prosím o kontrolu logu-virus nejde odstranit
Napsal: 05 lis 2008 17:19
Dobrý den prosím o kontrolu logu, NOD mi detekoval infiltraci v c:\WINDOWS\system32\cmsetAC.dll.
Při první kontrole napsal : "pravděpodobná varianta infiltrace Win32/BHO trojský kůň"
Při druhé kontrole : "varianta infiltrace Win32/Rootkit.Podnuha trojský kůň".
Uvedený soubor nejde léčit ani smazat. Zkoušel jsem ho odstranit různými programy (Hijackthis,NOD,Killbox,Combofix,RegRun Security Suite),ale bez úspěchu .
Log z Hijackthis:
---------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:39:43, on 5.11.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Antivir\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Antivir\a-squared Free\a2service.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ConMet\ConMet.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\TotalCmd UP4\totalcmd.exe
C:\Program Files\antivir\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {18BF432C-DBA1-4596-97C0-53EB14188BBE} - C:\WINDOWS\system32\cmsetAC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ConMet] C:\Program Files\ConMet\ConMet.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\Antivir\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Antivir\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
Log z Combofix:
---------------
ComboFix 08-07-26.1 - Jirka 2008-11-05 14:28:11.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.599 [GMT 1:00]
Running from: C:\Documents and Settings\Jirka\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jirka\Plocha\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
C:\WINDOWS\system32\cmsetac.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\cmsetac.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.
2008-11-05 14:22 . 2008-11-05 14:23 2,793,917 --a------ C:\WINDOWS\system32\VDSFNKPXVN
2008-11-05 12:50 . 2004-08-17 15:49 147,968 --a------ C:\WINDOWS\R.COM
2008-11-05 12:50 . 2004-08-17 15:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-11-05 12:50 . 2008-11-05 12:50 26 --a------ C:\WINDOWS\Lic.xxx
2008-11-05 12:21 . 2008-11-05 12:21 43 --a------ C:\WINDOWS\system32\Partizan.RRI
2008-11-05 11:56 . 2008-11-05 11:56 <DIR> d-------- C:\WINDOWS\RestoreSafeDeleted
2008-11-05 11:53 . 2008-11-05 12:07 (2) -rahs-ot- C:\WINDOWS\winstart.bat
2008-11-04 20:57 . 2008-11-04 20:57 82 --a------ C:\WINDOWS\SILCOM_P.INI
2008-11-04 17:53 . 1996-02-14 14:01 92,208 --a------ C:\WINDOWS\system32\WING.DLL
2008-11-04 17:53 . 1996-02-14 14:01 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2008-11-04 17:49 . 1996-02-14 14:01 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL
2008-11-04 17:49 . 1996-02-14 14:01 92,208 --a------ C:\WINDOWS\system\WING.DLL
2008-11-04 17:49 . 1998-09-02 12:43 81,920 --a------ C:\WINDOWS\system\LZSCMPRS.DLL
2008-11-04 17:49 . 1996-02-14 14:01 12,800 --a------ C:\WINDOWS\system\WING32.DLL
2008-11-04 17:49 . 1996-02-14 14:01 6,736 --a------ C:\WINDOWS\system\WINGDIB.DRV
2008-11-04 17:49 . 1996-02-14 14:01 5,024 --a------ C:\WINDOWS\system\WINGPAL.WND
2008-11-04 17:49 . 1996-02-14 14:01 1,966 --a------ C:\WINDOWS\system\DVA.386
2008-11-04 17:47 . 1997-04-18 11:45 252,928 --a------ C:\WINDOWS\UN160405.EXE
2008-11-04 17:47 . 1996-11-05 16:19 247,648 --a------ C:\WINDOWS\UNINST16.EXE
2008-11-04 17:47 . 1995-07-13 18:43 26,768 --a------ C:\WINDOWS\system\CTL3D.DLL
2008-11-04 17:47 . 2008-11-04 18:15 230 --a------ C:\WINDOWS\compedia.ini
2008-10-31 21:37 . 2008-10-31 21:37 <DIR> d-------- C:\Program Files\proDAD
2008-10-31 21:37 . 2008-10-31 21:37 <DIR> d-------- C:\Program Files\LooksBuilderSE
