Security TOOL. Už i já...
Napsal: 13 dub 2010 20:17
Ahoj,
tak i moje sestra se stala obětí Security TOOLu. Už jsem udělal COMBOfix. Přikládám LOG,
moc prosím o pomoc, jestli někdo víte. Aaa děkuju!!!
ComboFix 10-04-13.02 - Administrator 13.04.2010 21:06:23.5.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.377 [GMT 2:00]
Spuštěný z: c:\documents and settings\VERONIKA\Plocha\abraka.com.com
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikací\99909440
c:\documents and settings\All Users\Data aplikací\99909440\99909440.exe
c:\documents and settings\VERONIKA\Plocha\Security Tool.lnk
c:\windows\system32\acovcnt.exe
.
---- Předchozí spuštění -------
.
c:\documents and settings\All Users\Data aplikací\29572530\29572530.exe
c:\documents and settings\VERONIKA\Plocha\Security Tool.lnk
c:\windows\Temp\_ex-68.exe
-- Předchozí spuštění --
Nakažená kopie c:\windows\system32\drivers\AGP440.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\agp440.sys
--------
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-13 do 2010-04-13 )))))))))))))))))))))))))))))))
.
2010-04-13 19:04 . 2010-04-13 19:04 -------- d--h--w- c:\windows\PIF
2010-04-13 18:57 . 2010-04-13 18:57 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-13 19:00 . 2009-09-20 11:14 87168 ----a-w- c:\windows\system32\drivers\855feef2.sys
2010-03-28 07:27 . 2002-09-23 12:00 46394 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 07:27 . 2002-09-23 12:00 310228 ----a-w- c:\windows\system32\perfh005.dat
2008-10-12 20:16 . 2008-10-12 19:06 641056 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-08-26_21.59.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 00:07 . 2009-07-12 00:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 00:19 . 2009-07-12 00:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 18:41 . 2009-07-11 18:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2008-05-12 18:35 . 2008-03-21 12:57 23856 c:\windows\system32\spupdsvc.exe
+ 2010-02-02 19:08 . 2008-03-21 12:57 14640 c:\windows\system32\spmsgXP_2k3.dll
- 2002-09-23 12:00 . 2009-04-03 17:27 40326 c:\windows\system32\perfc009.dat
+ 2002-09-23 12:00 . 2010-03-28 07:27 40326 c:\windows\system32\perfc009.dat
+ 2010-02-02 19:03 . 2009-10-06 10:52 91136 c:\windows\system32\nmwcdcls.dll
+ 2010-02-02 19:04 . 2008-08-26 08:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
+ 2008-03-27 15:27 . 2008-03-27 15:27 35040 c:\windows\system32\drivers\wdfldr.sys
+ 2010-02-02 19:08 . 2004-08-03 22:08 25600 c:\windows\system32\drivers\usbser.sys
+ 2010-02-02 19:10 . 2006-08-29 14:56 32377 c:\windows\system32\drivers\prodigy.sys
+ 2010-02-02 19:04 . 2008-08-26 08:26 18816 c:\windows\system32\drivers\pccsmcfd.sys
+ 2008-05-12 19:23 . 2004-08-03 21:07 42368 c:\windows\system32\drivers\AGP440.sys
+ 2010-02-02 19:08 . 2004-08-03 22:08 25600 c:\windows\system32\dllcache\usbser.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 13824 c:\windows\system32\dllcache\cache\wscntfy.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 71680 c:\windows\system32\dllcache\cache\ssdpsrv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 59904 c:\windows\system32\dllcache\cache\regsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 89088 c:\windows\system32\dllcache\cache\rasauto.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-08-26 22:00 . 2005-01-28 06:53 25088 c:\windows\system32\dllcache\cache\MsPMSNSv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 33792 c:\windows\system32\dllcache\cache\msgsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 22016 c:\windows\system32\dllcache\cache\lpk.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 18944 c:\windows\system32\dllcache\cache\linkinfo.dll
+ 2009-08-26 22:00 . 2004-08-17 13:45 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-08-26 22:00 . 2004-08-03 21:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 55808 c:\windows\system32\dllcache\cache\eventlog.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 60416 c:\windows\system32\dllcache\cache\cryptsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 77312 c:\windows\system32\dllcache\cache\browser.dll
+ 2009-08-26 22:00 . 2004-08-03 21:05 14336 c:\windows\system32\dllcache\cache\asyncmac.sys
+ 2009-08-26 22:00 . 2002-09-23 12:00 11776 c:\windows\system32\dllcache\cache\acpiec.sys
+ 2010-02-02 19:04 . 2010-02-02 19:04 10134 c:\windows\Installer\{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}\ARPPRODUCTICON.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 5120 c:\windows\system32\dllcache\cache\sfc.dll
+ 2009-08-26 22:00 . 2002-09-23 12:00 2944 c:\windows\system32\dllcache\cache\null.sys
+ 2009-08-26 22:00 . 2002-09-23 12:00 4224 c:\windows\system32\dllcache\cache\beep.sys
+ 2009-07-12 00:12 . 2009-07-12 00:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09 . 2009-07-12 00:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08 . 2009-07-12 00:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2002-09-23 12:00 . 2010-03-28 07:27 311938 c:\windows\system32\perfh009.dat
- 2002-09-23 12:00 . 2009-04-03 17:27 311938 c:\windows\system32\perfh009.dat
