Re: Prosím o kontrolu logu RSIT
Napsal: 28 úno 2013 01:04
posílám log z CF
ComboFix 13-02-24.01 - Administrator 28.02.2013 0:34.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.894.590 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
c:\windows\System32\regsvc.dll chyběl.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\regsvc.dll
.
.
--------------- FCopy ---------------
.
c:\windows\ServicePackFiles\i386\srsvc.dll --> c:\windows\system32\srsvc.dll
c:\windows\ServicePackFiles\i386\psched.sys --> c:\windows\system32\drivers\psched.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DBWGOGJKA
-------\Service_dbwgogjka
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-27 do 2013-02-27 )))))))))))))))))))))))))))))))
.
.
2013-02-27 23:48 . 2008-04-14 07:51 59904 ----a-w- c:\windows\system32\regsvc.dll
2013-02-27 23:48 . 2008-04-14 07:51 59904 ----a-w- c:\windows\system32\dllcache\regsvc.dll
2013-02-27 23:34 . 2008-04-13 23:26 69120 ----a-w- c:\windows\system32\drivers\psched.sys
2013-02-27 23:34 . 2008-04-13 23:26 69120 ----a-w- c:\windows\system32\dllcache\psched.sys
2013-02-27 23:34 . 2008-04-14 07:52 171008 ----a-w- c:\windows\system32\srsvc.dll
2013-02-27 23:34 . 2008-04-14 07:52 171008 ----a-w- c:\windows\system32\dllcache\srsvc.dll
2013-02-27 23:27 . 2008-04-14 06:42 52480 ----a-w- c:\windows\system32\drivers\Volsnap.sys
2013-02-26 07:47 . 2004-06-11 15:33 290304 ----a-w- C:\subinacl.exe
2013-02-26 07:47 . 2013-02-26 07:54 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-02-26 07:38 . 2013-02-26 07:38 19456 ----a-w- c:\windows\system32\dllcache\agt041f.dll
2013-02-26 07:38 . 2013-02-26 07:38 22016 ----a-w- c:\windows\system32\dllcache\agt0408.dll
2013-02-26 07:38 . 2008-04-14 07:52 272384 ----a-w- c:\windows\system32\dllcache\sptip.dll
2013-02-26 07:38 . 2008-04-14 07:51 130048 ----a-w- c:\windows\system32\dllcache\softkbd.dll
2013-02-26 07:38 . 2008-04-14 07:51 220160 ----a-w- c:\windows\system32\dllcache\mscandui.dll
2013-02-26 07:31 . 2013-02-26 07:31 -------- d-----w- c:\program files\DLLSuite
2013-02-26 05:31 . 2013-02-26 05:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2013-02-25 23:07 . 2008-04-14 07:00 80896 ----a-w- c:\windows\system32\dllcache\msxml6r.dll
2013-02-25 23:07 . 2008-04-14 07:51 1306624 ----a-w- c:\windows\system32\dllcache\msxml6.dll
2013-02-25 23:07 . 2008-04-14 07:52 1001472 ----a-w- c:\windows\system32\dllcache\wmvdmoe2.dll
2013-02-25 23:07 . 2008-04-14 07:52 897024 ----a-w- c:\windows\system32\dllcache\wmspdmoe.dll
2013-02-25 23:07 . 2008-04-14 07:52 485376 ----a-w- c:\windows\system32\dllcache\wmspdmod.dll
2013-02-25 23:07 . 2008-04-14 07:52 1119744 ----a-w- c:\windows\system32\dllcache\wmsdmoe2.dll
2013-02-25 23:00 . 2013-02-25 23:07 -------- d-----w- c:\windows\ServicePackFiles
2013-02-25 22:59 . 2008-04-14 07:53 356352 ----a-w- c:\windows\system32\dllcache\msscp.dll
2013-02-25 22:58 . 2006-12-28 23:31 19569 ----a-w- c:\windows\000001_.tmp
2013-02-25 22:58 . 2013-02-26 07:37 -------- d-----w- c:\windows\EHome
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\wbem\snmp
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\restore
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\npp
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\srchasst
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\xircom
2013-02-25 21:40 . 2013-02-25 21:40 -------- d-----w- c:\program files\microsoft frontpage
2013-02-25 20:41 . 2013-02-25 20:42 -------- d-----w- c:\program files\trend micro
2013-02-25 20:41 . 2013-02-25 20:42 -------- d-----w- C:\rsit
2013-02-25 20:12 . 2013-02-26 17:17 -------- d-----w- c:\program files\SpeedFan
2013-02-23 07:40 . 2013-02-23 07:40 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\TuneUp Software
2013-02-23 07:39 . 2012-11-02 14:57 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2013-02-23 07:36 . 2013-02-23 07:36 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2013-02-23 07:35 . 2013-02-23 07:39 -------- d-----w- c:\program files\TuneUp Utilities 2013
2013-02-23 07:35 . 2013-02-23 07:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2013-02-23 07:32 . 2013-02-23 07:32 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-02-23 07:29 . 2011-03-04 19:44 126448 ----a-w- c:\windows\system32\pxinsi64.exe
2013-02-23 07:29 . 2011-03-04 19:44 123888 ----a-w- c:\windows\system32\pxcpyi64.exe
2013-02-23 07:29 . 2011-03-04 19:44 59888 ----a-w- c:\windows\system32\pxwma.dll
2013-02-22 06:26 . 2013-02-22 06:26 -------- d-----w- c:\documents and settings\Administrator\Downloads
2013-02-21 10:57 . 2013-02-21 10:57 -------- d-----w- c:\windows\hpq
2013-02-19 17:40 . 2013-02-19 17:41 -------- d-----w- c:\program files\K-Lite Codec Pack
2013-02-19 13:23 . 2013-02-19 13:24 -------- d-----w- c:\program files\CCleaner
