prosím o kontrolu
Napsal: 17 dub 2013 20:27
ComboFix 13-04-17.01 - pc 17.04.2013 19:04:12.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.429 [GMT 2:00]
Spuštěný z: c:\documents and settings\pc\Dokumenty\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\pc\LOCALS~1\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
c:\documents and settings\pc\Local Settings\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
c:\documents and settings\pc\Local Settings\TempFullTiltSetup.exe
c:\documents and settings\pc\WINDOWS
c:\program files\daemon4304-lite.exe
c:\windows\IsUn0405.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\autorun.i
c:\windows\system32\autorun.in
c:\windows\system32\muzapp.exe
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-17 do 2013-04-17 )))))))))))))))))))))))))))))))
.
.
2013-04-16 12:38 . 2013-04-16 12:38 -------- d-----w- c:\documents and settings\Administrator.DOMA-66D9B28BC3
2013-04-15 22:38 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2013-04-15 22:38 . 2013-04-15 22:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\Spyware Terminator
2013-04-15 22:00 . 2013-04-15 22:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2013-04-15 21:19 . 2013-04-15 21:19 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Deployment
2013-04-15 19:24 . 2013-04-15 20:42 -------- d-----w- c:\windows\D8167CA8236B4334B77DF388F494EE18.TMP
2013-04-15 19:01 . 2013-04-15 19:02 -------- d-----w- c:\program files\CCleaner
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\VS Revo Group
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\documents and settings\All Users\Data aplikací\VS Revo Group
2013-04-15 18:32 . 2009-12-30 08:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\program files\VS Revo Group
2013-04-14 21:02 . 2013-04-14 21:03 -------- d-----w- c:\windows\system32\jmdp
2013-04-14 21:02 . 2013-04-14 21:02 -------- d-----w- c:\windows\system32\ARFC
2013-04-14 21:02 . 2011-05-13 23:17 632656 ----a-w- c:\windows\system32\msvcr80.dll
2013-04-14 21:02 . 2011-05-13 23:17 479232 ----a-w- c:\windows\system32\msvcm80.dll
2013-04-14 21:02 . 2011-05-13 23:17 554832 ----a-w- c:\windows\system32\msvcp80.dll
2013-04-14 21:02 . 2013-02-27 11:24 1013552 ----a-w- c:\windows\system32\dmwu.exe
2013-04-14 21:02 . 2013-02-27 11:21 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-04-14 21:02 . 2013-04-15 12:38 -------- d-----w- c:\windows\system32\WNLT
2013-04-14 20:58 . 2013-04-14 21:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SeaaRchh--NewTAb
2013-04-14 20:57 . 2013-04-14 21:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BrOwwse2Saavei
2013-04-13 21:34 . 2013-04-14 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Seaarch-uNewTab
2013-04-13 21:34 . 2013-04-14 21:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Broiwse2saVe
2013-04-13 21:33 . 2013-04-15 18:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\InstallMate
2013-04-13 21:29 . 2013-04-15 19:05 -------- d-----w- c:\documents and settings\pc\Data aplikací\uTorrent
2013-04-10 22:38 . 2013-04-10 22:38 -------- d-----w- C:\Downloads
2013-04-10 22:37 . 2013-04-13 17:51 -------- d-----w- c:\documents and settings\pc\Data aplikací\BitComet
2013-04-08 23:30 . 2013-04-10 09:23 -------- d-----w- C:\SW Battlefornt
2013-03-25 22:05 . 2013-03-25 22:05 -------- d-----w- c:\documents and settings\Default User\Data aplikací\TuneUp Software
2013-03-25 22:01 . 2013-03-25 22:01 -------- d-----w- c:\documents and settings\pc\Data aplikací\AVG2013
2013-03-25 22:01 . 2013-03-25 22:01 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\AVG2013
2013-03-25 22:00 . 2013-03-25 22:00 -------- d-----w- c:\documents and settings\pc\Data aplikací\TuneUp Software
2013-03-25 22:00 . 2013-03-25 22:01 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG2013
2013-03-25 21:59 . 2013-04-12 21:41 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Avg2013
2013-03-25 21:59 . 2013-03-25 21:59 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\MFAData
2013-03-25 21:54 . 2013-03-25 21:58 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG8UPG
2013-03-22 16:36 . 2013-03-22 16:36 -------- d-----w- c:\program files\Common Files\Skype
