Prosím o kontrolu logu - podezření na vir
Napsal: 27 led 2011 10:51
Na jednom PC je zrejme vir, ktery nedovoli instalaci antiviru. Prosim o kontrolu logu.
Logfile of random's system information tool 1.08 (written by random/random)
Run by spravce at 2011-01-27 10:22:01
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 68 GB (89%) free of 76 GB
Total RAM: 1014 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:22:14, on 27.1.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\spravce.PRAHA2\Local Settings\Temporary Internet Files\Content.IE5\BT92EVVC\RSIT[1].exe
C:\Program Files\trend micro\spravce.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.33.10.33:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.33.4.*;10.33.5.*;10.33.6.*;10.33.7.*;10.33.8.*;10.33.9.*;10.33.10.33;*.p2.mepnet.cz,helpdesk;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKUS\S-1-5-21-1445019073-709728891-461039229-2380\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'kleckao')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://10.33.7.215/VatDec.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3059198468
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = praha2.p2.mepnet.cz
O17 - HKLM\Software\..\Telephony: DomainName = praha2.p2.mepnet.cz
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F4616FC-F269-42F8-90F3-D90D5F20FB8D}: NameServer = 10.33.10.21,10.33.4.150
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = praha2.p2.mepnet.cz
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F4616FC-F269-42F8-90F3-D90D5F20FB8D}: NameServer = 10.33.10.21,10.33.4.150
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
--
End of file - 4919 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2004-08-20 155648]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2004-08-20 118784]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2004-08-17 143872]
"ToolBoxFX"=C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe [2006-02-02 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-08-20 344064]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\\Aplcity\geovap\cityware\poplatky\Poplatky.exe"="\\Aplcity\geovap\cityware\poplatky\Poplatky.exe:*:Disabled:Poplatky"
======List of files/folders created in the last 1 months======
2011-01-27 10:22:01 ----D---- C:\rsit
2011-01-27 10:22:01 ----D---- C:\Program Files\trend micro
2011-01-27 10:21:15 ----A---- C:\ComboFix.txt
2011-01-26 09:56:57 ----A---- C:\WINDOWS\MBR.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\zip.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWSC.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWREG.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\sed.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\PEV.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\NIRCMD.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\grep.exe
2011-01-26 09:51:57 ----D---- C:\WINDOWS\ERDNT
2011-01-26 09:50:00 ----D---- C:\Qoobox
2011-01-25 10:44:12 ----A---- C:\WINDOWS\ntbtlog.txt
2011-01-25 10:34:53 ----D---- C:\Program Files\CCleaner
2011-01-25 10:32:56 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Macromedia
2011-01-25 10:22:56 ----D---- C:\Program Files\Symantec
2011-01-25 10:22:56 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-01-25 10:22:15 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\pdfforge
2011-01-25 10:06:11 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Search Settings
2011-01-25 10:06:07 ----D---- C:\Program Files\pdfforge Toolbar
2011-01-25 10:06:07 ----D---- C:\Program Files\Common Files\Spigot
2011-01-25 10:06:07 ----D---- C:\Program Files\Application Updater
2011-01-25 10:05:30 ----D---- C:\Program Files\IrfanView
2011-01-25 10:04:56 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-01-25 10:04:55 ----D---- C:\Program Files\PDFCreator
2011-01-25 10:04:55 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-01-25 10:01:55 ----D---- C:\WINDOWS\SchCache
2011-01-13 10:36:16 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-01-13 10:36:15 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-01-13 10:36:15 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-01-13 08:29:36 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Adobe
2011-01-13 08:28:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-01-13 08:25:35 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Google
2011-01-13 08:23:56 ----A---- C:\WINDOWS\system32\MFC71.DLL