2013-02-18 17:54 . 2013-02-18 17:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2013-02-18 17:46 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-18 17:46 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-18 17:45 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-18 17:45 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-18 17:45 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-18 17:45 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-18 17:45 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-18 17:45 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-18 17:38 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-18 17:38 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-18 17:36 . 2013-02-18 17:36 -------- d-----w- c:\program files\AVAST Software
2013-02-18 17:36 . 2013-02-18 17:36 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2013-02-18 14:11 . 2013-02-20 04:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2013-02-18 14:10 . 2013-02-26 06:58 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-02-18 06:01 . 2013-02-18 06:01 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-03 14:48 . 2013-02-03 14:48 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Leadertech
2013-02-03 07:17 . 2013-02-03 07:17 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2013-02-03 07:16 . 2013-02-03 07:16 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2013-02-03 07:10 . 2013-02-03 07:10 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2013-02-03 07:05 . 2013-02-03 07:07 -------- dc-h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 06:01 . 2012-08-19 12:58 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-18 06:01 . 2010-09-16 13:52 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-18 06:01 . 2009-09-18 14:05 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-20 06:24 . 2013-02-20 06:23 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-09-09 1871872]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-12-19 1044480]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccelerometerSysTrayApplet]
2008-06-18 12:26 82224 ----a-w- c:\windows\system32\accelerometerST.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
2008-06-03 14:34 65536 ----a-w- c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
2008-07-08 16:48 204800 ----a-w- c:\windows\system32\S3Trayp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snuvcdsm]
2007-05-23 09:21 20480 ----a-w- c:\windows\snuvcdsm.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [10.12.2007 12:41 23040]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.9.2009 19:30 721904]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [18.2.2013 18:45 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [18.2.2013 18:46 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18.2.2013 18:46 21256]
R2 Nexis 3.5 license server - dT 2004;Nexis 3.5 license server - dT 2004;c:\crack\lmgrd.exe [10.8.2010 17:30 195584]
R2 S3LoadSv;S3LoadSv;c:\windows\system32\s3loadsv.exe [20.1.2009 15:22 69632]
R3 ts_arusb;[CommView] Atheros Wireless Network Adapter Service;c:\windows\system32\drivers\ts_arusb.sys [22.5.2010 9:16 1054312]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2.11.2012 15:57 1699168]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys --> c:\windows\system32\DRIVERS\SCR3XX2K.sys [?]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [19.9.2012 9:50 10088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-26 07:48 1629648 ----a-w- c:\program files\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2013-02-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-18 22:50]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-21 11:28]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-21 11:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.toggle.com/?lang=en&cid=adfaa7a7
uDefault_Search_URL = about:blank
mSearch Bar = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.1.1 192.168.0.1
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\p0abfo70.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-02-18 18:44; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-SDTray - c:\program files\Spybot - Search & Destroy 2\SDTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-28 00:52
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(576)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(920)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\progra~1\MICROS~1\OFFICE11\MCPS.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Celkový čas: 2013-02-28 01:02:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-28 00:02
ComboFix2.txt 2013-02-25 19:59
.
Před spuštěním: Volných bajtů: 40 959 397 888
Po spuštění: Volných bajtů: 41 167 970 304
.