2013-03-22 16:36 . 2013-03-22 16:36 -------- d-----r- c:\program files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-12 18:48 . 2012-04-14 11:16 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 18:48 . 2011-05-21 18:26 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 08:36 . 2006-03-02 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2006-03-02 12:00 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 15:56 . 2004-08-17 15:45 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 01:48 . 2013-03-07 01:48 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-07 01:48 . 2013-03-07 01:48 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-07 01:48 . 2012-06-24 17:38 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-07 01:48 . 2010-12-08 16:37 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-02 02:08 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 02:08 . 2006-03-02 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 02:08 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:57 . 2006-03-02 12:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-02-27 07:58 . 2008-09-17 17:32 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 18:56 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2006-03-02 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2006-03-02 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2009-09-04 16:01 . 2009-09-04 16:01 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-04 16:01 . 2009-09-04 16:01 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-04 16:01 . 2009-09-04 16:01 1691464 ----a-w- c:\program files\dsetup32.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2006-03-02 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-11-29 935312]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-11-29 21392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-06-20 577536]
"SiSRaid"="c:\program files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2006-01-23 872448]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"NetSoftware"="c:\program files\NetSoftware\Starter.exe" [2007-11-02 94208]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-11-29 3508624]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LogitechCameraAssistant"="c:\program files\Logitech\Video\CameraAssistant.exe" [2005-12-07 489472]
"LogitechVideo[inspector]"="c:\program files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2011-05-24 16:20 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\FreeFileViewer\\FFVCheckForUpdates.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Documents and Settings\\pc\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dmwu.exe"=
"c:\\WINDOWS\\system32\\ARFC\\wrtc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12591:TCP"= 12591:TCP:BitComet 12591 TCP
"12591:UDP"= 12591:UDP:BitComet 12591 UDP
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [28.12.2012 21:24 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [28.12.2012 21:24 5248]
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [15.10.2012 4:48 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [21.9.2012 4:46 177376]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.2.2010 22:44 721904]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [22.10.2012 14:02 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [21.9.2012 4:45 19936]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [17.5.2011 23:55 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [21.9.2012 4:46 164832]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 11:51 19200]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [16.11.2012 0:34 5814904]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [22.10.2012 14:05 196664]
R2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [14.4.2013 23:02 1013552]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [8.1.2013 13:55 161536]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [24.12.2011 21:42 30312]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys --> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [18.2.2013 20:48 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [18.2.2013 20:48 100736]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [15.4.2013 20:32 27064]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [24.12.2011 21:42 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [24.12.2011 21:42 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [24.12.2011 21:42 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [24.12.2011 21:42 114280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-15 21:20 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-04-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 18:48]
.
2013-04-17 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2013-01-29 10:16]
.
2013-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-15 21:19]
.
2013-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-15 21:19]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} - hxxp://pl.recruit.netmonitor.cz/WebInstaller.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-17 19:15
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(9096)
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\windows\ATKKBService.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Google\Update\1.3.21.135\GoogleCrashHandler.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\jmdp\stij.exe
c:\windows\SOUNDMAN.EXE
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Celkový čas: 2013-04-17 19:23:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-04-17 17:23
.
Před spuštěním: Volných bajtů: 26 411 581 440
Po spuštění: Volných bajtů: 26 575 908 864
.
