Byl nalezen výskyt rootkitu mi to napsalo...jinak zde je log
ComboFix 11-01-14.01 - Kaul 15.01.2011 11:25:19.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2928 [GMT 1:00]
Spuštěný z: c:\documents and settings\Kaul\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\d3d10core.dll
c:\windows\system32\msvcsv60.dll
c:\windows\system32\sqlite3.dll
c:\windows\system32\sshnas21.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Service_SSHNAS
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-15 do 2011-01-15 )))))))))))))))))))))))))))))))
.
2011-01-15 08:48 . 2011-01-15 08:48 -------- d-----w- C:\rsit
2011-01-15 08:48 . 2011-01-15 08:48 -------- d-----w- c:\program files\trend micro
2011-01-15 03:53 . 2011-01-15 03:54 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Temp
2011-01-15 03:53 . 2011-01-15 03:55 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Google
2011-01-15 03:53 . 2011-01-15 03:53 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Deployment
2011-01-15 02:54 . 2011-01-15 02:53 220672 ----a-w- c:\windows\Bqytoa.exe
2011-01-15 02:18 . 2011-01-15 02:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Cakewalk
2011-01-15 02:15 . 2011-01-15 02:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\IK Multimedia
2011-01-15 01:37 . 2011-01-15 01:37 -------- d-----w- c:\program files\Common Files\Intel
2011-01-15 00:54 . 2011-01-15 00:54 -------- d-----w- c:\documents and settings\All Users\Nabdka Start
2011-01-15 00:53 . 2011-01-15 00:53 69632 ----a-w- c:\windows\system32\FxShared.dll
2011-01-15 00:53 . 2011-01-15 00:53 69632 ----a-w- c:\windows\system32\com.fxpansion.fxshared.dll
2011-01-15 00:53 . 2011-01-15 00:53 -------- d-----w- c:\program files\FXpansion
2011-01-15 00:53 . 2011-01-15 00:55 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\FXpansion
2011-01-15 00:22 . 2011-01-15 00:22 2892 ----a-w- c:\windows\system32\audcon.sys
2011-01-15 00:21 . 2011-01-15 01:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\eLicenser
2011-01-15 00:19 . 2011-01-15 00:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Syncrosoft
2011-01-14 13:18 . 2011-01-14 13:18 -------- d-----w- C:\Banks
2011-01-12 12:59 . 2011-01-12 12:59 -------- d-----w- c:\program files\Electronic Arts
2011-01-12 08:48 . 2011-01-12 08:48 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Command and Conquer 3 Kanes Wrath
2011-01-12 04:25 . 2011-01-12 04:43 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Command & Conquer 3 Tiberium Wars
2011-01-12 04:17 . 2011-01-12 04:17 218176 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-12 04:17 . 2011-01-15 03:42 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\AskToolbar
2011-01-12 04:17 . 2011-01-12 04:17 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2011-01-12 04:16 . 2011-01-13 09:05 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-12 04:16 . 2011-01-12 04:18 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\DAEMON Tools Lite
2011-01-12 04:16 . 2011-01-12 04:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DAEMON Tools Lite
2011-01-11 12:34 . 2011-01-11 12:44 -------- d-----w- c:\program files\EA Games
2011-01-10 18:41 . 2011-01-15 04:02 -------- d-----w- c:\program files\Ask.com
2011-01-10 18:40 . 2011-01-10 18:42 -------- d-----w- c:\program files\The KMPlayer
2011-01-10 18:33 . 2011-01-10 18:34 -------- d-----w- c:\program files\GRETECH
2011-01-07 22:06 . 2011-01-09 11:01 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\.minecraft
2011-01-07 14:57 . 2011-01-07 14:57 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Identities
2011-01-06 09:55 . 2011-01-06 10:14 -------- d-----w- c:\program files\Assassin's Creed II
2011-01-04 16:15 . 2011-01-04 16:15 -------- d-----w- c:\program files\Q3E Minimizer v1.51
2011-01-04 11:39 . 2008-04-13 23:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-01-04 10:37 . 2011-01-04 10:37 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\OLYMPUS
2011-01-04 10:36 . 2011-01-04 10:36 -------- d-----w- c:\program files\OLYMPUS
