kontrola logu,neprehrava stream videa
Napsal: 14 bře 2010 17:19
Prosim o kontrolu logu zkousel jsem neuspesne kde co ale nedari se mi vyresit problem s videama na youtube nacte se jen cca 1min videa a pak se to sekne zkousel jsem preinstal ovladace i jiny browser a nic tak mozna bude neco v tom logu snad jsem to udelal spravne
ComboFix 10-03-13.03 - Petr 14.03.2010 15:33:24.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.671 [GMT 1:00]
Spuštěný z: e:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Eset NOD32 Antivirus 2.50 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Kerio Personal Firewall *enabled* {333BECA0-DED8-4139-A516-8D9E44E22669}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\recycler\S-1-5-21-2052111302-1647877149-725345543-1004
e:\windows\system32\inter32.dll
Nakažená kopie e:\windows\system32\DRIVERS\nvata.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty ate it :p
Nakažená kopie e:\windows\system32\DRIVERS\nvata.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-14 do 2010-03-14 )))))))))))))))))))))))))))))))
.
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----w- e:\documents and settings\Administrator\Dokumenty
2010-03-14 13:38 . 2010-03-14 14:21 -------- d-----w- e:\documents and settings\Administrator\Plocha
2010-03-14 13:38 . 2010-03-14 13:38 -------- d-----w- e:\documents and settings\Administrator
2010-03-14 13:38 . 2007-07-02 14:42 -------- d--h--w- e:\documents and settings\Administrator\Okolní tiskárny
2010-03-14 13:38 . 2007-07-02 14:42 -------- d--h--w- e:\documents and settings\Administrator\Okolní síť
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----w- e:\documents and settings\Administrator\Oblíbené položky
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----r- e:\documents and settings\Administrator\Nabídka Start
2010-03-14 13:38 . 2007-07-02 12:47 -------- d--h--w- e:\documents and settings\Administrator\Šablony
2010-03-14 13:23 . 2010-03-14 13:23 -------- d-----w- e:\program files\Unibrain
2010-03-14 13:13 . 2010-03-14 13:11 389632 ----a-w- e:\windows\system32\CF27354.exe
2010-02-16 14:23 . 2010-02-16 14:33 -------- d-----w- e:\program files\Internet Download Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-14 14:50 . 2001-10-25 14:00 432890 ----a-w- e:\windows\system32\perfh005.dat
2010-03-14 14:50 . 2001-10-25 14:00 81016 ----a-w- e:\windows\system32\perfc005.dat
2010-03-14 13:41 . 2010-03-14 13:40 3808 ----a-w- E:\mapmem.tmp
2010-03-14 13:41 . 2010-03-14 13:40 5311 ----a-w- E:\huadio.tmp
2010-03-09 17:46 . 2007-07-14 07:08 137464 ----a-w- e:\windows\system32\drivers\PnkBstrK.sys
2010-03-09 17:46 . 2007-07-27 18:43 214520 ----a-w- e:\windows\system32\PnkBstrB.exe
2010-02-14 21:13 . 2008-06-30 13:46 -------- d-----w- e:\program files\Xvid
2010-02-14 21:13 . 2007-09-25 19:24 -------- d-----w- e:\program files\YouTube Downloader
2010-02-14 21:13 . 2010-01-09 07:24 -------- d-----w- e:\program files\DivX
2010-02-14 19:54 . 2008-11-13 14:41 -------- d-----w- e:\program files\Opera
2010-02-14 18:52 . 2008-06-06 07:02 -------- d-----w- e:\program files\Spybot - Search & Destroy
2010-02-11 20:44 . 2010-01-08 19:30 -------- d-----w- e:\program files\Any DVD Converter Professional
2010-02-10 21:49 . 2010-02-10 21:49 -------- d-----w- e:\program files\Microsoft Works
2010-02-10 21:49 . 2009-01-29 17:04 -------- d-----w- e:\program files\MSBuild
2010-02-10 21:47 . 2010-02-10 21:47 -------- d-----w- e:\program files\Microsoft.NET
2010-02-10 21:43 . 2010-02-10 21:43 -------- d-----w- e:\program files\Microsoft Visual Studio 8
2010-02-03 20:12 . 2010-02-03 20:12 -------- d-----w- e:\program files\Common Files\GeoVid
2010-02-03 20:08 . 2010-02-03 19:25 -------- d-----w- e:\program files\E.M. PowerPoint Video Converter
2010-02-01 18:50 . 2007-10-18 18:17 -------- d-----w- e:\program files\Common Files\Java
2010-02-01 18:49 . 2007-10-18 18:17 -------- d-----w- e:\program files\Java
2010-02-01 18:46 . 2010-02-01 18:46 0 ----a-w- e:\windows\system32\cid_store.dat
2010-02-01 18:42 . 2010-02-01 18:41 -------- d-----w- e:\program files\GIMP-2.0
2010-02-01 15:33 . 2008-11-04 15:39 -------- d-----w- e:\program files\Common Files\Macromedia
