Dorkbot.B
Napsal: 04 říj 2012 10:47
Ahoj snažím se kámošovi odvirovat PC, chytl něco na chatu Skypu a nejde se dostat na stránky eset.cz, prosím o pomoc.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Uživatel at 2012-10-04 11:44:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 56 GB (73%) free of 76 GB
Total RAM: 959 MB (49% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{AE69C157-92B8-484D-A4FB-1276CBE2F06C}.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\uvmd034b.default
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.278 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-17 7307264]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-17 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-04 90112]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2012-03-07 3117344]
"OutlookFriend"=C:\WINDOWS\system32\outinst.exe [2005-02-25 29184]
"PDFPrint"=C:\Program Files\PDF24\pdf24.exe [2012-05-22 160872]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Trans"=C:\Program Files\Trans\trans.exe [2012-04-30 3552768]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Trans\trans.exe"="C:\Program Files\Trans\trans.exe:*:Enabled:Trans instant messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-10-04 11:44:36 ----D---- C:\rsit
2012-10-04 11:44:36 ----D---- C:\Program Files\trend micro
2012-10-04 11:42:48 ----SHD---- C:\RECYCLER
2012-10-04 10:41:29 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\1.exe
2012-10-04 10:21:13 ----D---- C:\WINDOWS\temp
2012-10-04 10:21:09 ----A---- C:\ComboFix.txt
2012-10-04 09:51:22 ----A---- C:\WINDOWS\zip.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWSC.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWREG.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\sed.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\PEV.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\NIRCMD.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\MBR.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\grep.exe
2012-10-04 09:50:56 ----D---- C:\Qoobox
2012-10-04 09:48:44 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\93.exe
2012-10-04 09:48:32 ----D---- C:\WINDOWS\erdnt
2012-10-04 09:35:18 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\8A.exe
2012-10-04 09:32:20 ----D---- C:\Program Files\CCleaner
2012-10-04 09:20:55 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\81.exe
2012-10-04 08:54:36 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\2.exe
2012-10-03 11:22:48 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\11CA.exe
2012-10-03 02:11:41 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10F0.exe
2012-10-03 01:51:30 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EF.exe
2012-10-03 01:29:41 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EE.exe
2012-10-03 01:03:09 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10ED.exe
2012-10-03 00:41:26 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EC.exe
2012-10-03 00:02:15 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EB.exe
2012-10-02 23:38:03 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EA.exe
2012-10-02 23:16:42 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E9.exe
2012-10-02 20:39:39 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E2.exe
2012-10-02 20:03:07 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E1.exe
2012-10-02 19:49:45 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E0.exe
2012-10-02 19:22:46 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10DF.exe
2012-10-02 18:57:57 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10DE.exe
2012-10-02 16:01:03 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\5B9.exe
2012-10-02 15:45:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-10-02 15:31:05 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\55B.exe
2012-10-02 15:01:07 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\3ED.exe
2012-10-02 14:55:45 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\3E1.exe
2012-09-12 13:27:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$
2012-09-11 09:51:35 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2012-10-04 11:44:36 ----RD---- C:\Program Files
2012-10-04 11:42:48 ----D---- C:\WINDOWS
2012-10-04 11:37:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-10-04 11:37:09 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-10-04 11:20:05 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-04 10:40:06 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-10-04 10:28:29 ----D---- C:\Program Files\Trans
2012-10-04 10:21:16 ----D---- C:\WINDOWS\system32\drivers
2012-10-04 10:16:31 ----A---- C:\WINDOWS\system.ini
2012-10-04 10:16:24 ----D---- C:\WINDOWS\system32\drivers\etc
2012-10-04 10:14:57 ----D---- C:\WINDOWS\system32\config
2012-10-04 10:00:18 ----D---- C:\WINDOWS\system32
2012-10-04 10:00:17 ----D---- C:\WINDOWS\AppPatch
2012-10-04 10:00:05 ----D---- C:\Program Files\Common Files
2012-10-04 09:36:07 ----D---- C:\WINDOWS\Minidump
2012-10-04 09:36:07 ----D---- C:\WINDOWS\Debug
2012-10-04 09:34:43 ----SD---- C:\WINDOWS\Tasks
2012-10-04 09:34:43 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-10-04 09:32:20 ----D---- C:\WINDOWS\Prefetch
2012-10-04 08:54:27 ----HD---- C:\WINDOWS\inf
2012-10-03 09:57:14 ----SHD---- C:\WINDOWS\Installer
2012-10-02 16:18:19 ----SH---- C:\boot.ini
2012-10-02 16:08:12 ----D---- C:\Program Files\ESET
2012-10-02 15:59:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-10-02 15:59:10 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Skype
2012-09-25 07:38:22 ----D---- C:\Program Files\Internet Explorer
2012-09-24 15:44:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-09-24 15:43:39 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-12 13:36:08 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-12 13:26:01 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-08-12 98432]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\drivers\nvatabus.sys [2008-12-10 100736]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2012-03-14 160816]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2012-03-14 104160]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-04 3797632]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-17 3530880]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CFcatchme;CFcatchme; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\CFcatchme.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2012-03-07 913144]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-17 131139]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-04 250288]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-11 114144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Uživatel at 2012-10-04 11:44:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 56 GB (73%) free of 76 GB
