Log z MbAM:
Malwarebytes' Anti-Malware 1.40
Verze databáze: 2551
Windows 5.1.2600 Service Pack 3 (Safe Mode)
18.8.2009 18:10:45
mbam-log-2009-08-18 (18-10-45).txt
Typ skenu: Rychlý sken
Objektu skenováno: 89735
Uplynulý cas: 12 minute(s), 29 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 8
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 1
Infikované soubory: 7
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{18b0e5c2-99cb-11cf-ayx5-00401c648513} (Generic.Bot.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e24211b3-a78a-c6a9-d317-70979ace5058} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované soubory:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\iuhi64.exe (Generic.Bot.H) -> Quarantined and deleted successfully.
C:\lyusoqm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\yaewfl.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
Log z ComboFix:
ComboFix 09-08-10.06 - Kristynka 18.08.2009 18:20.1.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.495.331 [GMT 2:00]
Spuštěný z: c:\documents and settings\Kristynka\Plocha\ComboFix.exe
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-1065487665
c:\documents and settings\All Users\Data aplikací\17874684
c:\documents and settings\All Users\Data aplikací\17874684\17874684
c:\documents and settings\All Users\Data aplikací\17874684\17874684.exe
c:\documents and settings\All Users\Data aplikací\17874684\pc17874684ins
C:\wbwue.exe
c:\windows\system32\drivers\e5d311d2.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_e5d311d2
((((((((((((((((((((((((( Soubory vytvořené od 2009-07-18 do 2009-08-18 )))))))))))))))))))))))))))))))
.
2009-08-17 21:10 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 21:10 . 2009-08-17 21:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 21:10 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 15:14 . 2009-08-17 15:15 -------- d-----w- c:\program files\CCleaner
2009-08-17 15:09 . 2009-08-17 15:09 -------- d-----w- c:\program files\Trend Micro
2009-08-17 15:03 . 2009-08-17 15:03 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-10 20:06 . 2009-08-10 20:06 36352 ----a-w- c:\windows\system32\csbdll.dll
2009-08-10 20:06 . 2009-08-10 20:06 81408 ----a-w- C:\jnvcbaox.exe
2009-07-30 22:13 . 2009-07-30 22:13 -------- d-----w- c:\program files\ICQ6Toolbar
2009-07-30 19:36 . 2009-07-30 19:37 -------- d-----w- c:\program files\Paint.NET
2009-07-28 20:49 . 2009-07-03 16:59 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 20:49 . 2009-07-03 16:59 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-27 20:48 . 2008-11-20 19:19 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-27 20:48 . 2008-11-20 19:19 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-27 20:48 . 2009-07-27 20:48 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-07-24 16:05 . 2009-07-24 16:05 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-07-24 16:00 . 2009-07-27 20:47 -------- d-----w- c:\program files\Google
2009-07-24 15:59 . 2009-07-24 15:59 -------- d-----w- c:\program files\Common Files\Skype
2009-07-24 15:59 . 2009-07-24 16:00 -------- d-----r- c:\program files\Skype
2009-07-23 16:13 . 2009-07-23 16:13 -------- d-----w- c:\program files\Axesstel
2009-07-23 16:13 . 2008-06-17 09:35 212992 ----a-r- c:\program files\MSP_Uninstall.exe
2009-07-23 16:13 . 2007-04-04 07:24 90112 ----a-r- c:\program files\axesstel.dll
2009-07-23 16:13 . 2007-03-26 06:25 38784 ----a-w- c:\windows\system32\drivers\Axtmvprt.sys
2009-07-23 16:13 . 2007-03-26 06:25 40064 ----a-w- c:\windows\system32\drivers\Axtmvmdm.sys
2009-07-23 16:13 . 2007-03-22 08:36 3456 ----a-w- c:\windows\system32\drivers\Axtmvflt.sys
2009-07-22 21:19 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-07-22 21:19 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 22:13 . 2009-07-09 10:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-10 10:14 . 2009-07-10 10:14 -------- d-----w- c:\program files\Common Files\Nero
2009-07-10 10:14 . 2009-07-10 10:13 -------- d-----w- c:\program files\Common Files\LightScribe
2009-07-10 10:11 . 2009-07-10 10:10 -------- d-----w- c:\program files\Ahead
2009-07-10 10:10 . 2009-07-10 10:10 -------- d-----w- c:\program files\Common Files\Ahead
2009-07-10 09:07 . 2009-07-09 10:55 -------- d-----w- c:\program files\Asus
2009-07-10 07:23 . 2009-07-09 15:17 -------- d-----w- c:\program files\Windows Desktop Search