2008-10-31 21:37 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-10-31 21:36 . 2008-10-31 23:10 <DIR> d-------- C:\Program Files\Boris FX, Inc
2008-10-31 21:36 . 2003-06-26 10:04 237,568 -ra------ C:\WINDOWS\system32\qtmlClient.dll
2008-10-31 21:36 . 2003-07-01 16:49 69,632 --a------ C:\WINDOWS\system32\MtxPreview.dll
2008-10-31 21:36 . 2003-07-01 16:49 49,152 --a------ C:\WINDOWS\system32\MtxParhBFXPreview.dll
2008-10-31 21:36 . 2003-01-20 09:08 49,152 --a------ C:\WINDOWS\system32\CvoAPI.dll
2008-10-31 21:36 . 2003-07-09 10:43 45,056 --a------ C:\WINDOWS\system32\BFXSrcFilter.ax
2008-10-31 21:36 . 2008-10-31 23:18 2,689 --a------ C:\WINDOWS\Graffiti5.2Pin.ini
2008-10-31 21:32 . 2008-10-31 21:32 <DIR> d-------- C:\Program Files\Common Files\Pinnacle
2008-10-31 21:32 . 2005-09-23 23:18 171,520 --a------ C:\WINDOWS\system32\drivers\MarvinBus.sys
2008-10-31 21:31 . 2008-10-31 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikac
2008-10-31 21:28 . 2008-10-31 21:35 <DIR> d-------- C:\Program Files\Pinnacle
2008-10-31 21:28 . 2008-10-31 21:28 <DIR> d-------- C:\Program Files\Common Files\Yahoo!
2008-10-31 11:43 . 2008-10-31 11:43 459,857 --a------ C:\bookmarks 31.10.2008.html
2008-10-20 16:06 . 2004-03-09 16:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-10-20 16:06 . 2004-03-09 16:45 440,352 --a------ C:\WINDOWS\system32\MSHFLXGD.OCX
2008-10-20 16:06 . 2004-03-09 16:45 224,016 --a------ C:\WINDOWS\system32\TABCTL32.OCX
2008-10-20 16:06 . 2004-03-09 16:45 212,240 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2008-10-20 16:06 . 1998-06-26 21:22 205,848 --a------ C:\WINDOWS\system32\threed32.ocx
2008-10-20 16:06 . 2004-03-09 16:45 167,968 --a------ C:\WINDOWS\system32\MSMASK32.OCX
2008-10-20 16:06 . 1999-08-11 14:21 129,024 --a------ C:\WINDOWS\system32\VDGT.ocx
2008-10-20 16:06 . 1998-06-26 21:22 84,000 --a------ C:\WINDOWS\system32\msoutl32.ocx
2008-10-20 16:06 . 1998-06-23 20:57 67,376 --a------ C:\WINDOWS\system32\SYSINFO.OCX
2008-10-20 16:06 . 1998-06-26 21:22 57,880 --a------ C:\WINDOWS\system32\spin32.ocx
2008-10-20 15:56 . 2008-10-20 15:56 459,687 --a------ C:\bookmarks20.10.2008.html
2008-10-19 12:33 . 2008-10-19 12:33 <DIR> d-------- C:\Program Files\Ubi Soft
2008-10-19 12:33 . 2002-12-18 09:23 140,488 -ra------ C:\WINDOWS\system32\comdlg32.ocx
2008-10-19 12:33 . 2002-12-18 09:23 115,016 -ra------ C:\WINDOWS\system32\MSINET.OCX
2008-10-19 12:33 . 2002-12-18 09:23 89,360 -ra------ C:\WINDOWS\system32\VB5DB.DLL
2008-10-19 12:33 . 2002-12-18 09:23 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
2008-10-19 12:33 . 2002-12-18 09:23 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
2008-10-19 12:33 . 2002-12-18 09:23 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
2008-10-19 12:33 . 2002-12-18 22:20 26,096 -ra------ C:\WINDOWS\system32\xmlinst.exe
2008-10-13 21:46 . 2008-10-31 21:32 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-10-13 21:46 . 2008-10-13 21:46 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-10-13 21:46 . 2008-10-13 21:46 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-10-13 21:46 . 2004-08-17 15:49 93,184 --a------ C:\WINDOWS\system32\cmsetAC.dll
2008-10-05 19:48 . 2008-10-05 19:48 <DIR> d-------- C:\Program Files\IMSI
2008-10-05 11:59 . 2008-10-05 11:59 93 --a------ C:\WINDOWS\ALIK.INI
2008-10-05 11:57 . 2008-11-04 20:56 253,952 --------- C:\WINDOWS\Setup1.exe
2008-10-05 11:57 . 2008-11-04 20:56 73,728 --a------ C:\WINDOWS\ST6UNST.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 11:54 --------- d-----w C:\Program Files\Antivir
