Trojsky kon v operačnej pamäti + log na kontrolu pls pomoc
Napsal: 01 led 2012 20:02
Mám problém s trójskym koňom PSW.Papras.CA.
Mám antivírus Eset NOD 32 ktorý pri kontrole pri štarte vyhodí hlásenie že:
Infiltrácia nájdena v pamäti!
Objekt: explorer.exe (328)
Infiltrácia Win32/PSW.Papras.CA. trojrójsky kôň
Nedá sa liečiť
Skúšala som už asi všetko: Kontrolu s Avastom po reštarte, kontrolu všetkými možnými chytačmi trojanov ako napr : SpywareTerminator, EmsisoftAntiMalware, TrojanRemover a rôzne ďalšie a nič nepomohlo. Skúšala som uviesť PC do režimu dlhodobého spánku a následne potom po stačení F8 som dala vymazať súbory no ani to nepomohlo. Skúsila som ComboFix... vyhodil mi log, no aj napriek tomu mi stále Eset hlási že ten Trojan tam je. Čo s tým?
Prikladám aj log:
ComboFix 12-01-01.01 - Andrej . 01. 2012 19:07:03.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.190 [GMT 1:00]
Running from: c:\documents and settings\Andrej\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Legacy_WUAUSERV
-------\Service_wuauserv
.
.
((((((((((((((((((((((((( Files Created from 2011-12-01 to 2012-01-01 )))))))))))))))))))))))))))))))
.
.
2012-01-01 18:19 . 2012-01-01 18:19 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsleb00f48f.sys
2012-01-01 18:18 . 2012-01-01 18:18 56200 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\offreg.dll
2012-01-01 17:32 . 2012-01-01 17:32 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKslc221fe41.sys
2011-12-31 19:41 . 2011-12-31 19:41 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsla0d30769.sys
2011-12-30 14:59 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-12-30 14:38 . 2011-11-21 01:47 6823496 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\mpengine.dll
2011-12-30 14:19 . 2011-12-30 14:19 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\Simply Super Software
2011-12-30 14:19 . 2011-12-30 14:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Simply Super Software
2011-12-30 11:01 . 2011-12-30 14:00 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-12-30 09:57 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2011-12-30 09:56 . 2011-12-30 09:56 -------- d-----w- c:\program files\Ashampoo
2011-12-29 16:25 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-12-29 16:25 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-12-29 16:25 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-12-29 16:25 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-12-29 16:25 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-29 16:25 . 2011-11-28 17:52 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-12-29 16:25 . 2011-11-28 17:51 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-12-29 16:25 . 2011-11-28 17:48 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-12-29 16:24 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2011-12-29 16:24 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-12-29 16:23 . 2011-12-29 16:23 -------- d-----w- c:\program files\AVAST Software
2011-12-29 16:23 . 2011-12-29 16:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-12-29 13:00 . 2011-12-29 13:00 -------- d-----w- c:\program files\Microsoft Silverlight
2011-12-29 11:43 . 2011-12-29 11:43 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-12-29 11:40 . 2011-12-29 11:40 -------- d-----w- c:\program files\Common Files\Windows Live
2011-12-29 11:36 . 2011-12-29 11:36 -------- d-----w- c:\windows\system32\winrm
2011-12-29 11:35 . 2011-12-29 11:36 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2011-12-29 10:37 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-12-29 10:21 . 2011-12-29 10:21 -------- d-----w- c:\program files\TeamViewer
2011-12-29 10:14 . 2011-12-29 13:31 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\TeamViewer
2011-12-19 10:10 . 2011-12-19 10:10 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-12-19 10:09 . 2011-12-19 10:09 -------- d-----w- c:\documents and settings\Andrej\Local Settings\Data aplikací\ESET
2011-12-19 10:00 . 2011-12-19 10:00 -------- d-----w- c:\program files\ESET
2011-12-19 10:00 . 2011-12-19 10:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-12-19 09:14 . 2011-12-19 09:14 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-19 09:13 . 2011-12-19 09:51 -------- d-----w- c:\program files\Microsoft Security Client
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\Search Settings
2011-12-09 06:05 . 2011-12-19 10:10 -------- d-----w- c:\program files\Application Updater
