U\@000000cf
c:\windows\$NtUninstallKB4742$\2132906584\U\@80000000
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000c0
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000cb
c:\windows\$NtUninstallKB4742$\2132906584\U\@800000cf
c:\windows\$NtUninstallKB4742$\860576131
c:\windows\system32\c_61613.nls
.
Nakažená kopie c:\windows\system32\drivers\redbook.sys byla nalezena a vyléčena.
Obnovena kopie z - The cat found it

Nakažená kopie c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067223.exe
.
Nakažená kopie c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067215.exe
.
Nakažená kopie c:\program files\iPod\bin\iPodService.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{496A63E4-4524-4BE9-A822-0155887443DF}\RP309\A0067214.exe
.
Nakažená kopie c:\windows\system32\wuauclt.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\wuauclt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DDSERVICE
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_WINRING0_1_0_1
-------\Service_7f219258
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-25 do 2011-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-11 22:14 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-08-11 22:13 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2013-08-11 22:13 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2013-08-11 22:13 . 2008-04-14 06:52 16384 ----a-w- c:\windows\system32\ipsink.ax
2013-08-11 22:13 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2013-08-11 22:12 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2013-08-11 22:12 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2013-08-11 22:12 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2013-08-11 22:12 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2013-08-11 22:12 . 2008-04-14 06:52 91648 ----a-w- c:\windows\system32\kswdmcap.ax
2013-08-11 22:12 . 2008-04-14 06:52 28672 ----a-w- c:\windows\system32\vidcap.ax
2013-08-11 22:12 . 2008-04-14 06:52 61952 ----a-w- c:\windows\system32\kstvtune.ax
2013-08-11 22:12 . 2008-04-14 06:52 20992 ----a-w- c:\windows\system32\dshowext.ax
2013-08-11 22:12 . 2008-04-14 06:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-13 22:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-08-11 22:12 . 2008-04-14 06:52 43008 ----a-w- c:\windows\system32\ksxbar.ax
2013-08-11 22:12 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-18 08:11 . 2008-08-19 20:16 47272 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-09-18 08:11 . 2008-07-24 15:37 156816 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-09-18 08:11 . 2007-09-20 09:59 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-09-18 08:10 . 2008-08-19 20:16 991656 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-09-18 08:10 . 2008-05-30 09:46 534568 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-09-18 08:10 . 2008-02-04 15:57 37160 ----a-w- c:\windows\system32\drivers\btport.sys
2012-09-18 08:10 . 2012-09-18 08:10 -------- d-----w- c:\program files\WIDCOMM
2011-09-11 15:59 . 2011-09-11 15:59 -------- d-----w- c:\program files\EeePC
2011-09-11 15:59 . 2008-04-08 13:59 10752 ----a-w- c:\windows\system32\drivers\ASUSACPI.SYS
2011-09-11 15:17 . 2011-09-11 15:17 -------- d-----w- c:\program files\Elantech
2011-08-25 02:11 . 2008-04-14 05:44 58496 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2011-08-25 02:11 . 2008-04-14 05:44 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-08-23 13:03 . 2011-08-23 13:03 -------- d-----w- C:\_OTM
2011-08-23 02:07 . 2011-08-23 02:07 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Malwarebytes
2011-08-23 02:07 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-23 02:07 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-23 01:57 . 2011-08-23 01:57 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\ICQ
2011-08-23 01:54 . 2011-08-23 01:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Opera
2011-08-23 01:50 . 2011-08-23 01:50 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\Malwarebytes
2011-08-23 01:50 . 2011-08-23 01:50 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-08-23 01:50 . 2011-08-23 02:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-23 01:45 . 2011-08-23 01:45 -------- d--h--w- c:\windows\PIF
2011-08-21 01:52 . 2011-08-21 01:52 -------- d-----w- c:\program files\trend micro
2011-08-21 01:52 . 2011-08-21 01:53 -------- d-----w- C:\rsit
2011-08-20 01:43 . 2011-08-23 01:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-20 01:43 . 2011-08-23 01:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-08-20 01:37 . 2011-08-20 01:37 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-08-20 01:16 . 2011-08-20 01:16 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