2008-11-03 19:22 --------- d-----w C:\Program Files\ConMet
2008-10-31 20:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-31 14:18 59,488 ----a-w C:\WINDOWS\system32\GenSvcInst.exe
2008-10-31 10:36 --------- d-----w C:\Program Files\Mozilla Firefox3
2008-10-13 20:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-05 18:17 --------- d-----w C:\Program Files\ESET
2008-09-22 20:12 --------- d-----w C:\Program Files\WinPcap
2008-09-22 20:05 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-09-21 20:29 --------- d-----w C:\Program Files\Common Files\ParallelGraphics
2008-09-18 17:41 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-09-15 15:40 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-10 12:56 --------- d-----w C:\Program Files\Logitech
2008-09-10 12:56 --------- d-----w C:\Program Files\Common Files\Logitech
2008-09-08 15:38 --------- d-----w C:\Program Files\CyberLink
2008-09-08 15:37 505,392 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-08 14:38 67,072 ----a-w C:\WINDOWS\system32\realbap1.dll
2008-09-08 09:57 --------- d-----w C:\Program Files\Java
2008-09-08 09:56 --------- d-----w C:\Program Files\Common Files\Java
2008-09-05 16:32 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-05 16:28 --------- d-----w C:\Program Files\epson
2008-09-05 16:00 --------- d-----w C:\Program Files\MSBuild
2008-09-05 16:00 --------- d-----w C:\Program Files\Microsoft Works
2008-09-05 15:59 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-05 15:57 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-09-05 15:50 674,600 ----a-w C:\WINDOWS\system32\pbsvc.exe
2008-09-05 14:50 491,520 ----a-w C:\WINDOWS\WebIE.dll
2008-09-05 14:50 45,056 ----a-w C:\WINDOWS\TRNOEH.DLL
2008-09-05 14:50 356,352 ----a-w C:\WINDOWS\TrnOutl.dll
2008-09-05 14:50 294,912 ----a-w C:\WINDOWS\TrnWord.dll
2008-09-05 14:50 26,624 ----a-w C:\WINDOWS\OETRN.EXE
2008-09-05 14:50 200,704 ----a-w C:\WINDOWS\TRNOET.DLL
2008-09-05 14:47 516,096 ----a-w C:\WINDOWS\UN32.EXE
2008-09-03 16:06 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-09-03 16:06 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-09-03 15:37 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-09-01 13:50 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-28 17:50 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-08-20 05:38 660,480 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:46 2,182,528 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:46 2,059,904 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18BF432C-DBA1-4596-97C0-53EB14188BBE}]
2004-08-17 15:49 93184 --a------ C:\WINDOWS\system32\cmsetAC.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 07:21 1443072]
"ConMet"="C:\Program Files\ConMet\ConMet.exe" [2008-11-03 20:22 3590144]
"Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 10:38 88584]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 08:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"CHotkey"="mHotkey.exe" [2002-07-05 15:37 491008 C:\WINDOWS\mHotkey.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"vidc.mjpg"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 01:38 34672 D:\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX6000 Series]
--a------ 2006-02-13 05:00 131072 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIBIE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-26 23:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
Při první kontrole napsal : "pravděpodobná varianta infiltrace Win32/BHO trojský kůň"
Při druhé kontrole : "varianta infiltrace Win32/Rootkit.Podnuha trojský kůň".
