
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Total XP security
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Total XP security
Ahoj. Nějak se mi do počítače dostal mizera Total XP security a dělá tam problémy (pop-up okna, hlášky o ohrožení počítače, spouštění fiktivního malware testu apod.). MBAM ho detekuje, odstraní, ale stačí restartovat a je to tu znova. POradíte?
Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2010-03-17 06:15:40
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (17%) free of 56 GB
Total RAM: 895 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:43:18, on 16.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ASWLSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\av.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ASWL2K.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Plocha\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [syncman] c:\windows\system32\config\systemprofile\wuaucldt.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: monnwb32.exe
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
O4 - Global Startup: e-Backup 1.42 Scheduler.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7409 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-04-17 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-04-26 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-04-26 86016]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2006-01-19 544768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-19 15797248]
"ASUS Live Update"=C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2006-02-21 180224]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-21 761945]
"RemoteControl"=C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe [2005-01-12 32768]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"Power_Gear"=C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-03-06 86016]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2007-01-19 61440]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2006-12-20 98304]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"syncman"=c:\windows\system32\wuaucldt.exe [2010-03-17 51807]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"syncman"=c:\documents and settings\admin\wuaucldt.exe [2010-03-17 51807]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
ASUS ChkMail.lnk - C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
e-Backup 1.42 Scheduler.lnk - C:\WINDOWS\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe
C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění
monnwb32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoSMMyDocs"=01000000
"NoSMMyPictures"=01000000
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe"="C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic"
"C:\Digital Libraries\WHO Training Modules on GMP - July 2007\gsdl\server.exe"="C:\Digital Libraries\WHO Training Modules on GMP - July 2007\gsdl\server.exe:*:Disabled:GSDL Server Version"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.exe - open - "C:\Documents and Settings\Admin\Local Settings\Data aplikací\ave.exe" /START "%1" %*
======List of files/folders created in the last 1 months======
2010-03-17 06:03:47 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-17 02:16:35 ----N---- C:\WINDOWS\system32\wuaucldt.exe
2010-03-16 23:41:15 ----D---- C:\rsit
2010-03-16 23:30:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\avG
2010-03-16 23:30:16 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\vma.exe
2010-03-16 23:30:15 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\MSASCui.exe
2010-03-16 23:30:15 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\av.exe
2010-03-16 23:30:14 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\ave.exe
2010-03-16 23:13:11 ----A---- C:\WINDOWS\system32\fjhdyfhsn.bat
2010-03-16 06:31:16 ----SHD---- C:\FOUND.000
2010-03-10 19:48:21 ----A---- C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt
2010-03-10 19:40:16 ----A---- C:\WINDOWS\DelMR.bat
2010-03-10 01:30:57 ----HD---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-10 01:28:04 ----D---- C:\Program Files\MSXML 4.0
2010-03-09 21:23:18 ----D---- C:\Documents and Settings\Admin\Data aplikací\Teleca
2010-03-09 19:18:30 ----A---- C:\WINDOWS\ModemLog_Sony Ericsson P1 USB Modem.txt
2010-03-09 19:10:36 ----D---- C:\Documents and Settings\Admin\Data aplikací\Sony Ericsson
2010-03-09 19:09:40 ----D---- C:\Program Files\Common Files\Teleca Shared
2010-02-24 17:50:01 ----HD---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2010-03-17 06:02:30 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-17 00:02:46 ----A---- C:\WINDOWS\WINCMD.INI
2010-03-12 13:19:46 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-10 19:30:48 ----A---- C:\WINDOWS\win.ini
2010-03-02 06:30:12 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-05-10 43008]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2006-11-14 15781]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 BCM43XX;ASUS 802.11 ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-02-11 371712]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\WINDOWS\System32\Drivers\gHidPnp.Sys [2006-07-14 14848]
R3 gMouUsb;USB Mouse Device Drv; C:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2006-07-14 9984]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-19 4127232]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-04-26 3659968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 11136]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2005-11-16 78976]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-01-19 862340]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-21 191936]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 adqcapiw;adqcapiw; C:\WINDOWS\system32\drivers\adqcapiw.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ASWLSVC;ASWLSVC; C:\WINDOWS\system32\ASWLSVC.exe [2004-05-06 496640]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-04-26 143427]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-12 1029456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2010-03-17 06:15:40
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (17%) free of 56 GB
Total RAM: 895 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:43:18, on 16.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ASWLSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\av.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ASWL2K.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Plocha\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [syncman] c:\windows\system32\config\systemprofile\wuaucldt.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: monnwb32.exe
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
