prosím o kontrolu logu
Napsal: 16 říj 2011 21:48
Avast mě hlásil opakovaně výskyt Rootkitu v souboru C:\WINDOWS\system32\drivers\hardlock. Pokaždé nabídl smazání a následný scan počítače, to nepřineslo řešení. Použil jsem tedy ComboFix a zde je log z něj. Děkuji za posouzení a rady.
ComboFix 11-10-15.04 - user 16.10.2011 10:54:11.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.579 [GMT 2:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\user\Local Settings\Temporary Internet Files\TRNCOM.INI
c:\documents and settings\user\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\system32\CF29235.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-16 do 2011-10-16 )))))))))))))))))))))))))))))))
.
.
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\Babylon
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Babylon
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\user\Data aplikací\Babylon
2011-10-09 20:43 . 2011-10-09 20:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-10-09 20:23 . 2011-10-09 20:24 -------- d-----w- c:\documents and settings\user\Data aplikací\GetRightToGo
2011-10-02 08:18 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-10-02 08:18 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-10-02 08:15 . 2011-10-02 08:15 -------- d-----w- c:\program files\Microsoft Works
2011-10-02 08:15 . 2011-10-02 08:15 -------- d-----w- c:\program files\MSBuild
2011-10-02 08:13 . 2011-10-02 08:13 -------- d-----w- c:\program files\Microsoft.NET
2011-10-02 08:10 . 2011-10-02 08:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-10-02 08:09 . 2011-10-02 08:14 -------- d-----w- c:\windows\SHELLNEW
2011-10-02 08:08 . 2011-10-02 08:08 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\Microsoft Help
2011-10-02 08:08 . 2011-10-08 17:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Microsoft Help
2011-10-02 08:07 . 2011-10-02 08:07 -------- d-----r- C:\MSOCache
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\user\Data aplikací\ATI
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\ATI
2011-09-22 23:55 . 2011-09-22 23:55 0 ----a-w- c:\windows\ativpsrm.bin
2011-09-22 23:52 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-09-22 23:52 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-09-22 23:52 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-09-22 23:52 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-09-22 23:52 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-09-22 23:52 . 2011-09-22 23:52 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-09-22 23:52 . 2011-09-22 23:52 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-09-22 23:52 . 2010-02-10 19:20 593920 ------w- c:\windows\system32\ati2sgag.exe
2011-09-22 23:51 . 2011-09-22 23:54 -------- d-----w- c:\program files\ATI Technologies
2011-09-22 23:49 . 2011-09-22 23:49 -------- d-----w- C:\ATI
2011-09-22 22:50 . 2010-02-11 04:12 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2011-09-22 22:50 . 2004-08-17 13:49 516768 -c--a-w- c:\windows\system32\dllcache\ativvaxx.dll
2011-09-22 22:50 . 2010-02-11 04:25 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2011-09-22 22:50 . 2004-08-17 13:49 1888992 -c--a-w- c:\windows\system32\dllcache\ati3duag.dll
2011-09-22 22:50 . 2010-02-11 07:38 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-09-22 22:50 . 2004-08-17 13:43 701440 -c--a-w- c:\windows\system32\dllcache\ati2mtag.sys
2011-09-22 22:50 . 2004-08-17 13:49 870784 -c--a-w- c:\windows\system32\dllcache\ati3d1ag.dll
2011-09-22 22:50 . 2004-08-17 13:49 870784 ----a-w- c:\windows\system32\ati3d1ag.dll
2011-09-22 22:50 . 2010-02-11 04:45 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2011-09-22 22:50 . 2004-08-17 13:49 201728 -c--a-w- c:\windows\system32\dllcache\ati2dvag.dll
2011-09-22 22:50 . 2010-02-11 03:47 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2011-09-22 22:50 . 2004-08-17 13:49 229376 -c--a-w- c:\windows\system32\dllcache\ati2cqag.dll
2011-09-22 20:52 . 2011-09-22 20:52 -------- d-----w- c:\program files\Intel
2011-09-22 20:51 . 2004-08-03 20:59 95360 ----a-w- c:\windows\system32\drivers\SET32.tmp
2011-09-22 20:48 . 2011-09-22 20:48 -------- d-----w- C:\PNP
2011-09-22 20:10 . 2004-08-03 21:07 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2011-09-22 20:10 . 2004-08-03 21:07 42368 ----a-w- c:\windows\system32\drivers\AGP440.SYS
2011-09-22 20:10 . 2004-08-17 13:44 5504 -c--a-w- c:\windows\system32\dllcache\intelide.sys
2011-09-22 20:10 . 2004-08-17 13:44 5504 ----a-w- c:\windows\system32\drivers\intelide.sys
2011-09-22 20:10 . 2004-08-03 21:08 20480 -c--a-w- c:\windows\system32\dllcache\usbuhci.sys