Uvedený soubor nejde léčit ani smazat. Zkoušel jsem ho odstranit různými programy (Hijackthis,NOD,Killbox,Combofix,RegRun Security Suite),ale bez úspěchu .
Log z Hijackthis:
---------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:39:43, on 5.11.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Antivir\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Antivir\a-squared Free\a2service.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ConMet\ConMet.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\TotalCmd UP4\totalcmd.exe
C:\Program Files\antivir\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {18BF432C-DBA1-4596-97C0-53EB14188BBE} - C:\WINDOWS\system32\cmsetAC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ConMet] C:\Program Files\ConMet\ConMet.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\Antivir\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Antivir\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
Log z Combofix:
---------------
ComboFix 08-07-26.1 - Jirka 2008-11-05 14:28:11.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.599 [GMT 1:00]
Running from: C:\Documents and Settings\Jirka\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jirka\Plocha\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
C:\WINDOWS\system32\cmsetac.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\cmsetac.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.
2008-11-05 14:22 . 2008-11-05 14:23 2,793,917 --a------ C:\WINDOWS\system32\VDSFNKPXVN
2008-11-05 12:50 . 2004-08-17 15:49 147,968 --a------ C:\WINDOWS\R.COM
2008-11-05 12:50 . 2004-08-17 15:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-11-05 12:50 . 2008-11-05 12:50 26 --a------ C:\WINDOWS\Lic.xxx
2008-11-05 12:21 . 2008-11-05 12:21 43 --a------ C:\WINDOWS\system32\Partizan.RRI
2008-11-05 11:56 . 2008-11-05 11:56 <DIR> d-------- C:\WINDOWS\RestoreSafeDeleted
2008-11-05 11:53 . 2008-11-05 12:07 (2) -rahs-ot- C:\WINDOWS\winstart.bat
2008-11-04 20:57 . 2008-11-04 20:57 82 --a------ C:\WINDOWS\SILCOM_P.INI
2008-11-04 17:53 . 1996-02-14 14:01 92,208 --a------ C:\WINDOWS\system32\WING.DLL
2008-11-04 17:53 . 1996-02-14 14:01 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2008-11-04 17:49 . 1996-02-14 14:01 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL
2008-11-04 17:49 . 1996-02-14 14:01 92,208 --a------ C:\WINDOWS\system\WING.DLL
2008-11-04 17:49 . 1998-09-02 12:43 81,920 --a------ C:\WINDOWS\system\LZSCMPRS.DLL
2008-11-04 17:49 . 1996-02-14 14:01 12,800 --a------ C:\WINDOWS\system\WING32.DLL
2008-11-04 17:49 . 1996-02-14 14:01 6,736 --a------ C:\WINDOWS\system\WINGDIB.DRV
2008-11-04 17:49 . 1996-02-14 14:01 5,024 --a------ C:\WINDOWS\system\WINGPAL.WND
2008-11-04 17:49 . 1996-02-14 14:01 1,966 --a------ C:\WINDOWS\system\DVA.386
2008-11-04 17:47 . 1997-04-18 11:45 252,928 --a------ C:\WINDOWS\UN160405.EXE
2008-11-04 17:47 . 1996-11-05 16:19 247,648 --a------ C:\WINDOWS\UNINST16.EXE
2008-11-04 17:47 . 1995-07-13 18:43 26,768 --a------ C:\WINDOWS\system\CTL3D.DLL
2008-11-04 17:47 . 2008-11-04 18:15 230 --a------ C:\WINDOWS\compedia.ini
2008-10-31 21:37 . 2008-10-31 21:37 <DIR> d-------- C:\Program Files\proDAD
2008-10-31 21:37 . 2008-10-31 21:37 <DIR> d-------- C:\Program Files\LooksBuilderSE
2008-10-31 21:37 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-10-31 21:36 . 2008-10-31 23:10 <DIR> d-------- C:\Program Files\Boris FX, Inc
