nefunkční prohlížení webu - kontrola logu z ComboFixu
Napsal: 13 bře 2012 13:16
zdravím, fest zavirovaný notebook už jakž takž dejchá, ale nefunguje internet (na DNS, i číselnou adresu seznam.cz si pingnu, ale když dám přímo ping www.seznam.cz, tak jí nepřeloží. combofix spravil nemožnost načtení služeb brána firewall/sdílení připojení k internetu.. díky morty
log z ComboFixu zde:
ComboFix 12-03-12.03 - msi 13.03.2012 12:50:00.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2815.2516 [GMT 1:00]
Spuštěný z: c:\documents and settings\msi\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB15443$
c:\windows\$NtUninstallKB15443$\18386424
c:\windows\$NtUninstallKB15443$\2572835574\@
c:\windows\$NtUninstallKB15443$\2572835574\L\zaamqxei
c:\windows\$NtUninstallKB15443$\2572835574\loader.tlb
c:\windows\$NtUninstallKB15443$\2572835574\U\@00000001
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000c0
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000cb
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000cf
c:\windows\$NtUninstallKB15443$\2572835574\U\@80000000
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000c0
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000cb
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000cf
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\msmqinst.log
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\4da0e206b95a810c.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\ce62216e390a6e65.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d61a9a23fc5ad19f.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\dds_log_trash.cmd
c:\windows\system32\StillCam.dll
c:\windows\system32\tmp25.tmp
c:\windows\system32\tmp26.tmp
.
c:\windows\system32\drivers\afd.sys chyběl.
Obnovena kopie z - c:\windows\system32\dllcache\afd.sys
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_6TO4
-------\Legacy_EMU10K1
-------\Legacy_NM
-------\Legacy_RADIOSVR
-------\Service_6to4
-------\Service_emu10k1
-------\Service_nm
-------\Service_radiosvr
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-13 do 2012-03-13 )))))))))))))))))))))))))))))))
.
.
2012-03-11 17:14 . 2001-10-24 11:24 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2012-03-11 17:13 . 2008-04-13 22:53 1041536 -c--a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2012-03-11 17:12 . 2001-10-24 10:48 634134 -c--a-w- c:\windows\system32\dllcache\el656ct5.sys
2012-03-11 17:11 . 2001-10-24 10:51 49182 -c--a-w- c:\windows\system32\dllcache\cem56n5.sys
2012-03-11 17:10 . 2008-04-14 07:51 377984 -c--a-w- c:\windows\system32\dllcache\ati2dvaa.dll
2012-03-10 19:15 . 2012-03-10 19:26 -------- d-----w- c:\documents and settings\Administrator
2012-03-10 17:30 . 2012-03-10 17:30 -------- d-----w- c:\documents and settings\msi\Data aplikací\Malwarebytes
2012-03-10 17:30 . 2012-03-10 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-10 17:30 . 2012-03-10 17:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-03-10 17:30 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-09 19:36 . 2012-03-09 19:36 -------- d-----w- c:\documents and settings\msi\Local Settings\Data aplikací\Ahead
2012-03-05 18:18 . 2012-03-05 18:18 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2012-03-04 20:49 . 2012-03-05 15:08 -------- d-sh--w- c:\documents and settings\msi\Local Settings\Data aplikací\995a5af6
2012-03-02 15:46 . 2012-03-02 15:46 -------- d-----r- c:\documents and settings\msi\Data aplikací\Brother
2012-02-21 17:45 . 2012-02-21 17:45 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-02-21 17:45 . 2012-02-21 17:45 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-02-21 17:45 . 2012-02-21 17:45 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-02-21 17:45 . 2012-02-21 17:45 45016 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-02-17 18:44 . 2012-02-17 18:44 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-15 16:03 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 16:03 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-13 18:36 . 2012-02-13 18:36 -------- d-----w- c:\documents and settings\All Users\Data aplikací\VST3 Presets
2012-02-13 17:46 . 2012-02-13 17:46 -------- d-----w- c:\program files\Common Files\Steinberg
2012-02-13 17:46 . 2012-02-13 17:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Steinberg
2012-02-13 17:44 . 2012-02-13 17:52 -------- d-----w- c:\documents and settings\msi\Data aplikací\Steinberg
