Re: Security tool prosím o pomoc
Napsal: 14 úno 2010 13:27
ComboFix 10-02-12.01 - electroworld 14.02.2010 12:46:26.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.420.1029.18.1015.272 [GMT 1:00]
Spuštěný z: c:\users\electroworld\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100213-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1368 [VPS 100213-1] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2098520901-2607698888-1855745526-500
c:\$recycle.bin\S-1-5-21-2139252429-1018222934-1169608220-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-14 do 2010-02-14 )))))))))))))))))))))))))))))))
.
2010-02-14 11:57 . 2010-02-14 11:58 -------- d-----w- c:\users\electroworld\AppData\Local\temp
2010-02-14 11:57 . 2010-02-14 11:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-04 14:41 . 2010-02-04 14:41 22016 ----a-w- c:\windows\system32\prospeed_bmp2jpg.dll
2010-02-04 14:40 . 2010-02-04 14:43 -------- d-----w- c:\program files\erobottle46
2010-02-04 14:40 . 2010-02-04 14:41 -------- d-----w- c:\windows\uninstall\EroBottle
2010-02-04 14:40 . 2010-02-04 14:40 -------- d-----w- c:\windows\uninstall
2010-02-01 10:40 . 2010-02-01 10:40 -------- d-----w- c:\program files\PROFIT
2010-01-30 08:51 . 2010-01-30 08:51 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbCE1C.tmp.exe
2010-01-29 18:02 . 2010-01-29 18:02 -------- d-----w- c:\users\electroworld\AppData\Roaming\Anix Software
2010-01-29 18:00 . 2010-01-29 18:00 -------- d-----w- c:\program files\Common Files\Anix Shared
2010-01-29 18:00 . 2010-01-29 18:00 -------- d-----w- c:\program files\Slide Show Pilot
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 15:50 . 2009-12-20 07:36 -------- d-----w- c:\users\electroworld\AppData\Roaming\Skype
2010-02-12 15:03 . 2009-11-09 15:00 -------- d-----w- c:\users\electroworld\AppData\Roaming\skypePM
2010-02-12 08:58 . 2007-03-05 20:05 81404 ----a-w- c:\windows\system32\perfc005.dat
2010-02-12 08:58 . 2007-03-05 20:05 473598 ----a-w- c:\windows\system32\perfh005.dat
2010-01-31 10:42 . 2010-01-05 10:15 -------- d-----w- c:\users\electroworld\AppData\Roaming\SolidDocuments
2010-01-30 08:49 . 2008-03-23 08:22 2832 ----a-w- c:\users\electroworld\AppData\Roaming\wklnhst.dat
2010-01-14 10:12 . 2009-10-02 16:35 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-14 02:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-10 12:33 . 2010-01-10 12:33 -------- d-----w- c:\program files\IKEA HomePlanner
2010-01-10 12:23 . 2009-05-02 09:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-05 10:14 . 2010-01-05 10:14 2686232 ----a-w- c:\programdata\SolidDocuments\Installer\Solid Converter PDF\electroworld\SolidSFX_Data\components\vcredist_x86.exe
2010-01-05 10:13 . 2010-01-05 10:13 -------- d-----w- c:\program files\SolidDocuments
2010-01-05 10:13 . 2010-01-05 10:13 -------- d-----w- c:\programdata\SolidDocuments
2010-01-05 10:00 . 2007-03-01 14:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-26 11:23 . 2009-12-26 11:23 -------- d-----w- c:\users\electroworld\AppData\Roaming\HDRsoft
2009-12-26 11:15 . 2009-12-26 11:15 -------- d-----w- c:\program files\PhotomatixPro3
2009-12-20 07:34 . 2009-12-20 07:34 -------- d-----r- c:\program files\Skype
2009-12-20 07:34 . 2009-12-20 07:34 -------- d-----w- c:\program files\Common Files\Skype
2009-12-20 07:34 . 2009-11-09 14:41 -------- d-----w- c:\programdata\Skype
2009-12-18 12:52 . 2010-01-22 07:54 832512 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-22 07:54 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-22 07:54 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-22 07:54 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-22 07:54 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-22 07:54 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-22 07:54 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-12-18 05:03 . 2009-12-18 05:03 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-17 14:00 . 2009-12-17 14:00 -------- d-----w- c:\program files\DreamLight Photo Editor
2009-12-17 13:17 . 2009-12-17 12:48 -------- d-----w- c:\program files\GreenScreenWizardPro
2009-11-24 23:54 . 2008-03-28 17:39 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2008-05-24 09:41 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-05-24 09:41 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-03-28 17:39 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2008-03-28 17:39 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-03-28 17:39 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-03-28 17:39 97480 ----a-w- c:\windows\system32\AvastSS.scr
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznám
R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [1.3.2007 15:55 38400]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [1.3.2007 15:55 31360]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [24.5.2008 10:41 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [24.5.2008 10:41 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [28.3.2008 18:39 53328]
R2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\Installer\MSI83AA.tmp [5.1.2010 11:14 189760]
