Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Napsal: 09 led 2012 21:25
ComboFix 12-01-07.03 - Jakub 09.01.2012 21:06:55.2.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4095.2467 [GMT 1:00]
Spuštěný z: c:\users\Jakub\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jakub\Desktop\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-09 do 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-09 20:13 . 2012-01-09 20:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-09 20:13 . 2012-01-09 20:13 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-01-08 15:36 . 2012-01-08 15:36 -------- d-----w- c:\windows\system32\appmgmt
2012-01-08 14:58 . 2012-01-08 14:58 -------- d-----w- C:\_usb_temp
2012-01-08 12:51 . 2012-01-08 13:10 -------- d-----w- C:\UsbFix
2012-01-08 09:00 . 2012-01-08 09:09 -------- d-----w- c:\program files\trend micro
2012-01-08 09:00 . 2012-01-08 09:24 -------- d-----w- C:\rsit
2012-01-06 18:09 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\mpengine.dll
2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\program files\Microsoft Games
2011-12-26 22:04 . 2011-12-26 22:21 -------- d-----w- c:\users\Jakub\AppData\Roaming\Mumble
2011-12-26 22:04 . 2011-12-26 22:04 -------- d-----w- c:\users\Jakub\AppData\Local\Mumble
2011-12-26 22:03 . 2011-12-26 22:03 -------- d-----w- c:\program files (x86)\Mumble
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\users\Jakub\Calibre knihovna
2011-12-26 10:25 . 2011-12-26 12:04 -------- d-----w- c:\users\Jakub\AppData\Roaming\calibre
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\program files (x86)\Calibre2
2011-12-18 13:06 . 2011-12-18 18:42 -------- d-----w- c:\users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 12:37 . 2011-12-18 12:37 -------- d-----w- c:\programdata\Apple Computer
2011-12-18 12:35 . 2011-12-18 12:35 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-12-18 12:34 . 2011-12-18 12:34 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-12-18 10:34 . 2011-12-18 10:34 -------- d-----w- c:\users\Jakub\AppData\Local\Apple Computer
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\users\Jakub\AppData\Local\Apple
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\programdata\Apple
2011-12-16 09:53 . 2011-12-16 09:53 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2011-12-16 09:53 . 2011-12-16 09:53 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2011-12-14 11:11 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 11:11 . 2011-11-05 05:26 1197568 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 11:11 . 2011-11-05 04:35 981504 ----a-w- c:\windows\SysWow64\wininet.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-08 13:10 . 2012-01-08 13:10 642733 ----a-w- C:\UsbFix_Upload_Me_COHENW7.zip
2011-11-15 13:29 . 2010-03-07 06:46 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-28 17:58 . 2011-10-28 17:58 230864 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-10-24 13:29 . 2011-10-24 13:29 94208 ------w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ------w- c:\windows\SysWow64\QuickTime.qts
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-08_11.27.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-01-09 20:15 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-09 20:15 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-09 20:15 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-03-05 15:15 . 2012-01-09 19:31 91306 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2012-01-08 10:44 41862 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-09 19:31 41862 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-04 18:55 . 2012-01-09 19:31 23802 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2794234989-373363643-3910967931-1000_UserData.bin
- 2010-03-04 18:55 . 2012-01-08 10:44 23802 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2794234989-373363643-3910967931-1000_UserData.bin
+ 2009-07-14 04:46 . 2012-01-09 19:33 87032 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-06-19 05:37 . 2012-01-08 11:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-19 05:37 . 2012-01-09 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-19 05:37 . 2012-01-08 11:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-19 05:37 . 2012-01-09 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-08 10:41 . 2012-01-08 10:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-09 20:15 . 2012-01-09 20:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-09 20:15 . 2012-01-09 20:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-08 10:41 . 2012-01-08 10:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-01-08 10:40 317472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-09 20:14 317472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:45 . 2012-01-02 10:37 3955864 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-01-09 19:32 3955864 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 02:34 . 2012-01-08 11:02 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-01-09 19:42 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"="c:\windows\system32\DeltaIITray.exe" [2009-07-27 236040]
"MRUTray"="c:\program files (x86)\Marvell\raid\tray\MarvellTray.exe" [2010-04-12 731176]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SC2RAR - Shortcut.lnk - c:\sc2raru10\SC2RAR\SC2RAR.exe [2010-12-15 76800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener;k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
R3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
R3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08);c:\program files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
R3 MSSQL$SQL08;SQL Server (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
R3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
R3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent;c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent;k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleServiceORCL11;OracleServiceORCL11;k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL11 [x]