2011-01-04 10:36 . 2011-01-04 10:36 -------- d-----w- c:\program files\MSXML 4.0
2011-01-03 15:10 . 2011-01-03 15:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2011-01-03 15:06 . 2011-01-03 15:11 -------- d-----w- c:\program files\ATI
2011-01-03 15:04 . 2003-11-10 17:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-01-03 15:04 . 2003-11-10 17:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-01-03 15:04 . 2003-11-10 17:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-01-03 15:04 . 2003-11-10 17:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-01-03 15:04 . 2003-11-10 17:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-01-03 15:04 . 2011-01-03 15:04 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-01-03 15:04 . 2011-01-03 15:04 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-01-03 15:04 . 2008-12-01 13:35 593920 ------w- c:\windows\system32\ati2sgag.exe
2011-01-03 15:03 . 2011-01-03 15:06 -------- d-----w- c:\program files\ATI Technologies
2011-01-03 15:02 . 2011-01-03 15:02 -------- d-----w- C:\ATI
2011-01-02 23:03 . 2011-01-05 19:03 -------- d-----w- c:\program files\GamePark
2011-01-02 22:36 . 1999-12-17 09:13 86016 ----a-w- c:\windows\unvise32.exe
2011-01-02 22:35 . 2011-01-02 22:35 -------- d-----w- c:\program files\Mplayer
2011-01-02 22:34 . 2011-01-05 19:19 -------- d-----w- c:\program files\Quake III Arena
2011-01-02 20:43 . 2011-01-02 20:43 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Unity
2011-01-02 18:18 . 2011-01-02 18:18 -------- d-----w- c:\program files\Flash Game Downloader
2011-01-02 18:13 . 2011-01-02 18:13 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\ProgSense
2011-01-02 18:13 . 2011-01-03 18:40 -------- d-----w- C:\downloads
2011-01-02 18:13 . 2011-01-02 18:13 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\GrabPro
2011-01-02 18:13 . 2011-01-03 18:40 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Orbit
2011-01-02 16:58 . 2011-01-02 16:58 -------- d-----w- c:\program files\Bytescout XLS Viewer
2011-01-02 11:32 . 2011-01-15 00:22 -------- dc----w- c:\windows\system32\DRVSTORE
2011-01-01 23:13 . 2011-01-01 23:13 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Plogue Art et Technologie, Inc
2011-01-01 23:10 . 2011-01-01 23:10 -------- d-----w- c:\program files\Plogue
2011-01-01 22:57 . 2011-01-01 23:13 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Plogue
2011-01-01 22:57 . 2011-01-01 22:57 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Plogue
2010-12-31 05:29 . 2010-12-31 05:29 -------- d-----w- c:\program files\ASIO4ALL v2
2010-12-29 13:27 . 2010-12-29 13:27 -------- d-----w- c:\program files\VirtualDJ
2010-12-26 21:32 . 2010-12-29 22:18 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\vlc
2010-12-26 21:31 . 2010-12-26 21:31 -------- d-----w- c:\program files\VideoLAN
2010-12-26 07:43 . 2010-12-31 03:59 -------- d-----w- c:\program files\Image-Line
2010-12-26 06:06 . 2010-12-26 06:06 6051840 ----a-w- c:\windows\system32\PSP oldTimer.dll
2010-12-24 23:41 . 2010-12-26 09:26 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\KORG
2010-12-24 23:34 . 2010-12-24 23:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\KORG
2010-12-24 23:34 . 2010-12-24 23:34 -------- d-----w- c:\program files\Common Files\KORG
2010-12-24 23:34 . 2010-12-24 23:34 -------- d-----w- c:\program files\KORG
2010-12-24 13:43 . 2010-12-24 13:43 -------- d-----w- c:\documents and settings\Kaul\Local Settings\Data aplikací\Mozilla
2010-12-22 04:07 . 2010-12-22 04:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Pinnacle
2010-12-22 03:40 . 2010-12-22 03:40 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Antares
2010-12-22 03:40 . 2010-12-22 03:40 -------- d-----w- c:\program files\Antares Audio Technologies
2010-12-22 03:39 . 2005-05-09 19:08 33792 ----a-w- c:\windows\system32\drivers\cledx.sys
2010-12-22 03:39 . 2009-05-19 14:21 86016 ----a-w- c:\windows\system32\SYNSOPOS.exe
2010-12-22 03:39 . 2004-05-10 23:58 147456 ----a-w- c:\windows\system32\SynsoLChk.dll