+ 2010-02-02 19:04 . 2009-05-11 11:30 547840 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\PCCSWpdDriver.dll
+ 2008-03-27 15:27 . 2008-03-27 15:27 503008 c:\windows\system32\drivers\wdf01000.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 129536 c:\windows\system32\dllcache\cache\xmlprov.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 111104 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 657408 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 577024 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 185344 c:\windows\system32\dllcache\cache\upnphost.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 295936 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-08-26 22:00 . 2004-08-03 21:14 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 246272 c:\windows\system32\dllcache\cache\tapisrv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 170496 c:\windows\system32\dllcache\cache\srsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 190976 c:\windows\system32\dllcache\cache\schedsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 134656 c:\windows\system32\dllcache\cache\shsvcs.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 108544 c:\windows\system32\dllcache\cache\services.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 184832 c:\windows\system32\dllcache\cache\scecli.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 395776 c:\windows\system32\dllcache\cache\rpcss.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 382464 c:\windows\system32\dllcache\cache\qmgr.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 435712 c:\windows\system32\dllcache\cache\ntmssvc.dll
+ 2009-08-26 22:00 . 2004-08-03 21:15 574592 c:\windows\system32\dllcache\cache\ntfs.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 198144 c:\windows\system32\dllcache\cache\netman.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 407040 c:\windows\system32\dllcache\cache\netlogon.dll
+ 2009-08-26 22:00 . 2004-08-03 21:14 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 247296 c:\windows\system32\dllcache\cache\mswsock.dll
+ 2009-08-26 22:00 . 2002-09-23 12:00 924432 c:\windows\system32\dllcache\cache\mfc40u.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 982016 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 243200 c:\windows\system32\dllcache\cache\es.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 806912 c:\windows\system32\dllcache\cache\comres.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 611328 c:\windows\system32\dllcache\cache\comctl32.dll
+ 2009-08-26 22:00 . 2004-08-03 20:39 142464 c:\windows\system32\dllcache\cache\aec.sys
+ 2010-02-02 19:04 . 2010-02-02 19:04 496128 c:\windows\Installer\a3319.msi
+ 2010-02-02 19:03 . 2010-02-02 19:03 215552 c:\windows\Installer\a330b.msi
+ 2010-02-02 19:08 . 2008-03-21 12:57 379184 c:\windows\$NtUninstallWdf01007$\spuninst\updspapi.dll
+ 2010-02-02 19:08 . 2008-03-21 12:57 221488 c:\windows\$NtUninstallWdf01007$\spuninst\spuninst.exe
+ 2009-07-11 19:46 . 2009-07-11 19:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 19:46 . 2009-07-11 19:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2010-02-02 19:04 . 2009-05-11 10:47 1302600 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\WUDFUpdate_01007.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 1548288 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-08-26 22:00 . 2004-08-17 13:45 2150400 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-08-26 22:00 . 2004-08-17 13:45 2017280 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 3003392 c:\windows\system32\dllcache\cache\mshtml.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 1032704 c:\windows\system32\dllcache\cache\explorer.exe
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-13 282624]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-29 544768]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 569413]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2006-02-21 17920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"NodEnabler"="c:\program files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe" [2009-04-08 357521]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
S1 855feef2;855feef2;c:\windows\system32\drivers\855feef2.sys [20.9.2009 13:14 87168]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [15.7.2009 19:02 222968]
S3 SynMini;ASUS WebCam, 1.3M, USB2.0, FF;c:\windows\system32\drivers\SynMini.sys [12.5.2008 20:52 841110]
S3 SynScan;ASUS WebCam Still Image;c:\windows\system32\drivers\SynScan.sys [12.5.2008 20:52 8278]
.
.
------- Doplňkový sken -------
.
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
.
Celkový čas: 2010-04-13 21:11:45
ComboFix-quarantined-files.txt 2010-04-13 19:11
ComboFix2.txt 2009-08-27 18:28
ComboFix3.txt 2009-08-26 22:01
ComboFix4.txt 2008-10-13 19:40
Před spuštěním: Volných bajtů: 15 350 509 568
Po spuštění: Volných bajtů: 15 320 322 048
- - End Of File - - 0614647578143695408B9BBF715EF051
tak i moje sestra se stala obětí Security TOOLu. Už jsem udělal COMBOfix. Přikládám LOG,
moc prosím o pomoc, jestli někdo víte. Aaa děkuju!!!