2010-02-01 15:32 . 2008-03-18 15:02 -------- d-----w- e:\program files\Macromedia
2010-01-31 07:09 . 2010-01-31 07:09 -------- d-----w- e:\program files\Audacity
2009-12-17 16:14 . 2009-01-27 15:52 411368 ----a-w- e:\windows\system32\deploytk.dll
2008-01-18 13:32 . 2008-01-16 18:55 48 --sh--w- e:\windows\S72949288.tmp
2007-08-07 19:28 . 2007-08-07 19:28 131247 --sha-r- e:\windows\system32\opeD.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="e:\program files\Internet Download Manager\IDMan.exe" [2010-03-07 831744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"nwiz"="nwiz.exe" [2006-08-11 1519616]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"nod32kui"="e:\program files\Eset\nod32kui.exe" [2007-11-01 917504]
"QuickTime Task"="e:\program files\QuickTime\qttask.exe" [2007-10-18 98304]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
backup=e:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
backup=e:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Akcelerátor spuštění AutoCADu.lnk]
backup=e:\windows\pss\Akcelerátor spuštění AutoCADu.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
backup=e:\windows\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
backup=e:\windows\pss\hpoddt01.exe.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
backup=e:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^Petr^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
backup=e:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Screenshot Captor1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2007-12-21 12:34 1649600 ----a-w- e:\program files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2007-03-01 23:11 43008 ----a-w- d:\program files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2008-12-16 07:42 342848 ----a-w- e:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2006-09-28 19:21 57344 ----a-w- e:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-10-02 20:22 133104 ----atw- e:\documents and settings\Petr\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 11:39 1289000 ----a-w- e:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- e:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-10-18 19:17 98304 ----a-w- e:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"Autodesk Licensing Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="e:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Activision1\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"e:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"=
"e:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4ss.exe"=
"e:\\Program Files\\BitTorrent\\bittorrent.exe"=
"e:\\WINDOWS\\system32\\PnkBstrA.exe"=
"e:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\DNA\\btdna.exe"=
"e:\program files\Microsoft ActiveSync\rapimgr.exe"= e:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"e:\program files\Microsoft ActiveSync\wcescomm.exe"= e:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"e:\program files\Microsoft ActiveSync\WCESMgr.exe"= e:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Opera\\opera.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 d347bus;d347bus;e:\windows\system32\drivers\d347bus.sys [24.11.2008 20:08 155136]
R0 d347prt;d347prt;e:\windows\system32\drivers\d347prt.sys [24.11.2008 20:08 5248]
R0 ub1394;Unibrain 1394 Class Driver;e:\windows\system32\drivers\UB1394.sys [22.11.2004 17:24 115328]
R0 ubsbm;Unibrain 1394 SBM Driver;e:\windows\system32\drivers\UBSBM.sys [22.11.2004 17:25 11776]
R1 fwdrv;Firewall Driver;e:\windows\system32\drivers\fwdrv.sys [26.9.2005 10:05 286720]
R1 khips;Kerio HIPS Driver;e:\windows\system32\drivers\khips.sys [26.9.2005 10:05 81920]
R2 ubumapi;Unibrain 1394 FireAPI Driver;e:\windows\system32\drivers\UBUMAPI.sys [22.11.2004 17:25 29568]
R3 PhTVTune;TCL2002 TV Tuner;e:\windows\system32\drivers\phtvtune.sys [14.3.2007 16:51 19904]
R3 ubohci;Unibrain 1394 OHCI Driver;e:\windows\system32\drivers\ubohci.sys [22.11.2004 17:23 72832]
R3 ubsbp2;Unibrain SBP2 Bus Driver;e:\windows\system32\drivers\ubsbp2.sys [22.11.2004 17:24 32768]
S2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\program files\HWiNFO32\HWiNFO32.SYS --> c:\program files\HWiNFO32\HWiNFO32.SYS [?]
S3 autorun;autorun;E:\huadio.tmp [14.3.2010 14:40 5311]
S3 FlyPCI;FlyPCI;e:\windows\system32\drivers\FlyPCI.sys [14.2.2008 18:40 4134]
S3 mapmem_dv;mapmem_dv;E:\mapmem.tmp [14.3.2010 14:40 3808]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);e:\windows\system32\drivers\s816bus.sys [4.3.2009 21:20 81832]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;e:\windows\system32\drivers\s816mdfl.sys [4.3.2009 21:20 13864]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;e:\windows\system32\drivers\s816mdm.sys [4.3.2009 21:20 107304]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);e:\windows\system32\drivers\s816mgmt.sys [4.3.2009 21:33 99112]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);e:\windows\system32\drivers\s816nd5.sys [4.3.2009 21:33 21928]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;e:\windows\system32\drivers\s816obex.sys [4.3.2009 21:20 97320]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);e:\windows\system32\drivers\s816unic.sys [4.3.2009 21:33 97704]
S4 sptd;sptd;e:\windows\system32\drivers\sptd.sys [18.1.2008 13:27 639224]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download All Links with IDM - e:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - e:\program files\Internet Download Manager\IEExt.htm
IE: E&xportovat do aplikace Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: imon.dll
LSP: e:\windows\system32\idmmbc.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-zzGBK - G:\setup.exe
MSConfigStartUp-CmUsbSound - cmcnfgu.cpl
MSConfigStartUp-HTV Agent - e:\program files\HTV\HTV.exe
MSConfigStartUp-IDMan - d:\program files\Internet Download Manager\IDMan.exe
MSConfigStartUp-SunJavaUpdateSched - e:\program files\Java\jre6\bin\jusched.exe
AddRemove-0C5EDC3653FED5B121F464339EAC12534D253B25 - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-4077F884D1BB007055BDB83B621D87220A73F30F - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-B726756F5B5A5AA9D798B399386FC6205A45F19E - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-{00060000-0000-1004-8002-0000C06B5161} - e:\program files\WIBUKEY\Setup\Setup32.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-14 15:49
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8696C240]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75dafc3
\Driver\ACPI -> ACPI.sys @ 0xf7427cb8
\Driver\atapi -> atapi.sys @ 0xf73b97b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577ffe
ParseProcedure -> ntkrnlpa.exe @ 0x80576c60
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577ffe
ParseProcedure -> ntkrnlpa.exe @ 0x80576c60
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\autorun]
"ImagePath"="\??\E:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mapmem_dv]
"ImagePath"="\??\E:\mapmem.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-839522115-602162358-2146141123-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:60,e4,c4,23,3a,7c,48,1a,c3,2f,ed,28,af,a3,df,48,06,98,09,f5,be,27,28,
98,78,0f,e4,16,f0,d9,63,63,41,07,e6,88,42,39,1f,d8,19,01,37,07,d1,8c,b1,4f,\
"??"=hex:bc,82,7f,4a,96,db,01,60,c4,45,27,fc,ff,a4,1b,37
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{38f223f1-3a79-4b9a-8316-ea1d531e1fa0}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fc
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{535cdf91-dec3-4cf9-b189-6849b8ef9215}]
@Denied: (Full) (Everyone)
"Model"=dword:000000cc
"Therad"=dword:00000017
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):55,5d,ea,18,4b,88,ab,0a,bc,72,73,70,b2,2a,ef,df,47,f0,13,5c,a5,
00,17,20,5e,30,cf,66,95,41,24,65,7d,7a,4a,14,82,a9,22,d1,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):dd,2f,86,74,b0,96,5f,f8,25,eb,fd,28,51,15,f0,fc,7a,71,b2,f9,4d,
