Změna koncovky souboru na Flash disku na .Ink
Napsal: 07 čer 2016 11:49
Zdravím, mám tento problém . Procetl jsem postup u stejného tématu a provedl rkill.exe a Combofix.
Prosím o kontrolu všech txt. CHtěl jsem poslat jako přílohu,a le nelze poslat koncovku txt, omlouvam se , ale nejsem vyloženě IT typ.
USB fix :
############################## | UsbFix V 8.247 | [Research]
User: Satek (Administrator) # KVIK
Updated 25/05/2016 by SOSVirus
Started at 09:56:34 | 07/06/2016
Website : https://www.usb-antivirus.com/
Tutorial : https://www.usb-antivirus.com/tutorial/
Support : http://www.sosvirus.org/
Live detection : http://www.sosmalware.com/usbfix/
Contact : https://www.usb-antivirus.com/contact/
################## | System information |
CPU: Intel(R) Pentium(R) 4 CPU 3.40GHz
RAM -> [Total : 2047 Mo | Free : 1576 Mo]
Boot: Normal boot
OS: Microsoft Windows XP (5.1.2600 32-Bit) Service Pack 3
WB: Internet Explorer : 8.00.6001.18702
WB: Mozilla Firefox : 46.0.1
################## | Security Information |
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
################## | Disk Information |
C:\ (%SystemDrive%) -> Fixed disk # 56 Gb (11 Gb free - 20%) [] # NTFS
D:\ -> Fixed disk # 93 Gb (12 Gb free - 13%) [Data] # NTFS
H:\ -> Removable disk # 7 Gb (2 Gb free - 33%) [KINGSTON] # FAT32
L:\ -> Removable disk # 4 Gb (4 Gb free - 100%) [STORE N GO] # FAT32
################## | Startup |
F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
04 - HKCU\..\Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
04 - HKCU\..\Run : [SetDefaultMIDI] MIDIDef.exe
04 - HKCU\..\Run : [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - HKLM\..\Run : [CTSysVol] C:\Program Files\Creative\SB5.1 VX\Surround Mixer\CTSysVol.exe /r
04 - HKLM\..\Run : [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
04 - HKLM\..\Run : [igfxtray] C:\WINDOWS\system32\igfxtray.exe
04 - HKLM\..\Run : [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
04 - HKLM\..\Run : [igfxpers] C:\WINDOWS\system32\igfxpers.exe
04 - HKLM\..\Run : [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
04 - HKLM\..\Run : [Gaming mouse] C:\Program Files\TESORO Gaming\SHRIKE Gaming Mouse\mousehid.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
04 - HKLM\..\Run : [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
04 - HKLM\..\Run : [BF2Hub Client] C:\Program Files\BF2Hub Client\bf2hub.exe
04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [SetDefaultMIDI] MIDIDef.exe
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04GS - Microsoft Office.lnk : C:\Program Files\Microsoft Office\Office10\OSA.EXE
################## | Generic Research |
Found! H:\tmp465C.tmp.vbs
Found! L:\tmp465C.tmp.vbs
Found! H:\BOOTEX.lnk
Found! H:\2.lnk
Found! H:\FOUND.000.lnk
Found! H:\Bojová Technika.lnk
Found! H:\Odbaveni-RC1743079.lnk
Found! H:\Counter-Strike 1.6.lnk
Found! H:\Výživa F-sport.lnk
Found! H:\15_OKRESNI_PREBOR_SVADBA.lnk
Found! H:\.minecraft.lnk
Found! H:\System Volume Information.lnk
Found! H:\The KMPlayer.lnk
Found! H:\Rotaxmame.lnk
Found! H:\09_OKRESNI_PREBOR_NA VAHU.lnk
Found! H:\08_OKRESNI_PREBOR_SCHUZE.lnk
Found! H:\07_OKRESNI_PREBOR_KOPACAK.lnk
Found! H:\05_OKRESNI_PREBOR_FORBES.lnk
Found! H:\02_OKRESNI_PREBOR_NABOR.lnk
Found! H:\01_OKRESNI_PREBOR_POHREB.lnk
Found! L:\Denní příjem kalorií.lnk
Found! L:\NICKY Rotax.lnk
Found! L:\P1020896.lnk
Found! C:\Documents and Settings\Satek\Local Settings\Temp\tmp465C.tmp.vbs
Analysed in 157.3 seconds
################## | E.O.F | http://www.sosvirus.net/ | https://www.usb-antivirus.com/ |
rkill :
Rkill 2.8.4 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 06/07/2016 12:03:34 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Reparse Point/Junctions Found (Most likely legitimate)!