- - End Of File - - 23B9A0B91694632191E599E4A1B6078E
ComboFix 13-02-24.01 - Administrator 28.02.2013 0:34.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.894.590 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
c:\windows\System32\regsvc.dll chyběl.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\regsvc.dll
.
.
--------------- FCopy ---------------
.
c:\windows\ServicePackFiles\i386\srsvc.dll --> c:\windows\system32\srsvc.dll
c:\windows\ServicePackFiles\i386\psched.sys --> c:\windows\system32\drivers\psched.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DBWGOGJKA
-------\Service_dbwgogjka
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-27 do 2013-02-27 )))))))))))))))))))))))))))))))
.
.
2013-02-27 23:48 . 2008-04-14 07:51 59904 ----a-w- c:\windows\system32\regsvc.dll
2013-02-27 23:48 . 2008-04-14 07:51 59904 ----a-w- c:\windows\system32\dllcache\regsvc.dll
2013-02-27 23:34 . 2008-04-13 23:26 69120 ----a-w- c:\windows\system32\drivers\psched.sys
2013-02-27 23:34 . 2008-04-13 23:26 69120 ----a-w- c:\windows\system32\dllcache\psched.sys
2013-02-27 23:34 . 2008-04-14 07:52 171008 ----a-w- c:\windows\system32\srsvc.dll
2013-02-27 23:34 . 2008-04-14 07:52 171008 ----a-w- c:\windows\system32\dllcache\srsvc.dll
2013-02-27 23:27 . 2008-04-14 06:42 52480 ----a-w- c:\windows\system32\drivers\Volsnap.sys
2013-02-26 07:47 . 2004-06-11 15:33 290304 ----a-w- C:\subinacl.exe
2013-02-26 07:47 . 2013-02-26 07:54 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-02-26 07:38 . 2013-02-26 07:38 19456 ----a-w- c:\windows\system32\dllcache\agt041f.dll
2013-02-26 07:38 . 2013-02-26 07:38 22016 ----a-w- c:\windows\system32\dllcache\agt0408.dll
2013-02-26 07:38 . 2008-04-14 07:52 272384 ----a-w- c:\windows\system32\dllcache\sptip.dll
2013-02-26 07:38 . 2008-04-14 07:51 130048 ----a-w- c:\windows\system32\dllcache\softkbd.dll
2013-02-26 07:38 . 2008-04-14 07:51 220160 ----a-w- c:\windows\system32\dllcache\mscandui.dll
2013-02-26 07:31 . 2013-02-26 07:31 -------- d-----w- c:\program files\DLLSuite
2013-02-26 05:31 . 2013-02-26 05:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2013-02-25 23:07 . 2008-04-14 07:00 80896 ----a-w- c:\windows\system32\dllcache\msxml6r.dll
2013-02-25 23:07 . 2008-04-14 07:51 1306624 ----a-w- c:\windows\system32\dllcache\msxml6.dll
2013-02-25 23:07 . 2008-04-14 07:52 1001472 ----a-w- c:\windows\system32\dllcache\wmvdmoe2.dll
2013-02-25 23:07 . 2008-04-14 07:52 897024 ----a-w- c:\windows\system32\dllcache\wmspdmoe.dll
2013-02-25 23:07 . 2008-04-14 07:52 485376 ----a-w- c:\windows\system32\dllcache\wmspdmod.dll
2013-02-25 23:07 . 2008-04-14 07:52 1119744 ----a-w- c:\windows\system32\dllcache\wmsdmoe2.dll
2013-02-25 23:00 . 2013-02-25 23:07 -------- d-----w- c:\windows\ServicePackFiles
2013-02-25 22:59 . 2008-04-14 07:53 356352 ----a-w- c:\windows\system32\dllcache\msscp.dll
2013-02-25 22:58 . 2006-12-28 23:31 19569 ----a-w- c:\windows\000001_.tmp
2013-02-25 22:58 . 2013-02-26 07:37 -------- d-----w- c:\windows\EHome
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\wbem\snmp
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\restore
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\npp
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\srchasst
2013-02-25 21:41 . 2013-02-25 21:41 -------- d-----w- c:\windows\system32\xircom
2013-02-25 21:40 . 2013-02-25 21:40 -------- d-----w- c:\program files\microsoft frontpage
2013-02-25 20:41 . 2013-02-25 20:42 -------- d-----w- c:\program files\trend micro
2013-02-25 20:41 . 2013-02-25 20:42 -------- d-----w- C:\rsit
2013-02-25 20:12 . 2013-02-26 17:17 -------- d-----w- c:\program files\SpeedFan
2013-02-23 07:40 . 2013-02-23 07:40 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\TuneUp Software
2013-02-23 07:39 . 2012-11-02 14:57 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2013-02-23 07:36 . 2013-02-23 07:36 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2013-02-23 07:35 . 2013-02-23 07:39 -------- d-----w- c:\program files\TuneUp Utilities 2013
2013-02-23 07:35 . 2013-02-23 07:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2013-02-23 07:32 . 2013-02-23 07:32 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-02-23 07:29 . 2011-03-04 19:44 126448 ----a-w- c:\windows\system32\pxinsi64.exe
2013-02-23 07:29 . 2011-03-04 19:44 123888 ----a-w- c:\windows\system32\pxcpyi64.exe
2013-02-23 07:29 . 2011-03-04 19:44 59888 ----a-w- c:\windows\system32\pxwma.dll
2013-02-22 06:26 . 2013-02-22 06:26 -------- d-----w- c:\documents and settings\Administrator\Downloads
2013-02-21 10:57 . 2013-02-21 10:57 -------- d-----w- c:\windows\hpq
2013-02-19 17:40 . 2013-02-19 17:41 -------- d-----w- c:\program files\K-Lite Codec Pack
2013-02-19 13:23 . 2013-02-19 13:24 -------- d-----w- c:\program files\CCleaner
