Log z Combofix
Napsal: 08 črc 2008 18:16
Ahoj všem, vytvořil jsem si log z programu Combofix ale nevím jak postupovat dál, poradí někdo? dík
ComboFix 08-07-07.3 - uživatel 2008-07-08 17:41:34.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.460 [GMT 2:00]
Running from: C:\Documents and Settings\uživatel\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM7f70a1df.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aakmqgpt.ini
C:\WINDOWS\system32\akttzn.exe
C:\WINDOWS\system32\bdn.com
C:\WINDOWS\system32\bplsqjxe.dll
C:\WINDOWS\system32\cbXpNFwV.dll
C:\WINDOWS\system32\ceqrjdyc.ini
C:\WINDOWS\system32\cydjrqec.dll
C:\WINDOWS\system32\edpirffm.dll
C:\WINDOWS\system32\exjqslpb.ini
C:\WINDOWS\system32\exjqslpb.tmp
C:\WINDOWS\system32\hxiwlgpm.dat
C:\WINDOWS\system32\hxiwlgpm.exe
C:\WINDOWS\system32\kdvlf.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\msgp.exe
C:\WINDOWS\system32\mssecu.exe
C:\WINDOWS\system32\mtr2.exe
C:\WINDOWS\system32\mwin32.exe
C:\WINDOWS\system32\netode.exe
C:\WINDOWS\system32\opnkKddD.dll
C:\WINDOWS\system32\regm64.dll
C:\WINDOWS\system32\ssvchost.exe
C:\WINDOWS\system32\sysreq.exe
C:\WINDOWS\system32\taack.dat
C:\WINDOWS\system32\taack.exe
C:\WINDOWS\system32\uwsgckrt.dll
C:\WINDOWS\system32\VBIEWER.OCX
C:\WINDOWS\system32\VwFNpXbc.ini
C:\WINDOWS\system32\VwFNpXbc.ini2
C:\WINDOWS\system32\winlogonpc.exe
C:\WINDOWS\system32\WINWGPX.EXE
.
((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 )))))))))))))))))))))))))))))))
.
2008-07-07 17:02 . 2008-07-08 17:38 110,479 --a------ C:\WINDOWS\BM7f70a1df.xml
2008-07-06 19:02 . 2008-07-06 19:02 <DIR> d-------- C:\Program Files\Web Technologies
2008-07-06 11:12 . 2008-07-06 11:12 <DIR> d-------- C:\Program Files\ICQ6
2008-06-11 15:59 . 2008-06-14 20:00 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-08 15:51 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd1725.sys
2008-06-20 05:47 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-14 18:00 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-05 18:09 --------- d-----w C:\Program Files\AnMing
2008-05-08 18:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-08 17:37 --------- d-----w C:\Program Files\a-squared Free
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-04 15:25 691,545 ----a-w C:\WINDOWS\unins000.exe
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2004-09-14 20:44 5,632 --sha-w C:\Program Files\Thumbs.db
2006-03-26 05:07 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 16:03 1957888]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-05-19 18:11 18577448]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 16:50 1289000]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="F:\TOM\ICQ\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-18 21:41 286720]
"mouseElf"="C:\PROGRA~1\GAMING~1\MouseElf.EXE" [2006-02-27 05:47 471166]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 14:16 185896]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 13:45 75304]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 09:35 20480]
"ScanSoft OmniPage SE 4.0-reminder"="C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" [2006-09-26 16:38 1410600]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-11 01:26 406016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ICQ Lite"="F:\TOM\ICQ\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"this"="C:\Program Files\Web Technologies\wcs.exe" [2008-07-06 19:02 7680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.fvfw"= ffvfw.dll