2011-09-22 20:10 . 2004-08-03 21:08 20480 ----a-w- c:\windows\system32\drivers\usbuhci.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-05 19:36 . 2011-05-30 21:57 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 20:45 . 2010-10-07 22:42 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2010-10-07 22:42 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-06-19 20:48 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2010-10-07 22:42 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2010-10-07 22:42 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2010-10-07 22:42 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2010-10-07 22:42 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2010-10-07 22:42 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2010-10-07 22:42 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2010-10-07 22:42 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-08-25 20:04 . 2009-02-21 17:22 824042 ----a-w- c:\documents and settings\user\Data aplikací\mdbu.bin
2008-01-12 10:57 . 2008-01-12 10:56 6583976 ----a-w- c:\program files\Opera_9.25_International_Setup.exe
2004-11-08 15:39 . 2009-04-09 12:07 65952 ----a-w- c:\program files\ttdvblcd.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-03 20:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2011-01-17 14:54 175912 ----a-w- c:\program files\MyAshampoo\prxtbMyA2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\BS_Player\prxtbBS_2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-07-25 433360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-09-26 17353352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
"nwiz"="nwiz.exe" [2004-07-01 843776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-07-01 81920]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-27 113664]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Hauppauge\\WinTV NOVA\\DVB-TV.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\gamese\\Call of Duty\\CoDUOMP.exe"=
"c:\\Program Files\\Hauppauge\\WinTV NOVA\\DVBData.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\user\\Local Settings\\Data aplikací\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"f:\\Blitzkrieg Anthology\\BK\\game.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [16.2.2007 23:11 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [16.2.2007 23:11 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [19.6.2011 22:48 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.10.2010 0:42 320856]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.10.2010 0:42 20568]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 CX88IR;Conexant 2388x IR Decoder;c:\windows\system32\drivers\cx88ir.sys [26.9.2005 16:08 10368]
S2 CX88XBAR;Conexant 2388x Crossbar;c:\windows\system32\drivers\cx88xbar.sys [26.9.2005 16:09 6528]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31.1.2010 13:54 135664]
S2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\Drivers\p1c1394.sys --> c:\windows\system32\Drivers\p1c1394.sys [?]
S3 ADM8211;corega WLPCIB-11;c:\windows\system32\drivers\COWPCIB5.sys [23.10.2005 18:51 84992]
S3 CXAVSAUD;Conexant 2388x AvStream Audio Capture;c:\windows\system32\drivers\cxavsaud.sys [26.9.2005 16:07 8320]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [31.1.2010 13:54 135664]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\MTK.SYS [29.7.2007 11:14 15670]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [31.7.2011 20:24 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [31.7.2011 20:24 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [31.7.2011 20:24 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [31.7.2011 20:24 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [31.7.2011 20:24 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [31.7.2011 20:24 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [31.7.2011 20:24 123504]
S3 TTDVBLCD;TechnoTrend DVB PCI budget Driver;c:\windows\system32\drivers\ttdvblcd.sys [11.10.2005 21:24 65952]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:54]
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=101433&mntrId=c8c0618e000000000000001109769f60
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
TCP: Interfaces\{092B6781-51F5-46E1-AD4E-53519D34694F}: NameServer = 10.102.177.129,10.102.1.1
TCP: Interfaces\{D53F8F48-4E0C-4A0C-BFDA-349107E1EEB2}: NameServer = 10.102.0.252,10.102.0.253
TCP: Interfaces\{F90B2F85-CCD4-453E-A220-6D87A3286DD8}: NameServer = 10.102.0.252,10.102.0.253
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Hauppauge Digital Teletext - c:\program files\Hauppauge\Digital Teletext\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-16 11:05
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-10-16 11:11:28
ComboFix-quarantined-files.txt 2011-10-16 09:11
.
