Re: SERVICES.EXE
Napsal: 12 bře 2010 18:13
Tady je nový log z ComboFixu.
ComboFix 10-03-11.06 - Jaroslav 12.03.2010 17:52:40.7.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.584 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jaroslav\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jaroslav\Plocha\CFScript.txt
AV: Eset NOD32 Antivirus 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\ReadMe.txt
c:\windows\system32\services.exe . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-12 do 2010-03-12 )))))))))))))))))))))))))))))))
.
2010-03-11 17:52 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\57947352.sys
2010-03-11 17:52 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\5794735.sys
2010-03-11 17:52 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\57947351.sys
2010-03-10 19:23 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-10 19:23 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 19:23 . 2010-03-10 19:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-07 09:24 . 2010-03-07 09:24 -------- d-----w- c:\program files\trend micro
2010-03-07 09:24 . 2010-03-07 09:24 -------- d-----w- C:\rsit
2010-02-23 21:36 . 2010-02-23 21:36 -------- d-----w- c:\program files\CrystalDiskInfo
2010-02-23 21:31 . 2010-02-23 21:31 -------- d-----w- c:\program files\Common Files\AltrixSoft
2010-02-21 16:26 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
2010-02-21 09:24 . 2010-02-21 09:24 -------- d-----w- c:\windows\WinAVI Video Converter 9.0
2010-02-21 09:24 . 2010-02-21 09:24 -------- d-----w- c:\program files\WinAVI Video Converter 9.0
2010-02-19 18:53 . 2001-07-13 12:56 14976 ----a-w- c:\windows\system32\drivers\SBKUPNT.SYS
2010-02-19 18:53 . 1997-02-08 16:11 13312 ----a-w- c:\windows\system32\DEVLOAD.EXE
2010-02-15 17:01 . 2009-02-13 19:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 17:34 . 2010-02-05 17:34 -------- d-----w- c:\program files\linguatec
2010-02-04 19:04 . 2010-02-04 19:04 -------- d-----w- c:\program files\MyPlayCity.com
2010-02-04 17:37 . 2002-09-23 09:00 93496 ----a-w- c:\windows\system32\perfc005.dat
2010-02-04 17:37 . 2002-09-23 09:00 457398 ----a-w- c:\windows\system32\perfh005.dat
2009-12-31 16:50 . 2002-09-23 09:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2002-09-23 09:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-14 07:10 . 2002-09-23 09:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
------- Sigcheck -------
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2002-09-23 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[-] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\system32\drivers\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-09-17 77824]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-14 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-14 81920]
"NeroFilterCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVD.exe" [2005-09-22 454144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-04-09 949376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Jaroslav\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - taskmgr.exe.lnk - c:\windows\system32\taskmgr.exe [2002-9-23 137216]
setup_9.0.0.722_10.03.2010_22-29.lnk - c:\documents and settings\Jaroslav\Plocha\Virus Removal Tool\setup_9.0.0.722_10.03.2010_22-29\startup.exe [2010-3-11 72208]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2009-12-5 1601536]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\WINDOWS\\System32\\PnkBstrA.exe"=
"c:\\WINDOWS\\System32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ESET\\NOD32KUI.EXE"=
"c:\\Program Files\\EA Games\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\EA Games\\MOHAA\\moh_Breakthrough.exe"=
"c:\\Program Files\\EA Games\\MOHAA\\moh_spearhead.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 57947352;57947352 Boot Guard Driver;c:\windows\system32\drivers\57947352.sys [11.3.2010 18:52 37392]
R0 IODrv;IODrv;c:\windows\system32\drivers\Iodrv.sys [16.2.2009 21:59 8080]
R1 57947351;57947351;c:\windows\system32\drivers\57947351.sys [11.3.2010 18:52 128016]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [9.4.2009 19:22 15424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [28.9.2009 20:10 159600]
R1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [5.3.2003 16:39 115968]
R1 setup_9.0.0.722_10.03.2010_22-29drv;setup_9.0.0.722_10.03.2010_22-29drv;c:\windows\system32\drivers\5794735.sys [11.3.2010 18:52 315408]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [13.5.2008 21:08 142592]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [28.9.2009 20:10 73840]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [19.2.2010 19:53 14976]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [28.9.2009 20:09 95640]
R3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [27.12.2007 18:58 10260864]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.2.2010 20:00 135664]
S3 USBVSP;USBVSP;c:\windows\system32\drivers\usbvsp.sys [12.12.2003 19:51 89856]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [1.1.1980 1432836]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [15.2.2010 18:01 11520]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16.12.2005 18:18 642560]
.