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\program files\Common Files\Spigot
2011-12-06 19:37 . 2011-12-19 09:14 -------- d-----w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 14:40 . 2008-04-14 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-21 01:47 . 2011-01-31 08:54 6823496 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-04 19:13 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2008-04-14 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:32 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:50 . 2008-04-14 12:00 2194944 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 10:50 . 2008-04-14 08:06 2071552 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2008-04-14 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2011-01-26 18:43 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALi5289"="c:\program files\ULI5289\ALi5289.exe" [2005-03-10 405504]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 3080264]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 08:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-07-19 16:29 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-12-09 10:45 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [26. 1. 2011 20:14 51840]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [26. 1. 2011 20:14 44928]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29. 12. 2011 17:25 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29. 12. 2011 17:25 314456]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4. 8. 2011 9:20 118104]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [4. 8. 2011 9:20 103112]
R1 MpKsleb00f48f;MpKsleb00f48f;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsleb00f48f.sys [1. 1. 2012 19:19 29904]
R2 ALIEHCD;ULi PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\AliEhci.sys [26. 1. 2011 20:14 83596]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29. 12. 2011 17:25 20568]
R2 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 8\DfSdkS.exe [30. 12. 2011 10:57 406016]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [22. 9. 2011 12:03 974944]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [31. 7. 2011 12:58 90112]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [29. 12. 2011 11:21 2984832]
R3 aliroothub;USB 2.0 Root Hub;c:\windows\system32\drivers\AliRtHub.sys [26. 1. 2011 20:14 5331]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [31. 7. 2011 12:59 27632]
R3 ULI5261;ULi Based Ethernet NT Driver;c:\windows\system32\drivers\ULILAN.SYS [26. 1. 2011 20:14 28160]
S1 MpKsl0291cfe2;MpKsl0291cfe2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6D0CF53E-1F76-4B6E-B77C-DF326FA67E8A}\MpKsl0291cfe2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6D0CF53E-1F76-4B6E-B77C-DF326FA67E8A}\MpKsl0291cfe2.sys [?]
S1 MpKsl09216346;MpKsl09216346;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl09216346.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl09216346.sys [?]
S1 MpKsl170033f7;MpKsl170033f7;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{4A2CB5F8-2CC7-421C-B551-781796EF498A}\MpKsl170033f7.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{4A2CB5F8-2CC7-421C-B551-781796EF498A}\MpKsl170033f7.sys [?]
S1 MpKsl198c1960;MpKsl198c1960;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl198c1960.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl198c1960.sys [?]
S1 MpKsl1d649da7;MpKsl1d649da7;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl1d649da7.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl1d649da7.sys [?]
S1 MpKsl39a2102d;MpKsl39a2102d;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{C0EE2217-583F-497D-948F-9D66450859B2}\MpKsl39a2102d.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{C0EE2217-583F-497D-948F-9D66450859B2}\MpKsl39a2102d.sys [?]
S1 MpKsl4a5c88d6;MpKsl4a5c88d6;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4a5c88d6.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4a5c88d6.sys [?]
S1 MpKsl4ab8ec4e;MpKsl4ab8ec4e;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BBDF0701-2968-4948-97E7-B8931527B410}\MpKsl4ab8ec4e.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BBDF0701-2968-4948-97E7-B8931527B410}\MpKsl4ab8ec4e.sys [?]
S1 MpKsl4ebe2678;MpKsl4ebe2678;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{16971267-EAA7-477B-99A5-0DBF6649D69C}\MpKsl4ebe2678.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{16971267-EAA7-477B-99A5-0DBF6649D69C}\MpKsl4ebe2678.sys [?]