2008-10-31 21:36 . 2003-06-26 10:04 237,568 -ra------ C:\WINDOWS\system32\qtmlClient.dll
2008-10-31 21:36 . 2003-07-01 16:49 69,632 --a------ C:\WINDOWS\system32\MtxPreview.dll
2008-10-31 21:36 . 2003-07-01 16:49 49,152 --a------ C:\WINDOWS\system32\MtxParhBFXPreview.dll
2008-10-31 21:36 . 2003-01-20 09:08 49,152 --a------ C:\WINDOWS\system32\CvoAPI.dll
2008-10-31 21:36 . 2003-07-09 10:43 45,056 --a------ C:\WINDOWS\system32\BFXSrcFilter.ax
2008-10-31 21:36 . 2008-10-31 23:18 2,689 --a------ C:\WINDOWS\Graffiti5.2Pin.ini
2008-10-31 21:32 . 2008-10-31 21:32 <DIR> d-------- C:\Program Files\Common Files\Pinnacle
2008-10-31 21:32 . 2005-09-23 23:18 171,520 --a------ C:\WINDOWS\system32\drivers\MarvinBus.sys
2008-10-31 21:31 . 2008-10-31 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikac
2008-10-31 21:28 . 2008-10-31 21:35 <DIR> d-------- C:\Program Files\Pinnacle
2008-10-31 21:28 . 2008-10-31 21:28 <DIR> d-------- C:\Program Files\Common Files\Yahoo!
2008-10-31 11:43 . 2008-10-31 11:43 459,857 --a------ C:\bookmarks 31.10.2008.html
2008-10-20 16:06 . 2004-03-09 16:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-10-20 16:06 . 2004-03-09 16:45 440,352 --a------ C:\WINDOWS\system32\MSHFLXGD.OCX
2008-10-20 16:06 . 2004-03-09 16:45 224,016 --a------ C:\WINDOWS\system32\TABCTL32.OCX
2008-10-20 16:06 . 2004-03-09 16:45 212,240 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2008-10-20 16:06 . 1998-06-26 21:22 205,848 --a------ C:\WINDOWS\system32\threed32.ocx
2008-10-20 16:06 . 2004-03-09 16:45 167,968 --a------ C:\WINDOWS\system32\MSMASK32.OCX
2008-10-20 16:06 . 1999-08-11 14:21 129,024 --a------ C:\WINDOWS\system32\VDGT.ocx
2008-10-20 16:06 . 1998-06-26 21:22 84,000 --a------ C:\WINDOWS\system32\msoutl32.ocx
2008-10-20 16:06 . 1998-06-23 20:57 67,376 --a------ C:\WINDOWS\system32\SYSINFO.OCX
2008-10-20 16:06 . 1998-06-26 21:22 57,880 --a------ C:\WINDOWS\system32\spin32.ocx
2008-10-20 15:56 . 2008-10-20 15:56 459,687 --a------ C:\bookmarks20.10.2008.html
2008-10-19 12:33 . 2008-10-19 12:33 <DIR> d-------- C:\Program Files\Ubi Soft
2008-10-19 12:33 . 2002-12-18 09:23 140,488 -ra------ C:\WINDOWS\system32\comdlg32.ocx
2008-10-19 12:33 . 2002-12-18 09:23 115,016 -ra------ C:\WINDOWS\system32\MSINET.OCX
2008-10-19 12:33 . 2002-12-18 09:23 89,360 -ra------ C:\WINDOWS\system32\VB5DB.DLL
2008-10-19 12:33 . 2002-12-18 09:23 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
2008-10-19 12:33 . 2002-12-18 09:23 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
2008-10-19 12:33 . 2002-12-18 09:23 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
2008-10-19 12:33 . 2002-12-18 22:20 26,096 -ra------ C:\WINDOWS\system32\xmlinst.exe
2008-10-13 21:46 . 2008-10-31 21:32 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-10-13 21:46 . 2008-10-13 21:46 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-10-13 21:46 . 2008-10-13 21:46 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-10-13 21:46 . 2004-08-17 15:49 93,184 --a------ C:\WINDOWS\system32\cmsetAC.dll
2008-10-05 19:48 . 2008-10-05 19:48 <DIR> d-------- C:\Program Files\IMSI
2008-10-05 11:59 . 2008-10-05 11:59 93 --a------ C:\WINDOWS\ALIK.INI
2008-10-05 11:57 . 2008-11-04 20:56 253,952 --------- C:\WINDOWS\Setup1.exe
2008-10-05 11:57 . 2008-11-04 20:56 73,728 --a------ C:\WINDOWS\ST6UNST.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 11:54 --------- d-----w C:\Program Files\Antivir