Obsah adresáře 'Naplánované úlohy'
2010-03-12 c:\windows\Tasks\User_Feed_Synchronization-{4C1DBB86-7F64-4F0E-ACDE-03BAEADDB565}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
2010-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 19:00]
2010-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 19:00]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: c:\windows\system32\imon.dll
TCP: {109FD390-F319-4387-9CBD-7733B14B67BC} = 192.168.0.5
TCP: {9F785618-84F9-491C-B0A9-DA67810F72D1} = 10.97.39.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java
DPF: {70EDCF63-CA7E-4812-8528-DA1EA2FD53B6} - hxxp://www.skiosvetimany.cz/VitaminCtrl_2_1_0_26.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-12 18:04
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1659004503-1708537768-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1360)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3388)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Eset\nod32krn.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\SOUNDMAN.EXE
c:\program files\EDIMAX\Common\RalinkRegistryWriter.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\documents and settings\Jaroslav\Plocha\Virus Removal Tool\setup_9.0.0.722_10.03.2010_22-29\setup_9.0.0.722_10.03.2010_22-29.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-03-12 18:10:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-12 17:10
ComboFix2.txt 2010-03-07 11:32
ComboFix3.txt 2010-03-07 10:23
ComboFix4.txt 2007-08-03 22:31
Před spuštěním: Volných bajtů: 14 549 123 072
Po spuštění: Volných bajtů: 14 477 099 008
Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - 4BF2CC353A1128ABB2815861B4B8473D
ComboFix 10-03-11.06 - Jaroslav 12.03.2010 17:52:40.7.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.584 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jaroslav\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jaroslav\Plocha\CFScript.txt
AV: Eset NOD32 Antivirus 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\ReadMe.txt
c:\windows\system32\services.exe . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-12 do 2010-03-12 )))))))))))))))))))))))))))))))
.
2010-03-11 17:52 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\57947352.sys
2010-03-11 17:52 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\5794735.sys
2010-03-11 17:52 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\57947351.sys
2010-03-10 19:23 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-10 19:23 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 19:23 . 2010-03-10 19:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-07 09:24 . 2010-03-07 09:24 -------- d-----w- c:\program files\trend micro
2010-03-07 09:24 . 2010-03-07 09:24 -------- d-----w- C:\rsit
2010-02-23 21:36 . 2010-02-23 21:36 -------- d-----w- c:\program files\CrystalDiskInfo
2010-02-23 21:31 . 2010-02-23 21:31 -------- d-----w- c:\program files\Common Files\AltrixSoft
2010-02-21 16:26 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
2010-02-21 09:24 . 2010-02-21 09:24 -------- d-----w- c:\windows\WinAVI Video Converter 9.0
2010-02-21 09:24 . 2010-02-21 09:24 -------- d-----w- c:\program files\WinAVI Video Converter 9.0
2010-02-19 18:53 . 2001-07-13 12:56 14976 ----a-w- c:\windows\system32\drivers\SBKUPNT.SYS
2010-02-19 18:53 . 1997-02-08 16:11 13312 ----a-w- c:\windows\system32\DEVLOAD.EXE
2010-02-15 17:01 . 2009-02-13 19:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 17:34 . 2010-02-05 17:34 -------- d-----w- c:\program files\linguatec
2010-02-04 19:04 . 2010-02-04 19:04 -------- d-----w- c:\program files\MyPlayCity.com
2010-02-04 17:37 . 2002-09-23 09:00 93496 ----a-w- c:\windows\system32\perfc005.dat
2010-02-04 17:37 . 2002-09-23 09:00 457398 ----a-w- c:\windows\system32\perfh005.dat
2009-12-31 16:50 . 2002-09-23 09:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2002-09-23 09:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-14 07:10 . 2002-09-23 09:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
------- Sigcheck -------
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[-] 2002-09-23 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[-] 2002-08-29 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\system32\drivers\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-09-17 77824]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-14 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-14 81920]
"NeroFilterCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVD.exe" [2005-09-22 454144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-04-09 949376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Jaroslav\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - taskmgr.exe.lnk - c:\windows\system32\taskmgr.exe [2002-9-23 137216]
setup_9.0.0.722_10.03.2010_22-29.lnk - c:\documents and settings\Jaroslav\Plocha\Virus Removal Tool\setup_9.0.0.722_10.03.2010_22-29\startup.exe [2010-3-11 72208]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2009-12-5 1601536]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\WINDOWS\\System32\\PnkBstrA.exe"=
"c:\\WINDOWS\\System32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ESET\\NOD32KUI.EXE"=
"c:\\Program Files\\EA Games\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\EA Games\\MOHAA\\moh_Breakthrough.exe"=
"c:\\Program Files\\EA Games\\MOHAA\\moh_spearhead.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 57947352;57947352 Boot Guard Driver;c:\windows\system32\drivers\57947352.sys [11.3.2010 18:52 37392]
R0 IODrv;IODrv;c:\windows\system32\drivers\Iodrv.sys [16.2.2009 21:59 8080]
R1 57947351;57947351;c:\windows\system32\drivers\57947351.sys [11.3.2010 18:52 128016]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [9.4.2009 19:22 15424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [28.9.2009 20:10 159600]
R1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [5.3.2003 16:39 115968]
R1 setup_9.0.0.722_10.03.2010_22-29drv;setup_9.0.0.722_10.03.2010_22-29drv;c:\windows\system32\drivers\5794735.sys [11.3.2010 18:52 315408]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [13.5.2008 21:08 142592]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [28.9.2009 20:10 73840]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [19.2.2010 19:53 14976]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [28.9.2009 20:09 95640]
R3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [27.12.2007 18:58 10260864]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.2.2010 20:00 135664]
S3 USBVSP;USBVSP;c:\windows\system32\drivers\usbvsp.sys [12.12.2003 19:51 89856]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [1.1.1980 1432836]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [15.2.2010 18:01 11520]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16.12.2005 18:18 642560]
.
Obsah adresáře 'Naplánované úlohy'
2010-03-12 c:\windows\Tasks\User_Feed_Synchronization-{4C1DBB86-7F64-4F0E-ACDE-03BAEADDB565}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
2010-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 19:00]
2010-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 19:00]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: c:\windows\system32\imon.dll
TCP: {109FD390-F319-4387-9CBD-7733B14B67BC} = 192.168.0.5
TCP: {9F785618-84F9-491C-B0A9-DA67810F72D1} = 10.97.39.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java
DPF: {70EDCF63-CA7E-4812-8528-DA1EA2FD53B6} - hxxp://www.skiosvetimany.cz/VitaminCtrl_2_1_0_26.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-12 18:04
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1659004503-1708537768-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1360)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3388)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Eset\nod32krn.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\SOUNDMAN.EXE
c:\program files\EDIMAX\Common\RalinkRegistryWriter.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\documents and settings\Jaroslav\Plocha\Virus Removal Tool\setup_9.0.0.722_10.03.2010_22-29\setup_9.0.0.722_10.03.2010_22-29.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-03-12 18:10:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-12 17:10
ComboFix2.txt 2010-03-07 11:32
ComboFix3.txt 2010-03-07 10:23
ComboFix4.txt 2007-08-03 22:31
Před spuštěním: Volných bajtů: 14 549 123 072
Po spuštění: Volných bajtů: 14 477 099 008
Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - 4BF2CC353A1128ABB2815861B4B8473D