Kontrola logu z ComboFixu
Napsal: 03 bře 2011 12:18
Zdravím Vás,
Na na mém PC se vyskytl problém, který je stejný jako zde: http://www.viry.cz/forum/viewtopic.php?f=13&t=109700
Po důkladném přečtění návodu od Rádce, včetně návodu na spůštění a obsluhu ComboFixu jsem tedy postupoval dle těchto instrukcí. ComboFix proběhl, nalezl a snad i odstranil nalezemé rootkity. Byl vytvořen log z ComboFixu. Který přikládám.
Chtěl bych Vás tedy poprosit o kontrolu logu z ComboFixu zda jsem tuto havěť z PC vystrnadil.
Děkuji moc.
Log z ComboFixu:
ComboFix 11-03-01.03 - Petr Semmler 03.03.2011 11:30:40.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.958.661 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr Semmler\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\firststeps\FirstSteps.exe
c:\windows\system32\midas.dll
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-03 do 2011-03-03 )))))))))))))))))))))))))))))))
.
2011-03-03 09:43 . 2011-03-03 09:43 -------- d-----w- c:\program files\trend micro
2011-03-03 09:43 . 2011-03-03 09:43 -------- d-----w- C:\rsit
2011-02-27 16:18 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-14 11:07 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
2011-02-14 11:06 . 2011-02-14 11:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2011-02-10 09:35 . 2011-02-10 09:35 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2011-02-10 09:30 . 2011-02-14 11:07 -------- d-----w- c:\documents and settings\Petr Semmler\Local Settings\Data aplikací\Temp
2011-02-10 09:30 . 2011-02-10 09:30 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 10:25 . 2007-05-03 13:25 1409 ----a-w- c:\windows\QTFont.for
2011-02-23 15:04 . 2007-12-08 10:16 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2008-04-02 15:08 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2007-12-08 10:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2007-12-08 10:16 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2007-12-08 10:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2007-12-08 10:16 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2007-12-08 10:16 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2008-04-02 15:08 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-21 14:44 . 2000-05-27 10:10 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2000-05-27 10:10 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2000-05-27 10:10 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2000-05-27 10:10 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:14 . 2000-05-27 10:10 668160 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:14 . 2000-05-27 10:10 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:14 . 2000-05-27 10:10 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 22:13 . 2000-05-27 10:10 370176 ----a-w- c:\windows\system32\html.iec
2010-12-20 17:25 . 2000-05-27 10:10 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15 . 2000-05-27 10:10 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2000-05-27 10:10 2194944 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2004-08-17 15:45 2071552 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2000-05-27 10:10 33280 ----a-w- c:\windows\system32\csrsrv.dll
2005-03-31 20:17 . 2007-04-08 09:04 40960 ----a-w- c:\program files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-29 171464]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-05 68856]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 16264192]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-05-03 77824]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2009-03-24 606208]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-02-23 3451496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-7-22 151552]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.10.2007 8:26 685816]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27.2.2011 17:18 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2.4.2008 16:08 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.4.2008 16:08 19544]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [6.7.2008 9:28 222968]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10.2.2011 10:30 136176]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [16.5.2007 20:55 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [16.5.2007 20:55 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [16.5.2007 20:55 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [16.5.2007 20:55 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [16.5.2007 20:55 83344]
.
Obsah adresáře 'Naplánované úlohy'
2011-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-10 09:30]
2011-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-10 09:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Petr Semmler\Data aplikací\Mozilla\Firefox\Profiles\mwq1hx4i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AdVantage: {A89AED22-9133-424c-88E7-C8235C5FF302} - c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AdVantage - c:\program files\AdVantage\AdVantage.exe
HKCU-Run-ICQ - c:\program files\ICQ6\ICQ.exe
AddRemove-Max Payne CZ - c:\program files\Rockstar Games\Max Payne\uninstx.exe
AddRemove-ProHockeyManager 2005 - c:\games\phm2005\DeIsL1.isu
AddRemove-WhenUSearch - c:\program files\DAEMON Tools SearchBar\Uninst.exe
AddRemove-{587A2120-41D3-11DB-3D6C-00E19E4D4AE1} - c:\program files\Microsoft Games\Train Simulator\Uninst_MSTS Patch 1.7.0224.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-03 11:51
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-144695079-3828189859-3471768918-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-03-03 11:54:49
ComboFix-quarantined-files.txt 2011-03-03 10:54
Před spuštěním: Volných bajtů: 52 892 672 000
Po spuštění: Volných bajtů: 57 158 492 160
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 66F244D5B705F42FB6D3DA7BF47AC482
Na na mém PC se vyskytl problém, který je stejný jako zde: http://www.viry.cz/forum/viewtopic.php?f=13&t=109700
Po důkladném přečtění návodu od Rádce, včetně návodu na spůštění a obsluhu ComboFixu jsem tedy postupoval dle těchto instrukcí. ComboFix proběhl, nalezl a snad i odstranil nalezemé rootkity. Byl vytvořen log z ComboFixu. Který přikládám.
Chtěl bych Vás tedy poprosit o kontrolu logu z ComboFixu zda jsem tuto havěť z PC vystrnadil.
Děkuji moc.
Log z ComboFixu:
ComboFix 11-03-01.03 - Petr Semmler 03.03.2011 11:30:40.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.958.661 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr Semmler\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\firststeps\FirstSteps.exe
c:\windows\system32\midas.dll
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-03 do 2011-03-03 )))))))))))))))))))))))))))))))
.
2011-03-03 09:43 . 2011-03-03 09:43 -------- d-----w- c:\program files\trend micro
2011-03-03 09:43 . 2011-03-03 09:43 -------- d-----w- C:\rsit
2011-02-27 16:18 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-14 11:07 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
2011-02-14 11:06 . 2011-02-14 11:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2011-02-10 09:35 . 2011-02-10 09:35 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2011-02-10 09:30 . 2011-02-14 11:07 -------- d-----w- c:\documents and settings\Petr Semmler\Local Settings\Data aplikací\Temp
2011-02-10 09:30 . 2011-02-10 09:30 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 10:25 . 2007-05-03 13:25 1409 ----a-w- c:\windows\QTFont.for
2011-02-23 15:04 . 2007-12-08 10:16 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2008-04-02 15:08 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2007-12-08 10:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2007-12-08 10:16 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2007-12-08 10:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2007-12-08 10:16 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2007-12-08 10:16 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2008-04-02 15:08 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-21 14:44 . 2000-05-27 10:10 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2000-05-27 10:10 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2000-05-27 10:10 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2000-05-27 10:10 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:14 . 2000-05-27 10:10 668160 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:14 . 2000-05-27 10:10 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:14 . 2000-05-27 10:10 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 22:13 . 2000-05-27 10:10 370176 ----a-w- c:\windows\system32\html.iec
2010-12-20 17:25 . 2000-05-27 10:10 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15 . 2000-05-27 10:10 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2000-05-27 10:10 2194944 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2004-08-17 15:45 2071552 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2000-05-27 10:10 33280 ----a-w- c:\windows\system32\csrsrv.dll
2005-03-31 20:17 . 2007-04-08 09:04 40960 ----a-w- c:\program files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-29 171464]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-05 68856]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 16264192]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-05-03 77824]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2009-03-24 606208]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-02-23 3451496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-7-22 151552]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.10.2007 8:26 685816]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27.2.2011 17:18 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2.4.2008 16:08 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.4.2008 16:08 19544]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [6.7.2008 9:28 222968]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10.2.2011 10:30 136176]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [16.5.2007 20:55 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [16.5.2007 20:55 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [16.5.2007 20:55 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [16.5.2007 20:55 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [16.5.2007 20:55 83344]
.
Obsah adresáře 'Naplánované úlohy'
2011-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-10 09:30]
2011-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-10 09:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Petr Semmler\Data aplikací\Mozilla\Firefox\Profiles\mwq1hx4i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AdVantage: {A89AED22-9133-424c-88E7-C8235C5FF302} - c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AdVantage - c:\program files\AdVantage\AdVantage.exe
HKCU-Run-ICQ - c:\program files\ICQ6\ICQ.exe
AddRemove-Max Payne CZ - c:\program files\Rockstar Games\Max Payne\uninstx.exe
AddRemove-ProHockeyManager 2005 - c:\games\phm2005\DeIsL1.isu
AddRemove-WhenUSearch - c:\program files\DAEMON Tools SearchBar\Uninst.exe
AddRemove-{587A2120-41D3-11DB-3D6C-00E19E4D4AE1} - c:\program files\Microsoft Games\Train Simulator\Uninst_MSTS Patch 1.7.0224.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-03 11:51
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-144695079-3828189859-3471768918-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-03-03 11:54:49
ComboFix-quarantined-files.txt 2011-03-03 10:54
Před spuštěním: Volných bajtů: 52 892 672 000
Po spuštění: Volných bajtů: 57 158 492 160
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 66F244D5B705F42FB6D3DA7BF47AC482