Total RAM: 959 MB (49% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{AE69C157-92B8-484D-A4FB-1276CBE2F06C}.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\uvmd034b.default
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.278 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-17 7307264]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-17 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-04 90112]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2012-03-07 3117344]
"OutlookFriend"=C:\WINDOWS\system32\outinst.exe [2005-02-25 29184]
"PDFPrint"=C:\Program Files\PDF24\pdf24.exe [2012-05-22 160872]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Trans"=C:\Program Files\Trans\trans.exe [2012-04-30 3552768]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Trans\trans.exe"="C:\Program Files\Trans\trans.exe:*:Enabled:Trans instant messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-10-04 11:44:36 ----D---- C:\rsit
2012-10-04 11:44:36 ----D---- C:\Program Files\trend micro
2012-10-04 11:42:48 ----SHD---- C:\RECYCLER
2012-10-04 10:41:29 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\1.exe
2012-10-04 10:21:13 ----D---- C:\WINDOWS\temp
2012-10-04 10:21:09 ----A---- C:\ComboFix.txt
2012-10-04 09:51:22 ----A---- C:\WINDOWS\zip.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWSC.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\SWREG.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\sed.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\PEV.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\NIRCMD.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\MBR.exe
2012-10-04 09:51:22 ----A---- C:\WINDOWS\grep.exe
2012-10-04 09:50:56 ----D---- C:\Qoobox
2012-10-04 09:48:44 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\93.exe
2012-10-04 09:48:32 ----D---- C:\WINDOWS\erdnt
2012-10-04 09:35:18 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\8A.exe
2012-10-04 09:32:20 ----D---- C:\Program Files\CCleaner
2012-10-04 09:20:55 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\81.exe
2012-10-04 08:54:36 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\2.exe
2012-10-03 11:22:48 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\11CA.exe
2012-10-03 02:11:41 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10F0.exe
2012-10-03 01:51:30 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EF.exe
2012-10-03 01:29:41 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EE.exe
2012-10-03 01:03:09 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10ED.exe
2012-10-03 00:41:26 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EC.exe
2012-10-03 00:02:15 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EB.exe
2012-10-02 23:38:03 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10EA.exe
2012-10-02 23:16:42 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E9.exe
2012-10-02 20:39:39 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E2.exe
2012-10-02 20:03:07 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E1.exe
2012-10-02 19:49:45 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10E0.exe
2012-10-02 19:22:46 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10DF.exe
2012-10-02 18:57:57 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\10DE.exe
2012-10-02 16:01:03 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\5B9.exe
2012-10-02 15:45:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-10-02 15:31:05 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\55B.exe
2012-10-02 15:01:07 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\3ED.exe
2012-10-02 14:55:45 ----A---- C:\Documents and Settings\Uživatel\Data aplikací\3E1.exe
2012-09-12 13:27:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$
2012-09-11 09:51:35 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2012-10-04 11:44:36 ----RD---- C:\Program Files
2012-10-04 11:42:48 ----D---- C:\WINDOWS
2012-10-04 11:37:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-10-04 11:37:09 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-10-04 11:20:05 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-04 10:40:06 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-10-04 10:28:29 ----D---- C:\Program Files\Trans
2012-10-04 10:21:16 ----D---- C:\WINDOWS\system32\drivers
2012-10-04 10:16:31 ----A---- C:\WINDOWS\system.ini
2012-10-04 10:16:24 ----D---- C:\WINDOWS\system32\drivers\etc
2012-10-04 10:14:57 ----D---- C:\WINDOWS\system32\config
2012-10-04 10:00:18 ----D---- C:\WINDOWS\system32
2012-10-04 10:00:17 ----D---- C:\WINDOWS\AppPatch
2012-10-04 10:00:05 ----D---- C:\Program Files\Common Files
2012-10-04 09:36:07 ----D---- C:\WINDOWS\Minidump
2012-10-04 09:36:07 ----D---- C:\WINDOWS\Debug
2012-10-04 09:34:43 ----SD---- C:\WINDOWS\Tasks
2012-10-04 09:34:43 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-10-04 09:32:20 ----D---- C:\WINDOWS\Prefetch
2012-10-04 08:54:27 ----HD---- C:\WINDOWS\inf
2012-10-03 09:57:14 ----SHD---- C:\WINDOWS\Installer
2012-10-02 16:18:19 ----SH---- C:\boot.ini
2012-10-02 16:08:12 ----D---- C:\Program Files\ESET
2012-10-02 15:59:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-10-02 15:59:10 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Skype
2012-09-25 07:38:22 ----D---- C:\Program Files\Internet Explorer
2012-09-24 15:44:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-09-24 15:43:39 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-12 13:36:08 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-12 13:26:01 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-08-12 98432]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\drivers\nvatabus.sys [2008-12-10 100736]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2012-03-14 160816]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2012-03-14 104160]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-04 3797632]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-17 3530880]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CFcatchme;CFcatchme; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\CFcatchme.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2012-03-07 913144]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-17 131139]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-04 250288]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-11 114144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
-----------------EOF-----------------