Tady je log:
ComboFix 11-08-02.02 - Admin 02.08.2011 12:50:13.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.3439.2744 [GMT 2:00]
Spuštěný z: c:\documents and settings\Admin.SCADA\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\csrcs.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-02 do 2011-08-02 )))))))))))))))))))))))))))))))
.
.
2011-08-02 10:24 . 2011-08-02 10:26 -------- d-----w- C:\UsbFix
2011-08-02 10:20 . 2011-08-02 10:21 -------- d-----w- C:\rsit
2011-08-02 10:20 . 2011-08-02 10:20 -------- d-----w- c:\program files\trend micro
2011-08-02 10:08 . 2011-07-07 00:42 543336 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-02 10:08 . 2011-08-02 10:08 278004 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-08-02 10:08 . 2011-08-02 10:08 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-08-02 10:08 . 2011-08-02 10:08 278004 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-08-02 10:08 . 2011-07-07 00:42 899688 ----a-w- c:\windows\system32\nvdispco3220150.dll
2011-08-02 10:08 . 2011-07-07 00:42 876136 ----a-w- c:\windows\system32\nvgenco3220102.dll
2011-08-02 10:08 . 2011-07-07 00:42 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-02 10:08 . 2011-07-07 00:42 13004800 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-02 10:07 . 2011-08-02 10:07 -------- d-----w- C:\NVIDIA
2011-07-20 17:32 . 2011-07-20 17:32 -------- d-----w- c:\documents and settings\Admin.SCADA\Local Settings\Application Data\Microsoft Help
2011-07-13 05:25 . 2011-07-13 05:25 -------- d-----w- C:\totalcmd
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\UC.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\RAR.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\PKZIP.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\LHA.PIF
2011-07-13 05:25 . 2010-04-07 05:55 545 ----a-w- c:\windows\ARJ.PIF
2011-07-12 16:01 . 2010-08-24 18:58 104960 ----a-w- c:\windows\system32\HL-OdbcDrv.dll
2011-07-12 15:14 . 2011-07-12 15:14 -------- d-----w- c:\windows\SchCache
2011-07-11 11:58 . 2011-07-11 11:58 -------- d-----w- c:\program files\ESET
2011-07-11 11:58 . 2011-07-11 11:58 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-02 10:26 . 2011-08-02 10:26 12376 ----a-w- C:\UsbFix_Upload_Me_MHLWS6.zip
2011-07-07 00:42 . 2010-03-04 13:27 5332992 ----a-w- c:\windows\system32\nvcuda.dll
2011-07-07 00:42 . 2010-03-04 13:27 2808936 ----a-w- c:\windows\system32\nvcuvid.dll
2011-07-07 00:42 . 2010-03-04 13:27 2082408 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-07-07 00:42 . 2010-03-04 13:27 16072704 ----a-w- c:\windows\system32\nvoglnt.dll
2011-07-07 00:42 . 2010-03-04 13:27 4202112 ----a-w- c:\windows\system32\nv4_disp.dll
2011-07-07 00:42 . 2010-03-04 13:27 2330112 ----a-w- c:\windows\system32\nvapi.dll
2011-07-07 00:42 . 2010-03-04 13:27 12779904 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-07-07 00:42 . 2009-10-01 16:43 261632 ----a-w- c:\windows\system32\nvnt4cpl.dll
2011-07-07 00:42 . 2009-10-01 16:43 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-07-07 00:42 . 2009-10-01 16:43 335872 ----a-w- c:\windows\system32\nvrsar.dll
2011-07-07 00:42 . 2009-10-01 16:43 331776 ----a-w- c:\windows\system32\nvrshe.dll
2011-07-07 00:42 . 2009-10-01 16:43 286720 ----a-w- c:\windows\system32\nvrsfr.dll
2011-07-07 00:42 . 2009-10-01 16:43 282624 ----a-w- c:\windows\system32\nvrsit.dll
2011-07-07 00:42 . 2009-10-01 16:43 282624 ----a-w- c:\windows\system32\nvrses.dll
2011-07-07 00:42 . 2009-10-01 16:43 282624 ----a-w- c:\windows\system32\nvrsel.dll
2011-07-07 00:42 . 2009-10-01 16:43 278528 ----a-w- c:\windows\system32\nvrsde.dll
2011-07-07 00:42 . 2009-10-01 16:43 274432 ----a-w- c:\windows\system32\nvrspt.dll
2011-07-07 00:42 . 2009-10-01 16:43 274432 ----a-w- c:\windows\system32\nvrsnl.dll
2011-07-07 00:42 . 2009-10-01 16:43 274432 ----a-w- c:\windows\system32\nvrsesm.dll
2011-07-07 00:42 . 2009-10-01 16:43 270336 ----a-w- c:\windows\system32\nvrsru.dll
2011-07-07 00:42 . 2009-10-01 16:43 270336 ----a-w- c:\windows\system32\nvrsptb.dll
2011-07-07 00:42 . 2009-10-01 16:43 270336 ----a-w- c:\windows\system32\nvrsja.dll
2011-07-07 00:42 . 2009-10-01 16:43 266240 ----a-w- c:\windows\system32\nvrsko.dll
2011-07-07 00:42 . 2009-10-01 16:43 262144 ----a-w- c:\windows\system32\nvrshu.dll