f2,09,3e,19,36,c1,6d,27,54,56,ef,43,96,6d,be,fc,7e,04,25,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="566306325DCB6AE020E8DCB19CF74A3B37FB422E75F0039440BE1A27776189BE38DC7697916C33FA2102C00C410D9D38419BE6136142AF25F4EE1F6C7A091E10837F3C16ACAD0A9599BD10A6A5E228254014D9F12533FC4E6C334D82163729E29EB9A565332BBEE392AB41BABD42B14A79325C2AC5D84E0CCEB1CF10006DC30832B1E30B29F2432ED38BAF5600E5A583797213ED4BBBA5F00BC7B30AEFA22DE8AA3F0DE59709304FEB539BD9E57E14C00F0887C3BFDAAC224D83E83DA340C57C396F9D260EE43E35AEACA87D6FAFB0074D5AA30734A531D60D2A4649DBA39453558272CF1D704D64B0755C489E12D36E0C033A66BB01245E80B105FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A9C6AECB7A5D1407A9C6AECB7A5D1407EAE49B6F0BA99AD3ECC339951542C6A0ED7A28CD212AD002FA3DB76B7D3D58FD491542EB791FB6C3212CDB787A880FF0119BC96F56A93662FB5C54FA8716E315EDB45E412FC3BA1B46C4D41BE0171A9E2F98EA5DC708C4F16752A7B913C7D2B3595EBEA13B87780205BBC0C40E401839B5CE959B10162ACB8E4D48812FC4EF1FE130A85EC29C7605D53E30E25996EB36E29D45CE5C69C76C977D41D17EC1387DB14DD3F1FC7B6E158A812A06B1712EF0CB696E40705AAF387819124DB8BA5E5A455B6C7638DED006433C2663986E2825579CF55FA1872CF3FEDA2DBA286C46256F8692AC52C53F10782B1253A1EC5B73C02337BDD9503ACBCC7E79052DD90A3255FC59F6C0F210CFF38D4E5377127AE21AEC7E9098DA08CCD5C7D13B3B48763771704ADF0B6DCC4655262F84D6C56EDCC4EF0FB16E117C6963FA0610D8C20F509197DF914F8136D70F3EFE2B91B2512DF9239D20049EAEF81261D85BA196087C562E0B5CBB3DBDCB679F7A310C4B7207C484D57C91F46C3553C9819644574A21B6F22FB31774094F799B5222C041D6FE8515D40D66CAB53CEA06A961065A7503FC27A531B63DF3F235842B2FBB0F338EEED7AD3C64963E1171EAF1FEBB39D8CF4492B88E87F30DAA5A339FAE9EEF771389D5E49702986E1A5552ED55D153FA94017FA92C0C38154F0303BB179F63BECD321DF4D1C8CFE42155192270464916C6F8BCAC8ED56B849D98D20008072D5F65163D4B3FD801EF5507A28BFE2F82163DC39DE85E8F360634D80662C0B157DF61BBCA4C5BE2371649D2D2985231289D33D0F6F965F303F51958074BA5122D7B30795F4B422DBE8DF17715ACE30AA982C661A4F116530168B4FC3D1841AC3EA2A37A1793381328C4AA03569E4D06B84C7D0C06538191242453029C1ABF9BDF786FBF11E3A001C9DBB2DB0739CC89CA3BBDB87B95E12922A3A4741594710C2AD32E1DF4EC07FB"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(1700)
e:\windows\system32\imon.dll
e:\program files\Eset\pr_imon.dll
e:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3716)
e:\windows\system32\ieframe.dll
e:\windows\system32\webcheck.dll
e:\program files\Common Files\Ahead\lib\NeroDigitalExt.dll
e:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
e:\windows\system32\crypserv.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\program files\Kerio\Personal Firewall 4\kpf4ss.exe
e:\program files\Eset\nod32krn.exe
e:\windows\system32\nvsvc32.exe
e:\windows\system32\PnkBstrA.exe
e:\windows\system32\PnkBstrB.exe
e:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
e:\program files\Kerio\Personal Firewall 4\kpf4gui.exe
e:\windows\system32\wscntfy.exe
e:\program files\Kerio\Personal Firewall 4\kpf4gui.exe
e:\windows\SOUNDMAN.EXE
e:\progra~1\MICROS~4\rapimgr.exe
e:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Celkový čas: 2010-03-14 15:56:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-14 14:56
Před spuštěním: Volných bajtů: 24 380 112 896
Po spuštění: Volných bajtů: 25 203 437 568
Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 35F1F72B3EE37464023DC9F4E2C8D1EB
ComboFix 10-03-13.03 - Petr 14.03.2010 15:33:24.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.671 [GMT 1:00]
Spuštěný z: e:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Eset NOD32 Antivirus 2.50 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Kerio Personal Firewall *enabled* {333BECA0-DED8-4139-A516-8D9E44E22669}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\recycler\S-1-5-21-2052111302-1647877149-725345543-1004
e:\windows\system32\inter32.dll
Nakažená kopie e:\windows\system32\DRIVERS\nvata.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty ate it :p
Nakažená kopie e:\windows\system32\DRIVERS\nvata.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-14 do 2010-03-14 )))))))))))))))))))))))))))))))
.
