To je tedy drsná procedura - ale hotovo:
ComboFix 09-05-20.A1 - Poradna 21.05.2009 20:31.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.446.182 [GMT 2:00]
Spuštěný z: c:\documents and settings\Poradna\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-04-21 do 2009-05-21 )))))))))))))))))))))))))))))))
.
2009-05-21 17:23 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-21 17:23 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-21 17:23 . 2009-05-21 17:23 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-21 14:01 . 2009-05-21 14:01 -------- d-----w c:\program files\Trend Micro
2009-05-21 12:59 . 2008-06-19 15:24 28544 ----a-w c:\windows\system32\drivers\pavboot.sys
2009-05-21 12:57 . 2009-05-21 12:57 -------- d-----w c:\program files\Panda Security
2009-05-20 15:53 . 2009-05-20 15:52 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-19 20:44 . 2009-05-19 20:44 -------- d-----w c:\program files\CCleaner
2009-05-19 14:50 . 2009-05-19 14:50 -------- d-----w c:\program files\ESET
2009-05-04 16:57 . 2009-05-04 16:07 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-05-04 16:21 . 2009-05-04 16:21 -------- d-----w c:\documents and settings\LocalService\Plocha
2009-05-04 16:07 . 2009-05-04 16:06 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-05-04 15:53 . 2009-05-04 15:53 -------- d-----w c:\program files\Lavasoft
2009-04-30 13:27 . 2009-04-30 13:27 -------- d-----w c:\windows\system32\cs-cz
2009-04-30 13:27 . 2009-04-30 13:27 -------- d-----w c:\windows\l2schemas
2009-04-30 13:27 . 2009-04-30 13:27 -------- d-----w c:\windows\system32\cs
2009-04-30 13:27 . 2009-04-30 13:27 -------- d-----w c:\windows\system32\bits
2009-04-30 13:22 . 2009-04-30 13:22 -------- d-----w c:\windows\ServicePackFiles
2009-04-30 13:11 . 2009-04-30 13:11 -------- d-----w c:\windows\EHome
2009-04-30 12:44 . 2009-04-30 12:44 -------- d-----w c:\program files\AVG
2009-04-28 07:48 . 2004-08-03 20:41 180360 ------w c:\windows\system32\drivers\ntmtlfax.sys
2009-04-28 07:32 . 2008-06-14 17:35 272128 ------w c:\windows\system32\dllcache\bthport.sys
2009-04-28 07:32 . 2008-06-14 17:35 272128 ------w c:\windows\system32\drivers\bthport.sys
2009-04-28 07:30 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-28 07:30 . 2009-02-09 11:26 2191232 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-28 07:30 . 2009-03-06 14:23 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-28 07:30 . 2009-02-09 11:25 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-28 07:30 . 2009-02-09 10:56 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-28 07:30 . 2009-02-09 10:56 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-28 07:30 . 2009-02-09 10:56 684032 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-28 07:30 . 2009-02-09 10:56 728064 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-28 07:30 . 2009-02-09 10:56 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-28 07:30 . 2009-02-09 10:56 709632 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-28 07:30 . 2009-02-09 11:26 2147328 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-28 07:30 . 2009-02-09 11:26 2025984 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-28 07:28 . 2008-05-08 14:02 203136 ------w c:\windows\system32\dllcache\rmcast.sys
2009-04-28 07:28 . 2008-10-24 11:21 455296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-28 07:28 . 2008-12-11 10:57 333952 ------w c:\windows\system32\dllcache\srv.sys
2009-04-28 07:28 . 2008-04-11 19:06 691712 ------w c:\windows\system32\dllcache\inetcomm.dll
2009-04-28 07:27 . 2008-10-15 16:38 337408 ------w c:\windows\system32\dllcache\netapi32.dll
2009-04-28 07:26 . 2008-04-21 21:15 216576 ------w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 14:31 . 2006-06-02 15:20 75730 ----a-w c:\windows\system32\perfc005.dat
2009-04-30 14:31 . 2006-06-02 15:20 403062 ----a-w c:\windows\system32\perfh005.dat
2009-04-30 13:30 . 2006-06-02 14:54 2684 ----a-w c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-04-30 13:30 . 2006-06-02 14:54 76487 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-06 14:23 . 2004-08-18 18:00 284160 ----a-w c:\windows\system32\pdh.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 53248]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2006-04-27 151552]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 204800]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-18 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-06-23 602112]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-20 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-03-10 185784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-03-23 77824]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-04 516440]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-27 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.5.2009 18:07 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [21.5.2009 14:59 28544]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 14:23 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 14:24 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 14:23 727720]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18.1.2009 23:34 953168]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [24.2.2007 11:31 65152]
R3 hwusbapp;HUAWEI Mobile Connect - 3G PC UI Interface;c:\windows\system32\drivers\ewusbapp.sys [24.2.2007 11:31 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [24.2.2007 11:31 65152]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [18.8.2004 20:00 69120]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - PAVBOOT
.
Obsah adresáře 'Naplánované úlohy'
2009-05-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 16:05]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-LaunchApp - (no file)
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Poradna\Data aplikací\Mozilla\Firefox\Profiles\h1o4293s.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-21 20:32
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
- - - - - - - > 'lsass.exe'(712)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
- - - - - - - > 'explorer.exe'(1064)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\acer\Empowering Technology\ePower\SysHook.dll
.
Celkový čas: 2009-05-21 20:34
ComboFix-quarantined-files.txt 2009-05-21 18:34
Před spuštěním: Volných bajtů: 21 123 235 840
Po spuštění: Volných bajtů: 21 332 197 376
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
164 --- E O F --- 2009-05-13 17:00