R3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service;c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL [x]
R3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service;k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL11 [x]
R3 ReportServer$SQL08;SQL Server Reporting Services (SQL08);c:\program files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
R3 SQLAgent$SQL08;SQL Server Agent (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R4 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
R4 OracleJobSchedulerORCL;OracleJobSchedulerORCL;c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL [x]
R4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11;k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL11 [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 Marvell RAID;Marvell RAID Event Agent;c:\program files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
S2 MRUWebService;MRU Web Service;c:\program files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
S2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener;c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
S2 OracleServiceORCL;OracleServiceORCL;c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMwareHostd;VMware Host Agent;c:\program files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
S2 VMwareServerWebAccess;VMware Server Web Access;c:\program files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\DRIVERS\MAudioDelta.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\VMware\VMware Server\vsocklib.dll
Trusted Zone: cohenw7
TCP: DhcpNameServer = 192.168.10.1
Handler: qcom - {B8DBD265-42C3-43e6-B439-E968C71984C6} - c:\common~1\QUESTS~1\CODEXP~1\qcom.dll
DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574}
DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF}
FF - ProfilePath - c:\users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Digital Music Notebook: {0493D792-5C92-440b-81A8-AD6CDFC75212} - c:\program files (x86)\Yamaha Corporation\Digital Music Notebook\Common\Bootstrapper\XpCom
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-FCECAECourse_is1 - c:\program files (x86)\Edgard\FCE CAE Course\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1ClrAgent]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:c:\app\Jakub\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2ClrAgent]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:k:\oracle\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1TNSListener]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2TNSListener]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\VMware\VMware Server\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\windows\SysWOW64\DeltaIITray.exe
.
**************************************************************************
.
Celkový čas: 2012-01-09 21:21:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-09 20:21
ComboFix2.txt 2012-01-08 11:30
.
Před spuštěním: 105 877 798 912 bytes free
Po spuštění: 105 779 130 368 bytes free
.
- - End Of File - - A4C7B45545259587D2A796DB5201EAB5
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4095.2467 [GMT 1:00]
Spuštěný z: c:\users\Jakub\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jakub\Desktop\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-09 do 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-09 20:13 . 2012-01-09 20:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-09 20:13 . 2012-01-09 20:13 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-01-08 15:36 . 2012-01-08 15:36 -------- d-----w- c:\windows\system32\appmgmt
2012-01-08 14:58 . 2012-01-08 14:58 -------- d-----w- C:\_usb_temp
2012-01-08 12:51 . 2012-01-08 13:10 -------- d-----w- C:\UsbFix
2012-01-08 09:00 . 2012-01-08 09:09 -------- d-----w- c:\program files\trend micro
2012-01-08 09:00 . 2012-01-08 09:24 -------- d-----w- C:\rsit
2012-01-06 18:09 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\mpengine.dll
2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\program files\Microsoft Games
2011-12-26 22:04 . 2011-12-26 22:21 -------- d-----w- c:\users\Jakub\AppData\Roaming\Mumble
2011-12-26 22:04 . 2011-12-26 22:04 -------- d-----w- c:\users\Jakub\AppData\Local\Mumble
2011-12-26 22:03 . 2011-12-26 22:03 -------- d-----w- c:\program files (x86)\Mumble
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\users\Jakub\Calibre knihovna
2011-12-26 10:25 . 2011-12-26 12:04 -------- d-----w- c:\users\Jakub\AppData\Roaming\calibre
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\program files (x86)\Calibre2
2011-12-18 13:06 . 2011-12-18 18:42 -------- d-----w- c:\users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 12:37 . 2011-12-18 12:37 -------- d-----w- c:\programdata\Apple Computer
2011-12-18 12:35 . 2011-12-18 12:35 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-12-18 12:34 . 2011-12-18 12:34 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-12-18 10:34 . 2011-12-18 10:34 -------- d-----w- c:\users\Jakub\AppData\Local\Apple Computer
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\users\Jakub\AppData\Local\Apple
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\programdata\Apple
2011-12-16 09:53 . 2011-12-16 09:53 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2011-12-16 09:53 . 2011-12-16 09:53 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2011-12-14 11:11 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 11:11 . 2011-11-05 05:26 1197568 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 11:11 . 2011-11-05 04:35 981504 ----a-w- c:\windows\SysWow64\wininet.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-08 13:10 . 2012-01-08 13:10 642733 ----a-w- C:\UsbFix_Upload_Me_COHENW7.zip
2011-11-15 13:29 . 2010-03-07 06:46 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-28 17:58 . 2011-10-28 17:58 230864 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-10-24 13:29 . 2011-10-24 13:29 94208 ------w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ------w- c:\windows\SysWow64\QuickTime.qts