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----w- e:\documents and settings\Administrator\Dokumenty
2010-03-14 13:38 . 2010-03-14 14:21 -------- d-----w- e:\documents and settings\Administrator\Plocha
2010-03-14 13:38 . 2010-03-14 13:38 -------- d-----w- e:\documents and settings\Administrator
2010-03-14 13:38 . 2007-07-02 14:42 -------- d--h--w- e:\documents and settings\Administrator\Okolní tiskárny
2010-03-14 13:38 . 2007-07-02 14:42 -------- d--h--w- e:\documents and settings\Administrator\Okolní síť
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----w- e:\documents and settings\Administrator\Oblíbené položky
2010-03-14 13:38 . 2007-07-02 14:42 -------- d-----r- e:\documents and settings\Administrator\Nabídka Start
2010-03-14 13:38 . 2007-07-02 12:47 -------- d--h--w- e:\documents and settings\Administrator\Šablony
2010-03-14 13:23 . 2010-03-14 13:23 -------- d-----w- e:\program files\Unibrain
2010-03-14 13:13 . 2010-03-14 13:11 389632 ----a-w- e:\windows\system32\CF27354.exe
2010-02-16 14:23 . 2010-02-16 14:33 -------- d-----w- e:\program files\Internet Download Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-14 14:50 . 2001-10-25 14:00 432890 ----a-w- e:\windows\system32\perfh005.dat
2010-03-14 14:50 . 2001-10-25 14:00 81016 ----a-w- e:\windows\system32\perfc005.dat
2010-03-14 13:41 . 2010-03-14 13:40 3808 ----a-w- E:\mapmem.tmp
2010-03-14 13:41 . 2010-03-14 13:40 5311 ----a-w- E:\huadio.tmp
2010-03-09 17:46 . 2007-07-14 07:08 137464 ----a-w- e:\windows\system32\drivers\PnkBstrK.sys
2010-03-09 17:46 . 2007-07-27 18:43 214520 ----a-w- e:\windows\system32\PnkBstrB.exe
2010-02-14 21:13 . 2008-06-30 13:46 -------- d-----w- e:\program files\Xvid
2010-02-14 21:13 . 2007-09-25 19:24 -------- d-----w- e:\program files\YouTube Downloader
2010-02-14 21:13 . 2010-01-09 07:24 -------- d-----w- e:\program files\DivX
2010-02-14 19:54 . 2008-11-13 14:41 -------- d-----w- e:\program files\Opera
2010-02-14 18:52 . 2008-06-06 07:02 -------- d-----w- e:\program files\Spybot - Search & Destroy
2010-02-11 20:44 . 2010-01-08 19:30 -------- d-----w- e:\program files\Any DVD Converter Professional
2010-02-10 21:49 . 2010-02-10 21:49 -------- d-----w- e:\program files\Microsoft Works
2010-02-10 21:49 . 2009-01-29 17:04 -------- d-----w- e:\program files\MSBuild
2010-02-10 21:47 . 2010-02-10 21:47 -------- d-----w- e:\program files\Microsoft.NET
2010-02-10 21:43 . 2010-02-10 21:43 -------- d-----w- e:\program files\Microsoft Visual Studio 8
2010-02-03 20:12 . 2010-02-03 20:12 -------- d-----w- e:\program files\Common Files\GeoVid
2010-02-03 20:08 . 2010-02-03 19:25 -------- d-----w- e:\program files\E.M. PowerPoint Video Converter
2010-02-01 18:50 . 2007-10-18 18:17 -------- d-----w- e:\program files\Common Files\Java
2010-02-01 18:49 . 2007-10-18 18:17 -------- d-----w- e:\program files\Java
2010-02-01 18:46 . 2010-02-01 18:46 0 ----a-w- e:\windows\system32\cid_store.dat
2010-02-01 18:42 . 2010-02-01 18:41 -------- d-----w- e:\program files\GIMP-2.0
2010-02-01 15:33 . 2008-11-04 15:39 -------- d-----w- e:\program files\Common Files\Macromedia
2010-02-01 15:32 . 2008-03-18 15:02 -------- d-----w- e:\program files\Macromedia
2010-01-31 07:09 . 2010-01-31 07:09 -------- d-----w- e:\program files\Audacity
2009-12-17 16:14 . 2009-01-27 15:52 411368 ----a-w- e:\windows\system32\deploytk.dll
2008-01-18 13:32 . 2008-01-16 18:55 48 --sh--w- e:\windows\S72949288.tmp
2007-08-07 19:28 . 2007-08-07 19:28 131247 --sha-r- e:\windows\system32\opeD.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="e:\program files\Internet Download Manager\IDMan.exe" [2010-03-07 831744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"nwiz"="nwiz.exe" [2006-08-11 1519616]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"nod32kui"="e:\program files\Eset\nod32kui.exe" [2007-11-01 917504]
