win32:malware-gen (a kdoan.sys + mjvpvgz.sys)
Napsal: 23 říj 2010 19:36
mám v pc dvou soubory - kdoan.sys a mjvpvgz.sys které neumí avast odstarnit.
děkuji za radu co s tím.
výpis logu:
ComboFix 10-10-22.05 - admin 23.10.2010 20:01:00.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.895.389 [GMT 2:00]
Spuštěný z: d:\_download\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 101023-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\mjvpvgz.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_mjvpvgz
-------\Service_mjvpvgz
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-23 do 2010-10-23 )))))))))))))))))))))))))))))))
.
2010-10-23 17:33 . 2010-10-23 17:33 -------- d-----w- c:\documents and settings\admin\Local Settings\Data aplikací\AskToolbar
2010-10-22 17:56 . 2010-10-23 18:12 756224 ----a-w- c:\windows\system32\drivers\kdoan.sys
2010-10-19 09:47 . 2010-10-19 09:47 -------- d-----w- c:\program files\Ask.com
2010-10-07 18:42 . 2010-10-07 18:42 -------- d-----w- c:\documents and settings\admin\Data aplikací\Malwarebytes
2010-10-07 18:42 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-07 18:41 . 2010-10-07 18:41 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-07 18:41 . 2010-10-07 18:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-07 18:41 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-07 08:42 . 2010-10-07 11:04 -------- d-----w- c:\documents and settings\admin\Data aplikací\AIMP
2010-10-07 08:29 . 2010-10-07 08:29 -------- d-----w- c:\program files\AIMP2
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 07:07 . 2010-09-01 07:07 22558023 ----a-w- c:\windows\system32\CDSM_CDSM Designer_uninstaller.exe
2010-08-06 12:22 . 2007-10-28 18:08 94208 ----a-w- c:\windows\DUMP50b0.tmp
.
((((((((((((((((((((((((((((( SnapShot@2010-10-15_08.01.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-23 18:04 . 2010-10-23 18:04 16384 c:\windows\Temp\Perflib_Perfdata_734.dat
+ 2010-10-23 09:40 . 2010-10-23 09:40 16384 c:\windows\Temp\Perflib_Perfdata_72c.dat
+ 2010-10-23 18:04 . 2010-10-23 18:04 16384 c:\windows\Temp\Perflib_Perfdata_220.dat
+ 2010-10-15 18:48 . 2010-10-23 18:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-10-15 08:01 . 2010-10-15 08:01 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-28 17:28 . 2010-10-15 08:01 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-28 17:28 . 2010-10-23 18:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-10-15 18:48 . 2010-10-23 18:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-10-28 17:28 . 2010-10-15 08:01 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-10-19 09:47 . 2010-10-19 09:47 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2010-10-19 09:47 . 2010-10-19 09:47 1904640 c:\windows\Installer\b56557.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-17 16:43 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2006-05-18 450560]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
c:\documents and settings\admin\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-9-11 393216]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6.4.2008 0:13 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.4.2008 0:13 20560]
S3 5249569c070ed6b5;5249569c070ed6b5;\??\c:\windows\TEMP\940037ac3795 --> c:\windows\TEMP\940037ac3795 [?]
S3 af36d2516e9b5b2d;af36d2516e9b5b2d;\??\c:\windows\TEMP\92405e34f161 --> c:\windows\TEMP\92405e34f161 [?]
S3 AF9035BDA;GIGABYTE U7200 DVB-T Devices;c:\windows\system32\drivers\AF9035BDA.sys [29.5.2008 15:39 244096]
S4 078f0aba1620ca71;078f0aba1620ca71;\??\c:\windows\TEMP\9200682dd558 --> c:\windows\TEMP\9200682dd558 [?]
S4 0f971ebf42779f9b;0f971ebf42779f9b;\??\c:\windows\TEMP\9320c235a74a --> c:\windows\TEMP\9320c235a74a [?]
S4 10270bb7faa2f395;10270bb7faa2f395;\??\c:\windows\TEMP\92804bdbc8e5 --> c:\windows\TEMP\92804bdbc8e5 [?]
S4 159048c36599f5fd;159048c36599f5fd;\??\c:\windows\TEMP\92007631051 --> c:\windows\TEMP\92007631051 [?]
S4 1f3193a667460dca;1f3193a667460dca;\??\c:\windows\TEMP\9200ed1318db --> c:\windows\TEMP\9200ed1318db [?]