S2 gupdate1c9d0c84dd3c2d0;Google Update Service (gupdate1c9d0c84dd3c2d0);c:\program files\Google\Update\GoogleUpdate.exe [9.5.2009 18:05 133104]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\System32\drivers\Axtmvflt.sys [7.10.2009 19:46 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\System32\drivers\Axtmvmdm.sys [7.10.2009 19:46 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\System32\drivers\Axtmvprt.sys [7.10.2009 19:46 38784]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [19.4.2009 20:28 55264]
S3 fsssvc;Windows Live Zabezpečení rodiny;c:\program files\Windows Live\Family Safety\fsssvc.exe [8.12.2008 16:01 533344]
S3 vmcam325av;Vimicro USB2.0 PC Camera(VC0323);c:\windows\System32\drivers\vmcam323av.sys [7.9.2008 17:23 232448]
S3 vvftav323;vvftav323;c:\windows\System32\drivers\vvftav323.sys [7.9.2008 17:23 475136]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-09 17:04]
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-09 17:04]
2010-02-13 c:\windows\Tasks\User_Feed_Synchronization-{5061B87D-5249-4148-8A79-E5C2592BDFDC}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Přelož do češtiny - c:\program files\Seznam\Listicka\Toolbar.dll/5034
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Hlede&j v ČR - c:\program files\Seznam\Listicka\Toolbar.dll/5033
IE: Hledej v &encyklopedii - c:\program files\Seznam\Listicka\Toolbar.dll/5108
IE: Hledej ve &světě - c:\program files\Seznam\Listicka\Toolbar.dll/5035
IE: Hledej ve &zboží - c:\program files\Seznam\Listicka\Toolbar.dll/5107
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Verdict Free\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Verdict Free\etnxp.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 12:58
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSI83AA.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-02-14 13:04:38
ComboFix-quarantined-files.txt 2010-02-14 12:04
Před spuštěním: Volných bajtů: 20 306 595 840
Po spuštění: Volných bajtů: 22 759 804 928
- - End Of File - - A9A6AD8288811E42417BC4FEF3AD15D9ka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-25 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-06 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
"Seznam Postak"="c:\users\electroworld\AppData\Local\Seznam.cz\postak.exe" [2009-11-02 448664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-03-25 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-29 4317184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 815104]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-28 148888]
"EasySpeller"="c:\program files\EasyOffice\EasySpeller.exe" [2004-08-19 73728]
c:\users\electroworld\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\microsoft shared\Works Shared\WkCalRem.exe [2005-8-19 21504]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.420.1029.18.1015.272 [GMT 1:00]
Spuštěný z: c:\users\electroworld\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100213-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1368 [VPS 100213-1] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2098520901-2607698888-1855745526-500
c:\$recycle.bin\S-1-5-21-2139252429-1018222934-1169608220-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-14 do 2010-02-14 )))))))))))))))))))))))))))))))
.
2010-02-14 11:57 . 2010-02-14 11:58 -------- d-----w- c:\users\electroworld\AppData\Local\temp
2010-02-14 11:57 . 2010-02-14 11:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-04 14:41 . 2010-02-04 14:41 22016 ----a-w- c:\windows\system32\prospeed_bmp2jpg.dll
2010-02-04 14:40 . 2010-02-04 14:43 -------- d-----w- c:\program files\erobottle46
2010-02-04 14:40 . 2010-02-04 14:41 -------- d-----w- c:\windows\uninstall\EroBottle
2010-02-04 14:40 . 2010-02-04 14:40 -------- d-----w- c:\windows\uninstall
2010-02-01 10:40 . 2010-02-01 10:40 -------- d-----w- c:\program files\PROFIT
2010-01-30 08:51 . 2010-01-30 08:51 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbCE1C.tmp.exe
2010-01-29 18:02 . 2010-01-29 18:02 -------- d-----w- c:\users\electroworld\AppData\Roaming\Anix Software
2010-01-29 18:00 . 2010-01-29 18:00 -------- d-----w- c:\program files\Common Files\Anix Shared
2010-01-29 18:00 . 2010-01-29 18:00 -------- d-----w- c:\program files\Slide Show Pilot
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 15:50 . 2009-12-20 07:36 -------- d-----w- c:\users\electroworld\AppData\Roaming\Skype
2010-02-12 15:03 . 2009-11-09 15:00 -------- d-----w- c:\users\electroworld\AppData\Roaming\skypePM
2010-02-12 08:58 . 2007-03-05 20:05 81404 ----a-w- c:\windows\system32\perfc005.dat
2010-02-12 08:58 . 2007-03-05 20:05 473598 ----a-w- c:\windows\system32\perfh005.dat
2010-01-31 10:42 . 2010-01-05 10:15 -------- d-----w- c:\users\electroworld\AppData\Roaming\SolidDocuments
2010-01-30 08:49 . 2008-03-23 08:22 2832 ----a-w- c:\users\electroworld\AppData\Roaming\wklnhst.dat
2010-01-14 10:12 . 2009-10-02 16:35 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-14 02:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-10 12:33 . 2010-01-10 12:33 -------- d-----w- c:\program files\IKEA HomePlanner
2010-01-10 12:23 . 2009-05-02 09:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-05 10:14 . 2010-01-05 10:14 2686232 ----a-w- c:\programdata\SolidDocuments\Installer\Solid Converter PDF\electroworld\SolidSFX_Data\components\vcredist_x86.exe