ComboFix 10-04-13.02 - Administrator 13.04.2010 21:06:23.5.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.377 [GMT 2:00]
Spuštěný z: c:\documents and settings\VERONIKA\Plocha\abraka.com.com
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikací\99909440
c:\documents and settings\All Users\Data aplikací\99909440\99909440.exe
c:\documents and settings\VERONIKA\Plocha\Security Tool.lnk
c:\windows\system32\acovcnt.exe
.
---- Předchozí spuštění -------
.
c:\documents and settings\All Users\Data aplikací\29572530\29572530.exe
c:\documents and settings\VERONIKA\Plocha\Security Tool.lnk
c:\windows\Temp\_ex-68.exe
-- Předchozí spuštění --
Nakažená kopie c:\windows\system32\drivers\AGP440.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\agp440.sys
--------
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-13 do 2010-04-13 )))))))))))))))))))))))))))))))
.
2010-04-13 19:04 . 2010-04-13 19:04 -------- d--h--w- c:\windows\PIF
2010-04-13 18:57 . 2010-04-13 18:57 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-13 19:00 . 2009-09-20 11:14 87168 ----a-w- c:\windows\system32\drivers\855feef2.sys
2010-03-28 07:27 . 2002-09-23 12:00 46394 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 07:27 . 2002-09-23 12:00 310228 ----a-w- c:\windows\system32\perfh005.dat
2008-10-12 20:16 . 2008-10-12 19:06 641056 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-08-26_21.59.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 00:07 . 2009-07-12 00:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 00:19 . 2009-07-12 00:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 18:41 . 2009-07-11 18:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2008-05-12 18:35 . 2008-03-21 12:57 23856 c:\windows\system32\spupdsvc.exe
+ 2010-02-02 19:08 . 2008-03-21 12:57 14640 c:\windows\system32\spmsgXP_2k3.dll
- 2002-09-23 12:00 . 2009-04-03 17:27 40326 c:\windows\system32\perfc009.dat
+ 2002-09-23 12:00 . 2010-03-28 07:27 40326 c:\windows\system32\perfc009.dat
+ 2010-02-02 19:03 . 2009-10-06 10:52 91136 c:\windows\system32\nmwcdcls.dll
+ 2010-02-02 19:04 . 2008-08-26 08:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
+ 2008-03-27 15:27 . 2008-03-27 15:27 35040 c:\windows\system32\drivers\wdfldr.sys
+ 2010-02-02 19:08 . 2004-08-03 22:08 25600 c:\windows\system32\drivers\usbser.sys
+ 2010-02-02 19:10 . 2006-08-29 14:56 32377 c:\windows\system32\drivers\prodigy.sys
+ 2010-02-02 19:04 . 2008-08-26 08:26 18816 c:\windows\system32\drivers\pccsmcfd.sys
+ 2008-05-12 19:23 . 2004-08-03 21:07 42368 c:\windows\system32\drivers\AGP440.sys
+ 2010-02-02 19:08 . 2004-08-03 22:08 25600 c:\windows\system32\dllcache\usbser.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 13824 c:\windows\system32\dllcache\cache\wscntfy.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 71680 c:\windows\system32\dllcache\cache\ssdpsrv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 59904 c:\windows\system32\dllcache\cache\regsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 89088 c:\windows\system32\dllcache\cache\rasauto.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-08-26 22:00 . 2005-01-28 06:53 25088 c:\windows\system32\dllcache\cache\MsPMSNSv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 33792 c:\windows\system32\dllcache\cache\msgsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 22016 c:\windows\system32\dllcache\cache\lpk.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 18944 c:\windows\system32\dllcache\cache\linkinfo.dll
+ 2009-08-26 22:00 . 2004-08-17 13:45 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-08-26 22:00 . 2004-08-03 21:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 55808 c:\windows\system32\dllcache\cache\eventlog.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 60416 c:\windows\system32\dllcache\cache\cryptsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 77312 c:\windows\system32\dllcache\cache\browser.dll
+ 2009-08-26 22:00 . 2004-08-03 21:05 14336 c:\windows\system32\dllcache\cache\asyncmac.sys
+ 2009-08-26 22:00 . 2002-09-23 12:00 11776 c:\windows\system32\dllcache\cache\acpiec.sys
+ 2010-02-02 19:04 . 2010-02-02 19:04 10134 c:\windows\Installer\{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}\ARPPRODUCTICON.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 5120 c:\windows\system32\dllcache\cache\sfc.dll
+ 2009-08-26 22:00 . 2002-09-23 12:00 2944 c:\windows\system32\dllcache\cache\null.sys
+ 2009-08-26 22:00 . 2002-09-23 12:00 4224 c:\windows\system32\dllcache\cache\beep.sys
+ 2009-07-12 00:12 . 2009-07-12 00:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09 . 2009-07-12 00:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08 . 2009-07-12 00:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2002-09-23 12:00 . 2010-03-28 07:27 311938 c:\windows\system32\perfh009.dat
- 2002-09-23 12:00 . 2009-04-03 17:27 311938 c:\windows\system32\perfh009.dat
+ 2010-02-02 19:04 . 2009-05-11 11:30 547840 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\PCCSWpdDriver.dll