S4 21daad4a110130e9;21daad4a110130e9;\??\c:\windows\TEMP\9320aa22c075 --> c:\windows\TEMP\9320aa22c075 [?]
S4 2baebbe02e20191d;2baebbe02e20191d;\??\c:\windows\TEMP\92003da71f91 --> c:\windows\TEMP\92003da71f91 [?]
S4 35179bebb8e8cab3;35179bebb8e8cab3;\??\c:\windows\TEMP\92003a05f677 --> c:\windows\TEMP\92003a05f677 [?]
S4 4ccc71471f0eab03;4ccc71471f0eab03;\??\c:\windows\TEMP\92005d95e76d --> c:\windows\TEMP\92005d95e76d [?]
S4 53d3e5734868f3ba;53d3e5734868f3ba;\??\c:\windows\TEMP\9200aee16eaa --> c:\windows\TEMP\9200aee16eaa [?]
S4 61e6fb59dfa2c3e9;61e6fb59dfa2c3e9;\??\c:\windows\TEMP\92007d903262 --> c:\windows\TEMP\92007d903262 [?]
S4 64e9ca2ec768e6de;64e9ca2ec768e6de;\??\c:\windows\TEMP\920021cc7eb9 --> c:\windows\TEMP\920021cc7eb9 [?]
S4 71231cead0956b8d;71231cead0956b8d;\??\c:\windows\TEMP\9200ca3f533d --> c:\windows\TEMP\9200ca3f533d [?]
S4 9e7d78327bbd610e;9e7d78327bbd610e;\??\c:\windows\TEMP\9240dc18d502 --> c:\windows\TEMP\9240dc18d502 [?]
S4 b61e06d104588609;b61e06d104588609;\??\c:\windows\TEMP\9240ed8981c5 --> c:\windows\TEMP\9240ed8981c5 [?]
S4 bf7a9dc80811dafa;bf7a9dc80811dafa;\??\c:\windows\TEMP\92009089621e --> c:\windows\TEMP\92009089621e [?]
S4 c69e8e8de2f496ec;c69e8e8de2f496ec;\??\c:\windows\TEMP\9200e6037d68 --> c:\windows\TEMP\9200e6037d68 [?]
S4 cf5ecafa7c2ed4d4;cf5ecafa7c2ed4d4;\??\c:\windows\TEMP\92401b04169b --> c:\windows\TEMP\92401b04169b [?]
S4 cffc5fdfcd0d8579;cffc5fdfcd0d8579;\??\c:\windows\TEMP\92004085f092 --> c:\windows\TEMP\92004085f092 [?]
S4 d667dcbe3929be43;d667dcbe3929be43;\??\c:\windows\TEMP\9280c5fa95f0 --> c:\windows\TEMP\9280c5fa95f0 [?]
S4 dd24e9cc406a726a;dd24e9cc406a726a;\??\c:\windows\TEMP\9200583b6812 --> c:\windows\TEMP\9200583b6812 [?]
S4 f3c68bc4c8f51a06;f3c68bc4c8f51a06;\??\c:\windows\TEMP\92405952bbbf --> c:\windows\TEMP\92405952bbbf [?]
S4 f42efddd14a91613;f42efddd14a91613;\??\c:\windows\TEMP\9200be4dfcf0 --> c:\windows\TEMP\9200be4dfcf0 [?]
S4 fdf9c64d7c0e7240;fdf9c64d7c0e7240;\??\c:\windows\TEMP\932028d180da --> c:\windows\TEMP\932028d180da [?]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - kdoan
.