O4 - Global Startup: e-Backup 1.42 Scheduler.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7409 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-04-17 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-04-26 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-04-26 86016]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2006-01-19 544768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-19 15797248]
"ASUS Live Update"=C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2006-02-21 180224]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-21 761945]
"RemoteControl"=C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe [2005-01-12 32768]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"Power_Gear"=C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-03-06 86016]
"Tweak UI"=TWEAKUI.CPL,TweakMeUp []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2007-01-19 61440]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2006-12-20 98304]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"syncman"=c:\windows\system32\wuaucldt.exe [2010-03-17 51807]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"syncman"=c:\documents and settings\admin\wuaucldt.exe [2010-03-17 51807]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
ASUS ChkMail.lnk - C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
e-Backup 1.42 Scheduler.lnk - C:\WINDOWS\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe
C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění
monnwb32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoSMMyDocs"=01000000
"NoSMMyPictures"=01000000
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe"="C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic"
"C:\Digital Libraries\WHO Training Modules on GMP - July 2007\gsdl\server.exe"="C:\Digital Libraries\WHO Training Modules on GMP - July 2007\gsdl\server.exe:*:Disabled:GSDL Server Version"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.exe - open - "C:\Documents and Settings\Admin\Local Settings\Data aplikací\ave.exe" /START "%1" %*
======List of files/folders created in the last 1 months======
2010-03-17 06:03:47 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-17 02:16:35 ----N---- C:\WINDOWS\system32\wuaucldt.exe
2010-03-16 23:41:15 ----D---- C:\rsit
2010-03-16 23:30:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\avG
2010-03-16 23:30:16 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\vma.exe
2010-03-16 23:30:15 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\MSASCui.exe
2010-03-16 23:30:15 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\av.exe
2010-03-16 23:30:14 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\ave.exe
2010-03-16 23:13:11 ----A---- C:\WINDOWS\system32\fjhdyfhsn.bat
2010-03-16 06:31:16 ----SHD---- C:\FOUND.000
2010-03-10 19:48:21 ----A---- C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt
2010-03-10 19:40:16 ----A---- C:\WINDOWS\DelMR.bat
2010-03-10 01:30:57 ----HD---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-10 01:28:04 ----D---- C:\Program Files\MSXML 4.0
2010-03-09 21:23:18 ----D---- C:\Documents and Settings\Admin\Data aplikací\Teleca
2010-03-09 19:18:30 ----A---- C:\WINDOWS\ModemLog_Sony Ericsson P1 USB Modem.txt
2010-03-09 19:10:36 ----D---- C:\Documents and Settings\Admin\Data aplikací\Sony Ericsson
2010-03-09 19:09:40 ----D---- C:\Program Files\Common Files\Teleca Shared
2010-02-24 17:50:01 ----HD---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2010-03-17 06:02:30 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-17 00:02:46 ----A---- C:\WINDOWS\WINCMD.INI
2010-03-12 13:19:46 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-10 19:30:48 ----A---- C:\WINDOWS\win.ini
2010-03-02 06:30:12 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-05-10 43008]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2006-11-14 15781]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 BCM43XX;ASUS 802.11 ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-02-11 371712]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\WINDOWS\System32\Drivers\gHidPnp.Sys [2006-07-14 14848]
R3 gMouUsb;USB Mouse Device Drv; C:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2006-07-14 9984]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-19 4127232]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-04-26 3659968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 11136]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2005-11-16 78976]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-01-19 862340]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-21 191936]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 adqcapiw;adqcapiw; C:\WINDOWS\system32\drivers\adqcapiw.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ASWLSVC;ASWLSVC; C:\WINDOWS\system32\ASWLSVC.exe [2004-05-06 496640]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-04-26 143427]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-12 1029456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security


- Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
- Vložte do PC všechny flash disky, které používáte.
- Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
- Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna
- Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
- Během skenování může být počítač restartován.
Re: Total XP security
Zdravím.
Výpis z ComboFix:
ComboFix 10-03-16.03 - Admin 17.03.2010 7:31.3.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.532 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\02Fr6gkH.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\BjAgCG.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\gG3322.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\Jrujmcg.jpg
c:\documents and settings\Admin\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\MSASCui.exe
c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\system32\drivers\cdrom.sys chybìl.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\cdrom.sys
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 01:16 . 2010-03-17 01:16 51807 ----a-w- c:\documents and settings\Admin\wuaucldt.exe
2010-03-17 01:16 . 2010-03-17 01:16 51807 ------w- c:\windows\system32\wuaucldt.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 22:13 . 2010-03-16 22:13 116 ----a-w- c:\windows\system32\fjhdyfhsn.bat
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 18:40 . 2010-03-10 18:40 146 ----a-w- c:\windows\DelMR.bat
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2006-11-14 01:49 343552 ----a-w- c:\windows\system32\mspaint.exe
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"syncman"="c:\documents and settings\admin\wuaucldt.exe" [2010-03-17 51807]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
"syncman"="c:\windows\system32\wuaucldt.exe" [2010-03-17 51807]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANÌNÉ Z REGISTRU - - - -
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 07:35
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
.