"QuickTime Task"="e:\program files\QuickTime\qttask.exe" [2007-10-18 98304]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
backup=e:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
backup=e:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Akcelerátor spuštění AutoCADu.lnk]
backup=e:\windows\pss\Akcelerátor spuštění AutoCADu.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^hp psc 1000 series.lnk]
backup=e:\windows\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^hpoddt01.exe.lnk]
backup=e:\windows\pss\hpoddt01.exe.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
backup=e:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\E:^Documents and Settings^Petr^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
backup=e:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Screenshot Captor1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2007-12-21 12:34 1649600 ----a-w- e:\program files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2007-03-01 23:11 43008 ----a-w- d:\program files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2008-12-16 07:42 342848 ----a-w- e:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2006-09-28 19:21 57344 ----a-w- e:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-10-02 20:22 133104 ----atw- e:\documents and settings\Petr\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 11:39 1289000 ----a-w- e:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- e:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-10-18 19:17 98304 ----a-w- e:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"Autodesk Licensing Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="e:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Activision1\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"e:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"=
"e:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4ss.exe"=
"e:\\Program Files\\BitTorrent\\bittorrent.exe"=
"e:\\WINDOWS\\system32\\PnkBstrA.exe"=
"e:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\DNA\\btdna.exe"=
"e:\program files\Microsoft ActiveSync\rapimgr.exe"= e:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"e:\program files\Microsoft ActiveSync\wcescomm.exe"= e:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"e:\program files\Microsoft ActiveSync\WCESMgr.exe"= e:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Opera\\opera.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 d347bus;d347bus;e:\windows\system32\drivers\d347bus.sys [24.11.2008 20:08 155136]
R0 d347prt;d347prt;e:\windows\system32\drivers\d347prt.sys [24.11.2008 20:08 5248]
R0 ub1394;Unibrain 1394 Class Driver;e:\windows\system32\drivers\UB1394.sys [22.11.2004 17:24 115328]
R0 ubsbm;Unibrain 1394 SBM Driver;e:\windows\system32\drivers\UBSBM.sys [22.11.2004 17:25 11776]
R1 fwdrv;Firewall Driver;e:\windows\system32\drivers\fwdrv.sys [26.9.2005 10:05 286720]
R1 khips;Kerio HIPS Driver;e:\windows\system32\drivers\khips.sys [26.9.2005 10:05 81920]
R2 ubumapi;Unibrain 1394 FireAPI Driver;e:\windows\system32\drivers\UBUMAPI.sys [22.11.2004 17:25 29568]
R3 PhTVTune;TCL2002 TV Tuner;e:\windows\system32\drivers\phtvtune.sys [14.3.2007 16:51 19904]
R3 ubohci;Unibrain 1394 OHCI Driver;e:\windows\system32\drivers\ubohci.sys [22.11.2004 17:23 72832]
R3 ubsbp2;Unibrain SBP2 Bus Driver;e:\windows\system32\drivers\ubsbp2.sys [22.11.2004 17:24 32768]
S2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\program files\HWiNFO32\HWiNFO32.SYS --> c:\program files\HWiNFO32\HWiNFO32.SYS [?]