Obsah adresáře 'Naplánované úlohy'
2010-10-23 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-17 16:43]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\pwbdbsdi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 20:12
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\078f0aba1620ca71]
"ImagePath"="\??\c:\windows\TEMP\9200682dd558"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0f971ebf42779f9b]
"ImagePath"="\??\c:\windows\TEMP\9320c235a74a"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\10270bb7faa2f395]
"ImagePath"="\??\c:\windows\TEMP\92804bdbc8e5"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\159048c36599f5fd]
"ImagePath"="\??\c:\windows\TEMP\92007631051"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\1f3193a667460dca]
"ImagePath"="\??\c:\windows\TEMP\9200ed1318db"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\21daad4a110130e9]
"ImagePath"="\??\c:\windows\TEMP\9320aa22c075"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\2baebbe02e20191d]
"ImagePath"="\??\c:\windows\TEMP\92003da71f91"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\35179bebb8e8cab3]
"ImagePath"="\??\c:\windows\TEMP\92003a05f677"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\4ccc71471f0eab03]
"ImagePath"="\??\c:\windows\TEMP\92005d95e76d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\5249569c070ed6b5]
"ImagePath"="\??\c:\windows\TEMP\940037ac3795"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\53d3e5734868f3ba]
"ImagePath"="\??\c:\windows\TEMP\9200aee16eaa"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\61e6fb59dfa2c3e9]
"ImagePath"="\??\c:\windows\TEMP\92007d903262"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\64e9ca2ec768e6de]
"ImagePath"="\??\c:\windows\TEMP\920021cc7eb9"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\71231cead0956b8d]
"ImagePath"="\??\c:\windows\TEMP\9200ca3f533d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\9e7d78327bbd610e]
"ImagePath"="\??\c:\windows\TEMP\9240dc18d502"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\af36d2516e9b5b2d]
"ImagePath"="\??\c:\windows\TEMP\92405e34f161"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b61e06d104588609]
"ImagePath"="\??\c:\windows\TEMP\9240ed8981c5"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bf7a9dc80811dafa]
"ImagePath"="\??\c:\windows\TEMP\92009089621e"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\c69e8e8de2f496ec]
"ImagePath"="\??\c:\windows\TEMP\9200e6037d68"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cf5ecafa7c2ed4d4]
"ImagePath"="\??\c:\windows\TEMP\92401b04169b"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cffc5fdfcd0d8579]
"ImagePath"="\??\c:\windows\TEMP\92004085f092"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d667dcbe3929be43]
"ImagePath"="\??\c:\windows\TEMP\9280c5fa95f0"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dd24e9cc406a726a]
"ImagePath"="\??\c:\windows\TEMP\9200583b6812"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\f3c68bc4c8f51a06]
"ImagePath"="\??\c:\windows\TEMP\92405952bbbf"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\f42efddd14a91613]
"ImagePath"="\??\c:\windows\TEMP\9200be4dfcf0"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fdf9c64d7c0e7240]
"ImagePath"="\??\c:\windows\TEMP\932028d180da"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kdoan]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1732)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Celkový čas: 2010-10-23 20:14:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-23 18:14
ComboFix2.txt 2010-10-15 08:04
Před spuštěním: Volných bajtů: 25 932 341 248
Po spuštění: Volných bajtů: 25 914 732 544
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - DAB0BCBC02F9F5A1221DBB26DDB48B19
děkuji za radu co s tím.
výpis logu:
ComboFix 10-10-22.05 - admin 23.10.2010 20:01:00.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.895.389 [GMT 2:00]
Spuštěný z: d:\_download\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 101023-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\mjvpvgz.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_mjvpvgz
-------\Service_mjvpvgz
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-23 do 2010-10-23 )))))))))))))))))))))))))))))))
.
2010-10-23 17:33 . 2010-10-23 17:33 -------- d-----w- c:\documents and settings\admin\Local Settings\Data aplikací\AskToolbar
2010-10-22 17:56 . 2010-10-23 18:12 756224 ----a-w- c:\windows\system32\drivers\kdoan.sys
2010-10-19 09:47 . 2010-10-19 09:47 -------- d-----w- c:\program files\Ask.com
2010-10-07 18:42 . 2010-10-07 18:42 -------- d-----w- c:\documents and settings\admin\Data aplikací\Malwarebytes
2010-10-07 18:42 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-07 18:41 . 2010-10-07 18:41 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-07 18:41 . 2010-10-07 18:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-07 18:41 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-07 08:42 . 2010-10-07 11:04 -------- d-----w- c:\documents and settings\admin\Data aplikací\AIMP
2010-10-07 08:29 . 2010-10-07 08:29 -------- d-----w- c:\program files\AIMP2
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 07:07 . 2010-09-01 07:07 22558023 ----a-w- c:\windows\system32\CDSM_CDSM Designer_uninstaller.exe
2010-08-06 12:22 . 2007-10-28 18:08 94208 ----a-w- c:\windows\DUMP50b0.tmp
.