Celkový èas: 2010-03-17 07:36:48
ComboFix-quarantined-files.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 604 871 680
Po spuštìní: Volných bajtù: 10 592 681 984
- - End Of File - - A4BF05714BC3ECC14FD0ABC7A634353E
Výpis z ComboFix:
ComboFix 10-03-16.03 - Admin 17.03.2010 7:31.3.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.532 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\02Fr6gkH.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\BjAgCG.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\gG3322.jpg
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\Jrujmcg.jpg
c:\documents and settings\Admin\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\MSASCui.exe
c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\system32\drivers\cdrom.sys chybìl.
Obnovena kopie z - c:\windows\ServicePackFiles\i386\cdrom.sys
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 01:16 . 2010-03-17 01:16 51807 ----a-w- c:\documents and settings\Admin\wuaucldt.exe
2010-03-17 01:16 . 2010-03-17 01:16 51807 ------w- c:\windows\system32\wuaucldt.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 22:13 . 2010-03-16 22:13 116 ----a-w- c:\windows\system32\fjhdyfhsn.bat
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 18:40 . 2010-03-10 18:40 146 ----a-w- c:\windows\DelMR.bat
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2006-11-14 01:49 343552 ----a-w- c:\windows\system32\mspaint.exe
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"syncman"="c:\documents and settings\admin\wuaucldt.exe" [2010-03-17 51807]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
"syncman"="c:\windows\system32\wuaucldt.exe" [2010-03-17 51807]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANÌNÉ Z REGISTRU - - - -
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 07:35
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
.
Celkový èas: 2010-03-17 07:36:48
ComboFix-quarantined-files.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 604 871 680
Po spuštìní: Volných bajtù: 10 592 681 984
- - End Of File - - A4BF05714BC3ECC14FD0ABC7A634353E
Re: Total XP security
Aby řeč nestála, přikládám ještě log z MBAM. Trochu mě vylekal, ale nic jsem nemazal. Jinak momentálně je počítač rozhozený, hází chybové hlášky jako "nedostatek paměti k operaci read", "nedostatečně přidělená kvóta disku", task manager nejde spustit (nezdařila se inicializace 0xc0000017) a tak. Nevím, jestli to souvisí s použitím ComboFixu, vlastním Malwarem nebo jestli se notebook přehřívá (i to je možnost). Počkám, až bude počítač čistý, jestli to bude přetrvávat.
Log z MBAM:
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
17.3.2010 10:57:20
mbam-log-2010-03-17 (10-57-08).txt
Typ kontroly: Kompletní kontrola (C:\|D:\|)
Zkontrolované objekty: 105471
Uplynulý èas: 7 minute(s), 30 second(s)
Infikované procesy v pamìti: 0
Infikované moduly v pamìti: 0
Infikované klíèe registru: 0
Infikované hodnoty registru: 1
Infikované datové položky registru: 0
Infikované adresáøe: 0
Infikované soubory: 170
Infikované procesy v pamìti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v pamìti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíèe registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.FakeAlert.H) -> No action taken.
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáøe:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
c:\WINDOWS\system32\wuaucldt.exe (Trojan.FakeAlert.H) -> No action taken.
C:\WINDOWS\inf\cyzport.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\dfrg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\flash.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\flpydisk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\font.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\gameport.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\games.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\genprint.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hal.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpdigwia.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpojscan.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpscan.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ibmvcap.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam4usb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam5usb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icminst.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icwnt5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\iereset.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmaiwat.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmar1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmarch.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmcrtix.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdcm5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdcm6.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdf56F.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdgitn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdgden.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdp2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdsi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdyna.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeiger.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmelsa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeric.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeric2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmexp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmfj2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmisdn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\MDMJF56E.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmke.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmneuhs.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis1u.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis2u.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis3t.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis5t.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnokia.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnova.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmntt1.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttd2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttd6.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttme.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttp2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttte.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmolic.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmomrn3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmspq28.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsetup.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsiil6.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsii64.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsun1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmusrsp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmvdot.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmwhql0.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmx5560.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzoom.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyxel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyxlg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\memcard.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\memstpci.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mf.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mfsocket.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mfsupra.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\minioc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mmopt.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ndisuio.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net21x4.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net5515n.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netana.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netauni.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netbrdgm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netbrdgs.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcis.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netclass.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdav.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdefxa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdgdxb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netmadge.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnovel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnwlnk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_ym2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_ymh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdmaudio.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdmjoy.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wsh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\3dfxvs2k.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\adm_mult.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\adm_port.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\asynceqn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atim128.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atimpab.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atirage3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\irtos4mo.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmpctel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net656c5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net713.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net83820.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net8511.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netali.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netan983.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamd.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamd2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netambi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamdhl.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netasp2k.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqmt.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netctmrk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdlh5x.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdf650.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net650d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nete1000.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nete100i.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netejxmp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netel515.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netosi2c.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netosi5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpc100.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpnic.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpwr2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netw926.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netw940.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netx500.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netx56n5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netxcpq.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ntapm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nv3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ppa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ppa3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3sav3d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3sav4.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3savmx.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3trio3d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sgiu.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sis300i.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wceusbsh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma10k1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_aur.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\xscan_xp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wmtour.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\accessor.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\devxprop.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\disk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sysoc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\dwup.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\skins.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wstcodec.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\fxsocm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hdaudbus.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\drvindex.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hidserv.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ie.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\iis.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ieaccess.inf (Trojan.Agent) -> No action taken.
