Avast hlásí - Win32-Alureon
Napsal: 02 bře 2010 20:29
Dobrý den,
Avast mi po významném zpomalení počítače nahlásil Win32-Alureon BQ, Cu, BH a ne se jich zbavit. Můžete mi prosím pomoci?
Přikládám log z ComboFixu
ComboFix 10-03-01.04 - Šárka Pechová 02.03.2010 18:06:21.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1471.971 [GMT 1:00]
Spuštěný z: c:\documents and settings\Šárka Pechová\Dokumenty\Stažené soubory\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: F-Secure Anti-Virus 2006 6.10 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Anti-Virus 2006 6.10 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-02 do 2010-03-02 )))))))))))))))))))))))))))))))
.
2010-03-02 00:14 . 2010-03-02 00:25 -------- d-----w- c:\program files\Smaž co chceš
2010-03-01 23:59 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-01 23:59 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-01 23:59 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-01 23:59 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-01 23:59 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-01 23:59 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-01 23:59 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-01 23:56 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-01 23:56 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-01 23:56 . 2010-03-01 23:56 -------- d-----w- c:\program files\Alwil Software
2010-03-01 19:14 . 2010-03-01 19:14 389632 ----a-w- c:\windows\system32\CF2138.exe
2010-02-09 21:08 . 2010-02-09 21:08 -------- d-----w- c:\windows\system32\MpEngineStore
2010-02-09 19:54 . 2010-02-14 12:49 -------- d-----w- c:\program files\Studio V5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 13:18 . 2007-09-06 18:33 -------- d-----w- c:\program files\DreamCom
2010-02-13 19:40 . 2008-09-20 21:02 -------- d-----w- c:\program files\Katalog filmů
2010-01-10 19:53 . 2010-01-10 19:53 -------- d-----w- c:\program files\gs
2010-01-08 20:07 . 2010-01-08 20:07 -------- d-----w- c:\program files\Electronic Arts
2010-01-08 19:52 . 2009-12-09 10:58 -------- d-----w- c:\program files\StormWare
2010-01-08 19:47 . 2010-01-08 19:47 -------- d-----w- c:\program files\directx
2010-01-08 19:35 . 2006-03-23 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-03 10:52 . 2008-11-26 21:16 -------- d-----w- c:\program files\ICQ6.5
2009-12-31 16:14 . 2001-10-25 13:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2002-09-20 17:05 663040 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-03-23 22:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 08:00 . 2006-03-23 21:16 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 22:11 . 2001-10-25 13:00 64830 ----a-w- c:\windows\system32\perfc005.dat
2009-12-14 22:11 . 2001-10-25 13:00 385714 ----a-w- c:\windows\system32\perfh005.dat
2009-12-14 07:37 . 2002-09-20 17:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 10:28 . 2002-09-20 17:12 2059904 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-09 10:28 . 2002-09-20 16:12 2182528 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-04 14:41 . 2002-08-29 00:59 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2006-12-31 14:11 . 2006-12-31 14:11 604 -c-ha-w- c:\program files\STLL Notifier
2005-01-29 07:53 . 2005-01-29 07:53 99840 --sha-r- c:\windows\canary-std.exe
2005-01-26 04:20 . 2005-01-26 13:07 49152 --sha-r- c:\windows\settings-std.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="mHotkey.exe" [2002-07-05 491008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\ć rka Pechov \Nabˇdka Start\Programy\Po spuçtŘnˇ\
winesm32.exe [2004-8-17 29184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=alcxnt.dll
"aux"=alcxnt.dll
"mixer1"=alcxnt.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^UltraVNC Server.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\UltraVNC Server.lnk
backup=c:\windows\pss\UltraVNC Server.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinVNC4"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\DreamCom\\DreamCom.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2.6.2009 12:03 70864]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2.3.2010 0:59 162512]
R1 SpyMng;SpyMng;c:\windows\system32\drivers\SpyMng.sys [11.10.2009 7:47 7552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.3.2010 0:59 19024]
R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [3.9.2002 19:31 19296]
S2 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [?]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys [?]
S2 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S3 KProcWatch;KProcWatch;\??\c:\windows\system32\drivers\KProcWatch.sys --> c:\windows\system32\drivers\KProcWatch.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [18.10.2006 15:13 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.10.2006 20:54 639224]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWSP
*NewlyCreated* - AVAST!_ANTIVIRUS
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: &Blokovat toto překryvné okno - c:\program files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Šárka Pechová\Data aplikací\Mozilla\Firefox\Profiles\5a0ww6q3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npcosmop211.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-02 18:30
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:őwjY*]
"DisplayName"="???\16?\11\09"
"DeviceDesc"="???\16?\11\09"
"ProviderName"="???\11?#@\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.5"
"DeviceInstanceIds"=multi:"d:\\ati\\rs480\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(564)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2088)
c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-02 18:39:30
ComboFix-quarantined-files.txt 2010-03-02 17:39
ComboFix2.txt 2010-03-01 20:16
Před spuštěním: 5 886 537 728
Po spuštění: 5 856 194 560
- - End Of File - - 90AD053A187D389585BC3D66C59DF599
Avast mi po významném zpomalení počítače nahlásil Win32-Alureon BQ, Cu, BH a ne se jich zbavit. Můžete mi prosím pomoci?