"msacm.avis"= ffvfw.dll
"msacm.WRPR"= aviwrap.dll
"msacm.l3radius"= l3codecp.acm
"msacm.divxa"= divxa32.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"SENTINEL"= snti386.dll
"vidc.yv12"= yv12vfw.dll
"vidc.i420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"G:\\WOLF\\ET.exe"=
"F:\\TOM\\StrongDC.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"G:\\ARMA\\ArmA Demo\\ArmADemo.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"F:\\TOM\\ICQ\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2001-12-20 18:00]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 17:11]
R1 Cinemsup;Cinemsup;C:\WINDOWS\System32\drivers\cinemsup.sys [2002-07-19 10:10]
R2 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-02-08 12:16]
R3 genmcmn;Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2005-07-02 06:35]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S2 Parclass;Parclass;C:\WINDOWS\system32\Drivers\Parclass.sys []
S3 MA8630C;MA8630C;C:\WINDOWS\system32\DRIVERS\MA8630C.sys [2004-08-30 13:26]
S3 MA8630M;MA8630M;C:\WINDOWS\system32\DRIVERS\MA8630M.sys [2004-09-01 11:56]
S3 MA8630U;MA8630U;C:\WINDOWS\system32\DRIVERS\MA8630U.sys [2004-09-01 13:59]
S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-08-12 09:30]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 23:34:01 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-C:\WINDOWS\system32\kdvlf.exe - C:\WINDOWS\system32\kdvlf.exe
HKLM-Run-BM7f70a1df - C:\WINDOWS\system32\uwsgckrt.dll
HKLM-Run-7c439243 - C:\WINDOWS\system32\bplsqjxe.dll
SSODL-wetkadmr-{21DEFFE9-D389-44D8-AD07-B1F6E1409A56} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 17:53:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ALWIL Software\Avast4\aswUpdSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-07-08 17:58:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-08 15:58:11
ComboFix2.txt 2008-05-08 18:08:26
ComboFix3.txt 2008-05-08 17:51:17
ComboFix4.txt 2008-05-08 17:15:29
ComboFix5.txt 2008-05-06 16:57:17
Adresářů: 16, Volných bajtů: 6,111,166,464
Adres ý…: 19, Volněch bajt…: 6,724,956,160
179 --- E O F --- 2008-06-20 21:33:24
ComboFix 08-07-07.3 - uživatel 2008-07-08 17:41:34.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.460 [GMT 2:00]
Running from: C:\Documents and Settings\uživatel\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM7f70a1df.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aakmqgpt.ini
C:\WINDOWS\system32\akttzn.exe
C:\WINDOWS\system32\bdn.com
C:\WINDOWS\system32\bplsqjxe.dll
C:\WINDOWS\system32\cbXpNFwV.dll
C:\WINDOWS\system32\ceqrjdyc.ini
C:\WINDOWS\system32\cydjrqec.dll
C:\WINDOWS\system32\edpirffm.dll
C:\WINDOWS\system32\exjqslpb.ini
C:\WINDOWS\system32\exjqslpb.tmp
C:\WINDOWS\system32\hxiwlgpm.dat
C:\WINDOWS\system32\hxiwlgpm.exe
C:\WINDOWS\system32\kdvlf.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\msgp.exe
C:\WINDOWS\system32\mssecu.exe
C:\WINDOWS\system32\mtr2.exe
C:\WINDOWS\system32\mwin32.exe
C:\WINDOWS\system32\netode.exe
C:\WINDOWS\system32\opnkKddD.dll
C:\WINDOWS\system32\regm64.dll
C:\WINDOWS\system32\ssvchost.exe
C:\WINDOWS\system32\sysreq.exe
C:\WINDOWS\system32\taack.dat
C:\WINDOWS\system32\taack.exe
C:\WINDOWS\system32\uwsgckrt.dll
C:\WINDOWS\system32\VBIEWER.OCX
C:\WINDOWS\system32\VwFNpXbc.ini
C:\WINDOWS\system32\VwFNpXbc.ini2
C:\WINDOWS\system32\winlogonpc.exe
C:\WINDOWS\system32\WINWGPX.EXE
.
((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 )))))))))))))))))))))))))))))))
.