Log z MBAM:
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
17.3.2010 10:57:20
mbam-log-2010-03-17 (10-57-08).txt
Typ kontroly: Kompletní kontrola (C:\|D:\|)
Zkontrolované objekty: 105471
Uplynulý èas: 7 minute(s), 30 second(s)
Infikované procesy v pamìti: 0
Infikované moduly v pamìti: 0
Infikované klíèe registru: 0
Infikované hodnoty registru: 1
Infikované datové položky registru: 0
Infikované adresáøe: 0
Infikované soubory: 170
Infikované procesy v pamìti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v pamìti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíèe registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.FakeAlert.H) -> No action taken.
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáøe:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
c:\WINDOWS\system32\wuaucldt.exe (Trojan.FakeAlert.H) -> No action taken.
C:\WINDOWS\inf\cyzport.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\dfrg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\flash.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\flpydisk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\font.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\gameport.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\games.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\genprint.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hal.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpdigwia.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpojscan.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hpscan.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ibmvcap.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam4usb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icam5usb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icminst.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\icwnt5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\iereset.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmaiwat.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmar1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmarch.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmcrtix.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdcm5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdcm6.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdf56F.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdgitn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdgden.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdp2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdsi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmdyna.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeiger.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmelsa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeric.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmeric2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmexp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmfj2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmisdn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\MDMJF56E.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmke.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmneuhs.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis1u.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis2u.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis3t.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\Mdmnis5t.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnokia.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnova.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmntt1.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttd2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttd6.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttme.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttp2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmnttte.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmolic.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmomrn3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmspq28.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsetup.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsiil6.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsii64.INF (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmsun1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmusrsp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmvdot.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmwhql0.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmx5560.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzoom.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyxel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmzyxlg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\memcard.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\memstpci.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mf.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mfsocket.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mfsupra.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\minioc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mmopt.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ndisuio.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net21x4.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net5515n.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netana.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netauni.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netbrdgm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netbrdgs.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcis.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netclass.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdav.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdefxa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdgdxb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netmadge.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnb.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnovel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netnwlnk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_ym2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_ymh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdmaudio.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdmjoy.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wsh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\3dfxvs2k.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\adm_mult.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\adm_port.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\asynceqn.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atim128.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atimpab.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\atirage3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\irtos4mo.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\mdmpctel.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net656c5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net713.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net83820.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net8511.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netali.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netan983.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamd.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamd2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netambi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netamdhl.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netasp2k.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqg.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqi.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netcpqmt.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netctmrk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdlh5x.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdf650.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netdm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\net650d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nete1000.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nete100i.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netejxmp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netel515.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netosi2c.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netosi5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpc100.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpnic.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netpwr2.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netw926.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netw940.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netx500.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netx56n5.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\netxcpq.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ntapm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\nv3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ppa.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ppa3.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3sav3d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3sav4.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3savmx.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\s3trio3d.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sgiu.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sis300i.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wceusbsh.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma10k1.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wdma_aur.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\xscan_xp.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wmtour.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\accessor.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\devxprop.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\disk.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\sysoc.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\dwup.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\skins.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\wstcodec.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\fxsocm.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hdaudbus.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\drvindex.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\hidserv.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ie.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\iis.inf (Trojan.Agent) -> No action taken.
C:\WINDOWS\inf\ieaccess.inf (Trojan.Agent) -> No action taken.
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security

- Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.
Kód: Vybrat vše
File::
C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění\monnwb32.exe
c:\windows\system32\fjhdyfhsn.bat
c:\windows\DelMR.bat
c:\windows\system32\wuaucldt.exe
c:\documents and settings\admin\wuaucldt.exe
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"syncman"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"syncman"=-
- Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
- Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:
- Po aplikaci na Vás vypadne další log,vložte ho sem

Re: Total XP security
Zrdavím opět. Počítač nabehl po provedení scriptu (zatím) bez problémů.
Log z ComboFixu:
ComboFix 10-03-16.03 - Admin 17.03.2010 14:30:07.4.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.541 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe"
"c:\documents and settings\admin\wuaucldt.exe"
"c:\windows\DelMR.bat"
"c:\windows\system32\fjhdyfhsn.bat"
"c:\windows\system32\wuaucldt.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\admin\wuaucldt.exe
c:\windows\DelMR.bat
c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\wuaucldt.exe
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 14:34
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
.