- - End Of File - - 0D8540D686076216A547950750FFE07C
Šlo o problém se souborem csrcs.exe
Při startu mi hlásil že nelze najít. Kámoš mi poradil combofix. Neumim s tim a už jsem byl za to patřičně pokárán, že to nemám používat. Po restartu se mi už neobjevil warning. Díky za pomoc
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.429 [GMT 2:00]
Spuštěný z: c:\documents and settings\pc\Dokumenty\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\pc\LOCALS~1\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
c:\documents and settings\pc\Local Settings\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
c:\documents and settings\pc\Local Settings\TempFullTiltSetup.exe
c:\documents and settings\pc\WINDOWS
c:\program files\daemon4304-lite.exe
c:\windows\IsUn0405.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\autorun.i
c:\windows\system32\autorun.in
c:\windows\system32\muzapp.exe
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-17 do 2013-04-17 )))))))))))))))))))))))))))))))
.
.
2013-04-16 12:38 . 2013-04-16 12:38 -------- d-----w- c:\documents and settings\Administrator.DOMA-66D9B28BC3
2013-04-15 22:38 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2013-04-15 22:38 . 2013-04-15 22:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\Spyware Terminator
2013-04-15 22:00 . 2013-04-15 22:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2013-04-15 21:19 . 2013-04-15 21:19 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Deployment
2013-04-15 19:24 . 2013-04-15 20:42 -------- d-----w- c:\windows\D8167CA8236B4334B77DF388F494EE18.TMP
2013-04-15 19:01 . 2013-04-15 19:02 -------- d-----w- c:\program files\CCleaner
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\VS Revo Group
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\documents and settings\All Users\Data aplikací\VS Revo Group
2013-04-15 18:32 . 2009-12-30 08:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2013-04-15 18:32 . 2013-04-15 18:32 -------- d-----w- c:\program files\VS Revo Group
2013-04-14 21:02 . 2013-04-14 21:03 -------- d-----w- c:\windows\system32\jmdp
2013-04-14 21:02 . 2013-04-14 21:02 -------- d-----w- c:\windows\system32\ARFC
2013-04-14 21:02 . 2011-05-13 23:17 632656 ----a-w- c:\windows\system32\msvcr80.dll
2013-04-14 21:02 . 2011-05-13 23:17 479232 ----a-w- c:\windows\system32\msvcm80.dll
2013-04-14 21:02 . 2011-05-13 23:17 554832 ----a-w- c:\windows\system32\msvcp80.dll
2013-04-14 21:02 . 2013-02-27 11:24 1013552 ----a-w- c:\windows\system32\dmwu.exe
2013-04-14 21:02 . 2013-02-27 11:21 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-04-14 21:02 . 2013-04-15 12:38 -------- d-----w- c:\windows\system32\WNLT
2013-04-14 20:58 . 2013-04-14 21:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SeaaRchh--NewTAb
2013-04-14 20:57 . 2013-04-14 21:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BrOwwse2Saavei
2013-04-13 21:34 . 2013-04-14 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Seaarch-uNewTab
2013-04-13 21:34 . 2013-04-14 21:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Broiwse2saVe
2013-04-13 21:33 . 2013-04-15 18:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\InstallMate
2013-04-13 21:29 . 2013-04-15 19:05 -------- d-----w- c:\documents and settings\pc\Data aplikací\uTorrent
2013-04-10 22:38 . 2013-04-10 22:38 -------- d-----w- C:\Downloads
2013-04-10 22:37 . 2013-04-13 17:51 -------- d-----w- c:\documents and settings\pc\Data aplikací\BitComet
2013-04-08 23:30 . 2013-04-10 09:23 -------- d-----w- C:\SW Battlefornt
2013-03-25 22:05 . 2013-03-25 22:05 -------- d-----w- c:\documents and settings\Default User\Data aplikací\TuneUp Software
2013-03-25 22:01 . 2013-03-25 22:01 -------- d-----w- c:\documents and settings\pc\Data aplikací\AVG2013
2013-03-25 22:01 . 2013-03-25 22:01 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\AVG2013
2013-03-25 22:00 . 2013-03-25 22:00 -------- d-----w- c:\documents and settings\pc\Data aplikací\TuneUp Software
2013-03-25 22:00 . 2013-03-25 22:01 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG2013
2013-03-25 21:59 . 2013-04-12 21:41 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Avg2013
2013-03-25 21:59 . 2013-03-25 21:59 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\MFAData
2013-03-25 21:54 . 2013-03-25 21:58 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG8UPG
2013-03-22 16:36 . 2013-03-22 16:36 -------- d-----w- c:\program files\Common Files\Skype
2013-03-22 16:36 . 2013-03-22 16:36 -------- d-----r- c:\program files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-12 18:48 . 2012-04-14 11:16 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 18:48 . 2011-05-21 18:26 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 08:36 . 2006-03-02 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2006-03-02 12:00 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 15:56 . 2004-08-17 15:45 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 01:48 . 2013-03-07 01:48 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-07 01:48 . 2013-03-07 01:48 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-07 01:48 . 2012-06-24 17:38 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-07 01:48 . 2010-12-08 16:37 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-02 02:08 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 02:08 . 2006-03-02 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 02:08 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:57 . 2006-03-02 12:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-02-27 07:58 . 2008-09-17 17:32 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 18:56 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2006-03-02 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2006-03-02 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2009-09-04 16:01 . 2009-09-04 16:01 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-04 16:01 . 2009-09-04 16:01 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-04 16:01 . 2009-09-04 16:01 1691464 ----a-w- c:\program files\dsetup32.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2006-03-02 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-11-29 935312]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-11-29 21392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-06-20 577536]
"SiSRaid"="c:\program files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2006-01-23 872448]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"NetSoftware"="c:\program files\NetSoftware\Starter.exe" [2007-11-02 94208]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-11-29 3508624]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LogitechCameraAssistant"="c:\program files\Logitech\Video\CameraAssistant.exe" [2005-12-07 489472]
"LogitechVideo[inspector]"="c:\program files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2011-05-24 16:20 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\FreeFileViewer\\FFVCheckForUpdates.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Documents and Settings\\pc\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dmwu.exe"=
"c:\\WINDOWS\\system32\\ARFC\\wrtc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12591:TCP"= 12591:TCP:BitComet 12591 TCP
"12591:UDP"= 12591:UDP:BitComet 12591 UDP
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [28.12.2012 21:24 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [28.12.2012 21:24 5248]
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [15.10.2012 4:48 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [21.9.2012 4:46 177376]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.2.2010 22:44 721904]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [22.10.2012 14:02 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [21.9.2012 4:45 19936]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [17.5.2011 23:55 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [21.9.2012 4:46 164832]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 11:51 19200]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [16.11.2012 0:34 5814904]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [22.10.2012 14:05 196664]
R2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [14.4.2013 23:02 1013552]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [8.1.2013 13:55 161536]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [24.12.2011 21:42 30312]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys --> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [18.2.2013 20:48 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [18.2.2013 20:48 100736]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [15.4.2013 20:32 27064]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [24.12.2011 21:42 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [24.12.2011 21:42 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [24.12.2011 21:42 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [24.12.2011 21:42 114280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-15 21:20 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-04-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 18:48]
.
2013-04-17 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2013-01-29 10:16]
.
2013-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-15 21:19]
.
2013-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-15 21:19]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} - hxxp://pl.recruit.netmonitor.cz/WebInstaller.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-17 19:15
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(9096)
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\windows\ATKKBService.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Google\Update\1.3.21.135\GoogleCrashHandler.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\jmdp\stij.exe
c:\windows\SOUNDMAN.EXE
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Celkový čas: 2013-04-17 19:23:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-04-17 17:23
.
Před spuštěním: Volných bajtů: 26 411 581 440
Po spuštění: Volných bajtů: 26 575 908 864
.
- - End Of File - - 0D8540D686076216A547950750FFE07C
Šlo o problém se souborem csrcs.exe
Při startu mi hlásil že nelze najít. Kámoš mi poradil combofix. Neumim s tim a už jsem byl za to patřičně pokárán, že to nemám používat. Po restartu se mi už neobjevil warning. Díky za pomoc