S1 MpKsl4f3a2b56;MpKsl4f3a2b56;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4f3a2b56.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4f3a2b56.sys [?]
S1 MpKsl50729e58;MpKsl50729e58;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{64403C45-BCED-43D3-96F0-206FD34ECF07}\MpKsl50729e58.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{64403C45-BCED-43D3-96F0-206FD34ECF07}\MpKsl50729e58.sys [?]
S1 MpKsl6d243d40;MpKsl6d243d40;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0A43367D-418B-43FE-AC29-FFCC4176BA81}\MpKsl6d243d40.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0A43367D-418B-43FE-AC29-FFCC4176BA81}\MpKsl6d243d40.sys [?]
S1 MpKsl6da53cd2;MpKsl6da53cd2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl6da53cd2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl6da53cd2.sys [?]
S1 MpKsl788c0a60;MpKsl788c0a60;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl788c0a60.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl788c0a60.sys [?]
S1 MpKsl7a8c3fbd;MpKsl7a8c3fbd;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl7a8c3fbd.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl7a8c3fbd.sys [?]
S1 MpKsl805c9a21;MpKsl805c9a21;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl805c9a21.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl805c9a21.sys [?]
S1 MpKsl9595b0f9;MpKsl9595b0f9;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A6ED3860-72AB-4BA7-BDC4-EBF38ED88229}\MpKsl9595b0f9.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A6ED3860-72AB-4BA7-BDC4-EBF38ED88229}\MpKsl9595b0f9.sys [?]
S1 MpKsl97cb5649;MpKsl97cb5649;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CC07DEDF-D087-4C01-B58B-2AEAF651B6A1}\MpKsl97cb5649.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CC07DEDF-D087-4C01-B58B-2AEAF651B6A1}\MpKsl97cb5649.sys [?]
S1 MpKsl9bbe3881;MpKsl9bbe3881;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl9bbe3881.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl9bbe3881.sys [?]
S1 MpKslbf9c73f3;MpKslbf9c73f3;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslbf9c73f3.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslbf9c73f3.sys [?]
S1 MpKsle85ea9d9;MpKsle85ea9d9;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF8A9E5C-8181-467C-AB3E-52E89B46799F}\MpKsle85ea9d9.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF8A9E5C-8181-467C-AB3E-52E89B46799F}\MpKsle85ea9d9.sys [?]
S1 MpKslff5f15b2;MpKslff5f15b2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslff5f15b2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslff5f15b2.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [31. 1. 2011 18:00 247096]
S3 aligp;USB Composite Device;c:\windows\system32\drivers\AliGP.sys [26. 1. 2011 20:14 10326]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14. 4. 2008 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLEB00F48F
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.119.113.244 217.119.113.245
FF - ProfilePath - c:\documents and settings\Andrej\Data aplikací\Mozilla\Firefox\Profiles\mrqnrq5s.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep: wrc@avast.com - c:\program files\AVAST Software\Avast\WebRep\FF
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: User Agent Switcher: {e968fc70-8f95-4ab9-9e79-304de2a71ee1} - %profile%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-HP OrderReminder - c:\program files\Hewlett-Packard\OrderReminder\uninstall\hpuninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-01 19:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(328)
c:\windows\system32\msi.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\cs-cz\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\cs-cz\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\TeamViewer\Version7\TeamViewer.exe
c:\windows\system32\wscntfy.exe
c:\program files\TeamViewer\Version7\tv_w32.exe
c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
**************************************************************************
.
Completion time: 2012-01-01 19:28:33 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-01 18:28
.
Pre-Run: Volných bajtů: 58 694 987 776
Post-Run: Volných bajtů: 58 796 945 408
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 80D7C5E67FE1FE359135295602DF2CFA
Mám antivírus Eset NOD 32 ktorý pri kontrole pri štarte vyhodí hlásenie že:
Infiltrácia nájdena v pamäti!