Celkový èas: 2010-03-17 14:36:03
ComboFix-quarantined-files.txt 2010-03-17 13:36
ComboFix2.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 369 630 208
Po spuštìní: Volných bajtù: 10 335 125 504
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - BEDB935EBDF0D613276C67A2CA99CCFD
Log z ComboFixu:
ComboFix 10-03-16.03 - Admin 17.03.2010 14:30:07.4.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.541 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe"
"c:\documents and settings\admin\wuaucldt.exe"
"c:\windows\DelMR.bat"
"c:\windows\system32\fjhdyfhsn.bat"
"c:\windows\system32\wuaucldt.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\admin\wuaucldt.exe
c:\windows\DelMR.bat
c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\wuaucldt.exe
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 14:34
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
.
Celkový èas: 2010-03-17 14:36:03
ComboFix-quarantined-files.txt 2010-03-17 13:36
ComboFix2.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 369 630 208
Po spuštìní: Volných bajtù: 10 335 125 504
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - BEDB935EBDF0D613276C67A2CA99CCFD
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security

- Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.
Kód: Vybrat vše
KillAll::
File::
c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe
- Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
- Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:
- Po aplikaci na Vás vypadne další log,vložte ho sem
Re: Total XP security
ComboFix 10-03-16.03 - Admin 17.03.2010 14:54:54.5.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.608 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe"
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 15:00
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spyw.sys >>UNKNOWN [0x8578E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7600f28
\Driver\ACPI -> ACPI.sys @ 0xf735bcb8
\Driver\atapi -> atapi.sys @ 0xf72f8b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84 SendCompleteHandler -> NDIS.sys @ 0xf726abb0
PacketIndicateHandler -> NDIS.sys @ 0xf7259a0d
SendHandler -> NDIS.sys @ 0xf726db40
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na bìžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2816)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\sm56hlpr.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ASWLSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ASWL2K.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Celkový èas: 2010-03-17 15:04:27 - poèítaè byl restartován
ComboFix-quarantined-files.txt 2010-03-17 14:04
ComboFix2.txt 2010-03-17 13:36
ComboFix3.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 343 841 792
Po spuštìní: Volných bajtù: 10 301 734 912
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - E0740497329EA1792DBF386D8DF94D46
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.608 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe"
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 15:00
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spyw.sys >>UNKNOWN [0x8578E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7600f28
\Driver\ACPI -> ACPI.sys @ 0xf735bcb8
\Driver\atapi -> atapi.sys @ 0xf72f8b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84 SendCompleteHandler -> NDIS.sys @ 0xf726abb0
PacketIndicateHandler -> NDIS.sys @ 0xf7259a0d
SendHandler -> NDIS.sys @ 0xf726db40
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na bìžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2816)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\sm56hlpr.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ASWLSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ASWL2K.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Celkový èas: 2010-03-17 15:04:27 - poèítaè byl restartován
ComboFix-quarantined-files.txt 2010-03-17 14:04
ComboFix2.txt 2010-03-17 13:36
ComboFix3.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 343 841 792
Po spuštìní: Volných bajtù: 10 301 734 912
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - E0740497329EA1792DBF386D8DF94D46
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security

Kód: Vybrat vše
KillAll::
Rootkit::
c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe
Re: Total XP security
Jsem tady s dalším logem. Teď na chvíli skončím, připojím se zase večer. Zatím moc děkuju za pomoc.
ComboFix 10-03-16.03 - Admin 17.03.2010 15:14:40.6.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.538 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-17_14.00.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-17 14:20 . 2010-03-17 14:20 16384 c:\windows\Temp\Perflib_Perfdata_6ec.dat
+ 2010-03-17 14:20 . 2010-03-17 14:20 16384 c:\windows\Temp\Perflib_Perfdata_118.dat
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 15:20
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spoc.sys >>UNKNOWN [0x8578E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7600f28
\Driver\ACPI -> ACPI.sys @ 0xf735bcb8
\Driver\atapi -> atapi.sys @ 0xf72f8b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84 SendCompleteHandler -> NDIS.sys @ 0xf726abb0
PacketIndicateHandler -> NDIS.sys @ 0xf7259a0d
SendHandler -> NDIS.sys @ 0xf726db40
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na bìžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2472)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\sm56hlpr.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ASWLSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ASWL2K.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Celkový èas: 2010-03-17 15:24:10 - poèítaè byl restartován
ComboFix-quarantined-files.txt 2010-03-17 14:24
ComboFix2.txt 2010-03-17 14:04
ComboFix3.txt 2010-03-17 13:36
ComboFix4.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 308 485 120
Po spuštìní: Volných bajtù: 10 267 754 496
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - 3F5157108953F33914404275984CBEC2