* C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]
* C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
209.250.2.163 battlefield2.ms1.gamespy.com
209.250.2.163 battlefield2.ms2.gamespy.com
209.250.2.163 battlefield2.ms3.gamespy.com
209.250.2.163 battlefield2.ms4.gamespy.com
209.250.2.163 battlefield2.ms5.gamespy.com
209.250.2.163 battlefield2.ms6.gamespy.com
209.250.2.163 battlefield2.ms7.gamespy.com
209.250.2.163 battlefield2.ms8.gamespy.com
209.250.2.163 battlefield2.ms9.gamespy.com
209.250.2.163 battlefield2.ms10.gamespy.com
209.250.2.163 battlefield2.ms11.gamespy.com
209.250.2.163 battlefield2.ms12.gamespy.com
209.250.2.163 battlefield2.ms13.gamespy.com
209.250.2.163 battlefield2.ms15.gamespy.com
209.250.2.163 battlefield2.ms16.gamespy.com
209.250.2.163 battlefield2.ms17.gamespy.com
209.250.2.163 battlefield2.ms18.gamespy.com
209.250.2.163 battlefield2.ms19.gamespy.com
209.250.2.163 battlefield2.ms20.gamespy.com
20 out of 48 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 06/07/2016 12:04:09 PM
Execution time: 0 hours(s), 0 minute(s), and 34 seconds(s)
Combofix :
ComboFix 16-06-01.01 - Satek 07.06.2016 12:08:07.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1561 [GMT 2:00]
Spuštěný z: d:\upload\ComboFix.exe
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Satek\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\system32\SET1409.tmp
c:\windows\system32\tmp317.tmp
c:\windows\system32\tmp318.tmp
c:\windows\system32\tmp59A8.tmp
c:\windows\system32\tmp59A9.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-05-07 do 2016-06-07 )))))))))))))))))))))))))))))))
.
.
2016-06-07 09:55 . 2016-06-07 09:55 -------- d--h--w- c:\windows\PIF
2016-06-07 07:54 . 2016-06-07 07:55 -------- d-----w- C:\UsbFix
2016-06-07 07:32 . 2016-06-07 07:32 -------- d-----w- c:\windows\system32\wbem\Repository
2016-06-06 12:19 . 2016-06-07 07:31 -------- d-----w- c:\program files\Ask.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-06-01 17:59 . 2013-05-05 13:19 138992 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2016-06-01 17:59 . 2013-05-05 13:19 281152 ----a-w- c:\windows\system32\PnkBstrB.exe
2016-06-01 17:59 . 2010-07-26 19:04 281152 ----a-w- c:\windows\system32\PnkBstrB.xtr
2016-05-31 18:35 . 2013-05-05 13:19 281152 ----a-w- c:\windows\system32\PnkBstrB.ex0
2016-05-12 19:10 . 2012-07-23 09:06 797376 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-05-12 19:10 . 2011-12-30 07:38 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-24 94208]
"SetDefaultMIDI"="MIDIDef.exe" [2002-12-03 49152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SB5.1 VX\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-03-13 75048]
"Gaming mouse"="c:\program files\TESORO Gaming\SHRIKE Gaming Mouse\mousehid.exe" [2012-07-06 289280]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-05-08 959904]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-07 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"BF2Hub Client"="c:\program files\BF2Hub Client\bf2hub.exe" [2015-12-19 1927680]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 115440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2014-10-31 10:53 85864 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-05-08 13:48 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
2013-06-04 23:01 4489472 ----a-w- c:\documents and settings\Satek\Local Settings\Data aplikací\Akamai\netsession_win.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BF2Hub Client]
2015-12-19 18:09 1927680 ----a-w- c:\program files\BF2Hub Client\bf2hub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 15:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-07-09 14:24 13923432 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-07-09 14:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2011-06-16 13:21 1500160 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
2010-02-02 23:08 87336 ------w- c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 12:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2015-09-26 13:38 6815512 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\--- GAMES ---\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Satek\\Local Settings\\Data aplikací\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\EA Games\\Battlefield 2\\BF2.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\EA Games\\Battlefield 2\\BF2RG.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\bin\\steamwebhelper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [11.6.2010 20:16 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [11.6.2010 20:16 5248]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.2.2010 12:30 691696]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [20.3.2013 17:02 21576]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [11.10.2013 0:54 142648]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2012/02/12 19:29];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [13.3.2010 13:58 87536]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [?]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\d:\--- games ---\Unturned\x86\RaInfo.sys --> d:\--- games ---\Unturned\x86\RaInfo.sys [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [11.12.2014 11:30 315496]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [29.12.2011 18:22 5824]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys --> c:\windows\system32\DRIVERS\avchv.sys [?]
S3 cleanhlp;cleanhlp;\??\c:\program files\Emsisoft Anti-Malware\cleanhlp32.sys --> c:\program files\Emsisoft Anti-Malware\cleanhlp32.sys [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\Satek\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Satek\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [1.7.2010 21:34 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [1.7.2010 21:34 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [1.7.2010 21:34 94064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [16.2.2012 12:17 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [16.2.2012 12:17 8576]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2016-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-23 19:10]
.
2015-11-08 c:\windows\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-27 23:28]
.
2016-06-07 c:\windows\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-27 23:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: ulozto.cz
TCP: DhcpNameServer = 77.48.254.254 77.48.100.254
FF - ProfilePath - c:\documents and settings\Satek\Data aplikací\Mozilla\Firefox\Profiles\3prn2y9e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-RunOnce-<NO NAME> - (no file)
Notify-AtiExtEvent - (no file)
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-AdAwareTray - c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
MSConfigStartUp-KiesPreload - c:\program files\Samsung\Kies\Kies.exe
MSConfigStartUp-KiesTrayAgent - c:\program files\Samsung\Kies\KiesTrayAgent.exe
MSConfigStartUp-LogMeIn GUI - d:\--- games ---\Unturned\x86\LogMeInSystray.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
MSConfigStartUp-TO2SSM_McciTrayApp - c:\program files\TO2SSM\McciTrayApp.exe
AddRemove-FlatOut Ultimate Carnage - j:\flatout uc\FlatOut Ultimate Carnage\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2016-06-07 12:12
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-527237240-1606980848-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-527237240-1606980848-1801674531-1003\Control Panel\Desktop*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"WheelScrollLines"="3"
DUMPHIVE0.003 (REGF)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(572)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\igfxdev.dll
.
Celkový čas: 2016-06-07 12:13:49
ComboFix-quarantined-files.txt 2016-06-07 10:13
.
Před spuštěním: Volných bajtů: 12 009 418 752
Po spuštění: Volných bajtů: 12 253 278 208
.
- - End Of File - - 36FE6B8FFB113C7D43C19A3F0FF893B1
413FC2A0C716421B3158746D63736515
Prosím o kontrolu všech txt. CHtěl jsem poslat jako přílohu,a le nelze poslat koncovku txt, omlouvam se , ale nejsem vyloženě IT typ.
USB fix :
############################## | UsbFix V 8.247 | [Research]
User: Satek (Administrator) # KVIK
Updated 25/05/2016 by SOSVirus
Started at 09:56:34 | 07/06/2016
Website : https://www.usb-antivirus.com/
Tutorial : https://www.usb-antivirus.com/tutorial/
Support : http://www.sosvirus.org/
Live detection : http://www.sosmalware.com/usbfix/
Contact : https://www.usb-antivirus.com/contact/
################## | System information |
CPU: Intel(R) Pentium(R) 4 CPU 3.40GHz
RAM -> [Total : 2047 Mo | Free : 1576 Mo]
Boot: Normal boot
OS: Microsoft Windows XP (5.1.2600 32-Bit) Service Pack 3
WB: Internet Explorer : 8.00.6001.18702
WB: Mozilla Firefox : 46.0.1
################## | Security Information |
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
################## | Disk Information |
C:\ (%SystemDrive%) -> Fixed disk # 56 Gb (11 Gb free - 20%) [] # NTFS
D:\ -> Fixed disk # 93 Gb (12 Gb free - 13%) [Data] # NTFS
H:\ -> Removable disk # 7 Gb (2 Gb free - 33%) [KINGSTON] # FAT32
L:\ -> Removable disk # 4 Gb (4 Gb free - 100%) [STORE N GO] # FAT32
################## | Startup |
F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
04 - HKCU\..\Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
