Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

conficker.AA

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

conficker.AA

#1 Příspěvek od zack111 »

zdravim....nevie mi niekto poradiť čo s confickerom?....stale ked vypnem firewall na Esete (lebo chcem pozerť tv na vlc) tak sa mi po chvily ukáže od Esetu hlasenie že červ conficker.AA bol odstraneni, pričom nemam žiadny usb kluč ani nič ine napojene na comp. Skušal som aj EConfickerRemover od Esetu ale ten nič nenašiel. Nechapem odkial sa berie.

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#2 Příspěvek od meteorolog »

Dobrý den :-)

vložte sem log z RSIT
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#3 Příspěvek od zack111 »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Vilo at 2009-12-09 10:21:01
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 1 GB (8%) free of 15 GB
Total RAM: 894 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:24, on 9.12.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
D:\my downloads\RSIT.exe
C:\Program Files\trend micro\Vilo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://download.cnet.com/Advanced-Syste ... tag=button
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 6349 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-13 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-11-13 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2007-02-19 303104]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-27 851968]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2007-03-16 1392640]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2007-05-14 1191936]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-11-13 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Advanced SystemCare 3"=C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe [2009-11-04 2334856]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2007-12-29 486856]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-03-02 110592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9eb52534-d06f-11de-9ee9-001c23a5e0e0}]
shell\AutoRun\command - F:\Setup.exe