2009-07-09 16:10 . 2004-11-20 09:15 90924 ----a-w- c:\windows\system32\perfc005.dat
2009-07-09 16:10 . 2004-11-20 09:15 458882 ----a-w- c:\windows\system32\perfh005.dat
2009-07-09 15:33 . 2009-07-09 15:33 -------- d-----w- c:\program files\MSBuild
2009-07-09 15:32 . 2009-07-09 15:32 -------- d-----w- c:\program files\Reference Assemblies
2009-07-09 15:16 . 2009-07-09 15:16 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-09 14:52 . 2009-07-09 10:36 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-09 14:52 . 2009-07-09 10:36 2684 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-07-09 14:02 . 2009-07-09 10:36 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-07-09 13:36 . 2009-07-09 13:36 -------- d-----w- c:\program files\ASUS_1280x1024_white
2009-07-09 11:16 . 2009-07-09 11:16 546 ----a-w- c:\windows\system32\ABA3HF.DAT
2009-07-09 11:04 . 2009-07-09 11:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-09 11:02 . 2009-07-09 11:02 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-09 11:02 . 2009-07-09 11:02 -------- d-----w- c:\program files\ASUS WLAN Adapter
2009-07-09 10:57 . 2009-07-09 10:57 -------- d-----w- c:\program files\Synaptics
2009-07-09 10:57 . 2009-07-09 10:57 -------- d-----w- c:\program files\Wireless Console 2
2009-07-09 10:53 . 2009-07-09 10:53 -------- d-----w- c:\program files\Realtek
2009-07-09 10:53 . 2009-07-09 10:53 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-09 10:46 . 2009-07-09 10:46 -------- d-----w- c:\program files\Symantec
2009-07-09 10:46 . 2009-07-09 10:46 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-09 10:41 . 2009-07-09 10:41 -------- d-----w- c:\program files\Intel
2009-07-09 10:37 . 2009-07-09 10:37 -------- d-----w- c:\program files\microsoft frontpage
2009-07-09 10:34 . 2009-07-09 10:34 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-03 16:59 . 2004-11-20 09:14 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-16 14:40 . 2004-11-20 09:14 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:40 . 2004-11-20 09:14 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:11 . 2004-11-20 09:14 1293824 ----a-w- c:\windows\system32\quartz.dll
2009-05-24 22:24 . 2008-05-26 20:18 350208 ----a-w- c:\windows\system32\mssph.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-24 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-27 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-27 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-27 118784]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 86016]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"ACU"="c:\program files\ASUS WLAN Adapter\ACU.exe" [2006-04-14 307200]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-02-10 15969280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
ASUS ChkMail.lnk - c:\program files\Asus\Asus ChkMail\ChkMail.exe [2009-7-9 32768]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\csbdll]
2009-08-10 20:06 36352 ----a-w- c:\windows\system32\csbdll.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [31.7.2009 0:13 222456]
R3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\ATK0100\ASNDIS5.sys [9.7.2009 12:09 16269]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [23.7.2009 18:13 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [23.7.2009 18:13 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [23.7.2009 18:13 38784]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Net4Switch - c:\program files\ASUS\Net4Switch\Net4Switch.exe
HKCU-Run-ICQ - c:\program files\ICQ6.5\ICQ.exe
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-18 18:31
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\csbdll.dll
- - - - - - - > 'explorer.exe'(3628)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\ATK0100\ATKOSD.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Celkový čas: 2009-08-18 18:34 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-08-18 16:34
Před spuštěním: Volných bajtů: 38 484 909 568
Po spuštění: Volných bajtů: 38 086 908 928
176 --- E O F --- 2009-07-28 22:03
Musím dodat, že jakmile Combo restartovalo laptop, tak sem si nebyl jistý, jestli mám to pak ručně přepnout do nouzového režimu a nebo nechat běžet do normálního režimu. Dle Tvé instrukce a instrukce Combo sem se rozhodl, že na nic šahat nebudu a došlo to bezproblému na normál režim automaticky a vyšel mi onen výpis, viz výše