2011-01-13 08:23:56 ----A---- C:\WINDOWS\system32\capicom.dll
2011-01-13 08:23:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2011-01-13 08:17:22 ----A---- C:\WINDOWS\User Profile Migration Service.exe
2011-01-13 08:17:08 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\HP
2011-01-13 08:10:57 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Identities
2011-01-13 08:10:44 ----ASH---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\desktop.ini
2011-01-13 08:10:43 ----SD---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Microsoft
======List of files/folders modified in the last 1 months======
2011-01-27 10:22:08 ----D---- C:\WINDOWS\Prefetch
2011-01-27 10:22:01 ----RD---- C:\Program Files
2011-01-27 10:19:50 ----D---- C:\WINDOWS
2011-01-27 10:19:50 ----A---- C:\WINDOWS\system.ini
2011-01-27 10:19:44 ----D---- C:\WINDOWS\system32\drivers\etc
2011-01-27 10:18:56 ----D---- C:\WINDOWS\Temp
2011-01-27 10:18:10 ----D---- C:\WINDOWS\system32\drivers
2011-01-27 10:18:10 ----D---- C:\WINDOWS\system32
2011-01-27 10:18:10 ----D---- C:\WINDOWS\AppPatch
2011-01-27 10:18:06 ----D---- C:\Program Files\Common Files
2011-01-27 10:12:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-27 10:12:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-27 10:12:12 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-01-27 10:12:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-01-27 10:10:43 ----SHD---- C:\WINDOWS\Installer
2011-01-27 10:10:42 ----D---- C:\Config.Msi
2011-01-27 10:06:22 ----D---- C:\WINDOWS\WinSxS
2011-01-27 10:05:03 ----D---- C:\Temp
2011-01-27 07:38:18 ----D---- C:\WINDOWS\security
2011-01-25 10:45:57 ----D---- C:\WINDOWS\system32\appmgmt
2011-01-25 10:35:22 ----D---- C:\WINDOWS\Debug
2011-01-25 09:46:59 ----D---- C:\VITA
2011-01-14 07:30:58 ----D---- C:\WINDOWS\system32\config
2011-01-13 10:36:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-13 08:44:32 ----D---- C:\Program Files\BackSave
2011-01-13 08:44:26 ----A---- C:\WINDOWS\ST6UNST.EXE
2011-01-13 08:44:23 ----D---- C:\Program Files\Info
2011-01-13 08:39:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-13 08:39:38 ----D---- C:\WINDOWS\ShellNew
2011-01-13 08:39:38 ----D---- C:\WINDOWS\Help
2011-01-13 08:38:45 ----A---- C:\WINDOWS\ODBC.INI
2011-01-13 08:38:40 ----RSD---- C:\WINDOWS\Fonts
2011-01-13 08:37:53 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-13 08:37:51 ----D---- C:\WINDOWS\Downloaded Installations
2011-01-13 08:37:49 ----D---- C:\Program Files\Kaspersky Lab
2011-01-13 08:31:41 ----D---- C:\Documents and Settings
2011-01-13 08:28:32 ----D---- C:\Program Files\Common Files\Adobe
2011-01-13 08:28:16 ----D---- C:\Program Files\Adobe
2011-01-13 08:26:28 ----D---- C:\Program Files\Google
2011-01-13 08:26:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 ShldDrv;Panda File Shield Driver; C:\WINDOWS\system32\drivers\ShldDrv.sys [2005-11-09 26656]
R2 PavProc;Panda Process Protection Driver; \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys []
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 b57w2k;Broadcom NetXtreme 57xx Gigabit Controller; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2004-04-29 186112]
R3 catchme;catchme; \??\C:\DOCUME~1\SPRAVC~1.PRA\LOCALS~1\Temp\catchme.sys []
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2003-08-07 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2004-08-20 737874]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2003-08-07 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-09 612352]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 HPFXBULK;HPFXBULK; C:\WINDOWS\system32\drivers\hpfxbulk.sys [2005-09-20 9344]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-10-28 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-28 21568]
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 TSP;TSP; \??\C:\WINDOWS\system32\drivers\klif.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-08-07 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-10-22 386560]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 PavPrSrv;Panda Process Protection Service; C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe [2004-11-16 32768]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-10-22 69632]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2004-08-17 32256]
R2 spkrmon;spkrmon; C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe [2003-08-28 61440]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2010-02-17 3093880]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2004-08-17 8704]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by spravce at 2011-01-27 10:22:01