04 - HKCU\..\Run : [SetDefaultMIDI] MIDIDef.exe
04 - HKCU\..\Run : [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - HKLM\..\Run : [CTSysVol] C:\Program Files\Creative\SB5.1 VX\Surround Mixer\CTSysVol.exe /r
04 - HKLM\..\Run : [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
04 - HKLM\..\Run : [igfxtray] C:\WINDOWS\system32\igfxtray.exe
04 - HKLM\..\Run : [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
04 - HKLM\..\Run : [igfxpers] C:\WINDOWS\system32\igfxpers.exe
04 - HKLM\..\Run : [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
04 - HKLM\..\Run : [Gaming mouse] C:\Program Files\TESORO Gaming\SHRIKE Gaming Mouse\mousehid.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
04 - HKLM\..\Run : [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
04 - HKLM\..\Run : [BF2Hub Client] C:\Program Files\BF2Hub Client\bf2hub.exe
04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [SetDefaultMIDI] MIDIDef.exe
04 - HKU\S-1-5-21-527237240-1606980848-1801674531-1003\..\Run : [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04GS - Microsoft Office.lnk : C:\Program Files\Microsoft Office\Office10\OSA.EXE
################## | Generic Research |
Found! H:\tmp465C.tmp.vbs
Found! L:\tmp465C.tmp.vbs
Found! H:\BOOTEX.lnk
Found! H:\2.lnk
Found! H:\FOUND.000.lnk
Found! H:\Bojová Technika.lnk
Found! H:\Odbaveni-RC1743079.lnk
Found! H:\Counter-Strike 1.6.lnk
Found! H:\Výživa F-sport.lnk
Found! H:\15_OKRESNI_PREBOR_SVADBA.lnk
Found! H:\.minecraft.lnk
Found! H:\System Volume Information.lnk
Found! H:\The KMPlayer.lnk
Found! H:\Rotaxmame.lnk
Found! H:\09_OKRESNI_PREBOR_NA VAHU.lnk
Found! H:\08_OKRESNI_PREBOR_SCHUZE.lnk
Found! H:\07_OKRESNI_PREBOR_KOPACAK.lnk
Found! H:\05_OKRESNI_PREBOR_FORBES.lnk
Found! H:\02_OKRESNI_PREBOR_NABOR.lnk
Found! H:\01_OKRESNI_PREBOR_POHREB.lnk
Found! L:\Denní příjem kalorií.lnk
Found! L:\NICKY Rotax.lnk
Found! L:\P1020896.lnk
Found! C:\Documents and Settings\Satek\Local Settings\Temp\tmp465C.tmp.vbs
Analysed in 157.3 seconds
################## | E.O.F | http://www.sosvirus.net/ | https://www.usb-antivirus.com/ |
rkill :
Rkill 2.8.4 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 06/07/2016 12:03:34 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Reparse Point/Junctions Found (Most likely legitimate)!
* C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]
* C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
209.250.2.163 battlefield2.ms1.gamespy.com
209.250.2.163 battlefield2.ms2.gamespy.com
209.250.2.163 battlefield2.ms3.gamespy.com
209.250.2.163 battlefield2.ms4.gamespy.com
209.250.2.163 battlefield2.ms5.gamespy.com
209.250.2.163 battlefield2.ms6.gamespy.com
209.250.2.163 battlefield2.ms7.gamespy.com
209.250.2.163 battlefield2.ms8.gamespy.com
209.250.2.163 battlefield2.ms9.gamespy.com
209.250.2.163 battlefield2.ms10.gamespy.com
209.250.2.163 battlefield2.ms11.gamespy.com
209.250.2.163 battlefield2.ms12.gamespy.com
209.250.2.163 battlefield2.ms13.gamespy.com
209.250.2.163 battlefield2.ms15.gamespy.com
209.250.2.163 battlefield2.ms16.gamespy.com
209.250.2.163 battlefield2.ms17.gamespy.com
209.250.2.163 battlefield2.ms18.gamespy.com
209.250.2.163 battlefield2.ms19.gamespy.com
209.250.2.163 battlefield2.ms20.gamespy.com
20 out of 48 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 06/07/2016 12:04:09 PM
Execution time: 0 hours(s), 0 minute(s), and 34 seconds(s)
Combofix :
ComboFix 16-06-01.01 - Satek 07.06.2016 12:08:07.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1561 [GMT 2:00]
Spuštěný z: d:\upload\ComboFix.exe
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Satek\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\system32\SET1409.tmp
c:\windows\system32\tmp317.tmp
c:\windows\system32\tmp318.tmp
c:\windows\system32\tmp59A8.tmp
c:\windows\system32\tmp59A9.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-05-07 do 2016-06-07 )))))))))))))))))))))))))))))))
.
.