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 07:50 . 2011-06-10 06:45 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 17:20 . 2008-04-14 05:45 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2008-04-14 06:52 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-17 19:42 . 2008-04-14 06:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2008-04-14 06:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-16 12:23 . 2008-04-14 05:50 385024 ------w- c:\windows\system32\html.iec
2012-02-21 17:45 . 2011-05-08 20:06 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
2011-04-01 03:10 351448 ------w- c:\progra~1\SITERA~1\SiteRank.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2011-4-3 745472]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-10-23 15:10 140568 ------w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-23 16:58 906648 ------w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2009-02-10 09:03 745472 ------r- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-10-30 13:05 77824 ------w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative KSRun Persistence Module]
2010-08-03 04:22 25600 ------r- c:\windows\system32\KSRun.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTAPR2]
2008-08-07 14:50 61546 ------w- c:\program files\Creative\Sound Blaster X-Fi Go Pro\Console Launcher 3\Entertainment Console\CTAPR2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 06:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-10-11 18:01 46368 ------w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-01-13 13:53 460872 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ------w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-05-08 17:28 13594624 ------w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-05-08 17:28 1650688 ------w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
2009-11-23 17:02 26624 ------w- c:\documents and settings\msi\Data aplikací\OETRN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-10-11 18:03 29984 ------w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-27 03:22 17567744 ------w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 07:03 210472 ------w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-10-23 15:05 2615624 ------w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00 90112 ------w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
2010-02-18 17:27 241789 ------w- c:\program files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TryAndDecideService"=2 (0x2)
"NVSvc"=2 (0x2)
"NitroReaderDriverReadSpool"=2 (0x2)
"MDM"=2 (0x2)
"MBAMService"=2 (0x2)
"idsvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"CTAudSvcService"=2 (0x2)
"Creative Media Toolbox 6 Licensing Service"=3 (0x3)
"Creative Audio Engine Licensing Service"=3 (0x3)
"avgwd"=2 (0x2)
"AVGIDSAgent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [24.11.2009 0:37 45344]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [24.11.2009 0:40 1684736]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [25.2.2011 8:31 1210624]
S3 ksaudfl;ksaudfl;c:\windows\system32\drivers\ksaudfl.sys [25.2.2011 8:31 2016640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10.3.2012 18:30 20464]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys --> c:\windows\system32\Drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [25.2.2011 8:29 79360]
S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [25.2.2011 8:49 79360]
S4 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.4.2011 17:22 136176]
S4 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.4.2011 17:22 136176]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10.3.2012 18:30 652360]
S4 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [14.1.2011 12:35 196912]
.
NETSVCS MUSÍ BÝT OPRAVENY - dosavadní položky jsou:
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Messenger
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
S3GIGP
sdcoreservice
autocomplete
ezplay
EIO
pdlncbas
ipodservice
G400DH
easdrv
epstnt01
WmHidLo
w810obex
bthenum
ctxhttp
hamachi
rtl8023
zebrmdm
comhost
atitunep
IASJet
arrayssl_vpn_service3,0,1,9
WmXlCore
se44mgmt
SNC
anbmservice
ntrtscan
dptrackerd
sfsync04
was
bc_ip_f
bwmservice
roxupnprenderer
FGDSCSI
SrvcTPIOMngr
pcradminserver
CTERFXFX.DLL
cpqvcagent
cpqdmi
tmesbs32
pavdrv
elbydelay
pcx1unic
U2SP
fsssvc
FontCache3.0.0.0.