2008-11-03 19:22 --------- d-----w C:\Program Files\ConMet
2008-10-31 20:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-31 14:18 59,488 ----a-w C:\WINDOWS\system32\GenSvcInst.exe
2008-10-31 10:36 --------- d-----w C:\Program Files\Mozilla Firefox3
2008-10-13 20:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-05 18:17 --------- d-----w C:\Program Files\ESET
2008-09-22 20:12 --------- d-----w C:\Program Files\WinPcap
2008-09-22 20:05 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-09-21 20:29 --------- d-----w C:\Program Files\Common Files\ParallelGraphics
2008-09-18 17:41 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-09-15 15:40 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-10 12:56 --------- d-----w C:\Program Files\Logitech
2008-09-10 12:56 --------- d-----w C:\Program Files\Common Files\Logitech
2008-09-08 15:38 --------- d-----w C:\Program Files\CyberLink
2008-09-08 15:37 505,392 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-08 14:38 67,072 ----a-w C:\WINDOWS\system32\realbap1.dll
2008-09-08 09:57 --------- d-----w C:\Program Files\Java
2008-09-08 09:56 --------- d-----w C:\Program Files\Common Files\Java
2008-09-05 16:32 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-05 16:28 --------- d-----w C:\Program Files\epson
2008-09-05 16:00 --------- d-----w C:\Program Files\MSBuild
2008-09-05 16:00 --------- d-----w C:\Program Files\Microsoft Works
2008-09-05 15:59 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-05 15:57 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-09-05 15:50 674,600 ----a-w C:\WINDOWS\system32\pbsvc.exe
2008-09-05 14:50 491,520 ----a-w C:\WINDOWS\WebIE.dll
2008-09-05 14:50 45,056 ----a-w C:\WINDOWS\TRNOEH.DLL
2008-09-05 14:50 356,352 ----a-w C:\WINDOWS\TrnOutl.dll
2008-09-05 14:50 294,912 ----a-w C:\WINDOWS\TrnWord.dll
2008-09-05 14:50 26,624 ----a-w C:\WINDOWS\OETRN.EXE
2008-09-05 14:50 200,704 ----a-w C:\WINDOWS\TRNOET.DLL
2008-09-05 14:47 516,096 ----a-w C:\WINDOWS\UN32.EXE
2008-09-03 16:06 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-09-03 16:06 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-09-03 15:37 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-09-01 13:50 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-28 17:50 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-08-20 05:38 660,480 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:46 2,182,528 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:46 2,059,904 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18BF432C-DBA1-4596-97C0-53EB14188BBE}]
2004-08-17 15:49 93184 --a------ C:\WINDOWS\system32\cmsetAC.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 07:21 1443072]
"ConMet"="C:\Program Files\ConMet\ConMet.exe" [2008-11-03 20:22 3590144]
"Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 10:38 88584]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 08:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"CHotkey"="mHotkey.exe" [2002-07-05 15:37 491008 C:\WINDOWS\mHotkey.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"vidc.mjpg"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 01:38 34672 D:\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX6000 Series]
--a------ 2006-02-13 05:00 131072 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIBIE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-26 23:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe