Re: Trojský kůň PSW.Agent a Generic27.AKPW
Napsal: 23 srp 2012 19:45
Spuštěno z C:\ . Konzole nešla stáhnout.
ComboFix 12-08-22.03 - Ing. Karel Mikeš 23.08.2012 20:11:57.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1022.502 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2012 *Disabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\windows\system32\drivers\11147367.sys"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-23 do 2012-08-23 )))))))))))))))))))))))))))))))
.
.
2012-08-23 15:26 . 2012-08-23 15:26 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-23 12:49 . 2012-08-23 12:49 177496 ----a-w- c:\windows\system32\drivers\11147367.sys
2012-08-23 11:57 . 2012-08-23 11:58 -------- d-----w- c:\program files\trend micro
2012-08-23 11:57 . 2012-08-23 11:58 -------- d-----w- C:\rsit
2012-08-19 19:35 . 2012-08-19 19:35 -------- d-----w- c:\program files\TeamViewer
2012-08-19 17:51 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-08-19 17:51 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2012-08-17 23:13 . 2012-08-17 23:13 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-17 23:13 . 2012-08-17 23:13 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 21:10 . 2012-08-17 21:10 -------- d-----w- c:\program files\PANDORA.TV
2012-08-17 21:09 . 2012-08-17 21:13 -------- d-----w- c:\program files\The KMPlayer
2012-08-17 21:09 . 2012-08-17 21:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Ask
2012-08-17 18:27 . 2012-08-17 18:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG Secure Search
2012-08-17 18:27 . 2012-08-17 18:27 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-08-17 18:27 . 2012-08-17 18:28 -------- d-----w- c:\program files\AVG Secure Search
2012-08-17 18:07 . 2012-08-23 11:44 -------- d-----w- c:\windows\system32\drivers\AVG
2012-08-17 18:07 . 2012-08-17 18:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG2012
2012-08-17 18:07 . 2012-08-17 18:07 -------- d-----w- C:\$AVG
2012-08-17 18:07 . 2012-08-17 18:07 -------- d-----w- c:\program files\AVG
2012-08-17 18:00 . 2012-08-23 11:45 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2012-08-17 18:00 . 2012-08-17 18:00 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2012-08-17 17:57 . 2012-08-17 17:57 -------- d-----w- c:\program files\7-Zip
2012-08-17 17:32 . 2012-08-17 17:34 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2012-08-17 17:32 . 2012-08-17 17:32 -------- d-----w- c:\program files\Autodesk
2012-08-17 16:55 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2012-08-17 16:55 . 2012-08-17 17:32 -------- d-----w- c:\windows\Logs
2012-08-17 15:09 . 2012-08-17 17:33 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Autodesk
2012-08-17 15:07 . 2012-08-17 15:07 -------- d-----w- C:\Autodesk
2012-08-17 12:52 . 2012-08-17 12:53 -------- d-----w- C:\totalcmd
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\UC.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\RAR.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\PKZIP.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\PKUNZIP.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\LHA.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\ARJ.PIF
2012-08-17 12:49 . 2012-08-17 12:51 -------- d-----w- C:\Data
2012-08-15 21:13 . 2007-06-29 03:45 183056 ----a-w- c:\windows\UNINST32.EXE
2012-08-15 21:13 . 2006-01-20 21:42 17408 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS
2012-08-15 21:13 . 2004-12-09 19:04 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL
2012-08-15 21:11 . 2012-08-15 12:14 -------- d-----w- c:\windows\VGA
2012-08-15 12:57 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-08-15 12:57 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2012-08-15 12:49 . 2012-08-15 12:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2012-08-15 12:45 . 2012-08-15 12:46 -------- d-----w- c:\program files\Launch Manager
2012-08-15 12:45 . 2007-12-10 15:59 8704 ----a-w- c:\windows\system32\drivers\TVicPort64.sys
2012-08-15 12:45 . 2007-12-10 15:59 6144 ----a-w- c:\windows\system32\drivers\zntport64.sys
2012-08-15 12:45 . 2007-12-10 15:59 6080 ----a-w- c:\windows\system32\drivers\zntport.sys
2012-08-15 12:45 . 2007-12-10 15:59 14544 ----a-w- c:\windows\system32\drivers\TVicPort.sys
2012-08-15 12:45 . 2007-12-10 15:59 8704 ----a-w- c:\windows\system32\drivers\int15_64.sys
2012-08-15 12:45 . 2007-12-10 15:59 14120 ----a-w- c:\windows\system32\drivers\int15.sys
2012-08-15 12:44 . 2007-04-13 09:51 321024 ----a-w- c:\windows\system32\ERUpdateHidden.EXE
2012-08-15 12:44 . 2006-03-30 11:06 258048 ----a-w- c:\windows\system32\CheckD2DSystem.exe
2012-08-15 12:44 . 2006-03-23 10:02 258048 ----a-w- c:\windows\system32\Uninstall_eRecovery.exe
2012-08-15 12:44 . 2005-12-09 07:12 16384 ----a-w- c:\windows\system32\ClearEvent.exe
2012-08-15 12:44 . 2004-11-03 07:06 159744 ----a-w- c:\windows\system32\CloseProcessWindow.dll
2012-08-15 12:44 . 2005-11-02 12:32 32512 ----a-w- c:\windows\system32\drivers\npf.sys
2012-08-15 12:44 . 2012-08-15 12:44 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2012-08-15 12:44 . 2012-08-15 12:44 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\Intel
2012-08-15 12:43 . 2012-08-15 12:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Intel
2012-08-15 12:43 . 2007-07-20 12:30 65536 ----a-w- c:\windows\system32\acerGina.dll
2012-08-15 12:43 . 2007-07-20 12:29 888832 ----a-w- c:\windows\system32\WirelessMgr.dll
2012-08-15 12:42 . 2012-08-15 12:42 -------- d-----w- c:\windows\Downloaded Installations
2012-08-15 12:41 . 2006-07-20 08:33 65536 ----a-w- c:\windows\system32\NATTraversal.dll
2012-08-15 12:41 . 2007-03-06 12:58 57344 ----a-w- c:\windows\system32\acpimof.dll
2012-08-15 12:41 . 2005-04-07 16:08 78208 ----a-w- c:\windows\system32\drivers\epm-shd.sys
2012-08-15 12:41 . 2004-07-19 11:10 4096 ----a-w- c:\windows\system32\drivers\epm-psd.sys
2012-08-15 12:41 . 2006-02-16 13:39 45056 ----a-w- c:\windows\system32\Epm-Po.dll
2012-08-15 12:40 . 2012-08-15 12:41 -------- d-----w- c:\program files\Mozilla Thunderbird
2012-08-15 12:39 . 2006-02-22 09:19 69632 ----a-w- c:\windows\system32\eRecUtil.dll
2012-08-15 12:39 . 2006-06-13 12:42 602112 ----a-w- c:\windows\system32\Acer.Empowering.Windows.Forms_v820.dll
2012-08-15 12:39 . 2007-07-12 07:30 618496 ----a-w- c:\windows\system32\Acer.Empowering.Windows.Forms.dll
2012-08-15 12:39 . 2007-07-12 07:30 53248 ----a-w- c:\windows\system32\Interop.Shell32.dll
2012-08-15 12:39 . 2006-05-25 16:18 331776 ----a-w- c:\windows\system32\ScrollBarLib.dll
2012-08-15 12:39 . 2006-04-18 17:54 49152 ----a-w- c:\windows\system32\SysMonitor.exe
2012-08-15 12:38 . 2012-08-15 12:39 -------- d-----w- C:\Acer
2012-08-15 12:38 . 2012-08-17 12:35 -------- d-----w- c:\program files\Yahoo!
2012-08-15 12:37 . 2007-09-07 18:56 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2012-08-15 12:37 . 2007-04-18 20:02 36909056 ----a-w- c:\windows\system32\acer.scr
2012-08-15 12:37 . 2007-05-16 14:52 8076468 ----a-w- c:\windows\system32\acer.exe
2012-08-15 12:37 . 2012-08-15 12:37 -------- d-----w- c:\windows\ACER
2012-08-15 12:35 . 2004-08-03 21:08 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2012-08-15 12:34 . 2012-08-15 12:34 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2012-08-15 12:34 . 2012-08-15 12:34 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2012-08-15 12:34 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2012-08-15 12:34 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2012-08-15 12:34 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2012-08-15 12:34 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2012-08-15 12:34 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-08-15 12:34 . 2012-08-15 12:36 -------- d-----w- c:\program files\ATI Technologies
2012-08-15 12:34 . 2007-10-03 19:05 212992 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2012-08-15 12:33 . 2012-08-15 12:33 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-08-15 12:33 . 2004-08-17 13:49 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-08-15 12:33 . 2004-08-17 13:49 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2012-08-15 12:32 . 2001-10-24 09:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-08-15 12:32 . 2001-10-24 09:54 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2012-08-15 12:27 . 2007-03-31 20:02 55352 ----a-w- c:\windows\system32\drivers\btwhid.sys
2012-08-15 12:27 . 2007-03-23 17:50 67960 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-08-15 12:27 . 2007-03-23 17:50 149123 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-08-15 12:27 . 2007-03-23 17:50 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-08-15 12:27 . 2007-03-23 17:50 37424 ----a-w- c:\windows\system32\drivers\btport.sys
2012-08-15 12:27 . 2007-03-31 20:02 876384 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-08-15 12:27 . 2007-03-23 17:49 539072 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-08-15 12:26 . 2012-08-15 12:26 -------- d-----w- c:\program files\WIDCOMM
2012-08-15 12:23 . 2012-08-23 18:16 -------- d-----w- c:\documents and settings\Ing. Karel Mikeš
2012-08-15 12:21 . 2012-08-15 21:04 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\InstallShield
2012-08-15 12:15 . 2012-08-15 12:15 0 ----a-w- c:\windows\ativpsrm.bin
2012-08-15 12:14 . 2012-08-15 12:14 -------- d-----w- c:\program files\CONEXANT
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-14 00:15 . 2012-08-15 12:33 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-17 18:27 2069088 ----a-w- c:\program files\AVG Secure Search\11.0.0.10\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.0.0.10\AVG Secure Search_toolbar.dll" [2012-08-17 2069088]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-07 1015808]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-17 1118304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acer Empowering Technology.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk
backup=c:\windows\pss\Acer Empowering Technology.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
2007-03-02 09:25 208896 ----a-w- c:\acer\Empowering Technology\ePresentation\ePresentation.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 16:43 69632 ----a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2005-06-11 17:51 53248 ------w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]
2006-03-15 20:12 579584 ----a-w- c:\acer\Empowering Technology\ePower\Boot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
2007-05-28 13:56 342528 ----a-w- c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]
2007-07-04 09:44 475136 ----a-w- c:\acer\Empowering Technology\ePower\ePower_DMC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
2007-07-11 12:07 421888 ----a-w- c:\acer\Empowering Technology\eRecovery\eRAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2007-03-21 11:00 174872 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-18 03:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 20:17 52256 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2007-10-17 17:59 858632 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2004-08-18 03:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-18 03:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-18 03:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2007-07-05 10:35 94208 ----a-w- c:\windows\PLFSetL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\preload]
2007-04-21 00:56 20480 ----a-w- c:\windows\RunXMLPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-05-28 14:32 16132608 ----a-w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2006-11-10 10:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2007-02-20 06:14 61440 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vToolbarUpdater11.0.2"=2 (0x2)
"PanService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Program Files\\PANDORA.TV\\PanService\\PandoraService.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19.4.2012 4:50 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31.1.2012 4:46 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22.2.2012 5:25 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19.3.2012 5:17 301248]
R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [13.6.2012 3:48 2321560]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [4.7.2012 17:25 5160568]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [14.2.2012 4:53 193288]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23.12.2011 13:32 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [23.12.2011 13:32 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23.12.2011 13:32 17232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [18.8.2012 1:13 250056]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [15.8.2012 14:33 113120]
S4 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [17.8.2012 23:10 625816]
S4 vToolbarUpdater11.0.2;vToolbarUpdater11.0.2;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe [17.8.2012 20:27 934496]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-17 23:13]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 10.254.254.254
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\Ing. Karel Mikeš\Data aplikací\Mozilla\Firefox\Profiles\gm2i7nz4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-23 20:18
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2312)
c:\windows\system32\AcSignIcon.dll
c:\windows\system32\btmmhook.dll
c:\program files\Common Files\Autodesk Shared\AcSignCore16.dll
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\AVG\AVG2012\avgrsx.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
.
**************************************************************************
.
Celkový čas: 2012-08-23 20:21:04 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-23 18:21
ComboFix2.txt 2012-08-23 17:35
ComboFix3.txt 2012-08-23 17:03
ComboFix4.txt 2012-08-23 16:12
.
Před spuštěním: Volných bajtů: 40 637 702 144
Po spuštění: Volných bajtů: 40 610 009 088
.