S3 autorun;autorun;E:\huadio.tmp [14.3.2010 14:40 5311]
S3 FlyPCI;FlyPCI;e:\windows\system32\drivers\FlyPCI.sys [14.2.2008 18:40 4134]
S3 mapmem_dv;mapmem_dv;E:\mapmem.tmp [14.3.2010 14:40 3808]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);e:\windows\system32\drivers\s816bus.sys [4.3.2009 21:20 81832]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;e:\windows\system32\drivers\s816mdfl.sys [4.3.2009 21:20 13864]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;e:\windows\system32\drivers\s816mdm.sys [4.3.2009 21:20 107304]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);e:\windows\system32\drivers\s816mgmt.sys [4.3.2009 21:33 99112]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);e:\windows\system32\drivers\s816nd5.sys [4.3.2009 21:33 21928]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;e:\windows\system32\drivers\s816obex.sys [4.3.2009 21:20 97320]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);e:\windows\system32\drivers\s816unic.sys [4.3.2009 21:33 97704]
S4 sptd;sptd;e:\windows\system32\drivers\sptd.sys [18.1.2008 13:27 639224]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download All Links with IDM - e:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - e:\program files\Internet Download Manager\IEExt.htm
IE: E&xportovat do aplikace Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: imon.dll
LSP: e:\windows\system32\idmmbc.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-zzGBK - G:\setup.exe
MSConfigStartUp-CmUsbSound - cmcnfgu.cpl
MSConfigStartUp-HTV Agent - e:\program files\HTV\HTV.exe
MSConfigStartUp-IDMan - d:\program files\Internet Download Manager\IDMan.exe
MSConfigStartUp-SunJavaUpdateSched - e:\program files\Java\jre6\bin\jusched.exe
AddRemove-0C5EDC3653FED5B121F464339EAC12534D253B25 - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-4077F884D1BB007055BDB83B621D87220A73F30F - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-B726756F5B5A5AA9D798B399386FC6205A45F19E - e:\progra~1\DIFX\270581355A767BF1\dpinst.exe
AddRemove-{00060000-0000-1004-8002-0000C06B5161} - e:\program files\WIBUKEY\Setup\Setup32.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-14 15:49
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8696C240]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75dafc3
\Driver\ACPI -> ACPI.sys @ 0xf7427cb8
\Driver\atapi -> atapi.sys @ 0xf73b97b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577ffe
ParseProcedure -> ntkrnlpa.exe @ 0x80576c60
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577ffe
ParseProcedure -> ntkrnlpa.exe @ 0x80576c60
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\autorun]
"ImagePath"="\??\E:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mapmem_dv]
"ImagePath"="\??\E:\mapmem.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-839522115-602162358-2146141123-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:60,e4,c4,23,3a,7c,48,1a,c3,2f,ed,28,af,a3,df,48,06,98,09,f5,be,27,28,
98,78,0f,e4,16,f0,d9,63,63,41,07,e6,88,42,39,1f,d8,19,01,37,07,d1,8c,b1,4f,\
"??"=hex:bc,82,7f,4a,96,db,01,60,c4,45,27,fc,ff,a4,1b,37
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{38f223f1-3a79-4b9a-8316-ea1d531e1fa0}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fc
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{535cdf91-dec3-4cf9-b189-6849b8ef9215}]
@Denied: (Full) (Everyone)
"Model"=dword:000000cc
"Therad"=dword:00000017
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):55,5d,ea,18,4b,88,ab,0a,bc,72,73,70,b2,2a,ef,df,47,f0,13,5c,a5,