2010-12-22 03:39 . 2011-01-15 01:43 -------- d-----w- c:\program files\Syncrosoft
2010-12-22 03:39 . 2009-09-17 15:20 1261568 ----a-w- c:\windows\system32\SYNSOACC.dll
2010-12-22 03:39 . 2001-04-09 13:03 17784 ----a-w- c:\windows\system32\drivers\NSynas32.sys
2010-12-22 01:02 . 2010-12-22 01:07 691551 ----a-w- c:\program files\Uninstall Information\{842C6AFC-7856-4fd9-99AF-8900554ACAA2}\unins000.exe
2010-12-22 01:00 . 2010-12-22 01:00 691551 ----a-w- c:\program files\Uninstall Information\{ABAF1232-6213-4062-9D52-04E04A730CEA}\unins000.exe
2010-12-22 00:54 . 2010-12-22 00:54 3191296 ----a-w- c:\windows\system32\PSP Nitro.dll
2010-12-22 00:10 . 2010-12-22 00:10 4332032 ----a-w- c:\windows\system32\PSP MixBass2.dll
2010-12-21 23:52 . 2010-12-21 23:52 -------- d-----w- c:\program files\VOB
2010-12-21 23:52 . 2002-09-26 16:34 153088 ----a-w- c:\windows\system32\IWUninstall.exe
2010-12-21 23:52 . 2002-08-28 10:09 611840 ----a-w- c:\windows\system32\vobhw.dll
2010-12-21 23:52 . 2002-04-17 19:27 11264 ----a-w- c:\windows\system32\drivers\asapi.sys
2010-12-21 23:52 . 2000-04-27 11:31 19456 ----a-w- c:\windows\system32\asapi.dll
2010-12-21 23:52 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-12-21 23:49 . 2010-12-21 23:49 -------- d-----w- c:\documents and settings\Kaul\WINDOWS
2010-12-21 23:36 . 2010-12-21 23:36 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\iZotope
2010-12-21 23:32 . 2010-12-21 23:32 -------- d-----w- c:\program files\Common Files\VST3
2010-12-21 21:06 . 2010-12-21 21:06 -------- d-----w- c:\program files\VSTPlugins
2010-12-21 21:06 . 2010-12-21 21:06 6618624 ----a-w- c:\windows\system32\PSP VintageWarmer2.dll
2010-12-21 21:06 . 2010-12-21 21:06 6580224 ----a-w- c:\windows\system32\PSP MicroWarmer.dll
2010-12-21 21:06 . 2010-12-21 21:06 6611456 ----a-w- c:\windows\system32\PSP VintageWarmer.dll
2010-12-21 21:01 . 2010-12-21 21:01 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Daichi
2010-12-21 20:53 . 2010-12-21 20:53 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Xfer
2010-12-21 20:47 . 2011-01-15 00:53 233472 ----a-w- c:\windows\system32\REX Shared Library.dll
2010-12-21 20:47 . 2009-09-08 21:01 368640 ------w- c:\windows\system32\ReWire.dll
2010-12-21 19:49 . 2010-12-22 06:01 -------- d-----w- c:\program files\Common Files\Native Instruments
2010-12-21 19:13 . 2010-12-21 19:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Ableton
2010-12-21 19:13 . 2010-12-21 20:50 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\Ableton
2010-12-20 09:36 . 2010-11-06 00:23 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-12-20 09:36 . 2010-11-06 00:23 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-12-20 09:36 . 2010-11-06 00:23 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-20 09:36 . 2010-11-06 00:23 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-20 09:36 . 2010-11-06 00:23 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-12-20 09:36 . 2010-11-06 00:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-20 09:36 . 2010-11-06 00:23 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-12-19 22:52 . 2010-12-19 22:52 -------- d-----w- c:\documents and settings\Kaul\Data aplikací\RigNRoll_usa_ws
2010-12-19 22:48 . 2008-02-29 01:50 782336 ----a-r- c:\windows\system32\tmp1F0.tmp
2010-12-19 22:48 . 2008-02-29 01:50 782336 ----a-r- c:\windows\system32\tmp1EF.tmp
2010-12-19 21:39 . 2010-12-19 21:39 -------- d-sh--w- c:\documents and settings\Kaul\PrivacIE
2010-12-19 21:35 . 2010-12-19 21:35 -------- d-sh--w- c:\documents and settings\Kaul\IETldCache
2010-12-19 21:31 . 2010-12-19 21:33 -------- dc-h--w- c:\windows\ie8
2010-12-17 19:45 . 2010-12-17 19:45 -------- d-----w- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-06 14:06 . 2010-12-06 14:06 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-12-06 14:06 . 2010-12-06 14:06 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2010-12-03 11:00 . 2010-12-03 11:00 348160 ----a-w- c:\windows\system32\Msvcr71.dll