======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2009-12-09 10:21:02 ----D---- C:\Program Files\trend micro
2009-12-09 10:21:01 ----D---- C:\rsit
2009-12-09 09:58:06 ----D---- C:\Program Files\AutoCAD 2009
2009-12-09 09:57:28 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-12-09 09:57:21 ----D---- C:\WINDOWS\LastGood
2009-12-09 09:57:19 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-12-09 00:02:45 ----D---- C:\WINDOWS\system32\XPSViewer
2009-12-09 00:02:43 ----D---- C:\WINDOWS\system32\en-us
2009-12-09 00:01:39 ----D---- C:\Program Files\Reference Assemblies
2009-12-09 00:01:18 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-12-09 00:01:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-12-09 00:01:00 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2009-12-07 21:52:31 ----RA---- C:\WINDOWS\LgUninst.exe
2009-12-07 21:52:31 ----A---- C:\WINDOWS\setup.INI
2009-12-07 21:48:59 ----D---- C:\Program Files\Lingea
2009-12-06 13:43:52 ----D---- C:\Documents and Settings\Vilo\Application Data\Help
2009-12-02 20:04:40 ----D---- C:\Reservoir Dogs (Gauneri) (1992) (dab)
2009-12-01 17:34:33 ----D---- C:\Program Files\Common Files\AB Studio Shared
2009-12-01 17:34:32 ----D---- C:\Program Files\AB Studio
2009-12-01 17:26:54 ----D---- C:\Program Files\Common Files\Wextech Shared
2009-12-01 17:04:34 ----HD---- C:\C_DILLA
2009-12-01 17:04:02 ----A---- C:\WINDOWS\system32\Mrt7enu.dll
2009-12-01 17:04:02 ----A---- C:\WINDOWS\system32\Hlp95en.dll
2009-12-01 17:04:02 ----A---- C:\WINDOWS\system32\acdbres.dll
2009-12-01 17:03:47 ----D---- C:\Program Files\Volo View Express
2009-12-01 17:03:39 ----A---- C:\WINDOWS\uninst.exe
2009-12-01 17:02:29 ----D---- C:\Program Files\AutoCAD 2002 Cz
2009-11-30 12:22:17 ----D---- C:\Program Files\NEXIS32-2
2009-11-22 21:31:22 ----D---- C:\Documents and Settings\Vilo\Application Data\Real
2009-11-19 13:30:33 ----D---- C:\Documents and Settings\Vilo\Application Data\BitTorrent
2009-11-19 13:29:42 ----D---- C:\Program Files\DNA
2009-11-19 13:29:42 ----D---- C:\Documents and Settings\Vilo\Application Data\DNA
2009-11-19 13:29:40 ----D---- C:\Program Files\BitTorrent
2009-11-19 12:07:11 ----D---- C:\Documents and Settings\Vilo\Application Data\skypePM
2009-11-19 12:05:02 ----D---- C:\Documents and Settings\Vilo\Application Data\Skype
2009-11-19 12:04:46 ----D---- C:\Program Files\Skype
2009-11-19 12:04:46 ----D---- C:\Program Files\Common Files\Skype
2009-11-19 12:04:34 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2009-11-18 09:22:28 ----D---- C:\Program Files\NEXIS32
2009-11-18 09:22:28 ----D---- C:\NEXIS32
2009-11-18 09:21:32 ----A---- C:\WINDOWS\IsUn0405.exe
2009-11-17 13:07:40 ----D---- C:\Program Files\Valentin EnergieSoftware
2009-11-17 13:07:40 ----D---- C:\Documents and Settings\All Users\Application Data\Valentin EnergieSoftware
2009-11-17 13:04:00 ----D---- C:\Program Files\Common Files\Nemetschek
2009-11-17 13:03:30 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-11-17 13:03:30 ----A---- C:\WINDOWS\system32\mfc71u.dll
2009-11-17 13:03:30 ----A---- C:\WINDOWS\system32\MFC71ITA.DLL
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\P2smon.dll
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\MFC71FRA.DLL
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\MFC71ESP.DLL
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\MFC71ENU.DLL
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\MFC71DEU.DLL
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\implode.dll
2009-11-17 13:03:29 ----A---- C:\WINDOWS\system32\FLXGDDE.DLL
2009-11-17 13:03:28 ----D---- C:\WINDOWS\Crystal
2009-11-17 13:03:28 ----A---- C:\WINDOWS\system32\crpe32.dll
2009-11-17 13:03:28 ----A---- C:\WINDOWS\system32\crpaig32.dll
2009-11-17 13:03:28 ----A---- C:\WINDOWS\system32\cr2c70de.dll
2009-11-17 13:03:28 ----A---- C:\WINDOWS\system32\cpeaut32.dll
2009-11-17 13:03:10 ----D---- C:\Data
2009-11-17 13:03:08 ----D---- C:\Program Files\Nemetschek
2009-11-15 16:36:47 ----D---- C:\revit
2009-11-15 15:12:51 ----D---- C:\Program Files\Revit Architecture 2009
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-11-15 13:21:19 ----N---- C:\WINDOWS\system32\px.dll
2009-11-15 13:21:15 ----D---- C:\Program Files\Winamp
2009-11-15 13:21:15 ----D---- C:\Documents and Settings\Vilo\Application Data\Winamp
2009-11-13 18:41:02 ----A---- C:\materská škola.bak
2009-11-13 17:34:27 ----D---- C:\Documents and Settings\Vilo\Application Data\Autodesk
2009-11-13 17:34:27 ----D---- C:\Documents and Settings\All Users\Application Data\Autodesk
2009-11-13 17:30:42 ----D---- C:\Program Files\Common Files\Autodesk Shared
2009-11-13 17:30:20 ----D---- C:\Program Files\Autodesk
2009-11-13 17:30:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-11-13 17:28:37 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-11-13 17:28:04 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-11-13 17:22:41 ----D---- C:\Program Files\Microsoft Works
2009-11-13 17:22:25 ----D---- C:\Program Files\MSBuild
2009-11-13 17:22:07 ----D---- C:\Program Files\Microsoft Visual Studio
2009-11-13 17:22:07 ----D---- C:\Program Files\Common Files\DESIGNER
2009-11-13 17:21:03 ----D---- C:\Program Files\Microsoft.NET
2009-11-13 17:18:55 ----D---- C:\Program Files\NOS
2009-11-13 17:18:55 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-11-13 17:18:35 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-11-13 17:17:38 ----D---- C:\WINDOWS\SHELLNEW
2009-11-13 17:17:09 ----D---- C:\Program Files\Microsoft Office
2009-11-13 17:17:08 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-11-13 17:16:44 ----RHD---- C:\MSOCache
2009-11-13 17:14:29 ----D---- C:\Documents and Settings\Vilo\Application Data\DAEMON Tools
2009-11-13 17:14:16 ----D---- C:\Program Files\DAEMON Tools Lite
2009-11-13 17:06:55 ----D---- C:\Documents and Settings\Vilo\Application Data\ICQ
2009-11-13 17:06:22 ----D---- C:\Program Files\ICQ6.5
2009-11-13 17:05:14 ----D---- C:\Documents and Settings\Vilo\Application Data\BSplayer Pro
2009-11-13 17:05:14 ----D---- C:\Documents and Settings\Vilo\Application Data\BSplayer
2009-11-13 17:05:05 ----D---- C:\Program Files\Webteh
2009-11-13 17:04:15 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-11-13 17:04:12 ----D---- C:\Documents and Settings\Vilo\Application Data\Macromedia
2009-11-13 17:04:12 ----D---- C:\Documents and Settings\Vilo\Application Data\Adobe
2009-11-13 17:03:34 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-11-13 17:03:24 ----D---- C:\Program Files\Common Files\Adobe
2009-11-13 17:03:24 ----D---- C:\Program Files\Adobe
2009-11-13 17:02:22 ----D---- C:\Program Files\totalcmd
2009-11-13 17:02:22 ----A---- C:\WINDOWS\wincmd.ini
2009-11-13 17:01:37 ----D---- C:\WINDOWS\system32\Adobe
2009-11-13 17:00:59 ----D---- C:\Documents and Settings\Vilo\Application Data\ACD Systems
2009-11-13 17:00:50 ----D---- C:\Documents and Settings\Vilo\Application Data\ESTsoft
2009-11-13 17:00:47 ----D---- C:\Documents and Settings\All Users\Application Data\ESTsoft
2009-11-13 17:00:37 ----D---- C:\Program Files\ESTsoft
2009-11-13 16:59:28 ----A---- C:\WINDOWS\system32\javaws.exe
2009-11-13 16:59:28 ----A---- C:\WINDOWS\system32\javaw.exe
2009-11-13 16:59:28 ----A---- C:\WINDOWS\system32\java.exe
2009-11-13 16:59:28 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-11-13 16:59:09 ----D---- C:\Program Files\Java
2009-11-13 16:58:52 ----D---- C:\Documents and Settings\Vilo\Application Data\Sun
2009-11-13 16:53:54 ----D---- C:\Documents and Settings\Vilo\Application Data\Mozilla
2009-11-13 16:53:36 ----D---- C:\Program Files\Mozilla Firefox
2009-11-13 16:49:40 ----D---- C:\Documents and Settings\All Users\Application Data\ACD Systems
2009-11-13 16:49:39 ----D---- C:\Program Files\Common Files\ACD Systems
2009-11-13 16:49:39 ----D---- C:\Program Files\ACD Systems
2009-11-13 16:48:58 ----D---- C:\WINDOWS\Downloaded Installations
2009-11-13 16:46:14 ----D---- C:\WINDOWS\RegisteredPackages
2009-11-13 16:43:54 ----D---- C:\Documents and Settings\Vilo\Application Data\vlc
2009-11-13 16:43:16 ----D---- C:\Program Files\The KMPlayer
2009-11-13 16:41:44 ----D---- C:\Program Files\VideoLAN
2009-11-13 16:40:37 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-11-13 16:40:37 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-11-13 16:40:37 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-11-13 16:40:37 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-11-13 16:40:35 ----A---- C:\WINDOWS\system32\unrar.dll
2009-11-13 16:40:34 ----A---- C:\WINDOWS\avisplitter.ini
2009-11-13 16:40:27 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-11-13 16:40:27 ----A---- C:\WINDOWS\system32\x264vfw.dll
2009-11-13 16:40:27 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2009-11-13 16:40:27 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2009-11-13 16:40:27 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-11-13 16:40:26 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-11-13 16:40:26 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-11-13 16:40:26 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2009-11-13 16:40:26 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-11-13 16:40:17 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-11-13 16:40:17 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-11-13 16:40:17 ----A---- C:\WINDOWS\system32\divx.dll
2009-11-13 16:40:14 ----D---- C:\Program Files\K-Lite Codec Pack
2009-11-13 16:39:23 ----D---- C:\Program Files\CCleaner
2009-11-13 16:33:27 ----SHD---- C:\RECYCLER
2009-11-13 16:31:25 ----D---- C:\Documents and Settings\Vilo\Application Data\IObit
2009-11-13 16:31:24 ----D---- C:\Program Files\IObit
2009-11-13 16:26:39 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-13 16:26:39 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-13 16:24:35 ----D---- C:\Documents and Settings\Vilo\Application Data\ESET
2009-11-13 16:23:31 ----D---- C:\Program Files\ESET
2009-11-13 16:23:31 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2009-11-13 16:21:52 ----D---- C:\Documents and Settings\Vilo\Application Data\ATI
2009-11-13 16:16:05 ----RSD---- C:\WINDOWS\assembly
2009-11-13 16:15:44 ----D---- C:\WINDOWS\Microsoft.NET
2009-11-13 16:14:46 ----D---- C:\Program Files\Digital Line Detect
2009-11-13 16:13:49 ----D---- C:\Documents and Settings\Vilo\Application Data\Dell
2009-11-13 16:12:04 ----D---- C:\Documents and Settings\Vilo\Application Data\InstallShield
2009-11-13 16:11:40 ----D---- C:\Program Files\ATI Technologies
2009-11-13 16:11:15 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2009-11-13 16:11:15 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2009-11-13 16:11:15 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2009-11-13 16:11:15 ----A---- C:\WINDOWS\system32\atitvo32.dll
2009-11-13 16:11:15 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\atioglxx.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\atikvmag.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\ati3duag.dll
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2009-11-13 16:11:14 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2009-11-13 16:11:13 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2009-11-13 16:11:13 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2009-11-13 16:11:13 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2009-11-13 16:11:13 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2009-11-13 16:08:48 ----A---- C:\WINDOWS\system32\BCMLogon.dll
2009-11-13 16:08:45 ----A---- C:\WINDOWS\system32\MSVCR71.DLL
2009-11-13 16:08:45 ----A---- C:\WINDOWS\system32\MSVCP71.DLL
2009-11-13 16:08:45 ----A---- C:\WINDOWS\system32\MFC71.DLL
2009-11-13 16:08:45 ----A---- C:\WINDOWS\system32\ATL71.DLL
2009-11-13 16:08:44 ----A---- C:\WINDOWS\system32\wltrynt.dll
2009-11-13 16:08:44 ----A---- C:\WINDOWS\system32\preflib.dll
2009-11-13 16:08:44 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2009-11-13 16:08:43 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2009-11-13 16:08:43 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2009-11-13 16:08:42 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2009-11-13 16:08:42 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2009-11-13 16:08:42 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2009-11-13 16:08:42 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2009-11-13 16:07:50 ----D---- C:\Program Files\Broadcom
2009-11-13 16:05:14 ----D---- C:\Program Files\Synaptics
2009-11-13 16:05:14 ----A---- C:\WINDOWS\system32\SynTPCo4.dll
2009-11-13 16:05:14 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2009-11-13 16:05:14 ----A---- C:\WINDOWS\system32\SynCtrl.dll
2009-11-13 16:05:14 ----A---- C:\WINDOWS\system32\SynCOM.dll
2009-11-13 16:02:09 ----D---- C:\Program Files\AMD
2009-11-13 16:01:29 ----D---- C:\Program Files\CONEXANT
2009-11-13 16:01:19 ----A---- C:\WINDOWS\system32\Uci32114.dll
2009-11-13 16:01:18 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
2009-11-13 16:01:04 ----D---- C:\Program Files\DIFX
2009-11-13 16:00:59 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-11-13 15:57:43 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-11-13 15:56:37 ----A---- C:\WINDOWS\system32\stlang.dll
2009-11-13 15:56:37 ----A---- C:\WINDOWS\stsystra.exe
2009-11-13 15:56:35 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-11-13 15:56:25 ----A---- C:\WINDOWS\system32\staco.dll
2009-11-13 15:55:55 ----HDC---- C:\WINDOWS\$NtUninstallKB835221WXP$
2009-11-13 15:55:50 ----D---- C:\Program Files\SigmaTel
2009-11-13 15:55:50 ----A---- C:\WINDOWS\system32\stacapi.dll
2009-11-13 15:55:49 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-13 15:55:46 ----D---- C:\Program Files\Common Files\InstallShield
2009-11-13 15:55:40 ----D---- C:\dell
2009-11-13 15:54:42 ----D---- C:\WINDOWS\system32\vmm32
2009-11-13 15:54:42 ----D---- C:\Program Files\Dell
2009-11-13 15:38:43 ----A---- C:\WINDOWS\system32\h323log.txt
2009-11-13 15:33:14 ----A---- C:\WINDOWS\system32\usbui.dll
2009-11-13 15:30:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-11-13 15:30:42 ----SHD---- C:\WINDOWS\Installer
2009-11-13 15:30:40 ----D---- C:\Program Files\Common Files\ODBC
2009-11-13 15:30:40 ----A---- C:\WINDOWS\ODBCINST.INI
2009-11-13 15:30:36 ----RD---- C:\Program Files
2009-11-13 15:30:36 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-11-13 15:30:36 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-11-13 15:30:36 ----D---- C:\Program Files\Common Files
2009-11-13 15:30:33 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-11-13 15:30:33 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-11-13 15:30:33 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-11-13 15:30:32 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-11-13 15:30:31 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-11-13 15:30:30 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-11-13 15:30:30 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-11-13 15:30:29 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-11-13 15:30:29 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-11-13 15:30:29 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-11-13 15:30:29 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-11-13 15:30:29 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-11-13 15:30:28 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-11-13 15:30:28 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-11-13 15:30:28 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-11-13 15:30:28 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-11-13 15:30:28 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-11-13 15:30:27 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-11-13 15:30:26 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-11-13 15:30:24 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-11-13 15:30:24 ----A---- C:\WINDOWS\system32\irclass.dll