((((((((((((((((((((((((((((( SnapShot@2010-10-15_08.01.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-23 18:04 . 2010-10-23 18:04 16384 c:\windows\Temp\Perflib_Perfdata_734.dat
+ 2010-10-23 09:40 . 2010-10-23 09:40 16384 c:\windows\Temp\Perflib_Perfdata_72c.dat
+ 2010-10-23 18:04 . 2010-10-23 18:04 16384 c:\windows\Temp\Perflib_Perfdata_220.dat
+ 2010-10-15 18:48 . 2010-10-23 18:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-10-15 08:01 . 2010-10-15 08:01 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-28 17:28 . 2010-10-15 08:01 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-28 17:28 . 2010-10-23 18:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-10-15 18:48 . 2010-10-23 18:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-10-28 17:28 . 2010-10-15 08:01 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-10-19 09:47 . 2010-10-19 09:47 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2010-10-19 09:47 . 2010-10-19 09:47 1904640 c:\windows\Installer\b56557.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-17 16:43 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2006-05-18 450560]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
c:\documents and settings\admin\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-9-11 393216]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6.4.2008 0:13 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.4.2008 0:13 20560]
S3 5249569c070ed6b5;5249569c070ed6b5;\??\c:\windows\TEMP\940037ac3795 --> c:\windows\TEMP\940037ac3795 [?]
S3 af36d2516e9b5b2d;af36d2516e9b5b2d;\??\c:\windows\TEMP\92405e34f161 --> c:\windows\TEMP\92405e34f161 [?]
S3 AF9035BDA;GIGABYTE U7200 DVB-T Devices;c:\windows\system32\drivers\AF9035BDA.sys [29.5.2008 15:39 244096]
S4 078f0aba1620ca71;078f0aba1620ca71;\??\c:\windows\TEMP\9200682dd558 --> c:\windows\TEMP\9200682dd558 [?]
S4 0f971ebf42779f9b;0f971ebf42779f9b;\??\c:\windows\TEMP\9320c235a74a --> c:\windows\TEMP\9320c235a74a [?]
S4 10270bb7faa2f395;10270bb7faa2f395;\??\c:\windows\TEMP\92804bdbc8e5 --> c:\windows\TEMP\92804bdbc8e5 [?]
S4 159048c36599f5fd;159048c36599f5fd;\??\c:\windows\TEMP\92007631051 --> c:\windows\TEMP\92007631051 [?]
S4 1f3193a667460dca;1f3193a667460dca;\??\c:\windows\TEMP\9200ed1318db --> c:\windows\TEMP\9200ed1318db [?]
S4 21daad4a110130e9;21daad4a110130e9;\??\c:\windows\TEMP\9320aa22c075 --> c:\windows\TEMP\9320aa22c075 [?]
S4 2baebbe02e20191d;2baebbe02e20191d;\??\c:\windows\TEMP\92003da71f91 --> c:\windows\TEMP\92003da71f91 [?]
S4 35179bebb8e8cab3;35179bebb8e8cab3;\??\c:\windows\TEMP\92003a05f677 --> c:\windows\TEMP\92003a05f677 [?]
S4 4ccc71471f0eab03;4ccc71471f0eab03;\??\c:\windows\TEMP\92005d95e76d --> c:\windows\TEMP\92005d95e76d [?]
S4 53d3e5734868f3ba;53d3e5734868f3ba;\??\c:\windows\TEMP\9200aee16eaa --> c:\windows\TEMP\9200aee16eaa [?]
S4 61e6fb59dfa2c3e9;61e6fb59dfa2c3e9;\??\c:\windows\TEMP\92007d903262 --> c:\windows\TEMP\92007d903262 [?]
S4 64e9ca2ec768e6de;64e9ca2ec768e6de;\??\c:\windows\TEMP\920021cc7eb9 --> c:\windows\TEMP\920021cc7eb9 [?]
S4 71231cead0956b8d;71231cead0956b8d;\??\c:\windows\TEMP\9200ca3f533d --> c:\windows\TEMP\9200ca3f533d [?]
S4 9e7d78327bbd610e;9e7d78327bbd610e;\??\c:\windows\TEMP\9240dc18d502 --> c:\windows\TEMP\9240dc18d502 [?]
S4 b61e06d104588609;b61e06d104588609;\??\c:\windows\TEMP\9240ed8981c5 --> c:\windows\TEMP\9240ed8981c5 [?]
S4 bf7a9dc80811dafa;bf7a9dc80811dafa;\??\c:\windows\TEMP\92009089621e --> c:\windows\TEMP\92009089621e [?]
S4 c69e8e8de2f496ec;c69e8e8de2f496ec;\??\c:\windows\TEMP\9200e6037d68 --> c:\windows\TEMP\9200e6037d68 [?]
S4 cf5ecafa7c2ed4d4;cf5ecafa7c2ed4d4;\??\c:\windows\TEMP\92401b04169b --> c:\windows\TEMP\92401b04169b [?]