pxfhbus
nalntservice
apache
oracle_load_balancer_60_client-forms6i
vzupsvc
aawservice
NWSLP
StMp3Rec
bc_filter
VirtualCam
netdevio
odclientservice
LHidFilt
W2acehid
U81xbus
dpc_srv_webcast
pdlndlpb
w200mgmt
PGPwded
3comtftp
sandradatasrv
zpjobq
s117unic
sonytvc
TVALG
ccpwdsvc
JavaQuickStarterService
tng-dts
Accelerometer
vmware
SprintRcAppSvc
imagedrv
FETNDISB
Anydlc
ntsyslog
TeamViewer
qkbfiltr
proxyhostservice
smcirda
RTLE8023xp
artourservice
SRS_SSCFilter
nisvcloc
bcoreusb
mferkdk
kl1
Via4in1
pdlnacom
CAMFLT
PAR1284
lemsgt
se59mdfl
symsnap
awlegacy
uclauncherservice
UimBus
mpfp
PSSdk21
defwatch
tvicport
FlexBios
DirectUpdate
TuneUp.Defrag
quickhealfirewall
protectionservice
ATIBTXBAR
incdpass
upperdev
puscsrvc
ksthunk
logonsvcid
cpqnicmgmt
dladresm
ASMMAP
wceusbsh
mcdbus
zppinger
statusagent
bdfdll
adpu320
clsched
efs
XUIF
nmwcdcm
mfetdik
ESDCR
remotelyanywhere
hidgame
AmdIde
atkdisplf
aswmon2
scdemu
ma763004
irsir
AMDPCI
atiavaiw
fingrd32
{d31a0762-0ceb-444e-acff-b049a1f6fe91}
dcpflics
hdthermal
ntiopnp
TMMEmu
rtl8029
LCcfltr
RivaTuner32
SimpTcp
z525mdfl
sansaservice
blueservice
adminserver
rismxdp
hpzipr12
BRGSp50
unrealircd
PTproct
s117mdfl
dtscsi
rchost
tbaspi
ithsgt
SPFDRV
dlacdbhm
webupdate
hpwirelessmgr
trackcam4
rkhdrv31
UlSata
HSFHWALI
SiSRaid2
epgspooler
msftpsvc
s125bus
issuser
cvspydr2
nscirda
clmtomcatstartersvc
siskp
STV680m
cobbmservice
sony_ssm.sys
s116mdm
SaiMini
CTMSHD
apache2
cacheserver
vaiomediaplatform-integratedserver-appserver
AFGSp50
ICAM5USB
mirrorv3
guardian2
Machnm32
InCDsrvR
belmonitorservice
zfdwm
tapvpn
transactional
DevUpper
gdihook5
msvad_simple
crystaloutputfileserver
PTDCVsp
mgactrl
pavfnsvr
p2pgasvc
ultra66
mqdmmdfl
caili
Rawwan
zebrsce
wpshelper
enecbpth
tifm21
lxcd_device
procmon10
ovmsmaccessmanager
palmusbd
LVVI500A
snmptrapdservice
dcevt32
ni_nic
Wuser32
pciSd
cygserver
backupexecjobengine
xpadminserver
NWDHCP
pdlnepkt
viagfx
Evian
FVNETusb
bdftdif
pavatscheduler
avg7alrt
VAIOMediaPlatform-VideoServer-HTTP
wdm_au8820
SE2Bobex
milshieldcleaner
el90xbc
M2500
db2ntsecserver
netrcacm
spmd
cq_mem
tfsndres
bcm4sbxp
wampapache
emproxy
erecoveryservice
FsVga
pdfcreatormessages
awservice
IWCA
NetMsmqActivator
ixiaendpoint
gotomypc
EMCFILT
n558
dlapoolm
mfesmfk
MTC0001_ESB
MREMP50
w29n51
vetmsgnt
AppnBase
carboncopy32
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
TrkWks
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
helpsvc
WmdmPmSN
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-25 16:22]
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-25 16:22]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.inbox.com/homepage.aspx?tbid=80093&lng=cs
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WebIE.dll
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A2861B4-74C7-46F8-9923-5D151BA79BED}: NameServer = 193.165.192.9
FF - ProfilePath - c:\documents and settings\msi\Data aplikací\Mozilla\Firefox\Profiles\gisd5287.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
MSConfigStartUp-ICQ - c:\program files\ICQ7.2\ICQ.exe
MSConfigStartUp-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-13 12:56
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(2384)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\Brother\Brmfcmon\BrMfcmon.exe
.
**************************************************************************
.
Celkový čas: 2012-03-13 12:59:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-03-13 11:59
.
Před spuštěním: Volných bajtů: 115 397 320 704
Po spuštění: Volných bajtů: 115 580 366 848
.
- - End Of File - - 1FB1AA6C709913C2D32FB307D2F90B43
log z ComboFixu zde:
ComboFix 12-03-12.03 - msi 13.03.2012 12:50:00.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2815.2516 [GMT 1:00]
Spuštěný z: c:\documents and settings\msi\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB15443$
c:\windows\$NtUninstallKB15443$\18386424
c:\windows\$NtUninstallKB15443$\2572835574\@
c:\windows\$NtUninstallKB15443$\2572835574\L\zaamqxei
c:\windows\$NtUninstallKB15443$\2572835574\loader.tlb
c:\windows\$NtUninstallKB15443$\2572835574\U\@00000001
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000c0
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000cb
c:\windows\$NtUninstallKB15443$\2572835574\U\@000000cf
c:\windows\$NtUninstallKB15443$\2572835574\U\@80000000
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000c0
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000cb
c:\windows\$NtUninstallKB15443$\2572835574\U\@800000cf
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\msmqinst.log
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\4da0e206b95a810c.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\ce62216e390a6e65.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d61a9a23fc5ad19f.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\dds_log_trash.cmd
c:\windows\system32\StillCam.dll
c:\windows\system32\tmp25.tmp
c:\windows\system32\tmp26.tmp
.
c:\windows\system32\drivers\afd.sys chyběl.
Obnovena kopie z - c:\windows\system32\dllcache\afd.sys
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_6TO4
-------\Legacy_EMU10K1
-------\Legacy_NM
-------\Legacy_RADIOSVR
-------\Service_6to4
-------\Service_emu10k1
-------\Service_nm
-------\Service_radiosvr
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-13 do 2012-03-13 )))))))))))))))))))))))))))))))
.
.
2012-03-11 17:14 . 2001-10-24 11:24 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2012-03-11 17:13 . 2008-04-13 22:53 1041536 -c--a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2012-03-11 17:12 . 2001-10-24 10:48 634134 -c--a-w- c:\windows\system32\dllcache\el656ct5.sys
2012-03-11 17:11 . 2001-10-24 10:51 49182 -c--a-w- c:\windows\system32\dllcache\cem56n5.sys
2012-03-11 17:10 . 2008-04-14 07:51 377984 -c--a-w- c:\windows\system32\dllcache\ati2dvaa.dll
2012-03-10 19:15 . 2012-03-10 19:26 -------- d-----w- c:\documents and settings\Administrator
2012-03-10 17:30 . 2012-03-10 17:30 -------- d-----w- c:\documents and settings\msi\Data aplikací\Malwarebytes
2012-03-10 17:30 . 2012-03-10 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-10 17:30 . 2012-03-10 17:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-03-10 17:30 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-09 19:36 . 2012-03-09 19:36 -------- d-----w- c:\documents and settings\msi\Local Settings\Data aplikací\Ahead
2012-03-05 18:18 . 2012-03-05 18:18 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2012-03-04 20:49 . 2012-03-05 15:08 -------- d-sh--w- c:\documents and settings\msi\Local Settings\Data aplikací\995a5af6
2012-03-02 15:46 . 2012-03-02 15:46 -------- d-----r- c:\documents and settings\msi\Data aplikací\Brother
2012-02-21 17:45 . 2012-02-21 17:45 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-02-21 17:45 . 2012-02-21 17:45 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-02-21 17:45 . 2012-02-21 17:45 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-02-21 17:45 . 2012-02-21 17:45 45016 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-02-17 18:44 . 2012-02-17 18:44 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-15 16:03 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 16:03 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-13 18:36 . 2012-02-13 18:36 -------- d-----w- c:\documents and settings\All Users\Data aplikací\VST3 Presets
2012-02-13 17:46 . 2012-02-13 17:46 -------- d-----w- c:\program files\Common Files\Steinberg
2012-02-13 17:46 . 2012-02-13 17:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Steinberg
2012-02-13 17:44 . 2012-02-13 17:52 -------- d-----w- c:\documents and settings\msi\Data aplikací\Steinberg