2009-11-13 15:30:24 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-11-13 15:30:24 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-11-13 15:30:24 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-11-13 15:30:22 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-11-13 15:30:22 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-11-13 15:30:21 ----A---- C:\WINDOWS\system32\batt.dll
2009-11-13 15:30:21 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-11-13 15:30:20 ----A---- C:\WINDOWS\system32\storprop.dll
2009-11-13 15:30:05 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-11-13 15:30:01 ----RA---- C:\WINDOWS\SET8.tmp
2009-11-13 15:29:57 ----RA---- C:\WINDOWS\SET4.tmp
2009-11-13 15:29:55 ----RA---- C:\WINDOWS\SET3.tmp
2009-11-13 15:29:47 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-13 15:29:47 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-13 15:29:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-11-13 15:29:06 ----SHD---- C:\System Volume Information
2009-11-13 15:29:06 ----D---- C:\Documents and Settings
2009-11-13 15:28:03 ----SH---- C:\boot.ini
2009-11-13 15:24:27 ----A---- C:\WINDOWS\system32\WMErrSKY.dll
2009-11-13 15:24:25 ----D---- C:\WINDOWS\system32\1051
2009-11-13 15:22:16 ----D---- C:\Documents and Settings\Vilo\Application Data\Identities
2009-11-13 15:22:15 ----HD---- C:\Program Files\Uninstall Information
2009-11-13 15:22:05 ----SD---- C:\Documents and Settings\Vilo\Application Data\Microsoft
2009-11-13 15:22:05 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-13 15:22:05 ----RSD---- C:\WINDOWS\Fonts
2009-11-13 15:22:05 ----RD---- C:\WINDOWS\Web
2009-11-13 15:22:05 ----HD---- C:\WINDOWS\inf
2009-11-13 15:22:05 ----D---- C:\WINDOWS\WinSxS
2009-11-13 15:22:05 ----D---- C:\WINDOWS\twain_32
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Temp
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\wins
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\wbem
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\usmt
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\spool
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\ShellExt
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\Setup
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\ras
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\oobe
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\npp
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\mui
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\inetsrv
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\IME
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\icsxml
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\ias
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\export
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\drivers
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\dhcp
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\config
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\3com_dmi
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\3076
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\2052
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1054
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1042
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1041
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1037
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1033
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1031
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1028
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32\1025
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system32
2009-11-13 15:22:05 ----D---- C:\WINDOWS\system
2009-11-13 15:22:05 ----D---- C:\WINDOWS\security
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Resources
2009-11-13 15:22:05 ----D---- C:\WINDOWS\repair
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Provisioning
2009-11-13 15:22:05 ----D---- C:\WINDOWS\pchealth
2009-11-13 15:22:05 ----D---- C:\WINDOWS\PeerNet
2009-11-13 15:22:05 ----D---- C:\WINDOWS\mui
2009-11-13 15:22:05 ----D---- C:\WINDOWS\msapps
2009-11-13 15:22:05 ----D---- C:\WINDOWS\msagent
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Media
2009-11-13 15:22:05 ----D---- C:\WINDOWS\java
2009-11-13 15:22:05 ----D---- C:\WINDOWS\ime
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Help
2009-11-13 15:22:05 ----D---- C:\WINDOWS\ehome
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Driver Cache
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Debug
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Cursors
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Connection Wizard
2009-11-13 15:22:05 ----D---- C:\WINDOWS\Config
2009-11-13 15:22:05 ----D---- C:\WINDOWS\AppPatch
2009-11-13 15:22:05 ----D---- C:\WINDOWS\addins
2009-11-13 15:22:05 ----D---- C:\WINDOWS
2009-11-13 15:22:05 ----ASH---- C:\Documents and Settings\Vilo\Application Data\desktop.ini
2009-11-13 15:21:03 ----D---- C:\WINDOWS\SoftwareDistribution
2009-11-13 15:21:02 ----D---- C:\WINDOWS\Prefetch
2009-11-13 15:21:01 ----SD---- C:\WINDOWS\system32\Microsoft
2009-11-13 15:21:01 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-13 14:48:20 ----D---- C:\WINDOWS\system32\xircom
2009-11-13 14:48:20 ----D---- C:\Program Files\xerox
2009-11-13 14:48:20 ----D---- C:\Program Files\microsoft frontpage
2009-11-13 14:47:49 ----A---- C:\WINDOWS\control.ini
2009-11-13 14:47:22 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-11-13 14:46:10 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-11-13 14:46:10 ----RD---- C:\WINDOWS\Offline Web Pages
2009-11-13 14:46:10 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-11-13 14:46:03 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-11-13 14:45:56 ----HD---- C:\Program Files\WindowsUpdate
2009-11-13 14:45:21 ----D---- C:\WINDOWS\system32\DirectX
2009-11-13 14:44:59 ----A---- C:\WINDOWS\system32\atrace.dll
2009-11-13 14:44:57 ----A---- C:\WINDOWS\system32\desktop.ini
2009-11-13 14:44:56 ----A---- C:\WINDOWS\desktop.ini
2009-11-13 14:44:50 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-11-13 14:44:49 ----D---- C:\Program Files\Common Files\Services
2009-11-13 14:44:49 ----A---- C:\WINDOWS\system32\acctres.dll
2009-11-13 14:44:46 ----SD---- C:\WINDOWS\Tasks
2009-11-13 14:44:46 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-11-13 14:44:45 ----D---- C:\Program Files\Common Files\MSSoap
2009-11-13 14:44:41 ----D---- C:\WINDOWS\srchasst
2009-11-13 14:44:40 ----D---- C:\WINDOWS\system32\Macromed
2009-11-13 14:44:37 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-11-13 14:44:37 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-11-13 14:44:37 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-11-13 14:44:36 ----A---- C:\WINDOWS\system32\wups.dll
2009-11-13 14:44:36 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-11-13 14:44:36 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-11-13 14:44:36 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-11-13 14:44:35 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-11-13 14:44:30 ----D---- C:\Program Files\Movie Maker
2009-11-13 14:44:27 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-11-13 14:44:26 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-11-13 14:44:26 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-11-13 14:44:26 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-11-13 14:44:21 ----D---- C:\WINDOWS\system32\Restore
2009-11-13 14:44:21 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-11-13 14:44:21 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-11-13 14:44:21 ----A---- C:\WINDOWS\system32\srclient.dll
2009-11-13 14:44:21 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-11-13 14:44:21 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-11-13 14:44:20 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-11-13 14:44:20 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-11-13 14:44:20 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-11-13 14:44:20 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-11-13 14:44:20 ----A---- C:\WINDOWS\system32\ils.dll
2009-11-13 14:44:19 ----A---- C:\WINDOWS\system32\msconf.dll
2009-11-13 14:44:17 ----D---- C:\Program Files\NetMeeting
2009-11-13 14:44:17 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-11-13 14:44:17 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-11-13 14:44:15 ----A---- C:\WINDOWS\system32\inetres.dll
2009-11-13 14:44:15 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-11-13 14:44:13 ----D---- C:\Program Files\Outlook Express
2009-11-13 14:44:13 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-11-13 14:44:13 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-11-13 14:44:12 ----A---- C:\WINDOWS\system32\mstask.dll
2009-11-13 14:44:12 ----A---- C:\WINDOWS\system32\isign32.dll
2009-11-13 14:44:12 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-11-13 14:44:12 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-11-13 14:44:12 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-11-13 14:44:06 ----D---- C:\Program Files\Common Files\System
2009-11-13 14:44:00 ----D---- C:\Program Files\Internet Explorer
2009-11-13 14:43:03 ----D---- C:\Program Files\ComPlus Applications
2009-11-13 14:42:58 ----A---- C:\WINDOWS\vbaddin.ini
2009-11-13 14:42:58 ----A---- C:\WINDOWS\vb.ini
2009-11-13 14:42:47 ----D---- C:\WINDOWS\Registration
2009-11-13 14:42:30 ----D---- C:\Program Files\Windows Media Player
2009-11-13 14:42:30 ----D---- C:\Program Files\Online Services
2009-11-13 14:42:16 ----D---- C:\Program Files\Messenger
2009-11-13 14:42:12 ----D---- C:\Program Files\MSN Gaming Zone
2009-11-13 14:42:12 ----A---- C:\WINDOWS\system32\write.exe
2009-11-13 14:42:04 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-11-13 14:42:04 ----A---- C:\WINDOWS\system32\hticons.dll
2009-11-13 14:42:03 ----A---- C:\WINDOWS\system32\winchat.exe
2009-11-13 14:42:03 ----A---- C:\WINDOWS\system32\avwav.dll
2009-11-13 14:42:03 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-11-13 14:42:03 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-11-13 14:41:56 ----A---- C:\WINDOWS\system32\charmap.exe
2009-11-13 14:41:56 ----A---- C:\WINDOWS\system32\getuname.dll
2009-11-13 14:41:56 ----A---- C:\WINDOWS\system32\calc.exe
2009-11-13 14:41:55 ----A---- C:\WINDOWS\system32\winmine.exe
2009-11-13 14:41:55 ----A---- C:\WINDOWS\system32\sol.exe
2009-11-13 14:41:55 ----A---- C:\WINDOWS\system32\reset.exe
2009-11-13 14:41:55 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-11-13 14:41:55 ----A---- C:\WINDOWS\system32\freecell.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\tskill.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\tscon.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\shadow.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\regini.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\msg.exe
2009-11-13 14:41:54 ----A---- C:\WINDOWS\system32\logoff.exe
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-11-13 14:41:53 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-11-13 14:41:52 ----A---- C:\WINDOWS\system32\stclient.dll
2009-11-13 14:41:52 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-11-13 14:41:52 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-11-13 14:41:52 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-11-13 14:41:47 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-11-13 14:41:30 ----D---- C:\Program Files\MSN
2009-11-13 14:41:29 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-11-13 14:41:29 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-11-13 14:41:29 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-11-13 14:41:29 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-11-13 14:41:28 ----D---- C:\Program Files\Windows NT
2009-11-13 14:41:28 ----A---- C:\WINDOWS\system32\spider.exe
2009-11-13 14:41:28 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-11-13 14:41:28 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-11-13 14:41:27 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-11-13 14:41:27 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-11-13 14:41:27 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-11-13 14:41:26 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-11-13 14:41:25 ----D---- C:\WINDOWS\system32\MsDtc
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-11-13 14:41:25 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-11-13 14:41:24 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-11-13 14:41:24 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-11-13 14:41:24 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-11-13 14:41:24 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-11-13 14:41:23 ----D---- C:\WINDOWS\system32\Com
2009-11-13 14:41:23 ----A---- C:\WINDOWS\system32\colbact.dll
2009-11-13 14:41:23 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-11-13 14:41:23 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-11-13 14:41:23 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-11-13 14:41:22 ----A---- C:\WINDOWS\system32\comuid.dll
2009-11-13 14:41:22 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-11-13 14:41:22 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-11-13 14:41:21 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-11-13 14:41:15 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-11-13 14:41:14 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-11-13 14:41:14 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-11-13 14:41:14 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-12-03 19:16:48 ----A---- C:\WINDOWS\win.ini
2009-11-13 15:52:13 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-04-09 55768]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-03-02 1972224]
R3 BCM43XX;Ovládač karty Dell bezdrôtovej WLAN; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2007-03-16 604928]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2006-11-21 45568]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-23 9600]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-11-02 989696]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-11-02 209152]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-02-19 1228296]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-04-27 202912]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-11-02 730112]
S3 azptpvom;azptpvom; C:\WINDOWS\system32\drivers\azptpvom.sys []
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-03-02 446464]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-11-13 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2007-03-16 20480]
R3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-11-15 79360]
S3 Autodesk Network Licensing Service;Autodesk Network Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe [2006-08-11 902760]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#4 Příspěvek od meteorolog »