2011-07-07 00:42 . 2009-10-01 16:43 258048 ----a-w- c:\windows\system32\nvrstr.dll
2011-07-07 00:42 . 2009-10-01 16:43 258048 ----a-w- c:\windows\system32\nvrssl.dll
2011-07-07 00:42 . 2009-10-01 16:43 258048 ----a-w- c:\windows\system32\nvrssk.dll
2011-07-07 00:42 . 2009-10-01 16:43 258048 ----a-w- c:\windows\system32\nvrspl.dll
2011-07-07 00:42 . 2009-10-01 16:43 253952 ----a-w- c:\windows\system32\nvrsth.dll
2011-07-07 00:42 . 2009-10-01 16:43 253952 ----a-w- c:\windows\system32\nvrssv.dll
2011-07-07 00:42 . 2009-10-01 16:43 253952 ----a-w- c:\windows\system32\nvrsno.dll
2011-07-07 00:42 . 2009-10-01 16:43 253952 ----a-w- c:\windows\system32\nvrsda.dll
2011-07-07 00:42 . 2009-10-01 16:43 249856 ----a-w- c:\windows\system32\nvrsfi.dll
2011-07-07 00:42 . 2009-10-01 16:43 249856 ----a-w- c:\windows\system32\nvrseng.dll
2011-07-07 00:42 . 2009-10-01 16:43 249856 ----a-w- c:\windows\system32\nvrscs.dll
2011-07-07 00:42 . 2009-10-01 16:43 229376 ----a-w- c:\windows\system32\nvrszhc.dll
2011-07-07 00:42 . 2009-10-01 16:43 126976 ----a-w- c:\windows\system32\nvrszht.dll
2011-07-07 00:42 . 2009-10-01 16:43 154728 ----a-w- c:\windows\system32\nvsvc32.exe
2011-07-07 00:42 . 2009-10-01 16:43 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-07-07 00:42 . 2009-10-01 16:43 13897832 ----a-w- c:\windows\system32\nvcpl.dll
2011-07-07 00:42 . 2009-10-01 16:43 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-05-19 2363392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"RTHDCPL"="RTHDCPL.EXE" [2009-07-29 18671104]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2006-05-12 1138688]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-31 761856]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-07-10 872448]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-07-07 13897832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-07-07 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-04 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP SkyRoom\\HP.SkyRoom.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP SkyRoom\\remote graphics receiver\\rgreceiver.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP SkyRoom\\remote graphics sender\\rgsender.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP SkyRoom\\remote graphics sender\\rgsender_gui.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 b06bdrv;Broadcom NetXtreme II VBD;c:\windows\system32\drivers\bxvbdx.sys [7.2.2011 14:35 453672]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21.12.2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21.12.2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.1.2011 16:41 810144]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [18.4.2007 6:09 11032]
R3 Blfm;BASP Virtual Adapter;c:\windows\system32\drivers\baspxp32.sys [29.10.2008 1:39 89600]
R3 l2nd;Broadcom NetXtreme II BXND;c:\windows\system32\drivers\bxnd52x.sys [7.2.2011 14:34 66600]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [24.9.2008 3:01 114688]
S2 Hp.Skyroom.Windows.Service;HP SkyRoom;c:\program files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [21.11.2009 0:10 124984]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [4.3.2010 15:41 635416]
S2 rgsender;Remote Graphics Sender Service;c:\program files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [4.3.2010 15:51 379904]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4.3.2010 15:42 1684736]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [13.6.2009 20:13 1120752]
S3 VirtDisk;XSS Virtual Disk Driver;c:\windows\SMINST\virtdisk.sys [4.3.2010 15:52 57344]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - NVSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-05-19 01:54 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://10.235.203.22/odoku/analoge_io.html#ana_rw
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{7756E7E6-3CA2-4E0D-B051-8DE555B8038C}: NameServer = 10.235.203.11,10.235.203.12
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-RunOnce-<NO NAME> - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-02 12:51
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Celkový čas: 2011-08-02 12:52:26
ComboFix-quarantined-files.txt 2011-08-02 10:52
.
Před spuštěním: 26 680 737 792 bytes free
Po spuštění: 26 686 771 200 bytes free
.
- - End Of File - - C35FF36179CF278AB4FA2E93EA3D4C56