- - End Of File - - 1F12B185B29583DBAA0A0D9E9475C73B
ComboFix 12-08-22.03 - Ing. Karel Mikeš 23.08.2012 20:11:57.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1022.502 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2012 *Disabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\windows\system32\drivers\11147367.sys"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-23 do 2012-08-23 )))))))))))))))))))))))))))))))
.
.
2012-08-23 15:26 . 2012-08-23 15:26 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-23 12:49 . 2012-08-23 12:49 177496 ----a-w- c:\windows\system32\drivers\11147367.sys
2012-08-23 11:57 . 2012-08-23 11:58 -------- d-----w- c:\program files\trend micro
2012-08-23 11:57 . 2012-08-23 11:58 -------- d-----w- C:\rsit
2012-08-19 19:35 . 2012-08-19 19:35 -------- d-----w- c:\program files\TeamViewer
2012-08-19 17:51 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-08-19 17:51 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2012-08-17 23:13 . 2012-08-17 23:13 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-17 23:13 . 2012-08-17 23:13 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 21:10 . 2012-08-17 21:10 -------- d-----w- c:\program files\PANDORA.TV
2012-08-17 21:09 . 2012-08-17 21:13 -------- d-----w- c:\program files\The KMPlayer
2012-08-17 21:09 . 2012-08-17 21:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Ask
2012-08-17 18:27 . 2012-08-17 18:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG Secure Search
2012-08-17 18:27 . 2012-08-17 18:27 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-08-17 18:27 . 2012-08-17 18:28 -------- d-----w- c:\program files\AVG Secure Search
2012-08-17 18:07 . 2012-08-23 11:44 -------- d-----w- c:\windows\system32\drivers\AVG
2012-08-17 18:07 . 2012-08-17 18:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG2012
2012-08-17 18:07 . 2012-08-17 18:07 -------- d-----w- C:\$AVG
2012-08-17 18:07 . 2012-08-17 18:07 -------- d-----w- c:\program files\AVG
2012-08-17 18:00 . 2012-08-23 11:45 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2012-08-17 18:00 . 2012-08-17 18:00 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2012-08-17 17:57 . 2012-08-17 17:57 -------- d-----w- c:\program files\7-Zip
2012-08-17 17:32 . 2012-08-17 17:34 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2012-08-17 17:32 . 2012-08-17 17:32 -------- d-----w- c:\program files\Autodesk
2012-08-17 16:55 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2012-08-17 16:55 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2012-08-17 16:55 . 2012-08-17 17:32 -------- d-----w- c:\windows\Logs
2012-08-17 15:09 . 2012-08-17 17:33 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Autodesk
2012-08-17 15:07 . 2012-08-17 15:07 -------- d-----w- C:\Autodesk
2012-08-17 12:52 . 2012-08-17 12:53 -------- d-----w- C:\totalcmd
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\UC.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\RAR.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\PKZIP.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\PKUNZIP.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\LHA.PIF
2012-08-17 12:52 . 2012-08-03 06:01 545 ----a-w- c:\windows\ARJ.PIF
2012-08-17 12:49 . 2012-08-17 12:51 -------- d-----w- C:\Data
2012-08-15 21:13 . 2007-06-29 03:45 183056 ----a-w- c:\windows\UNINST32.EXE