OK, pošlete ještě log z Combofix

Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#5 Příspěvek od zack111 »

ComboFix 09-12-19.03 - Vilo 20.12.2009 21:05:49.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.894.521 [GMT 1:00]
Running from: d:\my downloads\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\csrcs.exe

.
((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.

2009-12-20 17:26 . 2009-12-20 17:26 -------- d-----w- C:\For vilo
2009-12-20 17:10 . 2007-03-16 17:10 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS
2009-12-20 17:10 . 2007-03-16 17:10 86016 ----a-w- c:\windows\system32\preflib.dll
2009-12-20 17:10 . 2007-03-16 17:10 44032 ----a-w- c:\windows\system32\wltrynt.dll
2009-12-20 17:10 . 2007-03-16 17:10 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2009-12-20 17:10 . 2007-03-16 17:10 253952 ----a-w- c:\windows\system32\bcmwlu00.exe
2009-12-20 17:10 . 2007-03-16 17:10 1392640 ----a-w- c:\windows\system32\WLTRAY.EXE
2009-12-20 17:10 . 2007-03-16 17:10 1253376 ----a-w- c:\windows\system32\BCMWLTRY.EXE
2009-12-20 17:10 . 2007-03-16 17:10 20480 ----a-w- c:\windows\system32\WLTRYSVC.EXE
2009-12-20 17:10 . 2007-03-16 17:10 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2009-12-20 17:10 . 2007-03-16 17:10 757760 ----a-w- c:\windows\system32\bcm1xsup.dll
2009-12-20 14:09 . 2009-12-20 14:09 -------- d-----w- c:\program files\AskBarDis
2009-12-20 14:08 . 2009-12-20 14:08 -------- d-----w- c:\program files\Foxit Software
2009-12-20 14:08 . 2009-12-20 14:08 -------- d-----w- c:\documents and settings\Vilo\Application Data\Foxit
2009-12-17 12:41 . 2009-12-17 12:41 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Sony
2009-12-17 12:39 . 2009-12-17 12:39 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-12-17 12:38 . 2009-12-17 12:38 -------- d-----w- c:\program files\Sony
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\Common Files\Apple
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\QuickTime
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Apple
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\Apple Software Update
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-17 12:34 . 2009-12-17 12:34 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Apple Computer
2009-12-17 12:32 . 2009-12-17 12:42 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-12-17 12:32 . 2009-12-17 12:32 -------- d-----w- c:\windows\system32\LogFiles
2009-12-17 12:29 . 2009-12-17 12:40 -------- d-----w- c:\documents and settings\Vilo\Application Data\Sony
2009-12-14 19:34 . 2009-12-14 19:34 -------- d-----w- c:\windows\Application Data
2009-12-14 19:33 . 2009-12-14 19:34 -------- d-----w- c:\program files\Clarus
2009-12-09 18:02 . 2009-12-09 18:07 -------- d-----w- c:\program files\AutoCAD 2008
2009-12-09 18:00 . 2009-12-09 18:00 -------- d-----w- c:\program files\Autodesk
2009-12-09 17:48 . 2009-12-09 17:48 -------- d--h--w- c:\windows\PIF
2009-12-09 17:18 . 2009-12-09 17:18 -------- d-----w- C:\Autodesk
2009-12-09 15:11 . 2009-12-09 15:11 36864 ----a-w- c:\documents and settings\Vilo\Application Data\Autodesk\AutoCAD 2010\R18.0\enu\ContextualTabSelectorRules.dll
2009-12-09 15:10 . 2009-12-09 15:10 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-09 15:04 . 2009-12-09 15:04 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-09 14:58 . 2008-03-05 14:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-12-09 14:58 . 2008-02-05 22:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-12-09 14:58 . 2008-03-05 14:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-12-09 14:58 . 2009-12-09 14:58 -------- d-----w- c:\windows\Logs
2009-12-09 09:21 . 2009-12-09 09:21 -------- d-----w- c:\program files\trend micro
2009-12-09 09:21 . 2009-12-09 09:21 -------- d-----w- C:\rsit
2009-12-09 08:57 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-12-08 23:03 . 2009-12-09 14:55 158528 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-08 23:02 . 2009-12-09 14:53 -------- d-----w- c:\windows\system32\XPSViewer
2009-12-08 23:01 . 2009-12-08 23:01 -------- d-----w- c:\program files\Reference Assemblies
2009-12-08 23:01 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-12-08 23:01 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-12-08 23:01 . 2007-11-30 11:18 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-07 20:52 . 2001-12-06 05:00 26112 ----a-r- c:\windows\LgUninst.exe
2009-12-07 20:48 . 2009-12-07 20:48 -------- d-----w- c:\program files\Lingea
2009-12-06 12:43 . 2009-12-06 12:43 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Help
2009-12-01 16:34 . 2009-12-01 16:34 -------- d-----w- c:\program files\AB Studio
2009-12-01 16:04 . 2009-12-09 14:22 -------- d-----w- C:\C_DILLA
2009-12-01 16:04 . 2000-10-20 12:25 487184 ----a-w- c:\windows\system32\Mrt7enu.dll
2009-12-01 16:04 . 2000-10-20 12:25 31744 ----a-w- c:\windows\system32\Hlp95en.dll
2009-12-01 16:04 . 2000-10-20 12:25 79360 ----a-w- c:\windows\system32\acdbres.dll
2009-12-01 16:03 . 2000-10-20 12:25 299520 ----a-w- c:\windows\uninst.exe
2009-12-01 16:03 . 2009-12-01 16:03 -------- d-----w- c:\documents and settings\Vilo\WINDOWS
2009-11-30 11:22 . 2009-12-15 09:36 -------- d-----w- c:\program files\NEXIS32-2
2009-11-26 13:22 . 2004-08-03 21:58 7552 -c--a-w- c:\windows\system32\dllcache\mskssrv.sys
2009-11-26 13:22 . 2004-08-03 21:58 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 17:07 . 2009-12-20 17:07 0 ------w- c:\windows\system32\bcmD1.tmp
2009-12-20 13:57 . 2009-11-13 16:03 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-17 13:58 . 2009-11-19 11:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\Skype
2009-12-17 12:28 . 2009-11-19 11:07 -------- d-----w- c:\documents and settings\Vilo\Application Data\skypePM
2009-12-16 15:17 . 2009-11-13 15:43 -------- d-----w- c:\documents and settings\Vilo\Application Data\vlc
2009-12-15 09:41 . 2009-11-18 08:22 -------- d-----w- c:\program files\NEXIS32
2009-12-14 19:33 . 2009-11-13 14:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-09 18:10 . 2009-11-13 15:22 100024 ----a-w- c:\documents and settings\Vilo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-09 18:05 . 2009-11-13 16:30 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-12-09 18:02 . 2009-11-13 16:34 -------- d-----w- c:\documents and settings\Vilo\Application Data\Autodesk
2009-12-09 18:02 . 2009-11-13 16:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-12-09 18:01 . 2009-11-13 14:55 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-08 23:03 . 2009-11-19 12:29 -------- d-----w- c:\documents and settings\Vilo\Application Data\DNA
2009-12-08 22:27 . 2009-11-19 12:29 -------- d-----w- c:\program files\DNA
2009-11-30 08:13 . 2009-11-13 16:02 -------- d-----w- c:\program files\totalcmd
2009-11-25 12:36 . 2009-11-19 12:30 -------- d-----w- c:\documents and settings\Vilo\Application Data\BitTorrent
2009-11-23 18:44 . 2009-11-13 15:43 -------- d-----w- c:\program files\The KMPlayer
2009-11-22 14:12 . 2009-11-13 16:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\BSplayer
2009-11-20 16:47 . 2009-11-19 11:04 -------- d-----w- c:\program files\Skype
2009-11-19 12:30 . 2009-11-19 12:29 -------- d-----w- c:\program files\BitTorrent
2009-11-19 11:07 . 2009-11-19 11:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-11-19 11:04 . 2009-11-19 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-11-19 11:04 . 2009-11-19 11:04 -------- d-----w- c:\program files\Common Files\Skype
2009-11-17 12:07 . 2009-11-17 12:07 -------- d-----w- c:\program files\Valentin EnergieSoftware
2009-11-17 12:07 . 2009-11-17 12:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Valentin EnergieSoftware
2009-11-17 12:07 . 2009-11-17 12:04 -------- d-----w- c:\program files\Common Files\Nemetschek
2009-11-17 12:03 . 2009-11-17 12:03 -------- d-----w- c:\program files\Nemetschek
2009-11-15 14:28 . 2009-11-15 14:12 -------- d-----w- c:\program files\Revit Architecture 2009
2009-11-15 12:21 . 2009-11-15 12:21 -------- d-----w- c:\documents and settings\Vilo\Application Data\Winamp
2009-11-15 12:21 . 2009-11-15 12:21 -------- d-----w- c:\program files\Winamp
2009-11-13 16:24 . 2009-11-13 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-13 16:22 . 2009-11-13 16:22 -------- d-----w- c:\program files\Microsoft Works
2009-11-13 16:22 . 2009-11-13 16:22 -------- d-----w- c:\program files\MSBuild
2009-11-13 16:21 . 2009-11-13 16:21 -------- d-----w- c:\program files\Microsoft.NET
2009-11-13 16:19 . 2009-11-13 16:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-13 16:18 . 2009-11-13 16:18 -------- d-----w- c:\program files\NOS
2009-11-13 16:18 . 2009-11-13 16:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-13 16:14 . 2009-11-13 16:14 -------- d-----w- c:\documents and settings\Vilo\Application Data\DAEMON Tools
2009-11-13 16:14 . 2009-11-13 16:14 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-13 16:12 . 2009-11-13 16:12 715248 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-13 16:08 . 2009-11-13 16:06 -------- d-----w- c:\program files\ICQ6.5
2009-11-13 16:07 . 2009-11-13 16:06 -------- d-----w- c:\documents and settings\Vilo\Application Data\ICQ
2009-11-13 16:05 . 2009-11-13 16:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\BSplayer Pro
2009-11-13 16:05 . 2009-11-13 16:05 -------- d-----w- c:\program files\Webteh
2009-11-13 16:04 . 2009-11-13 16:04 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-13 16:01 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\Vilo\Application Data\ACD Systems
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\Vilo\Application Data\ESTsoft
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ESTsoft
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\program files\ESTsoft
2009-11-13 15:59 . 2009-11-13 15:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-13 15:59 . 2009-11-13 15:59 -------- d-----w- c:\program files\Java
2009-11-13 15:53 . 2009-11-13 15:53 0 ----a-w- c:\windows\nsreg.dat
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\program files\ACD Systems
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-11-13 15:41 . 2009-11-13 15:41 -------- d-----w- c:\program files\VideoLAN
2009-11-13 15:40 . 2009-11-13 15:40 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-13 15:39 . 2009-11-13 15:39 -------- d-----w- c:\program files\CCleaner
2009-11-13 15:31 . 2009-11-13 15:31 -------- d-----w- c:\documents and settings\Vilo\Application Data\IObit
2009-11-13 15:31 . 2009-11-13 15:31 -------- d-----w- c:\program files\IObit
2009-11-13 15:30 . 2009-11-13 15:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-13 15:28 . 2009-11-13 15:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-13 15:24 . 2009-11-13 15:24 -------- d-----w- c:\documents and settings\Vilo\Application Data\ESET
2009-11-13 15:23 . 2009-11-13 15:23 -------- d-----w- c:\program files\ESET
2009-11-13 15:23 . 2009-11-13 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-13 15:21 . 2009-11-13 15:21 -------- d-----w- c:\documents and settings\Vilo\Application Data\ATI
2009-11-13 15:19 . 2009-11-13 15:11 -------- d-----w- c:\program files\ATI Technologies
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{F868ADD5-65FC-97FB-D083-096292FA6E2F}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{B9F49E54-FEF1-1940-CA96-73DADDFEF2A2}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C29B157B-96F6-AEBC-B2A4-001ABB08B1D1}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C084FA87-793F-9590-C96B-9DE325C5FA6E}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C346B1F7-277F-8C0E-8961-56E6D543AA54}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{BAFCD194-FBC5-EA66-02E3-A44EBFAB7E27}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{2FA1A75E-AE60-FA59-D036-366D7F00B567}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C4E60A38-F0C1-AD6B-E130-CE214C98BD4B}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{14359DB5-5F07-6773-3E17-C7388229CCFC}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{D08C5590-7875-0E44-65EE-EE1D9C4A6FB1}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{DE8AC8C4-D7D2-D6A7-B28B-9043DD65AA09}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{921F7EF3-D850-9CB6-2811-180F7AC1358B}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{FE055AD6-C23A-B1B8-C0E6-A45C177E2E03}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{B48DBEEB-9EEF-9F27-E1D8-339340FC7178}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{6E0A0C2C-7D63-9786-6519-C94C9EC22599}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{611131AF-3475-B625-A987-9FBEA8584D39}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{F88F9DF7-042F-80D3-8883-19A8BF2A9DC7}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{8CF86054-49F7-D6E0-078A-CF7E2C03F487}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{0CCF6926-479F-FE86-FE27-9C944A8D242C}\ARPPRODUCTICON.exe
2009-11-13 15:14 . 2009-11-13 15:14 -------- d-----w- c:\program files\Digital Line Detect
2009-11-13 15:13 . 2009-11-13 15:13 -------- d-----w- c:\documents and settings\Vilo\Application Data\Dell
2009-11-13 15:13 . 2009-11-13 14:54 -------- d-----w- c:\program files\Dell
2009-11-13 15:12 . 2009-11-13 15:12 -------- d-----w- c:\documents and settings\Vilo\Application Data\InstallShield
2009-11-13 15:07 . 2009-11-13 15:07 -------- d-----w- c:\program files\Broadcom
2009-11-13 15:05 . 2009-11-13 15:05 -------- d-----w- c:\program files\Synaptics
2009-11-13 15:02 . 2009-11-13 15:02 -------- d-----w- c:\program files\AMD
2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\CONEXANT
2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\DIFX
2009-11-13 14:55 . 2009-11-13 14:55 -------- d-----w- c:\program files\SigmaTel
2009-11-13 14:54 . 2009-11-13 14:54 45056 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2009-11-13 14:54 . 2009-11-13 14:54 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2009-11-13 14:26 . 2009-11-13 13:46 5194 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-11-13 14:26 . 2009-11-13 13:46 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
.