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 07:50 . 2011-06-10 06:45 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 17:20 . 2008-04-14 05:45 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2008-04-14 06:52 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-17 19:42 . 2008-04-14 06:52 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2008-04-14 06:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-16 12:23 . 2008-04-14 05:50 385024 ------w- c:\windows\system32\html.iec
2012-02-21 17:45 . 2011-05-08 20:06 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
2011-04-01 03:10 351448 ------w- c:\progra~1\SITERA~1\SiteRank.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2011-4-3 745472]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-10-23 15:10 140568 ------w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-23 16:58 906648 ------w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2009-02-10 09:03 745472 ------r- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-10-30 13:05 77824 ------w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative KSRun Persistence Module]
2010-08-03 04:22 25600 ------r- c:\windows\system32\KSRun.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTAPR2]
2008-08-07 14:50 61546 ------w- c:\program files\Creative\Sound Blaster X-Fi Go Pro\Console Launcher 3\Entertainment Console\CTAPR2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 06:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-10-11 18:01 46368 ------w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-01-13 13:53 460872 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ------w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-05-08 17:28 13594624 ------w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-05-08 17:28 1650688 ------w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
2009-11-23 17:02 26624 ------w- c:\documents and settings\msi\Data aplikací\OETRN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-10-11 18:03 29984 ------w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-27 03:22 17567744 ------w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 07:03 210472 ------w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-10-23 15:05 2615624 ------w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00 90112 ------w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
2010-02-18 17:27 241789 ------w- c:\program files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TryAndDecideService"=2 (0x2)
"NVSvc"=2 (0x2)
"NitroReaderDriverReadSpool"=2 (0x2)
"MDM"=2 (0x2)
"MBAMService"=2 (0x2)
"idsvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"CTAudSvcService"=2 (0x2)
"Creative Media Toolbox 6 Licensing Service"=3 (0x3)
"Creative Audio Engine Licensing Service"=3 (0x3)
"avgwd"=2 (0x2)
"AVGIDSAgent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [24.11.2009 0:37 45344]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [24.11.2009 0:40 1684736]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [25.2.2011 8:31 1210624]
S3 ksaudfl;ksaudfl;c:\windows\system32\drivers\ksaudfl.sys [25.2.2011 8:31 2016640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10.3.2012 18:30 20464]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys --> c:\windows\system32\Drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [25.2.2011 8:29 79360]
S4 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [25.2.2011 8:49 79360]
S4 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.4.2011 17:22 136176]
S4 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.4.2011 17:22 136176]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10.3.2012 18:30 652360]
S4 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [14.1.2011 12:35 196912]
.
NETSVCS MUSÍ BÝT OPRAVENY - dosavadní položky jsou:
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Messenger
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
S3GIGP
sdcoreservice
autocomplete
ezplay
EIO
pdlncbas
ipodservice
G400DH
easdrv
epstnt01
WmHidLo
w810obex
bthenum
ctxhttp
hamachi
rtl8023
zebrmdm
comhost
atitunep
IASJet
arrayssl_vpn_service3,0,1,9
WmXlCore
se44mgmt
SNC
anbmservice
ntrtscan
dptrackerd
sfsync04
was
bc_ip_f
bwmservice
roxupnprenderer
FGDSCSI
SrvcTPIOMngr
pcradminserver
CTERFXFX.DLL
cpqvcagent
cpqdmi
tmesbs32
pavdrv
elbydelay
pcx1unic
U2SP
fsssvc
FontCache3.0.0.0.