2012-08-15 21:13 . 2006-01-20 21:42 17408 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS
2012-08-15 21:13 . 2004-12-09 19:04 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL
2012-08-15 21:11 . 2012-08-15 12:14 -------- d-----w- c:\windows\VGA
2012-08-15 12:57 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-08-15 12:57 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2012-08-15 12:49 . 2012-08-15 12:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2012-08-15 12:45 . 2012-08-15 12:46 -------- d-----w- c:\program files\Launch Manager
2012-08-15 12:45 . 2007-12-10 15:59 8704 ----a-w- c:\windows\system32\drivers\TVicPort64.sys
2012-08-15 12:45 . 2007-12-10 15:59 6144 ----a-w- c:\windows\system32\drivers\zntport64.sys
2012-08-15 12:45 . 2007-12-10 15:59 6080 ----a-w- c:\windows\system32\drivers\zntport.sys
2012-08-15 12:45 . 2007-12-10 15:59 14544 ----a-w- c:\windows\system32\drivers\TVicPort.sys
2012-08-15 12:45 . 2007-12-10 15:59 8704 ----a-w- c:\windows\system32\drivers\int15_64.sys
2012-08-15 12:45 . 2007-12-10 15:59 14120 ----a-w- c:\windows\system32\drivers\int15.sys
2012-08-15 12:44 . 2007-04-13 09:51 321024 ----a-w- c:\windows\system32\ERUpdateHidden.EXE
2012-08-15 12:44 . 2006-03-30 11:06 258048 ----a-w- c:\windows\system32\CheckD2DSystem.exe
2012-08-15 12:44 . 2006-03-23 10:02 258048 ----a-w- c:\windows\system32\Uninstall_eRecovery.exe
2012-08-15 12:44 . 2005-12-09 07:12 16384 ----a-w- c:\windows\system32\ClearEvent.exe
2012-08-15 12:44 . 2004-11-03 07:06 159744 ----a-w- c:\windows\system32\CloseProcessWindow.dll
2012-08-15 12:44 . 2005-11-02 12:32 32512 ----a-w- c:\windows\system32\drivers\npf.sys
2012-08-15 12:44 . 2012-08-15 12:44 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2012-08-15 12:44 . 2012-08-15 12:44 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\Intel
2012-08-15 12:43 . 2012-08-15 12:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Intel
2012-08-15 12:43 . 2007-07-20 12:30 65536 ----a-w- c:\windows\system32\acerGina.dll
2012-08-15 12:43 . 2007-07-20 12:29 888832 ----a-w- c:\windows\system32\WirelessMgr.dll
2012-08-15 12:42 . 2012-08-15 12:42 -------- d-----w- c:\windows\Downloaded Installations
2012-08-15 12:41 . 2006-07-20 08:33 65536 ----a-w- c:\windows\system32\NATTraversal.dll
2012-08-15 12:41 . 2007-03-06 12:58 57344 ----a-w- c:\windows\system32\acpimof.dll
2012-08-15 12:41 . 2005-04-07 16:08 78208 ----a-w- c:\windows\system32\drivers\epm-shd.sys
2012-08-15 12:41 . 2004-07-19 11:10 4096 ----a-w- c:\windows\system32\drivers\epm-psd.sys
2012-08-15 12:41 . 2006-02-16 13:39 45056 ----a-w- c:\windows\system32\Epm-Po.dll
2012-08-15 12:40 . 2012-08-15 12:41 -------- d-----w- c:\program files\Mozilla Thunderbird
2012-08-15 12:39 . 2006-02-22 09:19 69632 ----a-w- c:\windows\system32\eRecUtil.dll
2012-08-15 12:39 . 2006-06-13 12:42 602112 ----a-w- c:\windows\system32\Acer.Empowering.Windows.Forms_v820.dll
2012-08-15 12:39 . 2007-07-12 07:30 618496 ----a-w- c:\windows\system32\Acer.Empowering.Windows.Forms.dll
2012-08-15 12:39 . 2007-07-12 07:30 53248 ----a-w- c:\windows\system32\Interop.Shell32.dll
2012-08-15 12:39 . 2006-05-25 16:18 331776 ----a-w- c:\windows\system32\ScrollBarLib.dll
2012-08-15 12:39 . 2006-04-18 17:54 49152 ----a-w- c:\windows\system32\SysMonitor.exe
2012-08-15 12:38 . 2012-08-15 12:39 -------- d-----w- C:\Acer
2012-08-15 12:38 . 2012-08-17 12:35 -------- d-----w- c:\program files\Yahoo!