2010-01-05 10:13 . 2010-01-05 10:13 -------- d-----w- c:\program files\SolidDocuments
2010-01-05 10:13 . 2010-01-05 10:13 -------- d-----w- c:\programdata\SolidDocuments
2010-01-05 10:00 . 2007-03-01 14:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-26 11:23 . 2009-12-26 11:23 -------- d-----w- c:\users\electroworld\AppData\Roaming\HDRsoft
2009-12-26 11:15 . 2009-12-26 11:15 -------- d-----w- c:\program files\PhotomatixPro3
2009-12-20 07:34 . 2009-12-20 07:34 -------- d-----r- c:\program files\Skype
2009-12-20 07:34 . 2009-12-20 07:34 -------- d-----w- c:\program files\Common Files\Skype
2009-12-20 07:34 . 2009-11-09 14:41 -------- d-----w- c:\programdata\Skype
2009-12-18 12:52 . 2010-01-22 07:54 832512 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-22 07:54 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-22 07:54 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-22 07:54 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-22 07:54 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-22 07:54 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-22 07:54 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-12-18 05:03 . 2009-12-18 05:03 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-17 14:00 . 2009-12-17 14:00 -------- d-----w- c:\program files\DreamLight Photo Editor
2009-12-17 13:17 . 2009-12-17 12:48 -------- d-----w- c:\program files\GreenScreenWizardPro
2009-11-24 23:54 . 2008-03-28 17:39 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2008-05-24 09:41 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-05-24 09:41 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-03-28 17:39 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2008-03-28 17:39 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-03-28 17:39 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-03-28 17:39 97480 ----a-w- c:\windows\system32\AvastSS.scr
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznám
R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [1.3.2007 15:55 38400]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [1.3.2007 15:55 31360]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [24.5.2008 10:41 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [24.5.2008 10:41 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [28.3.2008 18:39 53328]
R2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\Installer\MSI83AA.tmp [5.1.2010 11:14 189760]
S2 gupdate1c9d0c84dd3c2d0;Google Update Service (gupdate1c9d0c84dd3c2d0);c:\program files\Google\Update\GoogleUpdate.exe [9.5.2009 18:05 133104]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\System32\drivers\Axtmvflt.sys [7.10.2009 19:46 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\System32\drivers\Axtmvmdm.sys [7.10.2009 19:46 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\System32\drivers\Axtmvprt.sys [7.10.2009 19:46 38784]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [19.4.2009 20:28 55264]
S3 fsssvc;Windows Live Zabezpečení rodiny;c:\program files\Windows Live\Family Safety\fsssvc.exe [8.12.2008 16:01 533344]
S3 vmcam325av;Vimicro USB2.0 PC Camera(VC0323);c:\windows\System32\drivers\vmcam323av.sys [7.9.2008 17:23 232448]
S3 vvftav323;vvftav323;c:\windows\System32\drivers\vvftav323.sys [7.9.2008 17:23 475136]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-09 17:04]
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-09 17:04]
2010-02-13 c:\windows\Tasks\User_Feed_Synchronization-{5061B87D-5249-4148-8A79-E5C2592BDFDC}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Přelož do češtiny - c:\program files\Seznam\Listicka\Toolbar.dll/5034
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Hlede&j v ČR - c:\program files\Seznam\Listicka\Toolbar.dll/5033
IE: Hledej v &encyklopedii - c:\program files\Seznam\Listicka\Toolbar.dll/5108
IE: Hledej ve &světě - c:\program files\Seznam\Listicka\Toolbar.dll/5035
IE: Hledej ve &zboží - c:\program files\Seznam\Listicka\Toolbar.dll/5107
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Verdict Free\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Verdict Free\etnxp.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 12:58
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSI83AA.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-02-14 13:04:38
ComboFix-quarantined-files.txt 2010-02-14 12:04
Před spuštěním: Volných bajtů: 20 306 595 840
Po spuštění: Volných bajtů: 22 759 804 928
- - End Of File - - A9A6AD8288811E42417BC4FEF3AD15D9ka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-25 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-06 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
"Seznam Postak"="c:\users\electroworld\AppData\Local\Seznam.cz\postak.exe" [2009-11-02 448664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-03-25 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-29 4317184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 815104]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-28 148888]
"EasySpeller"="c:\program files\EasyOffice\EasySpeller.exe" [2004-08-19 73728]
c:\users\electroworld\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\microsoft shared\Works Shared\WkCalRem.exe [2005-8-19 21504]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"