Další autorun.inf
Napsal: 28 úno 2011 19:07
Dobrý den,
nemohu se zbavit autorun.inf s textem:
[autorun]
USEAUTOPLAY=1
shellexcute=luckasta//tamanten.exe
icon=luckasta//tamanten.exe
Shell\going\home
#ęË×ÄÔŃŔĘËŽ×Ôëęă×ÔŚĹĘŁĂÎ×ĺšęĎŽśšęôžî÷śšĽô÷śšĽă×ŚŠĽăčë÷śšăĽôŚÎ×ëśšĽÎ×čęžśš÷꼊Ô
open=luckasta//tamanten.exe
shell\\\\\\Open\\\\\\command=luckasta//tamanten.exe
shell\\\\\\Explore\\\\\\command=luckasta//tamanten.exe
action=Open folder to view files using Windows Explorer
Už se rozšířil prakticky po všech médiích:) Zajímalo by mě, jestli jsou automaticky nakaženy i počítače, kde byl flashdisk, nebo exter zapojený? Jinak abych nedzdržoval zbytečnou omáčkou, provedl jsem první scan pomocí combofixu, je zde:
ComboFix 11-02-27.03 - HASH 28.02.2011 18:38:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1790.959 [GMT 1:00]
Spuštěný z: c:\users\HASH\Desktop\ComboFix.exe
AV: Trend Micro Internet Security Pro *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
FW: Trend Micro Personal Firewall *Disabled* {70A91CD9-303D-A217-A80E-6DEE136EDB2B}
SP: Trend Micro Internet Security Pro *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\common.data
c:\users\HASH\AppData\Roaming\juzjf.exe.ren
c:\users\HASH\AppData\Roaming\Microsoft\minnal.exe
c:\users\HASH\AppData\Roaming\winsysdrv32.txt
c:\users\HASH\xvlof.exe
c:\windows\system32\drivers\str.sys
c:\windows\system32\service
c:\windows\system32\service\23022011_TIS17_SfFniAU.log
H:\autorun.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-28 do 2011-02-28 )))))))))))))))))))))))))))))))
.
2011-02-28 17:46 . 2011-02-28 17:47 -------- d-----w- c:\users\HASH\AppData\Local\temp
2011-02-28 17:46 . 2011-02-28 17:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-28 17:35 . 2011-02-28 17:36 -------- d-----w- C:\32788R22FWJFW
2011-02-28 12:32 . 2011-02-28 12:32 -------- d-----w- c:\programdata\WindowsSearch
2011-02-26 17:38 . 2010-07-30 17:29 249424 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2011-02-26 17:38 . 2010-07-30 17:06 1331512 ----a-w- c:\windows\system32\drivers\vsapint.sys
2011-02-26 17:38 . 2010-07-30 17:29 36432 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2011-02-22 22:35 . 2011-02-22 22:35 -------- d-----w- c:\users\HASH\AppData\Local\Trend Micro
2011-02-22 22:18 . 2011-02-26 17:28 -------- d-----w- c:\programdata\Trend Micro
2011-02-22 22:17 . 2011-02-22 22:21 -------- d-----w- c:\program files\Trend Micro
2011-02-22 21:25 . 2011-02-22 21:25 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2011-02-22 21:25 . 2011-02-22 21:25 283152 ----a-w- c:\windows\system32\drivers\tmwfp.sys
2011-02-22 21:25 . 2011-02-22 21:25 146448 ----a-w- c:\windows\system32\drivers\tmlwf.sys
2011-02-22 21:25 . 2010-07-19 18:03 59472 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2011-02-22 21:25 . 2010-07-19 18:03 51792 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2011-02-22 21:25 . 2010-07-19 18:02 163408 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-22 21:23 . 2011-02-22 21:24 -------- d-----w- c:\program files\Launch Manager
2011-02-21 19:46 . 2011-02-21 19:46 89500 ---h--w- c:\users\HASH\VSPVSAVDAV.exe
2011-02-21 19:08 . 2011-02-02 16:10 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9AA8E3E3-2869-41CC-A4B4-7E5FBC03D830}\mpengine.dll
2011-02-21 19:01 . 2011-02-21 19:08 -------- d-----w- c:\program files\WinClamAVShield
2011-02-21 18:00 . 2011-02-21 17:59 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nijo86a3w1.exe
2011-02-21 18:00 . 2011-02-21 17:59 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\i6jufq4ci.exe
2011-02-21 17:59 . 2011-02-21 17:59 39936 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\y81k3g1x7.exe
2011-02-20 21:21 . 2011-02-21 20:33 -------- d-sh--r- c:\users\HASH\Microsoft-Update-Service-8-8586-7578-5800
2011-02-20 14:34 . 2011-02-20 14:34 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\inyjkfl6.exe
2011-02-20 14:34 . 2011-02-20 14:34 43008 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\81whdyo.exe
2011-02-20 14:34 . 2011-02-20 14:34 43008 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\te2v5b03i.exe