------- Sigcheck -------

[-] 2004-08-22 . 09EB23A4567BDD56D9580A059E616E23 . 359040 . . [5.1.2600.2505] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 11:58 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-11-04 2334856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-29 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-13 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-11-13 50688]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 15:18 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [9.4.2009 15:19 731840]
S2 MSR Service;Virtual Disk Service Manager;c:\program files\Clarus\Samsung SecretZone\MSSvc.exe [14.12.2009 20:34 114688]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.11.2009 17:12 715248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Connection Wizard,ShellNext = hxxp://download.cnet.com/Advanced-SystemCare-Free/3000-2086_4-10407614.html?part=dl-6271865&subj=dl&tag=button
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file://c:\program files\AutoCAD 2002 Cz\InstFred.ocx
DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\AutoCAD 2002 Cz\InstBanr.ocx
FF - ProfilePath - c:\documents and settings\Vilo\Application Data\Mozilla\Firefox\Profiles\lrrfjurd.default\
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-20 21:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1100)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-12-20 21:10:57
ComboFix-quarantined-files.txt 2009-12-20 20:10

Pre-Run: 844 316 672 bytes free
Post-Run: 1 298 403 328 voľných bajtov

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - DA29B9434286693BABC81AEDFC8A5956

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#6 Příspěvek od meteorolog »

otevřte poznámkový blok (Notepad) a zkopírujte do něj následující text:
KillAll::
File::
c:\windows\system32\bcmD1.tmp

Folder::
c:\program files\AskBarDis

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

DDS::
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Connection Wizard,ShellNext = hxxp://download.cnet.com/Advanced-Syste ... tag=button
Extra::
Firefox::
FF - ProfilePath - c:\documents and settings\Vilo\Application Data\Mozilla\Firefox\Profiles\lrrfjurd.default\
Soubor uložte na plochu jako CFScript.txt a podle obrázku přetáhněte nad ComboFix

Obrázek

spustí se ComboFix a vykoná příkaz ze skriptu - potom pošlete nový log
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#7 Příspěvek od zack111 »

ComboFix 09-12-19.03 - Vilo 21.12.2009 11:21:45.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.894.494 [GMT 1:00]
Running from: d:\my downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Vilo\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active


FILE ::
"c:\windows\system32\bcmD1.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\windows\system32\bcmD1.tmp

.
((((((((((((((((((((((((( Files Created from 2009-11-21 to 2009-12-21 )))))))))))))))))))))))))))))))
.