2012-08-15 12:37 . 2007-09-07 18:56 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2012-08-15 12:37 . 2007-04-18 20:02 36909056 ----a-w- c:\windows\system32\acer.scr
2012-08-15 12:37 . 2007-05-16 14:52 8076468 ----a-w- c:\windows\system32\acer.exe
2012-08-15 12:37 . 2012-08-15 12:37 -------- d-----w- c:\windows\ACER
2012-08-15 12:35 . 2004-08-03 21:08 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2012-08-15 12:34 . 2012-08-15 12:34 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2012-08-15 12:34 . 2012-08-15 12:34 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2012-08-15 12:34 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2012-08-15 12:34 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2012-08-15 12:34 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2012-08-15 12:34 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2012-08-15 12:34 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-08-15 12:34 . 2012-08-15 12:36 -------- d-----w- c:\program files\ATI Technologies
2012-08-15 12:34 . 2007-10-03 19:05 212992 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2012-08-15 12:33 . 2012-08-15 12:33 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-08-15 12:33 . 2004-08-17 13:49 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-08-15 12:33 . 2004-08-17 13:49 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2012-08-15 12:32 . 2001-10-24 09:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-08-15 12:32 . 2001-10-24 09:54 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2012-08-15 12:27 . 2007-03-31 20:02 55352 ----a-w- c:\windows\system32\drivers\btwhid.sys
2012-08-15 12:27 . 2007-03-23 17:50 67960 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-08-15 12:27 . 2007-03-23 17:50 149123 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-08-15 12:27 . 2007-03-23 17:50 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-08-15 12:27 . 2007-03-23 17:50 37424 ----a-w- c:\windows\system32\drivers\btport.sys
2012-08-15 12:27 . 2007-03-31 20:02 876384 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-08-15 12:27 . 2007-03-23 17:49 539072 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-08-15 12:26 . 2012-08-15 12:26 -------- d-----w- c:\program files\WIDCOMM
2012-08-15 12:23 . 2012-08-23 18:16 -------- d-----w- c:\documents and settings\Ing. Karel Mikeš
2012-08-15 12:21 . 2012-08-15 21:04 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\InstallShield
2012-08-15 12:15 . 2012-08-15 12:15 0 ----a-w- c:\windows\ativpsrm.bin
2012-08-15 12:14 . 2012-08-15 12:14 -------- d-----w- c:\program files\CONEXANT
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-14 00:15 . 2012-08-15 12:33 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-17 18:27 2069088 ----a-w- c:\program files\AVG Secure Search\11.0.0.10\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.0.0.10\AVG Secure Search_toolbar.dll" [2012-08-17 2069088]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-07 1015808]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-17 1118304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acer Empowering Technology.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk
backup=c:\windows\pss\Acer Empowering Technology.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
2007-03-02 09:25 208896 ----a-w- c:\acer\Empowering Technology\ePresentation\ePresentation.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 16:43 69632 ----a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2005-06-11 17:51 53248 ------w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]
2006-03-15 20:12 579584 ----a-w- c:\acer\Empowering Technology\ePower\Boot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
2007-05-28 13:56 342528 ----a-w- c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]
2007-07-04 09:44 475136 ----a-w- c:\acer\Empowering Technology\ePower\ePower_DMC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
2007-07-11 12:07 421888 ----a-w- c:\acer\Empowering Technology\eRecovery\eRAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2007-03-21 11:00 174872 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-18 03:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 20:17 52256 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2007-10-17 17:59 858632 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2004-08-18 03:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-18 03:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-18 03:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2007-07-05 10:35 94208 ----a-w- c:\windows\PLFSetL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\preload]
2007-04-21 00:56 20480 ----a-w- c:\windows\RunXMLPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-05-28 14:32 16132608 ----a-w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2006-11-10 10:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2007-02-20 06:14 61440 ----a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vToolbarUpdater11.0.2"=2 (0x2)
"PanService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Program Files\\PANDORA.TV\\PanService\\PandoraService.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19.4.2012 4:50 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31.1.2012 4:46 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22.2.2012 5:25 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19.3.2012 5:17 301248]
R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [13.6.2012 3:48 2321560]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [4.7.2012 17:25 5160568]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [14.2.2012 4:53 193288]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23.12.2011 13:32 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [23.12.2011 13:32 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23.12.2011 13:32 17232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [18.8.2012 1:13 250056]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [15.8.2012 14:33 113120]
S4 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [17.8.2012 23:10 625816]
S4 vToolbarUpdater11.0.2;vToolbarUpdater11.0.2;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe [17.8.2012 20:27 934496]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-17 23:13]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 10.254.254.254
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\Ing. Karel Mikeš\Data aplikací\Mozilla\Firefox\Profiles\gm2i7nz4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-23 20:18
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2312)
c:\windows\system32\AcSignIcon.dll
c:\windows\system32\btmmhook.dll
c:\program files\Common Files\Autodesk Shared\AcSignCore16.dll
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\AVG\AVG2012\avgrsx.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
.
**************************************************************************
.
Celkový čas: 2012-08-23 20:21:04 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-23 18:21
ComboFix2.txt 2012-08-23 17:35
ComboFix3.txt 2012-08-23 17:03
ComboFix4.txt 2012-08-23 16:12
.
Před spuštěním: Volných bajtů: 40 637 702 144
Po spuštění: Volných bajtů: 40 610 009 088
.
- - End Of File - - 1F12B185B29583DBAA0A0D9E9475C73B