2008-07-07 17:02 . 2008-07-08 17:38 110,479 --a------ C:\WINDOWS\BM7f70a1df.xml
2008-07-06 19:02 . 2008-07-06 19:02 <DIR> d-------- C:\Program Files\Web Technologies
2008-07-06 11:12 . 2008-07-06 11:12 <DIR> d-------- C:\Program Files\ICQ6
2008-06-11 15:59 . 2008-06-14 20:00 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-08 15:51 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd1725.sys
2008-06-20 05:47 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-14 18:00 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-05 18:09 --------- d-----w C:\Program Files\AnMing
2008-05-08 18:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-08 17:37 --------- d-----w C:\Program Files\a-squared Free
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-04 15:25 691,545 ----a-w C:\WINDOWS\unins000.exe
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2004-09-14 20:44 5,632 --sha-w C:\Program Files\Thumbs.db
2006-03-26 05:07 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 16:03 1957888]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-05-19 18:11 18577448]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 16:50 1289000]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="F:\TOM\ICQ\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-18 21:41 286720]
"mouseElf"="C:\PROGRA~1\GAMING~1\MouseElf.EXE" [2006-02-27 05:47 471166]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 14:16 185896]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 13:45 75304]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 09:35 20480]
"ScanSoft OmniPage SE 4.0-reminder"="C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" [2006-09-26 16:38 1410600]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-11 01:26 406016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ICQ Lite"="F:\TOM\ICQ\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"this"="C:\Program Files\Web Technologies\wcs.exe" [2008-07-06 19:02 7680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.fvfw"= ffvfw.dll
"msacm.avis"= ffvfw.dll
"msacm.WRPR"= aviwrap.dll
"msacm.l3radius"= l3codecp.acm
"msacm.divxa"= divxa32.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"SENTINEL"= snti386.dll
"vidc.yv12"= yv12vfw.dll
"vidc.i420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"G:\\WOLF\\ET.exe"=
"F:\\TOM\\StrongDC.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"G:\\ARMA\\ArmA Demo\\ArmADemo.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"F:\\TOM\\ICQ\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2001-12-20 18:00]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 17:11]
R1 Cinemsup;Cinemsup;C:\WINDOWS\System32\drivers\cinemsup.sys [2002-07-19 10:10]
R2 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-02-08 12:16]
R3 genmcmn;Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2005-07-02 06:35]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S2 Parclass;Parclass;C:\WINDOWS\system32\Drivers\Parclass.sys []
S3 MA8630C;MA8630C;C:\WINDOWS\system32\DRIVERS\MA8630C.sys [2004-08-30 13:26]
S3 MA8630M;MA8630M;C:\WINDOWS\system32\DRIVERS\MA8630M.sys [2004-09-01 11:56]
S3 MA8630U;MA8630U;C:\WINDOWS\system32\DRIVERS\MA8630U.sys [2004-09-01 13:59]
S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-08-12 09:30]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 23:34:01 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-C:\WINDOWS\system32\kdvlf.exe - C:\WINDOWS\system32\kdvlf.exe
HKLM-Run-BM7f70a1df - C:\WINDOWS\system32\uwsgckrt.dll
HKLM-Run-7c439243 - C:\WINDOWS\system32\bplsqjxe.dll
SSODL-wetkadmr-{21DEFFE9-D389-44D8-AD07-B1F6E1409A56} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 17:53:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ALWIL Software\Avast4\aswUpdSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-07-08 17:58:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-08 15:58:11
ComboFix2.txt 2008-05-08 18:08:26
ComboFix3.txt 2008-05-08 17:51:17
ComboFix4.txt 2008-05-08 17:15:29
ComboFix5.txt 2008-05-06 16:57:17
Adresářů: 16, Volných bajtů: 6,111,166,464
Adres ý…: 19, Volněch bajt…: 6,724,956,160
179 --- E O F --- 2008-06-20 21:33:24