2009-12-20 17:26 . 2009-12-20 17:26 -------- d-----w- C:\For vilo
2009-12-20 17:10 . 2007-03-16 17:10 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS
2009-12-20 17:10 . 2007-03-16 17:10 86016 ----a-w- c:\windows\system32\preflib.dll
2009-12-20 17:10 . 2007-03-16 17:10 44032 ----a-w- c:\windows\system32\wltrynt.dll
2009-12-20 17:10 . 2007-03-16 17:10 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2009-12-20 17:10 . 2007-03-16 17:10 253952 ----a-w- c:\windows\system32\bcmwlu00.exe
2009-12-20 17:10 . 2007-03-16 17:10 1392640 ----a-w- c:\windows\system32\WLTRAY.EXE
2009-12-20 17:10 . 2007-03-16 17:10 1253376 ----a-w- c:\windows\system32\BCMWLTRY.EXE
2009-12-20 17:10 . 2007-03-16 17:10 20480 ----a-w- c:\windows\system32\WLTRYSVC.EXE
2009-12-20 17:10 . 2007-03-16 17:10 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2009-12-20 17:10 . 2007-03-16 17:10 757760 ----a-w- c:\windows\system32\bcm1xsup.dll
2009-12-20 14:08 . 2009-12-20 14:08 -------- d-----w- c:\program files\Foxit Software
2009-12-20 14:08 . 2009-12-20 14:08 -------- d-----w- c:\documents and settings\Vilo\Application Data\Foxit
2009-12-17 12:41 . 2009-12-17 12:41 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Sony
2009-12-17 12:39 . 2009-12-17 12:39 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-12-17 12:38 . 2009-12-17 12:38 -------- d-----w- c:\program files\Sony
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\Common Files\Apple
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\QuickTime
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Apple
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\program files\Apple Software Update
2009-12-17 12:35 . 2009-12-17 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-17 12:34 . 2009-12-17 12:34 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Apple Computer
2009-12-17 12:32 . 2009-12-17 12:42 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-12-17 12:32 . 2009-12-17 12:32 -------- d-----w- c:\windows\system32\LogFiles
2009-12-17 12:29 . 2009-12-17 12:40 -------- d-----w- c:\documents and settings\Vilo\Application Data\Sony
2009-12-14 19:34 . 2009-12-14 19:34 -------- d-----w- c:\windows\Application Data
2009-12-14 19:33 . 2009-12-14 19:34 -------- d-----w- c:\program files\Clarus
2009-12-09 18:02 . 2009-12-09 18:07 -------- d-----w- c:\program files\AutoCAD 2008
2009-12-09 18:00 . 2009-12-09 18:00 -------- d-----w- c:\program files\Autodesk
2009-12-09 17:48 . 2009-12-09 17:48 -------- d--h--w- c:\windows\PIF
2009-12-09 17:18 . 2009-12-09 17:18 -------- d-----w- C:\Autodesk
2009-12-09 15:11 . 2009-12-09 15:11 36864 ----a-w- c:\documents and settings\Vilo\Application Data\Autodesk\AutoCAD 2010\R18.0\enu\ContextualTabSelectorRules.dll
2009-12-09 15:10 . 2009-12-09 15:10 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-09 15:04 . 2009-12-09 15:04 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-09 14:58 . 2008-03-05 14:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-12-09 14:58 . 2008-02-05 22:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-12-09 14:58 . 2008-03-05 14:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-12-09 14:58 . 2009-12-09 14:58 -------- d-----w- c:\windows\Logs
2009-12-09 09:21 . 2009-12-09 09:21 -------- d-----w- c:\program files\trend micro
2009-12-09 09:21 . 2009-12-09 09:21 -------- d-----w- C:\rsit
2009-12-09 08:57 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-12-08 23:03 . 2009-12-09 14:55 158528 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-08 23:02 . 2009-12-09 14:53 -------- d-----w- c:\windows\system32\XPSViewer
2009-12-08 23:01 . 2009-12-08 23:01 -------- d-----w- c:\program files\Reference Assemblies
2009-12-08 23:01 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-12-08 23:01 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-12-08 23:01 . 2007-11-30 11:18 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-07 20:52 . 2001-12-06 05:00 26112 ----a-r- c:\windows\LgUninst.exe
2009-12-07 20:48 . 2009-12-07 20:48 -------- d-----w- c:\program files\Lingea
2009-12-06 12:43 . 2009-12-06 12:43 -------- d-----w- c:\documents and settings\Vilo\Local Settings\Application Data\Help
2009-12-01 16:34 . 2009-12-01 16:34 -------- d-----w- c:\program files\AB Studio
2009-12-01 16:04 . 2009-12-09 14:22 -------- d-----w- C:\C_DILLA
2009-12-01 16:04 . 2000-10-20 12:25 487184 ----a-w- c:\windows\system32\Mrt7enu.dll
2009-12-01 16:04 . 2000-10-20 12:25 31744 ----a-w- c:\windows\system32\Hlp95en.dll
2009-12-01 16:04 . 2000-10-20 12:25 79360 ----a-w- c:\windows\system32\acdbres.dll
2009-12-01 16:03 . 2000-10-20 12:25 299520 ----a-w- c:\windows\uninst.exe
2009-12-01 16:03 . 2009-12-01 16:03 -------- d-----w- c:\documents and settings\Vilo\WINDOWS
2009-11-30 11:22 . 2009-12-15 09:36 -------- d-----w- c:\program files\NEXIS32-2
2009-11-26 13:22 . 2004-08-03 21:58 7552 -c--a-w- c:\windows\system32\dllcache\mskssrv.sys
2009-11-26 13:22 . 2004-08-03 21:58 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 13:57 . 2009-11-13 16:03 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-17 13:58 . 2009-11-19 11:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\Skype
2009-12-17 12:28 . 2009-11-19 11:07 -------- d-----w- c:\documents and settings\Vilo\Application Data\skypePM
2009-12-16 15:17 . 2009-11-13 15:43 -------- d-----w- c:\documents and settings\Vilo\Application Data\vlc
2009-12-15 09:41 . 2009-11-18 08:22 -------- d-----w- c:\program files\NEXIS32
2009-12-14 19:33 . 2009-11-13 14:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-09 18:10 . 2009-11-13 15:22 100024 ----a-w- c:\documents and settings\Vilo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-09 18:05 . 2009-11-13 16:30 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-12-09 18:02 . 2009-11-13 16:34 -------- d-----w- c:\documents and settings\Vilo\Application Data\Autodesk
2009-12-09 18:02 . 2009-11-13 16:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-12-09 18:01 . 2009-11-13 14:55 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-08 23:03 . 2009-11-19 12:29 -------- d-----w- c:\documents and settings\Vilo\Application Data\DNA
2009-12-08 22:27 . 2009-11-19 12:29 -------- d-----w- c:\program files\DNA
2009-11-30 08:13 . 2009-11-13 16:02 -------- d-----w- c:\program files\totalcmd
2009-11-25 12:36 . 2009-11-19 12:30 -------- d-----w- c:\documents and settings\Vilo\Application Data\BitTorrent
2009-11-23 18:44 . 2009-11-13 15:43 -------- d-----w- c:\program files\The KMPlayer
2009-11-22 14:12 . 2009-11-13 16:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\BSplayer
2009-11-20 16:47 . 2009-11-19 11:04 -------- d-----w- c:\program files\Skype
2009-11-19 12:30 . 2009-11-19 12:29 -------- d-----w- c:\program files\BitTorrent
2009-11-19 11:07 . 2009-11-19 11:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-11-19 11:04 . 2009-11-19 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-11-19 11:04 . 2009-11-19 11:04 -------- d-----w- c:\program files\Common Files\Skype
2009-11-17 12:07 . 2009-11-17 12:07 -------- d-----w- c:\program files\Valentin EnergieSoftware
2009-11-17 12:07 . 2009-11-17 12:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Valentin EnergieSoftware
2009-11-17 12:07 . 2009-11-17 12:04 -------- d-----w- c:\program files\Common Files\Nemetschek
2009-11-17 12:03 . 2009-11-17 12:03 -------- d-----w- c:\program files\Nemetschek
2009-11-15 14:28 . 2009-11-15 14:12 -------- d-----w- c:\program files\Revit Architecture 2009
2009-11-15 12:21 . 2009-11-15 12:21 -------- d-----w- c:\documents and settings\Vilo\Application Data\Winamp
2009-11-15 12:21 . 2009-11-15 12:21 -------- d-----w- c:\program files\Winamp
2009-11-13 16:24 . 2009-11-13 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-13 16:22 . 2009-11-13 16:22 -------- d-----w- c:\program files\Microsoft Works
2009-11-13 16:22 . 2009-11-13 16:22 -------- d-----w- c:\program files\MSBuild
2009-11-13 16:21 . 2009-11-13 16:21 -------- d-----w- c:\program files\Microsoft.NET
2009-11-13 16:19 . 2009-11-13 16:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-13 16:18 . 2009-11-13 16:18 -------- d-----w- c:\program files\NOS
2009-11-13 16:18 . 2009-11-13 16:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-13 16:14 . 2009-11-13 16:14 -------- d-----w- c:\documents and settings\Vilo\Application Data\DAEMON Tools
2009-11-13 16:14 . 2009-11-13 16:14 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-13 16:12 . 2009-11-13 16:12 715248 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-13 16:08 . 2009-11-13 16:06 -------- d-----w- c:\program files\ICQ6.5
2009-11-13 16:07 . 2009-11-13 16:06 -------- d-----w- c:\documents and settings\Vilo\Application Data\ICQ
2009-11-13 16:05 . 2009-11-13 16:05 -------- d-----w- c:\documents and settings\Vilo\Application Data\BSplayer Pro
2009-11-13 16:05 . 2009-11-13 16:05 -------- d-----w- c:\program files\Webteh
2009-11-13 16:04 . 2009-11-13 16:04 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-13 16:01 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\Vilo\Application Data\ACD Systems
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\Vilo\Application Data\ESTsoft
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ESTsoft
2009-11-13 16:00 . 2009-11-13 16:00 -------- d-----w- c:\program files\ESTsoft
2009-11-13 15:59 . 2009-11-13 15:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-13 15:59 . 2009-11-13 15:59 -------- d-----w- c:\program files\Java
2009-11-13 15:53 . 2009-11-13 15:53 0 ----a-w- c:\windows\nsreg.dat
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\program files\ACD Systems
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-11-13 15:49 . 2009-11-13 15:49 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-11-13 15:41 . 2009-11-13 15:41 -------- d-----w- c:\program files\VideoLAN
2009-11-13 15:40 . 2009-11-13 15:40 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-13 15:39 . 2009-11-13 15:39 -------- d-----w- c:\program files\CCleaner
2009-11-13 15:31 . 2009-11-13 15:31 -------- d-----w- c:\documents and settings\Vilo\Application Data\IObit
2009-11-13 15:31 . 2009-11-13 15:31 -------- d-----w- c:\program files\IObit
2009-11-13 15:30 . 2009-11-13 15:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-13 15:28 . 2009-11-13 15:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-13 15:24 . 2009-11-13 15:24 -------- d-----w- c:\documents and settings\Vilo\Application Data\ESET
2009-11-13 15:23 . 2009-11-13 15:23 -------- d-----w- c:\program files\ESET
2009-11-13 15:23 . 2009-11-13 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-11-13 15:21 . 2009-11-13 15:21 -------- d-----w- c:\documents and settings\Vilo\Application Data\ATI
2009-11-13 15:19 . 2009-11-13 15:11 -------- d-----w- c:\program files\ATI Technologies
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{F868ADD5-65FC-97FB-D083-096292FA6E2F}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{B9F49E54-FEF1-1940-CA96-73DADDFEF2A2}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C29B157B-96F6-AEBC-B2A4-001ABB08B1D1}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C084FA87-793F-9590-C96B-9DE325C5FA6E}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C346B1F7-277F-8C0E-8961-56E6D543AA54}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{BAFCD194-FBC5-EA66-02E3-A44EBFAB7E27}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{2FA1A75E-AE60-FA59-D036-366D7F00B567}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{C4E60A38-F0C1-AD6B-E130-CE214C98BD4B}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{14359DB5-5F07-6773-3E17-C7388229CCFC}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{D08C5590-7875-0E44-65EE-EE1D9C4A6FB1}\ARPPRODUCTICON.exe
2009-11-13 15:19 . 2009-11-13 15:19 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{DE8AC8C4-D7D2-D6A7-B28B-9043DD65AA09}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{921F7EF3-D850-9CB6-2811-180F7AC1358B}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{FE055AD6-C23A-B1B8-C0E6-A45C177E2E03}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{B48DBEEB-9EEF-9F27-E1D8-339340FC7178}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{6E0A0C2C-7D63-9786-6519-C94C9EC22599}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{611131AF-3475-B625-A987-9FBEA8584D39}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{F88F9DF7-042F-80D3-8883-19A8BF2A9DC7}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{8CF86054-49F7-D6E0-078A-CF7E2C03F487}\ARPPRODUCTICON.exe
2009-11-13 15:18 . 2009-11-13 15:18 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{0CCF6926-479F-FE86-FE27-9C944A8D242C}\ARPPRODUCTICON.exe
2009-11-13 15:14 . 2009-11-13 15:14 -------- d-----w- c:\program files\Digital Line Detect
2009-11-13 15:13 . 2009-11-13 15:13 -------- d-----w- c:\documents and settings\Vilo\Application Data\Dell
2009-11-13 15:13 . 2009-11-13 14:54 -------- d-----w- c:\program files\Dell
2009-11-13 15:12 . 2009-11-13 15:12 -------- d-----w- c:\documents and settings\Vilo\Application Data\InstallShield
2009-11-13 15:07 . 2009-11-13 15:07 -------- d-----w- c:\program files\Broadcom
2009-11-13 15:05 . 2009-11-13 15:05 -------- d-----w- c:\program files\Synaptics
2009-11-13 15:02 . 2009-11-13 15:02 -------- d-----w- c:\program files\AMD
2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\CONEXANT
2009-11-13 15:01 . 2009-11-13 15:01 -------- d-----w- c:\program files\DIFX
2009-11-13 14:55 . 2009-11-13 14:55 -------- d-----w- c:\program files\SigmaTel
2009-11-13 14:54 . 2009-11-13 14:54 45056 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2009-11-13 14:54 . 2009-11-13 14:54 10134 ----a-r- c:\documents and settings\Vilo\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2009-11-13 14:26 . 2009-11-13 13:46 5194 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-11-13 14:26 . 2009-11-13 13:46 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-13 14:25 . 2009-11-13 13:46 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
.