2010-12-03 11:00 . 2010-12-03 11:00 1060864 ----a-w- c:\windows\system32\mfc71.dll
2010-12-03 10:37 . 2010-12-03 10:37 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-12-02 12:30 . 2010-12-02 12:30 96874 ----a-w- c:\documents and settings\Kaul\Data aplikací\Uninstal.exe
2010-12-01 15:49 . 2010-12-01 15:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-12-01 15:49 . 2010-12-01 15:49 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-01 13:55 . 2010-12-01 13:55 315392 ----a-w- c:\windows\HideWin.exe
2010-11-18 18:15 . 2010-12-01 13:32 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2003-04-16 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:23 . 2003-04-16 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:23 . 2003-04-16 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:23 . 2003-04-16 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-12-01 17:12 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-04-16 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:09 . 2003-04-16 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:58 . 2003-04-16 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-01-13 08:47 120712 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]
"Google Update"="c:\documents and settings\Kaul\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2011-01-15 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 16132608]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-04-17 54576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 07:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-05 09:09 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Dirt 2game\\dirt2_game.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\VirtualDJ\\virtualdj_pro.exe"=
"c:\\Program Files\\Quake III Arena\\quake3.exe"=
"c:\\Program Files\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\generals.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\generals.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\WorldBuilder.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\WorldBuilder.exe"=
"d:\\Image-Line\\FL Studio 9\\FL.exe"=
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [22.12.2010 0:52 11264]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [17.12.2010 16:58 357968]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17.12.2010 16:58 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.12.2010 16:58 17744]
R2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [16.12.2010 21:06 685816]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [22.12.2010 4:39 33792]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [12.1.2011 5:17 218176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-15 c:\windows\Tasks\Game_Booster_Startup.job
- c:\program files\IObit\Game Booster\GameBox.exe [2010-12-17 18:08]
2011-01-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 21:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.msn.com
mStart Page = hxxp://
www.msn.com
TCP: {BB9FD199-B423-42A3-9F79-32051D771B0F} = 8.8.4.4,8.8.8.8
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-15 11:36
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1275210071-562591055-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:52,1e,2d,6e,db,66,89,c1,16,c8,8c,03,94,e9,b1,42,19,d3,ab,81,e3,f1,07,
97,9a,8c,99,28,2f,fa,35,43,62,61,0d,ca,db,1e,88,8d,fc,57,92,b1,07,84,6b,96,\
"??"=hex:0a,ad,90,f0,65,3c,48,de,9a,dd,e5,c4,ed,13,f0,dd
[HKEY_USERS\S-1-5-21-1275210071-562591055-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:05,64,79,3b,0a,d0,5a,d8,e5,f0,ef,86,0c,ce,51,e0,f7,6c,ce,22,65,
ea,d1,52,5f,cc,3c,32,cd,3c,d4,e6,df,68,8e,dc,01,7d,a8,c8,8d,da,af,dd,ec,82,\
"rkeysecu"=hex:aa,8d,e3,8f,71,49,b7,39,3d,c5,e4,0e,ea,7b,cd,75
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2396)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Celkový čas: 2011-01-15 11:41:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-01-15 10:41
Před spuštěním: 6 740 660 224
Po spuštění: 6 660 472 832
- - End Of File - - 04130F03F8F98ABC7786551B1FBB5566