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-08_11.27.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-01-09 20:15 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-09 20:15 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-09 20:15 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-08 10:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-03-05 15:15 . 2012-01-09 19:31 91306 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2012-01-08 10:44 41862 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-09 19:31 41862 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-04 18:55 . 2012-01-09 19:31 23802 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2794234989-373363643-3910967931-1000_UserData.bin
- 2010-03-04 18:55 . 2012-01-08 10:44 23802 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2794234989-373363643-3910967931-1000_UserData.bin
+ 2009-07-14 04:46 . 2012-01-09 19:33 87032 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-06-19 05:37 . 2012-01-08 11:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-19 05:37 . 2012-01-09 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-19 05:37 . 2012-01-08 11:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-19 05:37 . 2012-01-09 20:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-08 10:41 . 2012-01-08 10:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-09 20:15 . 2012-01-09 20:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-09 20:15 . 2012-01-09 20:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-08 10:41 . 2012-01-08 10:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-01-08 10:40 317472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-09 20:14 317472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:45 . 2012-01-02 10:37 3955864 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-01-09 19:32 3955864 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 02:34 . 2012-01-08 11:02 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-01-09 19:42 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"="c:\windows\system32\DeltaIITray.exe" [2009-07-27 236040]
"MRUTray"="c:\program files (x86)\Marvell\raid\tray\MarvellTray.exe" [2010-04-12 731176]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SC2RAR - Shortcut.lnk - c:\sc2raru10\SC2RAR\SC2RAR.exe [2010-12-15 76800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener;k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
R3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
R3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08);c:\program files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
R3 MSSQL$SQL08;SQL Server (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
R3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
R3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent;c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent;k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleServiceORCL11;OracleServiceORCL11;k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL11 [x]
R3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service;c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL [x]
R3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service;k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL11 [x]
R3 ReportServer$SQL08;SQL Server Reporting Services (SQL08);c:\program files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
R3 SQLAgent$SQL08;SQL Server Agent (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R4 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
R4 OracleJobSchedulerORCL;OracleJobSchedulerORCL;c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL [x]
R4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11;k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL11 [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 Marvell RAID;Marvell RAID Event Agent;c:\program files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
S2 MRUWebService;MRU Web Service;c:\program files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
S2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener;c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
S2 OracleServiceORCL;OracleServiceORCL;c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMwareHostd;VMware Host Agent;c:\program files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
S2 VMwareServerWebAccess;VMware Server Web Access;c:\program files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\DRIVERS\MAudioDelta.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\VMware\VMware Server\vsocklib.dll
Trusted Zone: cohenw7
TCP: DhcpNameServer = 192.168.10.1
Handler: qcom - {B8DBD265-42C3-43e6-B439-E968C71984C6} - c:\common~1\QUESTS~1\CODEXP~1\qcom.dll
DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574}
DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF}
FF - ProfilePath - c:\users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Digital Music Notebook: {0493D792-5C92-440b-81A8-AD6CDFC75212} - c:\program files (x86)\Yamaha Corporation\Digital Music Notebook\Common\Bootstrapper\XpCom
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-FCECAECourse_is1 - c:\program files (x86)\Edgard\FCE CAE Course\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1ClrAgent]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:c:\app\Jakub\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2ClrAgent]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:k:\oracle\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1TNSListener]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2TNSListener]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\VMware\VMware Server\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\windows\SysWOW64\DeltaIITray.exe
.
**************************************************************************
.
Celkový čas: 2012-01-09 21:21:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-09 20:21
ComboFix2.txt 2012-01-08 11:30
.
Před spuštěním: 105 877 798 912 bytes free
Po spuštění: 105 779 130 368 bytes free
.
- - End Of File - - A4C7B45545259587D2A796DB5201EAB5