2011-02-20 14:26 . 2008-09-26 17:04 621056 ----a-w- c:\windows\system32\drivers\mod7700.sys
2011-02-20 14:26 . 2008-09-26 17:04 113152 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2011-02-20 14:26 . 2008-09-26 17:04 101760 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2011-02-20 14:26 . 2008-09-26 17:03 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2011-02-20 14:15 . 2011-02-20 14:27 -------- d-----w- c:\program files\O2 Mobilni internet
2011-02-18 16:54 . 2011-02-23 20:29 -------- d-----w- c:\users\HASH\AppData\Roaming\Spyware Terminator
2011-02-18 16:54 . 2011-02-18 16:54 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-02-18 16:54 . 2011-02-23 20:29 -------- d-----w- c:\program files\Spyware Terminator
2011-02-18 16:54 . 2011-02-22 22:08 -------- d-----w- c:\programdata\Spyware Terminator
2011-02-16 17:06 . 2011-02-21 20:34 -------- d-----w- c:\users\HASH\AppData\Roaming\xtrvicdrwwunip2mlmaddyrxybujtpve2
2011-02-16 16:02 . 2011-02-16 16:02 -------- d-----w- c:\users\HASH\AppData\Roaming\xfznlgljfuqzpjtydnm2jnhvcmkma2td2
2011-02-16 15:06 . 2011-02-16 15:06 -------- d-----w- c:\users\HASH\AppData\Roaming\xqovcskxewp3zzbnjdfbbwrodtvywtgs2
2011-02-15 20:32 . 2011-02-15 20:32 -------- d-----w- c:\users\HASH\AppData\Roaming\x3ironobhlcw1vrejgmvcb1zy32bz2sb2
2011-02-15 16:08 . 2011-02-15 16:08 -------- d-----w- c:\users\HASH\AppData\Roaming\xodgblavjvlvxpdzrseio1ciy1pmebcw2
2011-02-13 21:43 . 2011-02-13 21:43 106496 ----a-w- c:\users\HASH\xvlof.exe.ren
2011-02-05 23:35 . 2011-02-05 23:35 18300 ----a-w- c:\windows\system32\MAIE62.tmp
2011-02-05 17:57 . 2003-11-10 17:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-02-05 17:57 . 2003-11-10 17:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-02-05 17:57 . 2003-11-10 17:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-02-05 17:57 . 2003-11-10 17:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-02-05 17:57 . 2003-11-10 17:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-02-05 17:57 . 2011-02-05 17:57 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-02-05 17:57 . 2011-02-05 17:57 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-02 16:11 . 2010-08-16 19:34 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-19 19:07 . 2011-01-19 19:07 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-02-18 3318784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-12-14 192512]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
81whdyo.exe [2011-2-20 43008]
i6jufq4ci.exe [2011-2-21 42496]
inyjkfl6.exe [2011-2-20 42496]
nijo86a3w1.exe [2011-2-21 42496]
te2v5b03i.exe [2011-2-20 43008]
y81k3g1x7.exe [2011-2-21 39936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2154561694-2073593054-3152204118-1000]
"EnableNotificationsRef"=dword:00000001
R0 dwcyxaupgqww;dwcyxaupgqww;c:\windows\system32\drivers\muldapczzflmzi.sys [x]
R1 mailKmd;mailKmd; [x]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2010-07-19 51792]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2011-02-22 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2011-02-22 689416]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-14 691696]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-02-18 142592]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2011-02-22 146448]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 36432]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2011-02-22 283152]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2006-11-17 118784]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - ttwzzs
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Export do &Tahiti - c:\program files\LightComp Tahiti 5\iehelper.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-28 18:47
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ttwzzs]
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2011-02-28 18:49:53
ComboFix-quarantined-files.txt 2011-02-28 17:49
Před spuštěním: Volných bajtů: 58 686 013 440
Po spuštění: Volných bajtů: 58 642 530 304
- - End Of File - - 60CBF0F2F14539F116E472AB2CF536F6
Zatím díky