2013-02-18 17:54 . 2013-02-18 17:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2013-02-18 17:46 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-18 17:46 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-18 17:45 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-18 17:45 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-18 17:45 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-18 17:45 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-18 17:45 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-18 17:45 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-18 17:38 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-18 17:38 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-18 17:36 . 2013-02-18 17:36 -------- d-----w- c:\program files\AVAST Software
2013-02-18 17:36 . 2013-02-18 17:36 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2013-02-18 14:11 . 2013-02-20 04:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2013-02-18 14:10 . 2013-02-26 06:58 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-02-18 06:01 . 2013-02-18 06:01 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-03 14:48 . 2013-02-03 14:48 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Leadertech
2013-02-03 07:17 . 2013-02-03 07:17 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2013-02-03 07:16 . 2013-02-03 07:16 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2013-02-03 07:10 . 2013-02-03 07:10 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2013-02-03 07:05 . 2013-02-03 07:07 -------- dc-h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 06:01 . 2012-08-19 12:58 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-18 06:01 . 2010-09-16 13:52 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-18 06:01 . 2009-09-18 14:05 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-20 06:24 . 2013-02-20 06:23 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-09-09 1871872]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-12-19 1044480]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccelerometerSysTrayApplet]
2008-06-18 12:26 82224 ----a-w- c:\windows\system32\accelerometerST.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
2008-06-03 14:34 65536 ----a-w- c:\program files\Hewlett-Packard\Default Settings\Cpqset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
2008-07-08 16:48 204800 ----a-w- c:\windows\system32\S3Trayp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snuvcdsm]
2007-05-23 09:21 20480 ----a-w- c:\windows\snuvcdsm.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [10.12.2007 12:41 23040]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.9.2009 19:30 721904]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [18.2.2013 18:45 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [18.2.2013 18:46 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18.2.2013 18:46 21256]
R2 Nexis 3.5 license server - dT 2004;Nexis 3.5 license server - dT 2004;c:\crack\lmgrd.exe [10.8.2010 17:30 195584]
R2 S3LoadSv;S3LoadSv;c:\windows\system32\s3loadsv.exe [20.1.2009 15:22 69632]
R3 ts_arusb;[CommView] Atheros Wireless Network Adapter Service;c:\windows\system32\drivers\ts_arusb.sys [22.5.2010 9:16 1054312]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2.11.2012 15:57 1699168]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys --> c:\windows\system32\DRIVERS\SCR3XX2K.sys [?]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [19.9.2012 9:50 10088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-26 07:48 1629648 ----a-w- c:\program files\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2013-02-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-18 22:50]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-21 11:28]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-21 11:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.toggle.com/?lang=en&cid=adfaa7a7
uDefault_Search_URL = about:blank
mSearch Bar = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.1.1 192.168.0.1
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\p0abfo70.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-02-18 18:44; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-SDTray - c:\program files\Spybot - Search & Destroy 2\SDTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-28 00:52
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(576)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(920)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\progra~1\MICROS~1\OFFICE11\MCPS.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Celkový čas: 2013-02-28 01:02:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-28 00:02
ComboFix2.txt 2013-02-25 19:59
.
Před spuštěním: Volných bajtů: 40 959 397 888
Po spuštění: Volných bajtů: 41 167 970 304
.
- - End Of File - - 23B9A0B91694632191E599E4A1B6078E