00,17,20,5e,30,cf,66,95,41,24,65,7d,7a,4a,14,82,a9,22,d1,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):dd,2f,86,74,b0,96,5f,f8,25,eb,fd,28,51,15,f0,fc,7a,71,b2,f9,4d,
f2,09,3e,19,36,c1,6d,27,54,56,ef,43,96,6d,be,fc,7e,04,25,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="566306325DCB6AE020E8DCB19CF74A3B37FB422E75F0039440BE1A27776189BE38DC7697916C33FA2102C00C410D9D38419BE6136142AF25F4EE1F6C7A091E10837F3C16ACAD0A9599BD10A6A5E228254014D9F12533FC4E6C334D82163729E29EB9A565332BBEE392AB41BABD42B14A79325C2AC5D84E0CCEB1CF10006DC30832B1E30B29F2432ED38BAF5600E5A583797213ED4BBBA5F00BC7B30AEFA22DE8AA3F0DE59709304FEB539BD9E57E14C00F0887C3BFDAAC224D83E83DA340C57C396F9D260EE43E35AEACA87D6FAFB0074D5AA30734A531D60D2A4649DBA39453558272CF1D704D64B0755C489E12D36E0C033A66BB01245E80B105FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A9C6AECB7A5D1407A9C6AECB7A5D1407EAE49B6F0BA99AD3ECC339951542C6A0ED7A28CD212AD002FA3DB76B7D3D58FD491542EB791FB6C3212CDB787A880FF0119BC96F56A93662FB5C54FA8716E315EDB45E412FC3BA1B46C4D41BE0171A9E2F98EA5DC708C4F16752A7B913C7D2B3595EBEA13B87780205BBC0C40E401839B5CE959B10162ACB8E4D48812FC4EF1FE130A85EC29C7605D53E30E25996EB36E29D45CE5C69C76C977D41D17EC1387DB14DD3F1FC7B6E158A812A06B1712EF0CB696E40705AAF387819124DB8BA5E5A455B6C7638DED006433C2663986E2825579CF55FA1872CF3FEDA2DBA286C46256F8692AC52C53F10782B1253A1EC5B73C02337BDD9503ACBCC7E79052DD90A3255FC59F6C0F210CFF38D4E5377127AE21AEC7E9098DA08CCD5C7D13B3B48763771704ADF0B6DCC4655262F84D6C56EDCC4EF0FB16E117C6963FA0610D8C20F509197DF914F8136D70F3EFE2B91B2512DF9239D20049EAEF81261D85BA196087C562E0B5CBB3DBDCB679F7A310C4B7207C484D57C91F46C3553C9819644574A21B6F22FB31774094F799B5222C041D6FE8515D40D66CAB53CEA06A961065A7503FC27A531B63DF3F235842B2FBB0F338EEED7AD3C64963E1171EAF1FEBB39D8CF4492B88E87F30DAA5A339FAE9EEF771389D5E49702986E1A5552ED55D153FA94017FA92C0C38154F0303BB179F63BECD321DF4D1C8CFE42155192270464916C6F8BCAC8ED56B849D98D20008072D5F65163D4B3FD801EF5507A28BFE2F82163DC39DE85E8F360634D80662C0B157DF61BBCA4C5BE2371649D2D2985231289D33D0F6F965F303F51958074BA5122D7B30795F4B422DBE8DF17715ACE30AA982C661A4F116530168B4FC3D1841AC3EA2A37A1793381328C4AA03569E4D06B84C7D0C06538191242453029C1ABF9BDF786FBF11E3A001C9DBB2DB0739CC89CA3BBDB87B95E12922A3A4741594710C2AD32E1DF4EC07FB"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(1700)
e:\windows\system32\imon.dll
e:\program files\Eset\pr_imon.dll
e:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3716)
e:\windows\system32\ieframe.dll
e:\windows\system32\webcheck.dll
e:\program files\Common Files\Ahead\lib\NeroDigitalExt.dll
e:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
e:\windows\system32\crypserv.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\program files\Kerio\Personal Firewall 4\kpf4ss.exe
e:\program files\Eset\nod32krn.exe
e:\windows\system32\nvsvc32.exe
e:\windows\system32\PnkBstrA.exe
e:\windows\system32\PnkBstrB.exe
e:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
e:\program files\Kerio\Personal Firewall 4\kpf4gui.exe
e:\windows\system32\wscntfy.exe
e:\program files\Kerio\Personal Firewall 4\kpf4gui.exe
e:\windows\SOUNDMAN.EXE
e:\progra~1\MICROS~4\rapimgr.exe
e:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Celkový čas: 2010-03-14 15:56:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-14 14:56
Před spuštěním: Volných bajtů: 24 380 112 896
Po spuštění: Volných bajtů: 25 203 437 568
Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 35F1F72B3EE37464023DC9F4E2C8D1EB