Re: Pravdepodobne vírus
Napsal: 16 srp 2012 14:36
Tu sú odkazy:
https://www.virustotal.com/file/37757bc ... 345123580/
https://www.virustotal.com/file/d16c571 ... 345123722/
https://www.virustotal.com/file/662d185 ... 345123886/
A tu je log:
SystemLook 30.07.11 by jpshortstuff
Log created at 15:33 on 16/08/2012 by Mato
Administrator - Elevation successful
========== folderfind ==========
Searching for "Akamai"
C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai d------ [07:05 05/04/2012]
========== regfind ==========
Searching for "Akamai"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\020079C0CE4AC02EED1888A2AE8CE447]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\0C42A6CD31370C8B4C429F1D10D847E7]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\admintool.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\18E8444AC870505B88DF1F2634E2B91E]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\accepteula.txt"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\438DC116E50D44649EE9CD814DD086DB]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Akamai\client"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\580682D1C0159847CCEC037C03087E26]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\client.ini"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\5B0A6CB367C495325A48DA1AB46E4E93]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\user.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\70F555577657DA47AE56C133D2D294E8]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\InstallLocation"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\8D541BF13BA1EE09CD1F6EA7B1FBFC67]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\UninstallString"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\AFAF4DC50343A11A1551AF29AEA69F90]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\C5E5634748AA8DC5623BE48DDFCF8A04]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\rswinui.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\DB748F92982DAED6D441C930AEC1DA8B]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E1B47BBDD70D8978E1D52D309B624221]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\ControlPanel_Installer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E34EEFC4F89581706B658D492BF98506]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\DisplayName"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E8B49D60B33C29DBB0BF46CF7F6AD30F]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\installer_uploader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\EACBC0EA4AB8DFC69FB2AD55A009EF37]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\Publisher"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="Akamai NetSession Client"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="Akamai NetSession Client"
-= EOF =-
https://www.virustotal.com/file/37757bc ... 345123580/
https://www.virustotal.com/file/d16c571 ... 345123722/
https://www.virustotal.com/file/662d185 ... 345123886/
A tu je log:
SystemLook 30.07.11 by jpshortstuff
Log created at 15:33 on 16/08/2012 by Mato
Administrator - Elevation successful
========== folderfind ==========
Searching for "Akamai"
C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai d------ [07:05 05/04/2012]
========== regfind ==========
Searching for "Akamai"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\020079C0CE4AC02EED1888A2AE8CE447]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\0C42A6CD31370C8B4C429F1D10D847E7]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\admintool.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\18E8444AC870505B88DF1F2634E2B91E]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\accepteula.txt"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\438DC116E50D44649EE9CD814DD086DB]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Akamai\client"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\580682D1C0159847CCEC037C03087E26]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\client.ini"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\5B0A6CB367C495325A48DA1AB46E4E93]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\user.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\70F555577657DA47AE56C133D2D294E8]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\InstallLocation"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\8D541BF13BA1EE09CD1F6EA7B1FBFC67]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\UninstallString"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\AFAF4DC50343A11A1551AF29AEA69F90]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\C5E5634748AA8DC5623BE48DDFCF8A04]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\rswinui.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\DB748F92982DAED6D441C930AEC1DA8B]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E1B47BBDD70D8978E1D52D309B624221]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\ControlPanel_Installer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E34EEFC4F89581706B658D492BF98506]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\DisplayName"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\E8B49D60B33C29DBB0BF46CF7F6AD30F]
"8189B9C5AD21C694D84D1384AA778EBA"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\installer_uploader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1960408961-1078145449-839522115-1006\Components\EACBC0EA4AB8DFC69FB2AD55A009EF37]
"8189B9C5AD21C694D84D1384AA778EBA"="01:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Akamai\Publisher"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3837:TCP"="3837:TCP:*:Enabled:Akamai NetSession Interface"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="Akamai NetSession Client"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\Documents and Settings\Tomas\Local Settings\Application Data\Akamai\netsession_win.exe"="Akamai NetSession Client"
-= EOF =-