+ 2008-03-27 15:27 . 2008-03-27 15:27 503008 c:\windows\system32\drivers\wdf01000.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 129536 c:\windows\system32\dllcache\cache\xmlprov.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 111104 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 657408 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 577024 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 185344 c:\windows\system32\dllcache\cache\upnphost.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 295936 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-08-26 22:00 . 2004-08-03 21:14 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 246272 c:\windows\system32\dllcache\cache\tapisrv.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 170496 c:\windows\system32\dllcache\cache\srsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 190976 c:\windows\system32\dllcache\cache\schedsvc.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 134656 c:\windows\system32\dllcache\cache\shsvcs.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 108544 c:\windows\system32\dllcache\cache\services.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 184832 c:\windows\system32\dllcache\cache\scecli.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 395776 c:\windows\system32\dllcache\cache\rpcss.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 382464 c:\windows\system32\dllcache\cache\qmgr.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 435712 c:\windows\system32\dllcache\cache\ntmssvc.dll
+ 2009-08-26 22:00 . 2004-08-03 21:15 574592 c:\windows\system32\dllcache\cache\ntfs.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 198144 c:\windows\system32\dllcache\cache\netman.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 407040 c:\windows\system32\dllcache\cache\netlogon.dll
+ 2009-08-26 22:00 . 2004-08-03 21:14 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-08-26 22:00 . 2004-08-17 13:49 247296 c:\windows\system32\dllcache\cache\mswsock.dll
+ 2009-08-26 22:00 . 2002-09-23 12:00 924432 c:\windows\system32\dllcache\cache\mfc40u.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 982016 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 243200 c:\windows\system32\dllcache\cache\es.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 806912 c:\windows\system32\dllcache\cache\comres.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 611328 c:\windows\system32\dllcache\cache\comctl32.dll
+ 2009-08-26 22:00 . 2004-08-03 20:39 142464 c:\windows\system32\dllcache\cache\aec.sys
+ 2010-02-02 19:04 . 2010-02-02 19:04 496128 c:\windows\Installer\a3319.msi
+ 2010-02-02 19:03 . 2010-02-02 19:03 215552 c:\windows\Installer\a330b.msi
+ 2010-02-02 19:08 . 2008-03-21 12:57 379184 c:\windows\$NtUninstallWdf01007$\spuninst\updspapi.dll
+ 2010-02-02 19:08 . 2008-03-21 12:57 221488 c:\windows\$NtUninstallWdf01007$\spuninst\spuninst.exe
+ 2009-07-11 19:46 . 2009-07-11 19:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 19:46 . 2009-07-11 19:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2010-02-02 19:04 . 2009-05-11 10:47 1302600 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\WUDFUpdate_01007.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 1548288 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-08-26 22:00 . 2004-08-17 13:45 2150400 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-08-26 22:00 . 2004-08-17 13:45 2017280 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-08-26 22:00 . 2004-08-17 13:49 3003392 c:\windows\system32\dllcache\cache\mshtml.dll
+ 2009-08-26 22:00 . 2004-08-17 13:49 1032704 c:\windows\system32\dllcache\cache\explorer.exe
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-13 282624]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-29 544768]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 602182]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 569413]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2006-02-21 17920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"NodEnabler"="c:\program files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe" [2009-04-08 357521]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
S1 855feef2;855feef2;c:\windows\system32\drivers\855feef2.sys [20.9.2009 13:14 87168]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [15.7.2009 19:02 222968]
S3 SynMini;ASUS WebCam, 1.3M, USB2.0, FF;c:\windows\system32\drivers\SynMini.sys [12.5.2008 20:52 841110]
S3 SynScan;ASUS WebCam Still Image;c:\windows\system32\drivers\SynScan.sys [12.5.2008 20:52 8278]
.
.
------- Doplňkový sken -------
.
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
.
Celkový čas: 2010-04-13 21:11:45
ComboFix-quarantined-files.txt 2010-04-13 19:11
ComboFix2.txt 2009-08-27 18:28
ComboFix3.txt 2009-08-26 22:01
ComboFix4.txt 2008-10-13 19:40
Před spuštěním: Volných bajtů: 15 350 509 568
Po spuštění: Volných bajtů: 15 320 322 048
- - End Of File - - 0614647578143695408B9BBF715EF051