nemohu se zbavit autorun.inf s textem:
[autorun]
USEAUTOPLAY=1
shellexcute=luckasta//tamanten.exe
icon=luckasta//tamanten.exe
Shell\going\home
#ęË×ÄÔŃŔĘËŽ×Ôëęă×ÔŚĹĘŁĂÎ×ĺšęĎŽśšęôžî÷śšĽô÷śšĽă×ŚŠĽăčë÷śšăĽôŚÎ×ëśšĽÎ×čęžśš÷꼊Ô
open=luckasta//tamanten.exe
shell\\\\\\Open\\\\\\command=luckasta//tamanten.exe
shell\\\\\\Explore\\\\\\command=luckasta//tamanten.exe
action=Open folder to view files using Windows Explorer
Už se rozšířil prakticky po všech médiích:) Zajímalo by mě, jestli jsou automaticky nakaženy i počítače, kde byl flashdisk, nebo exter zapojený? Jinak abych nedzdržoval zbytečnou omáčkou, provedl jsem první scan pomocí combofixu, je zde:
ComboFix 11-02-27.03 - HASH 28.02.2011 18:38:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1790.959 [GMT 1:00]
Spuštěný z: c:\users\HASH\Desktop\ComboFix.exe
AV: Trend Micro Internet Security Pro *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
FW: Trend Micro Personal Firewall *Disabled* {70A91CD9-303D-A217-A80E-6DEE136EDB2B}
SP: Trend Micro Internet Security Pro *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\common.data
c:\users\HASH\AppData\Roaming\juzjf.exe.ren
c:\users\HASH\AppData\Roaming\Microsoft\minnal.exe
c:\users\HASH\AppData\Roaming\winsysdrv32.txt
c:\users\HASH\xvlof.exe
c:\windows\system32\drivers\str.sys
c:\windows\system32\service
c:\windows\system32\service\23022011_TIS17_SfFniAU.log
H:\autorun.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-28 do 2011-02-28 )))))))))))))))))))))))))))))))
.
2011-02-28 17:46 . 2011-02-28 17:47 -------- d-----w- c:\users\HASH\AppData\Local\temp
2011-02-28 17:46 . 2011-02-28 17:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-28 17:35 . 2011-02-28 17:36 -------- d-----w- C:\32788R22FWJFW
2011-02-28 12:32 . 2011-02-28 12:32 -------- d-----w- c:\programdata\WindowsSearch
2011-02-26 17:38 . 2010-07-30 17:29 249424 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2011-02-26 17:38 . 2010-07-30 17:06 1331512 ----a-w- c:\windows\system32\drivers\vsapint.sys
2011-02-26 17:38 . 2010-07-30 17:29 36432 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2011-02-22 22:35 . 2011-02-22 22:35 -------- d-----w- c:\users\HASH\AppData\Local\Trend Micro
2011-02-22 22:18 . 2011-02-26 17:28 -------- d-----w- c:\programdata\Trend Micro
2011-02-22 22:17 . 2011-02-22 22:21 -------- d-----w- c:\program files\Trend Micro
2011-02-22 21:25 . 2011-02-22 21:25 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2011-02-22 21:25 . 2011-02-22 21:25 283152 ----a-w- c:\windows\system32\drivers\tmwfp.sys
2011-02-22 21:25 . 2011-02-22 21:25 146448 ----a-w- c:\windows\system32\drivers\tmlwf.sys
2011-02-22 21:25 . 2010-07-19 18:03 59472 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2011-02-22 21:25 . 2010-07-19 18:03 51792 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2011-02-22 21:25 . 2010-07-19 18:02 163408 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-22 21:23 . 2011-02-22 21:24 -------- d-----w- c:\program files\Launch Manager
2011-02-21 19:46 . 2011-02-21 19:46 89500 ---h--w- c:\users\HASH\VSPVSAVDAV.exe
2011-02-21 19:08 . 2011-02-02 16:10 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9AA8E3E3-2869-41CC-A4B4-7E5FBC03D830}\mpengine.dll
2011-02-21 19:01 . 2011-02-21 19:08 -------- d-----w- c:\program files\WinClamAVShield
2011-02-21 18:00 . 2011-02-21 17:59 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nijo86a3w1.exe
2011-02-21 18:00 . 2011-02-21 17:59 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\i6jufq4ci.exe
2011-02-21 17:59 . 2011-02-21 17:59 39936 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\y81k3g1x7.exe
2011-02-20 21:21 . 2011-02-21 20:33 -------- d-sh--r- c:\users\HASH\Microsoft-Update-Service-8-8586-7578-5800
2011-02-20 14:34 . 2011-02-20 14:34 42496 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\inyjkfl6.exe
2011-02-20 14:34 . 2011-02-20 14:34 43008 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\81whdyo.exe
2011-02-20 14:34 . 2011-02-20 14:34 43008 --sh--r- c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\te2v5b03i.exe
2011-02-20 14:26 . 2008-09-26 17:04 621056 ----a-w- c:\windows\system32\drivers\mod7700.sys