S4 cffc5fdfcd0d8579;cffc5fdfcd0d8579;\??\c:\windows\TEMP\92004085f092 --> c:\windows\TEMP\92004085f092 [?]
S4 d667dcbe3929be43;d667dcbe3929be43;\??\c:\windows\TEMP\9280c5fa95f0 --> c:\windows\TEMP\9280c5fa95f0 [?]
S4 dd24e9cc406a726a;dd24e9cc406a726a;\??\c:\windows\TEMP\9200583b6812 --> c:\windows\TEMP\9200583b6812 [?]
S4 f3c68bc4c8f51a06;f3c68bc4c8f51a06;\??\c:\windows\TEMP\92405952bbbf --> c:\windows\TEMP\92405952bbbf [?]
S4 f42efddd14a91613;f42efddd14a91613;\??\c:\windows\TEMP\9200be4dfcf0 --> c:\windows\TEMP\9200be4dfcf0 [?]
S4 fdf9c64d7c0e7240;fdf9c64d7c0e7240;\??\c:\windows\TEMP\932028d180da --> c:\windows\TEMP\932028d180da [?]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - kdoan
.
Obsah adresáře 'Naplánované úlohy'
2010-10-23 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-17 16:43]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\pwbdbsdi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 20:12
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\078f0aba1620ca71]
"ImagePath"="\??\c:\windows\TEMP\9200682dd558"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0f971ebf42779f9b]
"ImagePath"="\??\c:\windows\TEMP\9320c235a74a"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\10270bb7faa2f395]
"ImagePath"="\??\c:\windows\TEMP\92804bdbc8e5"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\159048c36599f5fd]
"ImagePath"="\??\c:\windows\TEMP\92007631051"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\1f3193a667460dca]
"ImagePath"="\??\c:\windows\TEMP\9200ed1318db"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\21daad4a110130e9]
"ImagePath"="\??\c:\windows\TEMP\9320aa22c075"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\2baebbe02e20191d]
"ImagePath"="\??\c:\windows\TEMP\92003da71f91"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\35179bebb8e8cab3]
"ImagePath"="\??\c:\windows\TEMP\92003a05f677"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\4ccc71471f0eab03]
"ImagePath"="\??\c:\windows\TEMP\92005d95e76d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\5249569c070ed6b5]
"ImagePath"="\??\c:\windows\TEMP\940037ac3795"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\53d3e5734868f3ba]
"ImagePath"="\??\c:\windows\TEMP\9200aee16eaa"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\61e6fb59dfa2c3e9]
"ImagePath"="\??\c:\windows\TEMP\92007d903262"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\64e9ca2ec768e6de]
"ImagePath"="\??\c:\windows\TEMP\920021cc7eb9"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\71231cead0956b8d]
"ImagePath"="\??\c:\windows\TEMP\9200ca3f533d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\9e7d78327bbd610e]
"ImagePath"="\??\c:\windows\TEMP\9240dc18d502"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\af36d2516e9b5b2d]
"ImagePath"="\??\c:\windows\TEMP\92405e34f161"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b61e06d104588609]
"ImagePath"="\??\c:\windows\TEMP\9240ed8981c5"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bf7a9dc80811dafa]
"ImagePath"="\??\c:\windows\TEMP\92009089621e"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\c69e8e8de2f496ec]
"ImagePath"="\??\c:\windows\TEMP\9200e6037d68"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cf5ecafa7c2ed4d4]
"ImagePath"="\??\c:\windows\TEMP\92401b04169b"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cffc5fdfcd0d8579]
"ImagePath"="\??\c:\windows\TEMP\92004085f092"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d667dcbe3929be43]
"ImagePath"="\??\c:\windows\TEMP\9280c5fa95f0"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dd24e9cc406a726a]
"ImagePath"="\??\c:\windows\TEMP\9200583b6812"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\f3c68bc4c8f51a06]
"ImagePath"="\??\c:\windows\TEMP\92405952bbbf"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\f42efddd14a91613]
"ImagePath"="\??\c:\windows\TEMP\9200be4dfcf0"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fdf9c64d7c0e7240]
"ImagePath"="\??\c:\windows\TEMP\932028d180da"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kdoan]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1732)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Celkový čas: 2010-10-23 20:14:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-23 18:14
ComboFix2.txt 2010-10-15 08:04
Před spuštěním: Volných bajtů: 25 932 341 248
Po spuštění: Volných bajtů: 25 914 732 544
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - DAB0BCBC02F9F5A1221DBB26DDB48B19