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 68 GB (89%) free of 76 GB
Total RAM: 1014 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:22:14, on 27.1.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\spravce.PRAHA2\Local Settings\Temporary Internet Files\Content.IE5\BT92EVVC\RSIT[1].exe
C:\Program Files\trend micro\spravce.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.33.10.33:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.33.4.*;10.33.5.*;10.33.6.*;10.33.7.*;10.33.8.*;10.33.9.*;10.33.10.33;*.p2.mepnet.cz,helpdesk;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKUS\S-1-5-21-1445019073-709728891-461039229-2380\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'kleckao')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://10.33.7.215/VatDec.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3059198468
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = praha2.p2.mepnet.cz
O17 - HKLM\Software\..\Telephony: DomainName = praha2.p2.mepnet.cz
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F4616FC-F269-42F8-90F3-D90D5F20FB8D}: NameServer = 10.33.10.21,10.33.4.150
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = praha2.p2.mepnet.cz
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F4616FC-F269-42F8-90F3-D90D5F20FB8D}: NameServer = 10.33.10.21,10.33.4.150
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
--
End of file - 4919 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2004-08-20 155648]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2004-08-20 118784]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2004-08-17 143872]
"ToolBoxFX"=C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe [2006-02-02 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-08-20 344064]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"\\Aplcity\geovap\cityware\poplatky\Poplatky.exe"="\\Aplcity\geovap\cityware\poplatky\Poplatky.exe:*:Disabled:Poplatky"
======List of files/folders created in the last 1 months======
2011-01-27 10:22:01 ----D---- C:\rsit
2011-01-27 10:22:01 ----D---- C:\Program Files\trend micro
2011-01-27 10:21:15 ----A---- C:\ComboFix.txt
2011-01-26 09:56:57 ----A---- C:\WINDOWS\MBR.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\zip.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWSC.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\SWREG.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\sed.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\PEV.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\NIRCMD.exe
2011-01-26 09:56:56 ----A---- C:\WINDOWS\grep.exe
2011-01-26 09:51:57 ----D---- C:\WINDOWS\ERDNT
2011-01-26 09:50:00 ----D---- C:\Qoobox
2011-01-25 10:44:12 ----A---- C:\WINDOWS\ntbtlog.txt
2011-01-25 10:34:53 ----D---- C:\Program Files\CCleaner
2011-01-25 10:32:56 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Macromedia
2011-01-25 10:22:56 ----D---- C:\Program Files\Symantec
2011-01-25 10:22:56 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-01-25 10:22:15 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\pdfforge
2011-01-25 10:06:11 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Search Settings
2011-01-25 10:06:07 ----D---- C:\Program Files\pdfforge Toolbar
2011-01-25 10:06:07 ----D---- C:\Program Files\Common Files\Spigot
2011-01-25 10:06:07 ----D---- C:\Program Files\Application Updater
2011-01-25 10:05:30 ----D---- C:\Program Files\IrfanView
2011-01-25 10:04:56 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-01-25 10:04:55 ----D---- C:\Program Files\PDFCreator
2011-01-25 10:04:55 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-01-25 10:01:55 ----D---- C:\WINDOWS\SchCache
2011-01-13 10:36:16 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-01-13 10:36:15 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-01-13 10:36:15 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-01-13 08:29:36 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Adobe
2011-01-13 08:28:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-01-13 08:25:35 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Google
2011-01-13 08:23:56 ----A---- C:\WINDOWS\system32\MFC71.DLL
2011-01-13 08:23:56 ----A---- C:\WINDOWS\system32\capicom.dll
2011-01-13 08:23:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2011-01-13 08:17:22 ----A---- C:\WINDOWS\User Profile Migration Service.exe