pxfhbus
nalntservice
apache
oracle_load_balancer_60_client-forms6i
vzupsvc
aawservice
NWSLP
StMp3Rec
bc_filter
VirtualCam
netdevio
odclientservice
LHidFilt
W2acehid
U81xbus
dpc_srv_webcast
pdlndlpb
w200mgmt
PGPwded
3comtftp
sandradatasrv
zpjobq
s117unic
sonytvc
TVALG
ccpwdsvc
JavaQuickStarterService
tng-dts
Accelerometer
vmware
SprintRcAppSvc
imagedrv
FETNDISB
Anydlc
ntsyslog
TeamViewer
qkbfiltr
proxyhostservice
smcirda
RTLE8023xp
artourservice
SRS_SSCFilter
nisvcloc
bcoreusb
mferkdk
kl1
Via4in1
pdlnacom
CAMFLT
PAR1284
lemsgt
se59mdfl
symsnap
awlegacy
uclauncherservice
UimBus
mpfp
PSSdk21
defwatch
tvicport
FlexBios
DirectUpdate
TuneUp.Defrag
quickhealfirewall
protectionservice
ATIBTXBAR
incdpass
upperdev
puscsrvc
ksthunk
logonsvcid
cpqnicmgmt
dladresm
ASMMAP
wceusbsh
mcdbus
zppinger
statusagent
bdfdll
adpu320
clsched
efs
XUIF
nmwcdcm
mfetdik
ESDCR
remotelyanywhere
hidgame
AmdIde
atkdisplf
aswmon2
scdemu
ma763004
irsir
AMDPCI
atiavaiw
fingrd32
{d31a0762-0ceb-444e-acff-b049a1f6fe91}
dcpflics
hdthermal
ntiopnp
TMMEmu
rtl8029
LCcfltr
RivaTuner32
SimpTcp
z525mdfl
sansaservice
blueservice
adminserver
rismxdp
hpzipr12
BRGSp50
unrealircd
PTproct
s117mdfl
dtscsi
rchost
tbaspi
ithsgt
SPFDRV
dlacdbhm
webupdate
hpwirelessmgr
trackcam4
rkhdrv31
UlSata
HSFHWALI
SiSRaid2
epgspooler
msftpsvc
s125bus
issuser
cvspydr2
nscirda
clmtomcatstartersvc
siskp
STV680m
cobbmservice
sony_ssm.sys
s116mdm
SaiMini
CTMSHD
apache2
cacheserver
vaiomediaplatform-integratedserver-appserver
AFGSp50
ICAM5USB
mirrorv3
guardian2
Machnm32
InCDsrvR
belmonitorservice
zfdwm
tapvpn
transactional
DevUpper
gdihook5
msvad_simple
crystaloutputfileserver
PTDCVsp
mgactrl
pavfnsvr
p2pgasvc
ultra66
mqdmmdfl
caili
Rawwan
zebrsce
wpshelper
enecbpth
tifm21
lxcd_device
procmon10
ovmsmaccessmanager
palmusbd
LVVI500A
snmptrapdservice
dcevt32
ni_nic
Wuser32
pciSd
cygserver
backupexecjobengine
xpadminserver
NWDHCP
pdlnepkt
viagfx
Evian
FVNETusb
bdftdif
pavatscheduler
avg7alrt
VAIOMediaPlatform-VideoServer-HTTP
wdm_au8820
SE2Bobex
milshieldcleaner
el90xbc
M2500
db2ntsecserver
netrcacm
spmd
cq_mem
tfsndres
bcm4sbxp
wampapache
emproxy
erecoveryservice
FsVga
pdfcreatormessages
awservice
IWCA
NetMsmqActivator
ixiaendpoint
gotomypc
EMCFILT
n558
dlapoolm
mfesmfk
MTC0001_ESB
MREMP50
w29n51
vetmsgnt
AppnBase
carboncopy32
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
TrkWks
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
helpsvc
WmdmPmSN
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-25 16:22]
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-25 16:22]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.inbox.com/homepage.aspx?tbid=80093&lng=cs
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WebIE.dll
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A2861B4-74C7-46F8-9923-5D151BA79BED}: NameServer = 193.165.192.9
FF - ProfilePath - c:\documents and settings\msi\Data aplikací\Mozilla\Firefox\Profiles\gisd5287.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
MSConfigStartUp-ICQ - c:\program files\ICQ7.2\ICQ.exe
MSConfigStartUp-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-13 12:56
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(2384)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\Brother\Brmfcmon\BrMfcmon.exe
.
**************************************************************************
.
Celkový čas: 2012-03-13 12:59:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-03-13 11:59
.
Před spuštěním: Volných bajtů: 115 397 320 704
Po spuštění: Volných bajtů: 115 580 366 848
.
- - End Of File - - 1FB1AA6C709913C2D32FB307D2F90B43