ComboFix 10-03-16.03 - Admin 17.03.2010 15:14:40.6.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.538 [GMT 1:00]
Spuštìný z: c:\documents and settings\Admin\Plocha\ComboFix.exe
Použité ovládací pøepínaèe :: c:\documents and settings\Admin\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 08:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-17 08:58 . 2010-03-17 08:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-17 06:35 . 2008-04-13 19:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2010-03-17 05:18 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-16 22:41 . 2010-03-16 22:41 -------- d-----w- C:\rsit
2010-03-16 05:31 . 2010-03-16 05:31 -------- d-----w- C:\FOUND.000
2010-03-10 00:28 . 2010-03-10 00:28 -------- d-----w- c:\program files\MSXML 4.0
2010-03-09 22:56 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:09 . 2010-03-09 18:09 -------- d-----w- c:\program files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30 . 2010-02-14 10:30 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54 . 2010-02-13 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-30 09:21 . 2010-01-30 09:20 -------- d-----w- c:\program files\Defraggler
2010-01-29 20:36 . 2010-01-29 20:36 -------- d-----w- c:\program files\CCleaner - zálohy reg
2010-01-28 03:57 . 2010-01-28 03:57 -------- d-----w- c:\program files\Winamp
2010-01-25 16:58 . 2004-11-20 10:15 47584 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 16:58 . 2004-11-20 10:15 313482 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 08:33 . 2010-01-17 08:33 -------- d-----w- c:\program files\Winamp Detect
2009-12-31 16:50 . 2004-11-20 10:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-11-20 10:14 916480 ------w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-17_14.00.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-17 14:20 . 2010-03-17 14:20 16384 c:\windows\Temp\Perflib_Perfdata_6ec.dat
+ 2010-03-17 14:20 . 2010-03-17 14:20 16384 c:\windows\Temp\Perflib_Perfdata_118.dat
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"nwiz"="nwiz.exe" [2006-04-26 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-26 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 106544]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2006-12-20 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
c:\documents and settings\All Users\Nab¡dka Start\Programy\Po spuçtØn¡\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-11-14 32768]
e-Backup 1.42 Scheduler.lnk - c:\windows\Installer\{CA217BDD-D941-454C-AA7E-C3ADA1648FE3}\_3e121a49.exe [2007-6-16 3638]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17.7.2009 20:55 64160]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.3.2009 17:55 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 9:46 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 9:46 20560]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18 14976]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.11.2008 16:04 14848]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.11.2008 16:04 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 19:56]
.
.
------- Doplòkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\b6wowqfp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 15:20
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesù ...
skenování skrytých položek 'Po spuštìní' ...
skenování skrytých souborù ...
sken byl úspešnì dokonèen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spoc.sys >>UNKNOWN [0x8578E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7600f28
\Driver\ACPI -> ACPI.sys @ 0xf735bcb8
\Driver\atapi -> atapi.sys @ 0xf72f8b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84 SendCompleteHandler -> NDIS.sys @ 0xf726abb0
PacketIndicateHandler -> NDIS.sys @ 0xf7259a0d
SendHandler -> NDIS.sys @ 0xf726db40
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na bìžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2472)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\sm56hlpr.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ASWLSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ASWL2K.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Celkový èas: 2010-03-17 15:24:10 - poèítaè byl restartován
ComboFix-quarantined-files.txt 2010-03-17 14:24
ComboFix2.txt 2010-03-17 14:04
ComboFix3.txt 2010-03-17 13:36
ComboFix4.txt 2010-03-17 06:36
Pøed spuštìním: Volných bajtù: 10 308 485 120
Po spuštìní: Volných bajtù: 10 267 754 496
Current=4 Default=4 Failed=2 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - 3F5157108953F33914404275984CBEC2
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security

Kód: Vybrat vše
Begin copying here:
Files to delete:
c:\documents and settings\Admin\Nabídka Start\Programy\Po spuštení\monnwb32.exe
Re: Total XP security
Zdravím. Jsem zpět a můj úžasný Total XP security také. V práci jsem pracoval s ComboFixem a vypadalo to, že je to na dobré cestě, ale teď jsem laptop zapnul s připojením k internetu a mizera byl první spustilo.
Chtěl jsem vložit log z ComboFixu, test proběhl v pořádku, ale teď už asi 30 minut připravuje log a PC nejeví známky aktivity. Vyřešil by to restart? Trochu se bojím s ComboFixem cokoliv dělat
.
Chtěl jsem vložit log z ComboFixu, test proběhl v pořádku, ale teď už asi 30 minut připravuje log a PC nejeví známky aktivity. Vyřešil by to restart? Trochu se bojím s ComboFixem cokoliv dělat

- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Total XP security
Restartujte PC a na disku C: se podívejte po logu.
Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Re: Total XP security
Já vím, vždyť už jsem si taky nafackoval
.
Počítač po restartu naběhl (XP security taky). Log jsem zkusil najít mělo by to snad být ono:
ComboFix 10-03-16.03 - Admin 17.03.2010 19:13:49.7.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.442 [GMT 1:00]
Spuštìný z: C:\Documents and Settings\Admin\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
Nakažená kopie C:\WINDOWS\system32\drivers\cdrom.sys byla nalezena a vyléèena.