Před spuštěním: 8 107 552 768
Po spuštění: Volných bajtů: 11 266 293 760
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 3E141D8F19AF5877757FFCDE57D9BFEE
ComboFix 11-10-15.04 - user 16.10.2011 10:54:11.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.579 [GMT 2:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\user\Local Settings\Temporary Internet Files\TRNCOM.INI
c:\documents and settings\user\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\system32\CF29235.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-16 do 2011-10-16 )))))))))))))))))))))))))))))))
.
.
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\Babylon
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Babylon
2011-10-09 20:44 . 2011-10-09 20:44 -------- d-----w- c:\documents and settings\user\Data aplikací\Babylon
2011-10-09 20:43 . 2011-10-09 20:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-10-09 20:23 . 2011-10-09 20:24 -------- d-----w- c:\documents and settings\user\Data aplikací\GetRightToGo
2011-10-02 08:18 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-10-02 08:18 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-10-02 08:15 . 2011-10-02 08:15 -------- d-----w- c:\program files\Microsoft Works
2011-10-02 08:15 . 2011-10-02 08:15 -------- d-----w- c:\program files\MSBuild
2011-10-02 08:13 . 2011-10-02 08:13 -------- d-----w- c:\program files\Microsoft.NET
2011-10-02 08:10 . 2011-10-02 08:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-10-02 08:09 . 2011-10-02 08:14 -------- d-----w- c:\windows\SHELLNEW
2011-10-02 08:08 . 2011-10-02 08:08 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\Microsoft Help
2011-10-02 08:08 . 2011-10-08 17:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Microsoft Help
2011-10-02 08:07 . 2011-10-02 08:07 -------- d-----r- C:\MSOCache
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\user\Data aplikací\ATI
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2011-09-22 23:56 . 2011-09-22 23:56 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\ATI
2011-09-22 23:55 . 2011-09-22 23:55 0 ----a-w- c:\windows\ativpsrm.bin
2011-09-22 23:52 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-09-22 23:52 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-09-22 23:52 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-09-22 23:52 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-09-22 23:52 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-09-22 23:52 . 2011-09-22 23:52 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-09-22 23:52 . 2011-09-22 23:52 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-09-22 23:52 . 2010-02-10 19:20 593920 ------w- c:\windows\system32\ati2sgag.exe
2011-09-22 23:51 . 2011-09-22 23:54 -------- d-----w- c:\program files\ATI Technologies
2011-09-22 23:49 . 2011-09-22 23:49 -------- d-----w- C:\ATI
2011-09-22 22:50 . 2010-02-11 04:12 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2011-09-22 22:50 . 2004-08-17 13:49 516768 -c--a-w- c:\windows\system32\dllcache\ativvaxx.dll
2011-09-22 22:50 . 2010-02-11 04:25 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2011-09-22 22:50 . 2004-08-17 13:49 1888992 -c--a-w- c:\windows\system32\dllcache\ati3duag.dll
2011-09-22 22:50 . 2010-02-11 07:38 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-09-22 22:50 . 2004-08-17 13:43 701440 -c--a-w- c:\windows\system32\dllcache\ati2mtag.sys
2011-09-22 22:50 . 2004-08-17 13:49 870784 -c--a-w- c:\windows\system32\dllcache\ati3d1ag.dll
2011-09-22 22:50 . 2004-08-17 13:49 870784 ----a-w- c:\windows\system32\ati3d1ag.dll
2011-09-22 22:50 . 2010-02-11 04:45 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2011-09-22 22:50 . 2004-08-17 13:49 201728 -c--a-w- c:\windows\system32\dllcache\ati2dvag.dll
2011-09-22 22:50 . 2010-02-11 03:47 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2011-09-22 22:50 . 2004-08-17 13:49 229376 -c--a-w- c:\windows\system32\dllcache\ati2cqag.dll
2011-09-22 20:52 . 2011-09-22 20:52 -------- d-----w- c:\program files\Intel
2011-09-22 20:51 . 2004-08-03 20:59 95360 ----a-w- c:\windows\system32\drivers\SET32.tmp
2011-09-22 20:48 . 2011-09-22 20:48 -------- d-----w- C:\PNP
2011-09-22 20:10 . 2004-08-03 21:07 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2011-09-22 20:10 . 2004-08-03 21:07 42368 ----a-w- c:\windows\system32\drivers\AGP440.SYS
2011-09-22 20:10 . 2004-08-17 13:44 5504 -c--a-w- c:\windows\system32\dllcache\intelide.sys
2011-09-22 20:10 . 2004-08-17 13:44 5504 ----a-w- c:\windows\system32\drivers\intelide.sys
2011-09-22 20:10 . 2004-08-03 21:08 20480 -c--a-w- c:\windows\system32\dllcache\usbuhci.sys