------- Sigcheck -------

[-] 2004-08-22 . 09EB23A4567BDD56D9580A059E616E23 . 359040 . . [5.1.2600.2505] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-12-20_20.09.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-21 10:27 . 2009-12-21 10:27 16384 c:\windows\temp\Perflib_Perfdata_1ec.dat
+ 2001-08-23 15:00 . 2009-12-21 09:13 68490 c:\windows\system32\perfc009.dat
- 2001-08-23 15:00 . 2009-12-20 19:47 68490 c:\windows\system32\perfc009.dat
+ 2001-08-23 15:00 . 2009-12-21 09:13 435594 c:\windows\system32\perfh009.dat
- 2001-08-23 15:00 . 2009-12-20 19:47 435594 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-11-04 2334856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-29 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-13 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-11-13 50688]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 15:18 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [9.4.2009 15:19 731840]
R2 MSR Service;Virtual Disk Service Manager;c:\program files\Clarus\Samsung SecretZone\MSSvc.exe [14.12.2009 20:34 114688]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.11.2009 17:12 715248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file://c:\program files\AutoCAD 2002 Cz\InstFred.ocx
DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\AutoCAD 2002 Cz\InstBanr.ocx
FF - ProfilePath - c:\documents and settings\Vilo\Application Data\Mozilla\Firefox\Profiles\lrrfjurd.default\
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-21 11:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1108)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(3792)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\stsystra.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-12-21 11:30:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-21 10:30
ComboFix2.txt 2009-12-20 20:10

Pre-Run: 1 276 755 968 bytes free
Post-Run: 1 245 593 600 voľných bajtov

- - End Of File - - B97C997542BE475E7C34E95BD425554A

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#8 Příspěvek od meteorolog »

v pořádku :-)

na dočištění použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter
(utilita může být označena antivirem jako vir - po použití ji smažte)

potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů

a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:

po spuštění staženého souboru se objeví okno:

Obrázek

zatrhněte Select All, klikněte na Empty Selected a Exit

stejným způsobem vymažte případně cache Firefoxu a Opery :-)

restartujte PC
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#9 Příspěvek od zack111 »

diki moc za ochotu, cenim si to....uvidime či sa ešte niekedy ukaže ten concficker....diki ešte raz :-)

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#10 Příspěvek od meteorolog »

nemáte zač :)
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#11 Příspěvek od zack111 »

zdravim......zase mi počitač napada conficker.AA, rovnako ako predtym, ked vypnem eset firewall tak sa po chvili zobrazi ozamenie že conficker bol zmazany, formatoval som aj disk kvôli tomu no nepomohlo. Neviete niekto ako sa toho zbaviť??odkiaľ ma to napada??? skušal som nastaviť esetfirewall a pridať tam vynimku pre VLC aby som nemusel vypinať fw no nefunguje to, vlc aj tak nejde ked je zapnuty fw....popripade neviete niekto ako nastaviť fw aby šlo vlc?? napr. dc++ mi ide bez problemov ked vo fw pridam vynimku....vopred diiik za radu

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#12 Příspěvek od meteorolog »

pošlete nový log z Combofix
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#13 Příspěvek od zack111 »

ComboFix 10-02-28.04 - VILEC 01.03.2010 18:04:01.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.894.514 [GMT 1:00]
Running from: c:\documents and settings\VILEC\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2010-02-01 to 2010-03-01 )))))))))))))))))))))))))))))))
.