Objekt: explorer.exe (328)
Infiltrácia Win32/PSW.Papras.CA. trojrójsky kôň
Nedá sa liečiť
Skúšala som už asi všetko: Kontrolu s Avastom po reštarte, kontrolu všetkými možnými chytačmi trojanov ako napr : SpywareTerminator, EmsisoftAntiMalware, TrojanRemover a rôzne ďalšie a nič nepomohlo. Skúšala som uviesť PC do režimu dlhodobého spánku a následne potom po stačení F8 som dala vymazať súbory no ani to nepomohlo. Skúsila som ComboFix... vyhodil mi log, no aj napriek tomu mi stále Eset hlási že ten Trojan tam je. Čo s tým?
Prikladám aj log:
ComboFix 12-01-01.01 - Andrej . 01. 2012 19:07:03.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.190 [GMT 1:00]
Running from: c:\documents and settings\Andrej\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Legacy_WUAUSERV
-------\Service_wuauserv
.
.
((((((((((((((((((((((((( Files Created from 2011-12-01 to 2012-01-01 )))))))))))))))))))))))))))))))
.
.
2012-01-01 18:19 . 2012-01-01 18:19 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsleb00f48f.sys
2012-01-01 18:18 . 2012-01-01 18:18 56200 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\offreg.dll
2012-01-01 17:32 . 2012-01-01 17:32 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKslc221fe41.sys
2011-12-31 19:41 . 2011-12-31 19:41 29904 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsla0d30769.sys
2011-12-30 14:59 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-12-30 14:38 . 2011-11-21 01:47 6823496 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\mpengine.dll
2011-12-30 14:19 . 2011-12-30 14:19 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\Simply Super Software
2011-12-30 14:19 . 2011-12-30 14:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Simply Super Software
2011-12-30 11:01 . 2011-12-30 14:00 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-12-30 09:57 . 2009-08-24 21:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2011-12-30 09:56 . 2011-12-30 09:56 -------- d-----w- c:\program files\Ashampoo
2011-12-29 16:25 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-12-29 16:25 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-12-29 16:25 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-12-29 16:25 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-12-29 16:25 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-29 16:25 . 2011-11-28 17:52 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-12-29 16:25 . 2011-11-28 17:51 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-12-29 16:25 . 2011-11-28 17:48 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-12-29 16:24 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2011-12-29 16:24 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-12-29 16:23 . 2011-12-29 16:23 -------- d-----w- c:\program files\AVAST Software
2011-12-29 16:23 . 2011-12-29 16:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-12-29 13:00 . 2011-12-29 13:00 -------- d-----w- c:\program files\Microsoft Silverlight
2011-12-29 11:43 . 2011-12-29 11:43 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-12-29 11:40 . 2011-12-29 11:40 -------- d-----w- c:\program files\Common Files\Windows Live
2011-12-29 11:36 . 2011-12-29 11:36 -------- d-----w- c:\windows\system32\winrm
2011-12-29 11:35 . 2011-12-29 11:36 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2011-12-29 10:37 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-12-29 10:21 . 2011-12-29 10:21 -------- d-----w- c:\program files\TeamViewer
2011-12-29 10:14 . 2011-12-29 13:31 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\TeamViewer
2011-12-19 10:10 . 2011-12-19 10:10 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-12-19 10:09 . 2011-12-19 10:09 -------- d-----w- c:\documents and settings\Andrej\Local Settings\Data aplikací\ESET
2011-12-19 10:00 . 2011-12-19 10:00 -------- d-----w- c:\program files\ESET
2011-12-19 10:00 . 2011-12-19 10:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-12-19 09:14 . 2011-12-19 09:14 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-19 09:13 . 2011-12-19 09:51 -------- d-----w- c:\program files\Microsoft Security Client
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\documents and settings\Andrej\Data aplikací\Search Settings
2011-12-09 06:05 . 2011-12-19 10:10 -------- d-----w- c:\program files\Application Updater
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2011-12-09 06:05 . 2011-12-09 06:05 -------- d-----w- c:\program files\Common Files\Spigot