Obnovena kopie z - C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 18:19:09 . 2010-03-17 18:19:10 98240 ----a-w- C:\WINDOWS\system32\dllcache\cdrom.sys
2010-03-17 18:02:57 . 2010-03-17 18:02:58 116 ----a-w- C:\WINDOWS\system32\fjhdyfhsn.bat
2010-03-17 18:02:16 . 2010-03-17 18:02:18 51807 ----a-w- C:\WINDOWS\system32\wuaucldt.exe
2010-03-17 18:02:16 . 2010-03-17 18:02:18 51807 ----a-w- C:\WINDOWS\system32\config\systemprofile\wuaucldt.exe
2010-03-17 08:58:59 . 2010-01-07 15:07:14 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58:23 . 2010-01-07 15:07:04 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-03-17 08:58:22 . 2010-03-17 08:58:24 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-17 06:35:09 . 2010-03-17 18:19:10 98240 ----a-w- C:\WINDOWS\system32\drivers\cdrom.sys
2010-03-17 05:18:10 . 2010-02-12 10:03:04 293376 ------w- C:\WINDOWS\system32\browserchoice.exe
2010-03-16 22:41:15 . 2010-03-16 22:41:16 -------- d-----w- C:\rsit
2010-03-16 05:31:16 . 2010-03-16 05:31:16 -------- d-----w- C:\FOUND.000
2010-03-10 00:28:04 . 2010-03-10 00:28:06 -------- d-----w- C:\Program Files\MSXML 4.0
2010-03-09 22:56:15 . 2009-10-23 15:28:38 3558912 ------w- C:\WINDOWS\system32\dllcache\moviemk.exe
2010-03-09 18:09:40 . 2010-03-09 18:09:42 -------- d-----w- C:\Program Files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30:40 . 2010-02-14 10:30:39 -------- d-----w- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54:22 . 2010-02-13 09:54:21 -------- d-----w- C:\Program Files\Microsoft Silverlight
2010-01-30 09:21:00 . 2010-01-30 09:20:59 -------- d-----w- C:\Program Files\Defraggler
2010-01-29 20:36:56 . 2010-01-29 20:36:54 -------- d-----w- C:\Program Files\CCleaner - zálohy reg
2010-01-28 03:57:08 . 2010-01-28 03:57:07 -------- d-----w- C:\Program Files\Winamp
2010-01-25 16:58:16 . 2004-11-20 10:15:02 47584 ----a-w- C:\WINDOWS\system32\perfc005.dat
2010-01-25 16:58:16 . 2004-11-20 10:15:02 313482 ----a-w- C:\WINDOWS\system32\perfh005.dat
2010-01-17 08:33:38 . 2010-01-17 08:33:37 -------- d-----w- C:\Program Files\Winamp Detect
2009-12-31 16:50:04 . 2004-11-20 10:14:50 353792 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2009-12-21 19:08:42 . 2004-11-20 10:14:54 916480 ------w- C:\WINDOWS\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-04-17 04:24:30 110592]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-26 21:48:00 7561216]
"nwiz"="nwiz.exe" [2006-04-26 21:48:00 1519616]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-26 21:48:00 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 22:34:26 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 00:52:52 15797248]
"ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 14:20:54 180224]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 01:26:48 761945]
"RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 02:01:32 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40:44 155648]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 16:13:56 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 04:49:02 106544]
"ioCentre"="C:\Genius\ioCentre\gTaskBar.exe" [2007-01-19 18:31:24 61440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16:00 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-10-11 03:17:36 149280]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2006-12-20 01:58:06 98304]
"syncman"="c:\windows\system32\wuaucldt.exe" [2010-03-17 18:02:18 51807]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:22:18 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58:06 1744896]
C:\Documents and Settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"C:\\Program Files\\QIP\\qip.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [17.7.2009 20:55:54 64160]
R0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [13.3.2009 17:55:02 717296]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [5.4.2008 9:46:35 114768]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [5.4.2008 9:46:35 20560]
R2 SBKUPNT;SBKUPNT;C:\WINDOWS\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18:28 14976]
R3 gHidPnp;USB Device Enhanced Function Driver;C:\WINDOWS\system32\drivers\gHidPnp.sys [26.11.2008 16:04:49 14848]
R3 gMouUsb;USB Mouse Device Drv;C:\WINDOWS\system32\drivers\gMouUsb.sys [26.11.2008 16:04:50 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49:08 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 15:49:08 . 2010-03-12 19:56:26]
.

Počítač po restartu naběhl (XP security taky). Log jsem zkusil najít mělo by to snad být ono:
ComboFix 10-03-16.03 - Admin 17.03.2010 19:13:49.7.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.442 [GMT 1:00]
Spuštìný z: C:\Documents and Settings\Admin\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100316-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
Nakažená kopie C:\WINDOWS\system32\drivers\cdrom.sys byla nalezena a vyléèena.
Obnovena kopie z - C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
.
