tak tady je log z toho programku
ComboFix 11-07-23.04 - Honza 02.07.2004 10:56:38.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1099 [GMT 2:00]
Spuštěný z: c:\documents and settings\Honza\Dokumenty\Sta×enÚ soubory\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Norton Internet Security *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
c:\documents and settings\Honza\WINDOWS
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\system\WINSPOOL.DRV
c:\windows\system32\Cache
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\system32\drivers\npf.sys
c:\windows\system32\ieuinit.inf
c:\windows\system32\Packet.dll
c:\windows\system32\rchnewver.dll
c:\windows\system32\scrnrdr.exe
c:\windows\system32\VIRepair
c:\windows\system32\VIRepair\RESHAC~1.ini
c:\windows\system32\VIRepair\RESHAC~1.log
c:\windows\system32\VIRepair\vi.sif
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\unin0411.exe
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
E:\AUTORUN.INF
E:\install.exe
.
c:\windows\system32\msgsvc.dll . . . je infikován!!
.
Nakažená kopie c:\windows\explorer.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\explorer.exe
.
Nakažená kopie c:\windows\regedit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\regedit.exe
.
Nakažená kopie c:\windows\system32\mspaint.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\mspaint.exe
.
Nakažená kopie c:\windows\system32\notepad.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\notepad.exe
.
Nakažená kopie c:\windows\system32\ntkrnlpa.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\ntkrnlpa.exe
.
Nakažená kopie c:\windows\system32\ntoskrnl.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\ntoskrnl.exe
.
Nakažená kopie c:\windows\system32\spider.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\spider.exe
.
Nakažená kopie c:\windows\system32\taskmgr.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\taskmgr.exe
.
Nakažená kopie c:\windows\system32\wiaacmgr.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\wiaacmgr.exe
.
Nakažená kopie c:\windows\system32\Restore\rstrui.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\rstrui.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Legacy_WXPDRIVERS
-------\Service_NPF
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2004-06-02 do 2004-07-02 )))))))))))))))))))))))))))))))
.
.
2011-05-21 07:42 . 2011-05-21 07:42 -------- d-----w- C:\ATI
2011-05-16 12:06 . 2011-05-16 12:08 -------- d-----w- C:\de030d62d865c4ae19900e5dcef383
2011-05-13 11:38 . 2011-05-13 11:45 -------- d-----w- C:\VTPFiles
2011-05-03 15:17 . 2011-05-03 15:17 -------- d-----w- C:\temp
2011-05-03 14:50 . 2011-05-03 14:50 -------- d-----w- C:\Acer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 06:53 . 2001-10-25 14:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-06-15 16:18 . 2001-10-25 14:00 143422 ----a-w- c:\windows\system32\l3codecx.ax
2010-06-14 14:31 . 2011-05-03 10:36 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2009-11-27 16:09 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-21 16:03 . 2008-04-14 06:51 471552 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-12 13:40 . 2008-04-14 06:51 79872 ----a-w- c:\windows\system32\raschap.dll
2009-02-06 10:39 . 2001-10-25 14:00 35328 ----a-w- c:\windows\system32\sc.exe
2008-04-14 06:52 . 2001-10-25 14:00 239616 ----a-w- c:\windows\system32\wstrenderer.ax
2008-04-14 06:52 . 2011-05-03 10:36 150528 ----a-w- c:\windows\pchealth\UploadLB\Binaries\UploadM.exe
2008-04-14 06:52 . 2001-10-25 14:00 72192 ----a-w- c:\windows\system32\systeminfo.exe
2008-04-14 06:52 . 2001-10-25 14:00 347136 ----a-w- c:\windows\system32\tourstart.exe
2008-04-14 06:52 . 2001-10-25 14:00 69120 ----a-w- c:\windows\system32\openfiles.exe
2008-04-14 06:52 . 2011-05-03 10:36 171008 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
2008-04-14 06:52 . 2011-05-03 10:36 18432 ----a-w- c:\windows\pchealth\helpctr\binaries\HscUpd.exe
2008-04-14 06:52 . 2011-05-03 10:36 769024 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
2008-04-14 06:52 . 2001-10-25 14:00 84992 ----a-w- c:\windows\system32\eventtriggers.exe
2008-04-14 06:52 . 2001-10-25 14:00 51712 ----a-w- c:\windows\system32\eventcreate.exe
2008-04-14 06:52 . 2001-10-25 14:00 64000 ----a-w- c:\windows\system32\driverquery.exe
2008-04-14 06:52 . 2008-04-14 06:52 601088 ----a-w- c:\windows\system32\autochk.exe
2008-04-14 06:52 . 2008-04-14 06:52 403456 ----a-w- c:\windows\system32\webcheck.dll
2008-04-14 06:52 . 2008-04-14 06:52 279040 ----a-w- c:\windows\help\tshoot.dll
2008-04-14 06:52 . 2001-10-25 14:00 712704 ----a-w- c:\windows\system32\windowscodecs.dll
2008-04-14 06:52 . 2001-10-25 14:00 346112 ----a-w- c:\windows\system32\windowscodecsext.dll
2008-04-14 06:52 . 2011-05-03 10:37 726590 ----a-w- c:\windows\srchasst\srchui.dll
2008-04-14 06:52 . 2011-05-03 10:37 58434 ----a-w- c:\windows\srchasst\srchctls.dll
2008-04-14 06:52 . 2008-04-14 06:52 33280 ----a-w- c:\windows\help\sstub.dll
2008-04-14 06:51 . 2008-04-14 06:51 34816 ----a-w- c:\windows\help\sniffpol.dll
2008-04-14 06:51 . 2011-05-03 10:36 38400 ----a-w- c:\windows\pchealth\helpctr\binaries\pchsvc.dll
2008-04-14 06:51 . 2011-05-03 10:36 102912 ----a-w- c:\windows\pchealth\helpctr\binaries\pchshell.dll
2008-04-14 06:51 . 2001-10-25 14:00 412160 ----a-w- c:\windows\system32\photometadatahandler.dll
2008-04-14 06:51 . 2011-05-03 10:37 3166208 ----a-w- c:\windows\srchasst\msgr3en.dll
2008-04-14 06:51 . 2011-05-03 10:36 378880 ----a-w- c:\windows\pchealth\helpctr\binaries\msinfo.dll
2008-04-14 06:51 . 2001-10-25 14:00 37376 ----a-w- c:\windows\system32\l2gpstore.dll
2008-04-14 06:51 . 2001-10-25 14:00 184320 ----a-w- c:\windows\system32\microsoft.managementconsole.dll
2008-04-14 06:51 . 2001-10-25 14:00 106496 ----a-w- c:\windows\system32\mmcfxcommon.dll
2008-04-14 06:51 . 2001-10-25 14:00 39936 ----a-w- c:\windows\system32\dot3gpclnt.dll
2008-04-14 06:51 . 2008-04-14 06:51 245248 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2008-04-14 06:51 . 2008-04-14 06:51 1852928 ----a-w- c:\windows\apppatch\AcGenral.dll
2008-04-14 06:51 . 2008-04-14 06:51 141312 ----a-w- c:\windows\apppatch\AcLua.dll
2008-04-14 06:51 . 2008-04-14 06:51 116224 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2008-04-14 06:51 . 2008-04-14 06:51 39424 ----a-w- c:\windows\apppatch\AcAdProc.dll
2008-04-14 05:58 . 2001-10-25 14:00 78848 ----a-w- c:\windows\system32\msshavmsg.dll
2007-04-02 16:19 . 2001-10-25 14:00 355112 ----a-w- c:\windows\system32\msjetoledb40.dll
2007-04-02 16:17 . 2007-04-02 16:17 518944 ----a-w- c:\windows\system32\msexch40.dll
2005-08-24 10:56 . 2011-05-03 15:01 40960 ----a-w- c:\windows\system32\ialmuCHT.dll
2005-08-24 10:56 . 2011-05-03 15:01 40960 ----a-w- c:\windows\system32\ialmuCHS.dll
2005-08-24 10:51 . 2011-05-03 15:01 81920 ----a-w- c:\windows\system32\igfxrcht.lrc
2005-08-24 10:51 . 2011-05-03 15:01 81920 ----a-w- c:\windows\system32\igfxrchs.lrc
2005-08-23 23:24 . 2011-05-03 14:50 10752 ----a-w- c:\windows\system32\MSNChatHook.dll
2005-04-15 17:58 . 2002-12-20 12:02 1071088 ----a-w- c:\windows\system32\mscomctl.ocx
2004-07-11 20:51 . 2001-10-25 14:00 199168 ----a-w- c:\windows\system32\ir32_32.dll
2011-07-08 07:29 . 2011-07-21 11:07 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-14 . E4A798DFDE7FE6E79F23548F0EF0F844 . 634648 . . [7.00.6000.17096] . . c:\windows\SoftwareDistribution\Download\220ee7a4702b5acde192c1e977145d42\SP3GDR\iexplore.exe
[7] 2011-02-14 . E3CC8CCF21BFDC954255BB17083FB9F0 . 634648 . . [7.00.6000.21298] . . c:\windows\SoftwareDistribution\Download\220ee7a4702b5acde192c1e977145d42\SP3QFE\iexplore.exe
[7] 2010-12-20 . 091D358EFC9D22901BD879EF37F0DAC4 . 634648 . . [7.00.6000.17095] . . c:\windows\SoftwareDistribution\Download\ccfc76cb81302cf2ad4b04bc37ddb0c2\SP3GDR\iexplore.exe
[7] 2010-12-20 . B74CBEBA34E3CAA2CCACC87FEE8A16C0 . 634648 . . [7.00.6000.21297] . . c:\windows\SoftwareDistribution\Download\ccfc76cb81302cf2ad4b04bc37ddb0c2\SP3QFE\iexplore.exe
[7] 2010-04-16 . C4BA5E36FB57F547117305BF1E0FE454 . 634656 . . [7.00.6000.17055] . . c:\windows\SoftwareDistribution\Download\d99e99d10cfba30ab13314ef40ddbe09\SP3GDR\iexplore.exe
[7] 2010-04-16 . B24A4E23A2FEDB6976EB04D334AD82B2 . 634648 . . [7.00.6000.21256] . . c:\windows\SoftwareDistribution\Download\d99e99d10cfba30ab13314ef40ddbe09\SP3QFE\iexplore.exe
[7] 2008-04-14 . 414AFE6E8CCDE984E16D5ED08624CEC6 . 93184 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2008-04-14 . 414AFE6E8CCDE984E16D5ED08624CEC6 . 93184 . . [6.00.2900.5512] . . c:\windows\system32\VITrans\IEXPLORE.EXE
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"iTV"="c:\program files\iTV\iTV.exe" [2004-07-25 633344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-10 212992]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"PowerKey"="c:\program files\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2005-11-08 69632]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2005-11-08 81920]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-01-31 253952]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2008-04-13 49152]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\Honza\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Typle.lnk - c:\program files\Typle2.0v\Typle.exe [2008-1-10 737280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Honza\\Plocha\\Age of Empires II - Conquedores - Full Game\\empires2.EXE"=
"e:\\TrackMania Original\\TrackManiaLauncher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Resounding\\Roger Wilco\\roger.exe"=
"e:\\MotoGP2\\motogp2.exe"=
.
R0 pe3ajcyb;TrackMania Original Environment Driver (pe3ajcyb);c:\windows\system32\drivers\pe3ajcyb.sys [6.2.2007 19:53 65424]
R0 pf2ajcyb;TrackMania Original File System Driver (pf2ajcyb);c:\windows\system32\drivers\pf2ajcyb.sys [6.2.2007 19:53 82832]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2.6.2011 23:33 685816]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1206000.01D\symds.sys [1.7.2004 22:28 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1206000.01D\symefa.sys [1.7.2004 22:28 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110701.001\BHDrvx86.sys [1.7.2011 0:11 810616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [15.5.2011 13:35 218688]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1206000.01D\ironx86.sys [1.7.2004 22:28 136312]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe [1.7.2004 22:28 130008]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [21.2.2011 23:17 66560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1.7.2004 23:08 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110722.031\IDSXpx86.sys [22.7.2011 4:16 355256]
R3 POWERKEY;POWERKEY;c:\program files\Launch Manager\POWERKEY.SYS [3.5.2011 17:05 2343]
S1 dozmbsht;dozmbsht;\??\c:\windows\system32\drivers\dozmbsht.sys --> c:\windows\system32\drivers\dozmbsht.sys [?]
S1 mailKmd;mailKmd; [x]
S1 MpKsl021bf506;MpKsl021bf506;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl021bf506.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl021bf506.sys [?]
S1 MpKsl04499c4c;MpKsl04499c4c;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl04499c4c.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl04499c4c.sys [?]
S1 MpKsl0e655d7e;MpKsl0e655d7e;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{492DF08C-D1BE-4380-B316-763E032C6675}\MpKsl0e655d7e.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{492DF08C-D1BE-4380-B316-763E032C6675}\MpKsl0e655d7e.sys [?]
S1 MpKsl10c0062a;MpKsl10c0062a;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl10c0062a.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl10c0062a.sys [?]
S1 MpKsl15d8e3cf;MpKsl15d8e3cf;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl15d8e3cf.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl15d8e3cf.sys [?]
S1 MpKsl6c6234f2;MpKsl6c6234f2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl6c6234f2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{73061B39-E968-4101-9E18-D1AB7C409534}\MpKsl6c6234f2.sys [?]
S1 MpKsl757517ec;MpKsl757517ec;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl757517ec.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{46153119-C49C-46F4-AEFE-0E70921F6401}\MpKsl757517ec.sys [?]
S1 mvutsnqh;mvutsnqh;\??\c:\windows\system32\drivers\mvutsnqh.sys --> c:\windows\system32\drivers\mvutsnqh.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31.5.2011 23:17 136176]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [12.7.2004 14:13 247608]
S2 pr2ajcyb;TrackMania Original Drivers Auto Removal (pr2ajcyb);c:\windows\system32\pr2ajcyb.exe svc --> c:\windows\system32\pr2ajcyb.exe svc [?]
S3 flash;flash;c:\windows\system32\drivers\flash.sys [3.5.2011 13:04 7040]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [1.7.2004 22:19 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [1.7.2004 22:20 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [1.7.2004 22:20 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [1.7.2004 22:20 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [1.7.2004 22:20 98568]
.
NETSVCS MUSÍ BÝT OPRAVENY - dosavadní položky jsou:
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Obsah adresáře 'Naplánované úlohy'
.
2004-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-31 21:17]
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-31 21:17]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local
IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
IE: Download Video on This Page - c:\program files\Tomato\YouTube Video Downloader\MDIEEx.dll/211
IE: Download Video This Links To - c:\program files\Tomato\YouTube Video Downloader\MDIEEx.dll/212
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Honza\Data aplikací\Mozilla\Firefox\Profiles\ek0sezrx.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://search.jzip.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&q=
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
HKLM-Run-eDataSecurity Loader - c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
HKLM-Run-nvch - rchnewver.dll
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-MsMpSvc
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2004-07-02 11:13
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1148)
c:\windows\system32\cscui.dll
.
- - - - - - - > 'explorer.exe'(2348)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\windows\system32\acs.exe
c:\acer\Empowering Technology\admServ.exe
c:\windows\system32\WLTRAY.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\windows\system32\inetsrv\inetinfo.exe
.
**************************************************************************
.
Celkový čas: 2004-07-02 11:17:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2004-07-02 09:16
.
Před spuštěním: 5 871 673 344
Po spuštění: 6 030 635 008
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect
.
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 2233E061AAA48758D9E9EEB9C9CBBBA5