2011-08-19 12:36 . 2011-08-12 02:44 7152464 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5EECDACE-63CF-4C98-A50E-CD6E9A58C2FF}\mpengine.dll
2011-08-18 12:03 . 2011-08-18 12:03 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\skypePM
2011-08-09 13:22 . 2011-07-13 03:39 6881616 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-06 00:52 . 2011-08-06 00:52 -------- d-----w- c:\program files\Yontoo Layers Runtime
2011-08-06 00:52 . 2011-08-06 00:52 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2011-08-06 00:51 . 2011-08-06 00:51 -------- d-----w- c:\program files\FoxTabMP3Converter
2011-08-01 02:37 . 2011-08-01 02:37 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Apple Computer
2011-08-01 01:20 . 2011-08-01 02:38 -------- d-----w- c:\documents and settings\Renuska-mini\Data aplikací\Apple Computer
2011-08-01 01:19 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-01 01:19 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-08-01 01:18 . 2011-08-01 01:18 -------- d-----w- c:\program files\iPod
2011-08-01 01:18 . 2011-08-01 01:19 -------- d-----w- c:\program files\iTunes
2011-08-01 01:18 . 2011-08-01 01:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-08-01 01:17 . 2011-08-01 01:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-08-01 01:16 . 2011-08-01 01:17 -------- d-----w- c:\program files\QuickTime
2011-08-01 01:16 . 2011-08-01 01:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple Computer
2011-08-01 01:15 . 2011-08-01 01:15 -------- d-----w- c:\documents and settings\Renuska-mini\Local Settings\Data aplikací\Apple
2011-08-01 01:15 . 2011-08-01 01:15 -------- d-----w- c:\program files\Apple Software Update
2011-08-01 01:15 . 2011-05-10 06:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-08-01 01:15 . 2011-05-10 06:06 42496 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-08-01 01:14 . 2011-08-01 01:14 -------- d-----w- c:\program files\Bonjour
2011-08-01 01:14 . 2011-08-01 02:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple
2011-08-01 01:14 . 2011-08-01 01:18 -------- d-----w- c:\program files\Common Files\Apple
2011-08-01 01:12 . 2011-08-01 01:20 -------- d-----w- c:\documents and settings\Renuska-mini\Local Settings\Data aplikací\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 12:52 . 2011-07-14 13:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-12 02:44 . 2010-01-01 21:27 7152464 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-15 13:29 . 2008-08-07 03:49 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2008-08-07 03:50 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 19:30 . 2011-07-05 19:30 38320 ----a-w- c:\windows\system32\f3PSSavr.scr
2011-06-24 14:10 . 2008-08-07 02:05 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2008-08-07 03:50 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2008-08-07 03:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2008-08-07 03:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2008-08-07 03:49 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2008-08-07 03:50 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2008-08-07 03:50 1858944 ----a-w- c:\windows\system32\win32k.sys
2008-05-07 14:34 . 2008-08-07 22:20 15523560 ----a-w- c:\program files\U1 Setup.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 ----a-w- c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-09-03 335872]
"ETDWareDetect"="c:\program files\Elantech\ETDDect.exe" [2008-08-22 204800]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-09-02 106496]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-09-02 593920]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 16806912]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2011-9-11 311296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17. 10. 2009 23:28 717296]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [7. 8. 2008 23:54 625024]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1 71.252.0.12
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-MSC - c:\program files\Microsoft Security Client\msseces.exe
AddRemove-Microsoft Security Client - c:\program files\Microsoft Security Client\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-25 04:46
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\btmmhook.dll
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\program files\eee storage\xpclient.dll
c:\program files\eee storage\logicnp.eznamespaceextensions.dll
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2011-08-25 04:51:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-25 02:51
.
Před spuštěním: Volných bajtů: 59 824 746 496
Po spuštění: Volných bajtů: 60 149 870 592
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - B4AEDF966E6F5333445F3678C9F7405A