((((((((((((((((((((((((( Soubory vytvoøené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 18:19:09 . 2010-03-17 18:19:10 98240 ----a-w- C:\WINDOWS\system32\dllcache\cdrom.sys
2010-03-17 18:02:57 . 2010-03-17 18:02:58 116 ----a-w- C:\WINDOWS\system32\fjhdyfhsn.bat
2010-03-17 18:02:16 . 2010-03-17 18:02:18 51807 ----a-w- C:\WINDOWS\system32\wuaucldt.exe
2010-03-17 18:02:16 . 2010-03-17 18:02:18 51807 ----a-w- C:\WINDOWS\system32\config\systemprofile\wuaucldt.exe
2010-03-17 08:58:59 . 2010-01-07 15:07:14 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-03-17 08:58:23 . 2010-01-07 15:07:04 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-03-17 08:58:22 . 2010-03-17 08:58:24 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-17 06:35:09 . 2010-03-17 18:19:10 98240 ----a-w- C:\WINDOWS\system32\drivers\cdrom.sys
2010-03-17 05:18:10 . 2010-02-12 10:03:04 293376 ------w- C:\WINDOWS\system32\browserchoice.exe
2010-03-16 22:41:15 . 2010-03-16 22:41:16 -------- d-----w- C:\rsit
2010-03-16 05:31:16 . 2010-03-16 05:31:16 -------- d-----w- C:\FOUND.000
2010-03-10 00:28:04 . 2010-03-10 00:28:06 -------- d-----w- C:\Program Files\MSXML 4.0
2010-03-09 22:56:15 . 2009-10-23 15:28:38 3558912 ------w- C:\WINDOWS\system32\dllcache\moviemk.exe
2010-03-09 18:09:40 . 2010-03-09 18:09:42 -------- d-----w- C:\Program Files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 10:30:40 . 2010-02-14 10:30:39 -------- d-----w- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-02-13 09:54:22 . 2010-02-13 09:54:21 -------- d-----w- C:\Program Files\Microsoft Silverlight
2010-01-30 09:21:00 . 2010-01-30 09:20:59 -------- d-----w- C:\Program Files\Defraggler
2010-01-29 20:36:56 . 2010-01-29 20:36:54 -------- d-----w- C:\Program Files\CCleaner - zálohy reg
2010-01-28 03:57:08 . 2010-01-28 03:57:07 -------- d-----w- C:\Program Files\Winamp
2010-01-25 16:58:16 . 2004-11-20 10:15:02 47584 ----a-w- C:\WINDOWS\system32\perfc005.dat
2010-01-25 16:58:16 . 2004-11-20 10:15:02 313482 ----a-w- C:\WINDOWS\system32\perfh005.dat
2010-01-17 08:33:38 . 2010-01-17 08:33:37 -------- d-----w- C:\Program Files\Winamp Detect
2009-12-31 16:50:04 . 2004-11-20 10:14:50 353792 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2009-12-21 19:08:42 . 2004-11-20 10:14:54 916480 ------w- C:\WINDOWS\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-04-17 04:24:30 110592]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-26 21:48:00 7561216]
"nwiz"="nwiz.exe" [2006-04-26 21:48:00 1519616]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-26 21:48:00 86016]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 22:34:26 544768]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 00:52:52 15797248]
"ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 14:20:54 180224]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 01:26:48 761945]
"RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 02:01:32 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40:44 155648]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 16:13:56 86016]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 04:49:02 106544]
"ioCentre"="C:\Genius\ioCentre\gTaskBar.exe" [2007-01-19 18:31:24 61440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16:00 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-10-11 03:17:36 149280]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2006-12-20 01:58:06 98304]
"syncman"="c:\windows\system32\wuaucldt.exe" [2010-03-17 18:02:18 51807]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:22:18 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58:06 1744896]
C:\Documents and Settings\Admin\Nab¡dka Start\Programy\Po spuçtØn¡\
monnwb32.exe [2008-4-14 16384]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Digital Libraries\\WHO Training Modules on GMP - July 2007\\gsdl\\server.exe"=
"C:\\Program Files\\QIP\\qip.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:Sdílený port 4662
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [17.7.2009 20:55:54 64160]
R0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [13.3.2009 17:55:02 717296]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [5.4.2008 9:46:35 114768]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [5.4.2008 9:46:35 20560]
R2 SBKUPNT;SBKUPNT;C:\WINDOWS\system32\drivers\SBKUPNT.SYS [29.12.2009 2:18:28 14976]
R3 gHidPnp;USB Device Enhanced Function Driver;C:\WINDOWS\system32\drivers\gHidPnp.sys [26.11.2008 16:04:49 14848]
R3 gMouUsb;USB Mouse Device Drv;C:\WINDOWS\system32\drivers\gMouUsb.sys [26.11.2008 16:04:50 9984]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49:08 1029456]
.
Obsah adresáøe 'Naplánované úlohy'
2010-03-15 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 15:49:08 . 2010-03-12 19:56:26]
.