2016-06-07 09:55 . 2016-06-07 09:55 -------- d--h--w- c:\windows\PIF
2016-06-07 07:54 . 2016-06-07 07:55 -------- d-----w- C:\UsbFix
2016-06-07 07:32 . 2016-06-07 07:32 -------- d-----w- c:\windows\system32\wbem\Repository
2016-06-06 12:19 . 2016-06-07 07:31 -------- d-----w- c:\program files\Ask.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-06-01 17:59 . 2013-05-05 13:19 138992 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2016-06-01 17:59 . 2013-05-05 13:19 281152 ----a-w- c:\windows\system32\PnkBstrB.exe
2016-06-01 17:59 . 2010-07-26 19:04 281152 ----a-w- c:\windows\system32\PnkBstrB.xtr
2016-05-31 18:35 . 2013-05-05 13:19 281152 ----a-w- c:\windows\system32\PnkBstrB.ex0
2016-05-12 19:10 . 2012-07-23 09:06 797376 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-05-12 19:10 . 2011-12-30 07:38 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-24 94208]
"SetDefaultMIDI"="MIDIDef.exe" [2002-12-03 49152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SB5.1 VX\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-03-13 75048]
"Gaming mouse"="c:\program files\TESORO Gaming\SHRIKE Gaming Mouse\mousehid.exe" [2012-07-06 289280]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-05-08 959904]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-07 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"BF2Hub Client"="c:\program files\BF2Hub Client\bf2hub.exe" [2015-12-19 1927680]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 115440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2014-10-31 10:53 85864 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-05-08 13:48 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
2013-06-04 23:01 4489472 ----a-w- c:\documents and settings\Satek\Local Settings\Data aplikací\Akamai\netsession_win.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BF2Hub Client]
2015-12-19 18:09 1927680 ----a-w- c:\program files\BF2Hub Client\bf2hub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 15:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 07:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-07-09 14:24 13923432 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-07-09 14:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2011-06-16 13:21 1500160 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
2010-02-02 23:08 87336 ------w- c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 12:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2015-09-26 13:38 6815512 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\--- GAMES ---\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Satek\\Local Settings\\Data aplikací\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\EA Games\\Battlefield 2\\BF2.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\EA Games\\Battlefield 2\\BF2RG.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\bin\\steamwebhelper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [11.6.2010 20:16 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [11.6.2010 20:16 5248]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.2.2010 12:30 691696]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [20.3.2013 17:02 21576]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [11.10.2013 0:54 142648]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2012/02/12 19:29];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [13.3.2010 13:58 87536]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [?]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\d:\--- games ---\Unturned\x86\RaInfo.sys --> d:\--- games ---\Unturned\x86\RaInfo.sys [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [11.12.2014 11:30 315496]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [29.12.2011 18:22 5824]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys --> c:\windows\system32\DRIVERS\avchv.sys [?]
S3 cleanhlp;cleanhlp;\??\c:\program files\Emsisoft Anti-Malware\cleanhlp32.sys --> c:\program files\Emsisoft Anti-Malware\cleanhlp32.sys [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\Satek\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Satek\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [1.7.2010 21:34 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [1.7.2010 21:34 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [1.7.2010 21:34 94064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [16.2.2012 12:17 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [16.2.2012 12:17 8576]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2016-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-23 19:10]
.
2015-11-08 c:\windows\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-27 23:28]
.
2016-06-07 c:\windows\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-27 23:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: ulozto.cz
TCP: DhcpNameServer = 77.48.254.254 77.48.100.254
FF - ProfilePath - c:\documents and settings\Satek\Data aplikací\Mozilla\Firefox\Profiles\3prn2y9e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-RunOnce-<NO NAME> - (no file)
Notify-AtiExtEvent - (no file)
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-AdAwareTray - c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
MSConfigStartUp-KiesPreload - c:\program files\Samsung\Kies\Kies.exe
MSConfigStartUp-KiesTrayAgent - c:\program files\Samsung\Kies\KiesTrayAgent.exe
MSConfigStartUp-LogMeIn GUI - d:\--- games ---\Unturned\x86\LogMeInSystray.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
MSConfigStartUp-TO2SSM_McciTrayApp - c:\program files\TO2SSM\McciTrayApp.exe
AddRemove-FlatOut Ultimate Carnage - j:\flatout uc\FlatOut Ultimate Carnage\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2016-06-07 12:12
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-527237240-1606980848-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-527237240-1606980848-1801674531-1003\Control Panel\Desktop*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"WheelScrollLines"="3"
DUMPHIVE0.003 (REGF)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(572)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\igfxdev.dll
.
Celkový čas: 2016-06-07 12:13:49
ComboFix-quarantined-files.txt 2016-06-07 10:13
.
Před spuštěním: Volných bajtů: 12 009 418 752
Po spuštění: Volných bajtů: 12 253 278 208
.
- - End Of File - - 36FE6B8FFB113C7D43C19A3F0FF893B1
413FC2A0C716421B3158746D63736515