2011-12-06 19:37 . 2011-12-19 09:14 -------- d-----w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 14:40 . 2008-04-14 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-21 01:47 . 2011-01-31 08:54 6823496 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-04 19:13 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2008-04-14 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:32 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:50 . 2008-04-14 12:00 2194944 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 10:50 . 2008-04-14 08:06 2071552 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2008-04-14 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2011-01-26 18:43 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALi5289"="c:\program files\ULI5289\ALi5289.exe" [2005-03-10 405504]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 3080264]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 08:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-07-19 16:29 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-12-09 10:45 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [26. 1. 2011 20:14 51840]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [26. 1. 2011 20:14 44928]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29. 12. 2011 17:25 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29. 12. 2011 17:25 314456]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4. 8. 2011 9:20 118104]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [4. 8. 2011 9:20 103112]
R1 MpKsleb00f48f;MpKsleb00f48f;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsleb00f48f.sys [1. 1. 2012 19:19 29904]
R2 ALIEHCD;ULi PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\AliEhci.sys [26. 1. 2011 20:14 83596]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29. 12. 2011 17:25 20568]
R2 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 8\DfSdkS.exe [30. 12. 2011 10:57 406016]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [22. 9. 2011 12:03 974944]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [31. 7. 2011 12:58 90112]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [29. 12. 2011 11:21 2984832]
R3 aliroothub;USB 2.0 Root Hub;c:\windows\system32\drivers\AliRtHub.sys [26. 1. 2011 20:14 5331]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [31. 7. 2011 12:59 27632]
R3 ULI5261;ULi Based Ethernet NT Driver;c:\windows\system32\drivers\ULILAN.SYS [26. 1. 2011 20:14 28160]
S1 MpKsl0291cfe2;MpKsl0291cfe2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6D0CF53E-1F76-4B6E-B77C-DF326FA67E8A}\MpKsl0291cfe2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6D0CF53E-1F76-4B6E-B77C-DF326FA67E8A}\MpKsl0291cfe2.sys [?]
S1 MpKsl09216346;MpKsl09216346;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl09216346.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl09216346.sys [?]
S1 MpKsl170033f7;MpKsl170033f7;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{4A2CB5F8-2CC7-421C-B551-781796EF498A}\MpKsl170033f7.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{4A2CB5F8-2CC7-421C-B551-781796EF498A}\MpKsl170033f7.sys [?]
S1 MpKsl198c1960;MpKsl198c1960;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl198c1960.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DD470124-A171-419F-AE37-4B6EF09A058F}\MpKsl198c1960.sys [?]
S1 MpKsl1d649da7;MpKsl1d649da7;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl1d649da7.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl1d649da7.sys [?]
S1 MpKsl39a2102d;MpKsl39a2102d;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{C0EE2217-583F-497D-948F-9D66450859B2}\MpKsl39a2102d.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{C0EE2217-583F-497D-948F-9D66450859B2}\MpKsl39a2102d.sys [?]
S1 MpKsl4a5c88d6;MpKsl4a5c88d6;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4a5c88d6.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4a5c88d6.sys [?]
S1 MpKsl4ab8ec4e;MpKsl4ab8ec4e;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BBDF0701-2968-4948-97E7-B8931527B410}\MpKsl4ab8ec4e.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BBDF0701-2968-4948-97E7-B8931527B410}\MpKsl4ab8ec4e.sys [?]
S1 MpKsl4ebe2678;MpKsl4ebe2678;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{16971267-EAA7-477B-99A5-0DBF6649D69C}\MpKsl4ebe2678.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{16971267-EAA7-477B-99A5-0DBF6649D69C}\MpKsl4ebe2678.sys [?]
S1 MpKsl4f3a2b56;MpKsl4f3a2b56;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4f3a2b56.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl4f3a2b56.sys [?]