2011-02-20 14:26 . 2008-09-26 17:04 113152 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2011-02-20 14:26 . 2008-09-26 17:04 101760 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2011-02-20 14:26 . 2008-09-26 17:03 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2011-02-20 14:15 . 2011-02-20 14:27 -------- d-----w- c:\program files\O2 Mobilni internet
2011-02-18 16:54 . 2011-02-23 20:29 -------- d-----w- c:\users\HASH\AppData\Roaming\Spyware Terminator
2011-02-18 16:54 . 2011-02-18 16:54 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-02-18 16:54 . 2011-02-23 20:29 -------- d-----w- c:\program files\Spyware Terminator
2011-02-18 16:54 . 2011-02-22 22:08 -------- d-----w- c:\programdata\Spyware Terminator
2011-02-16 17:06 . 2011-02-21 20:34 -------- d-----w- c:\users\HASH\AppData\Roaming\xtrvicdrwwunip2mlmaddyrxybujtpve2
2011-02-16 16:02 . 2011-02-16 16:02 -------- d-----w- c:\users\HASH\AppData\Roaming\xfznlgljfuqzpjtydnm2jnhvcmkma2td2
2011-02-16 15:06 . 2011-02-16 15:06 -------- d-----w- c:\users\HASH\AppData\Roaming\xqovcskxewp3zzbnjdfbbwrodtvywtgs2
2011-02-15 20:32 . 2011-02-15 20:32 -------- d-----w- c:\users\HASH\AppData\Roaming\x3ironobhlcw1vrejgmvcb1zy32bz2sb2
2011-02-15 16:08 . 2011-02-15 16:08 -------- d-----w- c:\users\HASH\AppData\Roaming\xodgblavjvlvxpdzrseio1ciy1pmebcw2
2011-02-13 21:43 . 2011-02-13 21:43 106496 ----a-w- c:\users\HASH\xvlof.exe.ren
2011-02-05 23:35 . 2011-02-05 23:35 18300 ----a-w- c:\windows\system32\MAIE62.tmp
2011-02-05 17:57 . 2003-11-10 17:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-02-05 17:57 . 2003-11-10 17:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-02-05 17:57 . 2003-11-10 17:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-02-05 17:57 . 2003-11-10 17:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-02-05 17:57 . 2003-11-10 17:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-02-05 17:57 . 2011-02-05 17:57 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-02-05 17:57 . 2011-02-05 17:57 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-02 16:11 . 2010-08-16 19:34 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-19 19:07 . 2011-01-19 19:07 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-02-18 3318784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-12-14 192512]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
c:\users\HASH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
81whdyo.exe [2011-2-20 43008]
i6jufq4ci.exe [2011-2-21 42496]
inyjkfl6.exe [2011-2-20 42496]
nijo86a3w1.exe [2011-2-21 42496]
te2v5b03i.exe [2011-2-20 43008]
y81k3g1x7.exe [2011-2-21 39936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2154561694-2073593054-3152204118-1000]
"EnableNotificationsRef"=dword:00000001
R0 dwcyxaupgqww;dwcyxaupgqww;c:\windows\system32\drivers\muldapczzflmzi.sys [x]
R1 mailKmd;mailKmd; [x]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2010-07-19 51792]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [2011-02-22 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2011-02-22 689416]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-14 691696]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-02-18 142592]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2011-02-22 146448]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2010-07-30 36432]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2011-02-22 283152]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2006-11-17 118784]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - ttwzzs
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Export do &Tahiti - c:\program files\LightComp Tahiti 5\iehelper.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-28 18:47
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ttwzzs]
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2011-02-28 18:49:53
ComboFix-quarantined-files.txt 2011-02-28 17:49
Před spuštěním: Volných bajtů: 58 686 013 440
Po spuštění: Volných bajtů: 58 642 530 304
- - End Of File - - 60CBF0F2F14539F116E472AB2CF536F6
Zatím díky