2011-09-22 20:10 . 2004-08-03 21:08 20480 ----a-w- c:\windows\system32\drivers\usbuhci.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-05 19:36 . 2011-05-30 21:57 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 20:45 . 2010-10-07 22:42 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2010-10-07 22:42 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-06-19 20:48 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2010-10-07 22:42 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2010-10-07 22:42 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2010-10-07 22:42 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2010-10-07 22:42 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2010-10-07 22:42 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2010-10-07 22:42 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2010-10-07 22:42 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-08-25 20:04 . 2009-02-21 17:22 824042 ----a-w- c:\documents and settings\user\Data aplikací\mdbu.bin
2008-01-12 10:57 . 2008-01-12 10:56 6583976 ----a-w- c:\program files\Opera_9.25_International_Setup.exe
2004-11-08 15:39 . 2009-04-09 12:07 65952 ----a-w- c:\program files\ttdvblcd.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-03 20:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2011-01-17 14:54 175912 ----a-w- c:\program files\MyAshampoo\prxtbMyA2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\BS_Player\prxtbBS_2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_2.dll" [2011-01-17 175912]
"{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}"= "c:\program files\MyAshampoo\prxtbMyA2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-07-25 433360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-09-26 17353352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
"nwiz"="nwiz.exe" [2004-07-01 843776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-07-01 81920]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-27 113664]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Hauppauge\\WinTV NOVA\\DVB-TV.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\gamese\\Call of Duty\\CoDUOMP.exe"=
"c:\\Program Files\\Hauppauge\\WinTV NOVA\\DVBData.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\user\\Local Settings\\Data aplikací\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"f:\\Blitzkrieg Anthology\\BK\\game.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [16.2.2007 23:11 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [16.2.2007 23:11 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [19.6.2011 22:48 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.10.2010 0:42 320856]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.10.2010 0:42 20568]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 CX88IR;Conexant 2388x IR Decoder;c:\windows\system32\drivers\cx88ir.sys [26.9.2005 16:08 10368]
S2 CX88XBAR;Conexant 2388x Crossbar;c:\windows\system32\drivers\cx88xbar.sys [26.9.2005 16:09 6528]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31.1.2010 13:54 135664]
S2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\Drivers\p1c1394.sys --> c:\windows\system32\Drivers\p1c1394.sys [?]
S3 ADM8211;corega WLPCIB-11;c:\windows\system32\drivers\COWPCIB5.sys [23.10.2005 18:51 84992]
S3 CXAVSAUD;Conexant 2388x AvStream Audio Capture;c:\windows\system32\drivers\cxavsaud.sys [26.9.2005 16:07 8320]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [31.1.2010 13:54 135664]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\MTK.SYS [29.7.2007 11:14 15670]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [31.7.2011 20:24 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [31.7.2011 20:24 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [31.7.2011 20:24 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [31.7.2011 20:24 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [31.7.2011 20:24 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [31.7.2011 20:24 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [31.7.2011 20:24 123504]
S3 TTDVBLCD;TechnoTrend DVB PCI budget Driver;c:\windows\system32\drivers\ttdvblcd.sys [11.10.2005 21:24 65952]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:54]
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=101433&mntrId=c8c0618e000000000000001109769f60
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
TCP: Interfaces\{092B6781-51F5-46E1-AD4E-53519D34694F}: NameServer = 10.102.177.129,10.102.1.1
TCP: Interfaces\{D53F8F48-4E0C-4A0C-BFDA-349107E1EEB2}: NameServer = 10.102.0.252,10.102.0.253
TCP: Interfaces\{F90B2F85-CCD4-453E-A220-6D87A3286DD8}: NameServer = 10.102.0.252,10.102.0.253
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Hauppauge Digital Teletext - c:\program files\Hauppauge\Digital Teletext\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-16 11:05
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-10-16 11:11:28
ComboFix-quarantined-files.txt 2011-10-16 09:11
.
Před spuštěním: 8 107 552 768
Po spuštění: Volných bajtů: 11 266 293 760
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 3E141D8F19AF5877757FFCDE57D9BFEE