S1 MpKsl50729e58;MpKsl50729e58;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{64403C45-BCED-43D3-96F0-206FD34ECF07}\MpKsl50729e58.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{64403C45-BCED-43D3-96F0-206FD34ECF07}\MpKsl50729e58.sys [?]
S1 MpKsl6d243d40;MpKsl6d243d40;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0A43367D-418B-43FE-AC29-FFCC4176BA81}\MpKsl6d243d40.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0A43367D-418B-43FE-AC29-FFCC4176BA81}\MpKsl6d243d40.sys [?]
S1 MpKsl6da53cd2;MpKsl6da53cd2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl6da53cd2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl6da53cd2.sys [?]
S1 MpKsl788c0a60;MpKsl788c0a60;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl788c0a60.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{0FFB68F0-09DB-4CE0-8B3D-63EE59AB2BF3}\MpKsl788c0a60.sys [?]
S1 MpKsl7a8c3fbd;MpKsl7a8c3fbd;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl7a8c3fbd.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl7a8c3fbd.sys [?]
S1 MpKsl805c9a21;MpKsl805c9a21;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl805c9a21.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{7CDA0556-32FA-4604-9190-F5F3557DDB16}\MpKsl805c9a21.sys [?]
S1 MpKsl9595b0f9;MpKsl9595b0f9;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A6ED3860-72AB-4BA7-BDC4-EBF38ED88229}\MpKsl9595b0f9.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A6ED3860-72AB-4BA7-BDC4-EBF38ED88229}\MpKsl9595b0f9.sys [?]
S1 MpKsl97cb5649;MpKsl97cb5649;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CC07DEDF-D087-4C01-B58B-2AEAF651B6A1}\MpKsl97cb5649.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CC07DEDF-D087-4C01-B58B-2AEAF651B6A1}\MpKsl97cb5649.sys [?]
S1 MpKsl9bbe3881;MpKsl9bbe3881;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl9bbe3881.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BB447E2D-62AA-4114-B6F0-9CBDBCD55A9D}\MpKsl9bbe3881.sys [?]
S1 MpKslbf9c73f3;MpKslbf9c73f3;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslbf9c73f3.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslbf9c73f3.sys [?]
S1 MpKsle85ea9d9;MpKsle85ea9d9;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF8A9E5C-8181-467C-AB3E-52E89B46799F}\MpKsle85ea9d9.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF8A9E5C-8181-467C-AB3E-52E89B46799F}\MpKsle85ea9d9.sys [?]
S1 MpKslff5f15b2;MpKslff5f15b2;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslff5f15b2.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{75555445-74B2-4212-8270-D7B3258FC677}\MpKslff5f15b2.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [31. 1. 2011 18:00 247096]
S3 aligp;USB Composite Device;c:\windows\system32\drivers\AliGP.sys [26. 1. 2011 20:14 10326]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14. 4. 2008 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLEB00F48F
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.119.113.244 217.119.113.245
FF - ProfilePath - c:\documents and settings\Andrej\Data aplikací\Mozilla\Firefox\Profiles\mrqnrq5s.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep: wrc@avast.com - c:\program files\AVAST Software\Avast\WebRep\FF
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: User Agent Switcher: {e968fc70-8f95-4ab9-9e79-304de2a71ee1} - %profile%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-HP OrderReminder - c:\program files\Hewlett-Packard\OrderReminder\uninstall\hpuninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-01 19:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(328)
c:\windows\system32\msi.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\cs-cz\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\cs-cz\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\TeamViewer\Version7\TeamViewer.exe
c:\windows\system32\wscntfy.exe
c:\program files\TeamViewer\Version7\tv_w32.exe
c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
**************************************************************************
.
Completion time: 2012-01-01 19:28:33 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-01 18:28
.
Pre-Run: Volných bajtů: 58 694 987 776
Post-Run: Volných bajtů: 58 796 945 408
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 80D7C5E67FE1FE359135295602DF2CFA