Přikládám log z ComboFixu
ComboFix 10-03-01.04 - Šárka Pechová 02.03.2010 18:06:21.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1471.971 [GMT 1:00]
Spuštěný z: c:\documents and settings\Šárka Pechová\Dokumenty\Stažené soubory\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: F-Secure Anti-Virus 2006 6.10 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Anti-Virus 2006 6.10 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-02 do 2010-03-02 )))))))))))))))))))))))))))))))
.
2010-03-02 00:14 . 2010-03-02 00:25 -------- d-----w- c:\program files\Smaž co chceš
2010-03-01 23:59 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-01 23:59 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-01 23:59 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-01 23:59 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-01 23:59 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-01 23:59 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-01 23:59 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-01 23:56 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-01 23:56 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-01 23:56 . 2010-03-01 23:56 -------- d-----w- c:\program files\Alwil Software
2010-03-01 19:14 . 2010-03-01 19:14 389632 ----a-w- c:\windows\system32\CF2138.exe
2010-02-09 21:08 . 2010-02-09 21:08 -------- d-----w- c:\windows\system32\MpEngineStore
2010-02-09 19:54 . 2010-02-14 12:49 -------- d-----w- c:\program files\Studio V5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 13:18 . 2007-09-06 18:33 -------- d-----w- c:\program files\DreamCom
2010-02-13 19:40 . 2008-09-20 21:02 -------- d-----w- c:\program files\Katalog filmů
2010-01-10 19:53 . 2010-01-10 19:53 -------- d-----w- c:\program files\gs
2010-01-08 20:07 . 2010-01-08 20:07 -------- d-----w- c:\program files\Electronic Arts
2010-01-08 19:52 . 2009-12-09 10:58 -------- d-----w- c:\program files\StormWare
2010-01-08 19:47 . 2010-01-08 19:47 -------- d-----w- c:\program files\directx
2010-01-08 19:35 . 2006-03-23 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-03 10:52 . 2008-11-26 21:16 -------- d-----w- c:\program files\ICQ6.5
2009-12-31 16:14 . 2001-10-25 13:00 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2002-09-20 17:05 663040 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2006-03-23 22:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 08:00 . 2006-03-23 21:16 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 22:11 . 2001-10-25 13:00 64830 ----a-w- c:\windows\system32\perfc005.dat
2009-12-14 22:11 . 2001-10-25 13:00 385714 ----a-w- c:\windows\system32\perfh005.dat
2009-12-14 07:37 . 2002-09-20 17:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 10:28 . 2002-09-20 17:12 2059904 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-09 10:28 . 2002-09-20 16:12 2182528 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-04 14:41 . 2002-08-29 00:59 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2006-12-31 14:11 . 2006-12-31 14:11 604 -c-ha-w- c:\program files\STLL Notifier
2005-01-29 07:53 . 2005-01-29 07:53 99840 --sha-r- c:\windows\canary-std.exe
2005-01-26 04:20 . 2005-01-26 13:07 49152 --sha-r- c:\windows\settings-std.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="mHotkey.exe" [2002-07-05 491008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\ć rka Pechov \Nabˇdka Start\Programy\Po spuçtŘnˇ\
winesm32.exe [2004-8-17 29184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=alcxnt.dll
"aux"=alcxnt.dll
"mixer1"=alcxnt.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^UltraVNC Server.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\UltraVNC Server.lnk
backup=c:\windows\pss\UltraVNC Server.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinVNC4"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\DreamCom\\DreamCom.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2.6.2009 12:03 70864]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2.3.2010 0:59 162512]
R1 SpyMng;SpyMng;c:\windows\system32\drivers\SpyMng.sys [11.10.2009 7:47 7552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.3.2010 0:59 19024]
R2 MLPTDR_C;MLPTDR_C;c:\windows\system32\MLPTDR_C.SYS [3.9.2002 19:31 19296]
S2 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [?]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys [?]
S2 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys --> c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S3 KProcWatch;KProcWatch;\??\c:\windows\system32\drivers\KProcWatch.sys --> c:\windows\system32\drivers\KProcWatch.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [18.10.2006 15:13 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.10.2006 20:54 639224]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWSP
*NewlyCreated* - AVAST!_ANTIVIRUS
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: &Blokovat toto překryvné okno - c:\program files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Šárka Pechová\Data aplikací\Mozilla\Firefox\Profiles\5a0ww6q3.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npcosmop211.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-02 18:30
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:őwjY*]
"DisplayName"="???\16?\11\09"
"DeviceDesc"="???\16?\11\09"
"ProviderName"="???\11?#@\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.5"
"DeviceInstanceIds"=multi:"d:\\ati\\rs480\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(564)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2088)
c:\documents and settings\Šárka Pechová\Data aplikací\Dropbox\bin\DropboxExt.3.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-02 18:39:30
ComboFix-quarantined-files.txt 2010-03-02 17:39
ComboFix2.txt 2010-03-01 20:16
Před spuštěním: 5 886 537 728
Po spuštění: 5 856 194 560
- - End Of File - - 90AD053A187D389585BC3D66C59DF599