2010-02-26 15:48 . 2010-02-26 15:54 -------- d-----w- c:\program files\Common Files\AB Studio Shared
2010-02-26 15:48 . 2010-02-26 15:48 -------- d-----w- c:\program files\AB Studio
2010-02-26 15:48 . 1998-10-09 17:04 327168 ----a-w- c:\windows\IsUn0405.exe
2010-02-26 15:34 . 2010-02-26 15:34 -------- d-----w- c:\program files\Common Files\Wextech Shared
2010-02-26 15:15 . 2010-02-26 15:38 -------- d-----w- C:\C_DILLA
2010-02-26 15:14 . 2000-10-20 12:25 299520 ----a-w- c:\windows\uninst.exe
2010-02-26 15:14 . 2010-02-26 15:14 -------- d-----w- c:\documents and settings\VILEC\WINDOWS
2010-02-26 15:13 . 2010-02-26 15:47 -------- d-----w- c:\program files\AutoCAD 2002 Cz
2010-02-24 10:51 . 2010-02-24 10:51 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\ESET
2010-02-23 21:31 . 2010-02-23 21:32 -------- d-----w- c:\program files\PDFCreator
2010-02-23 18:57 . 2010-02-23 18:57 48 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-02-23 18:57 . 2010-02-24 13:50 -------- d-----w- c:\documents and settings\VILEC\Application Data\skypePM
2010-02-22 20:13 . 2010-02-22 20:14 -------- d-----w- c:\program files\Counter-Strike 1.6
2010-02-21 22:48 . 2010-02-21 22:48 -------- d-----w- c:\program files\Clarus
2010-02-21 21:47 . 2010-02-21 21:47 -------- d-----w- c:\documents and settings\Vilo
2010-02-21 21:34 . 2010-02-21 21:34 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2010-02-21 20:14 . 2010-02-28 23:03 -------- d-----w- c:\documents and settings\VILEC\Application Data\vlc
2010-02-20 22:44 . 2004-08-04 00:56 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-02-20 20:51 . 2010-02-20 20:51 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\Adobe
2010-02-20 19:52 . 2010-02-20 19:52 -------- d-----w- c:\program files\Autodesk
2010-02-20 19:46 . 2010-02-20 19:54 -------- d-----w- c:\program files\Revit Architecture 2009
2010-02-20 19:13 . 2010-02-26 15:34 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-02-20 19:13 . 2010-02-23 07:05 -------- d-----w- c:\documents and settings\VILEC\Application Data\Autodesk
2010-02-20 19:13 . 2010-02-23 07:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2010-02-20 19:13 . 2010-02-21 10:05 -------- d-----w- c:\program files\AutoCAD 2009
2010-02-20 19:13 . 2010-02-20 20:48 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\Autodesk
2010-02-20 19:13 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2010-02-20 19:11 . 2010-02-28 20:51 753480 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-20 19:08 . 2010-02-20 19:08 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-20 19:07 . 2010-02-20 19:07 -------- d-----w- c:\program files\Reference Assemblies
2010-02-20 19:07 . 2006-10-14 15:43 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-20 19:07 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-02-20 19:06 . 2006-10-16 15:10 23856 ----a-w- c:\windows\system32\spupdsvc.exe
2010-02-20 19:02 . 2010-02-20 19:02 -------- d-----w- c:\documents and settings\VILEC\Application Data\ACD Systems
2010-02-20 18:49 . 2010-02-20 18:49 -------- d-----w- c:\program files\QuickTime
2010-02-20 18:49 . 2010-02-20 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-02-20 18:49 . 2010-02-20 18:49 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\Apple
2010-02-20 18:49 . 2010-02-20 18:49 -------- d-----w- c:\program files\Apple Software Update
2010-02-20 18:49 . 2010-02-20 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-02-20 18:48 . 2010-02-20 18:48 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\Apple Computer
2010-02-20 18:48 . 2008-04-13 16:26 36396 ----a-w- c:\documents and settings\VILEC\Application Data\BSplayer\AC3 Filter\uninstall.exe
2010-02-20 18:48 . 2007-08-18 08:53 16384 ----a-w- c:\documents and settings\VILEC\Application Data\BSplayer\AC3 Filter\dialog_patch.exe
2010-02-20 18:48 . 2007-07-05 02:33 892928 ----a-w- c:\documents and settings\VILEC\Application Data\BSplayer\AC3 Filter\iconv.dll
2010-02-20 18:48 . 2007-08-18 08:54 20480 ----a-w- c:\documents and settings\VILEC\Application Data\BSplayer\AC3 Filter\ac3config.exe
2010-02-20 18:47 . 2010-02-24 11:21 -------- d-----w- c:\documents and settings\VILEC\Application Data\BSplayer
2010-02-20 18:47 . 2010-02-20 18:47 -------- d-----w- c:\documents and settings\VILEC\Application Data\BSplayer Pro
2010-02-20 18:47 . 2010-02-20 18:47 -------- d-----w- c:\program files\Webteh
2010-02-20 18:45 . 2010-02-23 11:15 -------- d-----w- c:\program files\The KMPlayer
2010-02-20 18:43 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\divx.dll
2010-02-20 18:43 . 2009-10-13 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-20 18:43 . 2010-02-20 18:44 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-20 18:42 . 2010-02-24 19:11 -------- d-----w- c:\documents and settings\VILEC\Application Data\Skype
2010-02-20 18:42 . 2010-02-20 18:42 -------- d-----w- c:\program files\Skype
2010-02-20 18:42 . 2010-02-20 18:42 -------- d-----w- c:\program files\Common Files\Skype
2010-02-20 18:42 . 2010-02-20 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-02-20 18:39 . 2010-02-28 21:53 -------- d-----w- c:\documents and settings\VILEC\Application Data\ICQ
2010-02-20 18:38 . 2010-02-20 18:41 -------- d-----w- c:\program files\ICQ6.5
2010-02-20 18:34 . 2010-02-20 18:36 -------- d-----w- c:\documents and settings\VILEC\Application Data\Winamp
2010-02-20 18:34 . 2010-02-20 18:36 -------- d-----w- c:\program files\Winamp
2010-02-20 18:33 . 2010-02-20 18:33 -------- d-----w- c:\program files\VideoLAN
2010-02-20 18:32 . 2010-02-20 18:32 -------- d-----w- c:\program files\totalcmd
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\UC.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\RAR.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKZIP.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\LHA.PIF
2010-02-20 18:32 . 2007-09-05 06:02 545 ----a-w- c:\windows\ARJ.PIF
2010-02-20 18:31 . 2010-02-20 18:31 -------- d-----w- c:\windows\system32\Adobe
2010-02-20 18:31 . 2010-02-20 18:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-20 18:30 . 2010-02-20 18:30 -------- d-----w- c:\program files\Java
2010-02-20 18:28 . 2010-02-20 18:28 -------- d-----w- c:\documents and settings\VILEC\Application Data\ESTsoft
2010-02-20 18:28 . 2010-02-20 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ESTsoft
2010-02-20 18:28 . 2010-02-20 18:28 -------- d-----w- c:\program files\ESTsoft
2010-02-20 18:27 . 2010-02-20 18:27 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-20 18:26 . 2010-02-20 18:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-20 18:24 . 2010-02-20 18:24 -------- d-----w- c:\documents and settings\VILEC\Application Data\IObit
2010-02-20 18:24 . 2010-02-20 18:24 -------- d-----w- c:\program files\IObit
2010-02-20 18:23 . 2010-02-20 18:23 -------- d-----w- c:\program files\CCleaner
2010-02-20 18:22 . 2010-02-21 08:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-20 18:22 . 2010-02-20 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-20 18:12 . 2010-02-20 18:12 -------- d-----w- c:\documents and settings\VILEC\Application Data\ESET
2010-02-20 18:10 . 2010-02-20 18:10 -------- d-----w- c:\program files\ESET
2010-02-20 18:10 . 2010-02-20 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-02-20 18:06 . 2010-02-20 18:06 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2010-02-20 18:06 . 2010-02-20 18:06 -------- d-----w- c:\program files\ACD Systems
2010-02-20 18:06 . 2010-02-20 18:06 -------- d-----w- c:\program files\Common Files\ACD Systems
2010-02-20 18:05 . 2010-02-20 18:05 -------- d-----w- c:\windows\Downloaded Installations
2010-02-20 17:57 . 2010-02-20 17:57 -------- d-----w- c:\program files\Microsoft Works
2010-02-20 17:57 . 2010-02-20 19:11 -------- d-----w- c:\program files\MSBuild
2010-02-20 17:56 . 2010-02-20 17:56 -------- d-----w- c:\program files\Microsoft.NET
2010-02-20 17:54 . 2010-02-20 17:54 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-02-20 17:53 . 2010-02-20 17:57 -------- d-----w- c:\windows\SHELLNEW
2010-02-20 17:53 . 2010-02-20 17:53 -------- d-----w- c:\documents and settings\VILEC\Local Settings\Application Data\Microsoft Help
2010-02-20 17:53 . 2010-02-20 17:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-20 17:53 . 2010-02-20 17:53 -------- d-----r- C:\MSOCache
2010-02-20 17:50 . 2010-02-20 17:50 -------- d-----w- c:\documents and settings\VILEC\Application Data\DAEMON Tools
2010-02-20 17:49 . 2010-02-20 17:49 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-02-20 17:44 . 2010-02-20 17:44 715248 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-20 17:01 . 2004-08-03 22:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-02-20 17:01 . 2010-02-20 17:01 -------- d-----w- c:\documents and settings\VILEC\Application Data\Dell
2010-02-20 17:01 . 2005-08-12 16:50 16128 ----a-w- c:\windows\system32\drivers\APPDRV.SYS
2010-02-20 17:01 . 2010-02-20 17:01 -------- d-----w- c:\documents and settings\VILEC\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 15:19 . 2010-02-20 16:54 100472 ----a-w- c:\documents and settings\VILEC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-21 22:48 . 2010-02-20 16:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-20 18:44 . 2010-02-20 18:44 0 ----a-w- c:\windows\nsreg.dat
2010-02-20 17:01 . 2010-02-20 16:27 -------- d-----w- c:\program files\Dell
2010-02-20 16:56 . 2010-02-20 16:56 -------- d-----w- c:\program files\Lingea
2010-02-20 16:54 . 2010-02-20 16:54 -------- d-----w- c:\documents and settings\VILEC\Application Data\ATI
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{B48DBEEB-9EEF-9F27-E1D8-339340FC7178}\ARPPRODUCTICON.exe
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{6E0A0C2C-7D63-9786-6519-C94C9EC22599}\ARPPRODUCTICON.exe
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{611131AF-3475-B625-A987-9FBEA8584D39}\ARPPRODUCTICON.exe
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{F88F9DF7-042F-80D3-8883-19A8BF2A9DC7}\ARPPRODUCTICON.exe
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{8CF86054-49F7-D6E0-078A-CF7E2C03F487}\ARPPRODUCTICON.exe
2010-02-20 16:50 . 2010-02-20 16:50 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{0CCF6926-479F-FE86-FE27-9C944A8D242C}\ARPPRODUCTICON.exe
2010-02-20 16:41 . 2010-02-20 16:41 -------- d-----w- c:\program files\Broadcom
2010-02-20 16:39 . 2010-02-20 16:39 -------- d-----w- c:\program files\Synaptics
2010-02-20 16:38 . 2010-02-20 16:28 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-20 16:36 . 2010-02-20 16:36 -------- d-----w- c:\program files\AMD
2010-02-20 16:35 . 2010-02-20 16:35 -------- d-----w- c:\program files\CONEXANT
2010-02-20 16:34 . 2010-02-20 16:34 -------- d-----w- c:\program files\DIFX
2010-02-20 16:28 . 2010-02-20 16:28 -------- d-----w- c:\program files\SigmaTel
2010-02-20 16:27 . 2010-02-20 16:27 45056 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2010-02-20 16:27 . 2010-02-20 16:27 10134 ----a-r- c:\documents and settings\VILEC\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2010-02-20 16:22 . 2010-02-20 16:12 5194 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-20 16:22 . 2010-02-20 16:12 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-20 16:21 . 2010-02-20 16:13 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-02-20 16:14 . 2010-02-20 16:14 -------- d-----w- c:\program files\microsoft frontpage
2010-02-20 16:09 . 2010-02-20 16:09 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.

------- Sigcheck -------

[-] 2004-08-22 . 09EB23A4567BDD56D9580A059E616E23 . 359040 . . [5.1.2600.2505] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-29 486856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-20 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-10 385024]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 15:18 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [9.4.2009 15:19 731840]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.2.2010 18:44 715248]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.www.daemon-search.com/default
uInternet Connection Wizard,ShellNext = hxxp://www.www.daemon-search.com/default
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file://c:\program files\AutoCAD 2002 Cz\InstFred.ocx
DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\AutoCAD 2002 Cz\InstBanr.ocx
FF - ProfilePath - c:\documents and settings\VILEC\Application Data\Mozilla\Firefox\Profiles\bfukz6u5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-01 18:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1260)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(2552)
c:\windows\system32\msi.dll
.
Completion time: 2010-03-01 18:08:55
ComboFix-quarantined-files.txt 2010-03-01 17:08

Pre-Run: 7 865 335 808 bytes free
Post-Run: 7 912 308 736 voľných bajtov

- - End Of File - - 9BF7AD7299EEA21E0BCCC3B9214B0B0A

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: conficker.AA

#14 Příspěvek od meteorolog »

Confickera v logu nevidím, ale můžete mít poškozený boot sektor

:arrow: stáhněte MBR
http://www2.gmer.net/mbr/mbr.exe
- uložte ho na plochu
:arrow: start - spustit - napište
"%userprofile%\plocha\mbr.exe" -t
- vytvoří se log s názvem mbr.log, vložte ho sem
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

zack111
Návštěvník
Návštěvník
Příspěvky: 46
Registrován: 03 pro 2006 12:41

Re: conficker.AA

#15 Příspěvek od zack111 »

dufam že som to spravil dobre lebo jedine čo bolo v tom subore čo vytvoril mbr je toto:


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

Odpovědět