2011-01-13 08:17:08 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\HP
2011-01-13 08:10:57 ----D---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Identities
2011-01-13 08:10:44 ----ASH---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\desktop.ini
2011-01-13 08:10:43 ----SD---- C:\Documents and Settings\spravce.PRAHA2\Data aplikací\Microsoft
======List of files/folders modified in the last 1 months======
2011-01-27 10:22:08 ----D---- C:\WINDOWS\Prefetch
2011-01-27 10:22:01 ----RD---- C:\Program Files
2011-01-27 10:19:50 ----D---- C:\WINDOWS
2011-01-27 10:19:50 ----A---- C:\WINDOWS\system.ini
2011-01-27 10:19:44 ----D---- C:\WINDOWS\system32\drivers\etc
2011-01-27 10:18:56 ----D---- C:\WINDOWS\Temp
2011-01-27 10:18:10 ----D---- C:\WINDOWS\system32\drivers
2011-01-27 10:18:10 ----D---- C:\WINDOWS\system32
2011-01-27 10:18:10 ----D---- C:\WINDOWS\AppPatch
2011-01-27 10:18:06 ----D---- C:\Program Files\Common Files
2011-01-27 10:12:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-27 10:12:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-27 10:12:12 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-01-27 10:12:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-01-27 10:10:43 ----SHD---- C:\WINDOWS\Installer
2011-01-27 10:10:42 ----D---- C:\Config.Msi
2011-01-27 10:06:22 ----D---- C:\WINDOWS\WinSxS
2011-01-27 10:05:03 ----D---- C:\Temp
2011-01-27 07:38:18 ----D---- C:\WINDOWS\security
2011-01-25 10:45:57 ----D---- C:\WINDOWS\system32\appmgmt
2011-01-25 10:35:22 ----D---- C:\WINDOWS\Debug
2011-01-25 09:46:59 ----D---- C:\VITA
2011-01-14 07:30:58 ----D---- C:\WINDOWS\system32\config
2011-01-13 10:36:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-13 08:44:32 ----D---- C:\Program Files\BackSave
2011-01-13 08:44:26 ----A---- C:\WINDOWS\ST6UNST.EXE
2011-01-13 08:44:23 ----D---- C:\Program Files\Info
2011-01-13 08:39:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-13 08:39:38 ----D---- C:\WINDOWS\ShellNew
2011-01-13 08:39:38 ----D---- C:\WINDOWS\Help
2011-01-13 08:38:45 ----A---- C:\WINDOWS\ODBC.INI
2011-01-13 08:38:40 ----RSD---- C:\WINDOWS\Fonts
2011-01-13 08:37:53 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-13 08:37:51 ----D---- C:\WINDOWS\Downloaded Installations
2011-01-13 08:37:49 ----D---- C:\Program Files\Kaspersky Lab
2011-01-13 08:31:41 ----D---- C:\Documents and Settings
2011-01-13 08:28:32 ----D---- C:\Program Files\Common Files\Adobe
2011-01-13 08:28:16 ----D---- C:\Program Files\Adobe
2011-01-13 08:26:28 ----D---- C:\Program Files\Google
2011-01-13 08:26:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 ShldDrv;Panda File Shield Driver; C:\WINDOWS\system32\drivers\ShldDrv.sys [2005-11-09 26656]
R2 PavProc;Panda Process Protection Driver; \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys []
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 b57w2k;Broadcom NetXtreme 57xx Gigabit Controller; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2004-04-29 186112]
R3 catchme;catchme; \??\C:\DOCUME~1\SPRAVC~1.PRA\LOCALS~1\Temp\catchme.sys []
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2003-08-07 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2004-08-20 737874]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2003-08-07 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-09 612352]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 HPFXBULK;HPFXBULK; C:\WINDOWS\system32\drivers\hpfxbulk.sys [2005-09-20 9344]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-10-28 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-28 21568]
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 TSP;TSP; \??\C:\WINDOWS\system32\drivers\klif.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-08-07 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-10-22 386560]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 PavPrSrv;Panda Process Protection Service; C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe [2004-11-16 32768]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-10-22 69632]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2004-08-17 32256]
R2 spkrmon;spkrmon; C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe [2003-08-28 61440]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2010-02-17 3093880]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2004-08-17 8704]
-----------------EOF-----------------