Samozřejmě restartuj , některé nákazy se smažou až po něm.
Pak udělej Dr,Web CureIt a následně po něm teprve Combofix.
napadeni pocitace virem Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43292
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: napadeni pocitace virem
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: napadeni pocitace virem
Ten dr web mi nic nenasel podle tech vysledku.
Re: napadeni pocitace virem
Ten combo fix mi nejde spustit,napsalo mi to nejaky hlasky,jak to mam spustit v tom nouzovym rezimu.
Re: napadeni pocitace virem
ComboFix 10-10-08.01 - David 09.10.2010 12:37:22.1.2 - x86 NETWORK
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1498 [GMT 2:00]
Spuštěný z: c:\users\Davidek\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\page
c:\programdata\page\page.ico
c:\programdata\page\page.URL
c:\users\David\AppData\Roaming\inst.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\dudl.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\gid.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\SM.drv
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\windows\system32\skinboxer43.dll
c:\windows\TEMP\catchme.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-09 do 2010-10-09 )))))))))))))))))))))))))))))))
.
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Davidek\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\David\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-09 09:31 . 2010-10-09 09:31 -------- d-----w- c:\users\Davidek\DoctorWeb
2010-10-09 08:26 . 2010-10-09 08:26 -------- d-----w- c:\users\Davidek\AppData\Roaming\Malwarebytes
2010-10-08 16:18 . 2010-10-08 16:18 -------- d-----w- c:\users\Guest\AppData\Local\Opera
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\programdata\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-08 13:56 . 2010-10-08 13:56 -------- d-----w- C:\rsit
2010-10-08 06:53 . 2010-10-08 06:53 388096 ----a-r- c:\users\Davidek\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-07 16:20 . 2010-10-07 16:20 -------- d-----w- c:\program files\Trend Micro
2010-10-07 07:11 . 2010-10-07 07:11 119776 ----a-w- c:\users\Davidek\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-05 20:31 . 2010-10-09 05:48 -------- d-----w- c:\users\Davidek\AppData\Local\Diagnostics
2010-10-05 20:14 . 2010-10-05 20:14 -------- d-----w- c:\users\David\AppData\Local\ESET
2010-10-05 19:08 . 2010-10-06 07:10 -------- d-----w- c:\programdata\MFAData
2010-10-05 10:20 . 2010-10-05 10:20 -------- d-----w- c:\users\Davidek\AppData\Roaming\PC Suite
2010-10-05 09:19 . 2010-10-05 09:19 -------- d-----w- c:\users\Davidek\AppData\Local\ESET
2010-10-05 09:02 . 2010-10-05 09:02 -------- d-----w- c:\program files\ESET
2010-10-05 08:19 . 2009-08-17 16:05 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-10-05 07:29 . 2010-09-07 14:53 340048 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2010-10-05 07:29 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-10-05 07:29 . 2010-10-05 07:29 -------- d-----w- c:\programdata\Alwil Software
2010-10-05 07:22 . 2010-10-05 07:22 -------- d-----w- c:\users\Davidek\AppData\Local\Opera
2010-10-04 06:56 . 2010-10-06 08:10 -------- d-----w- c:\users\David\AppData\Local\Diagnostics
2010-10-04 06:39 . 2010-10-05 07:17 -------- d-sh--w- c:\programdata\SMNGRS
2010-10-04 06:39 . 2010-10-05 10:11 -------- d-sh--w- c:\programdata\642fa8
2010-09-29 05:38 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 05:38 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 02:33 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft
2010-09-27 07:25 . 2010-09-27 07:25 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-27 06:59 . 2010-09-29 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-27 06:58 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-27 06:58 . 2009-10-10 02:31 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-09-27 06:58 . 2010-09-27 06:58 -------- d-----w- c:\program files\CONEXANT
2010-09-26 07:49 . 2010-10-04 19:43 -------- d-----w- c:\users\David\AppData\Local\Deployment
2010-09-23 09:13 . 2010-09-23 09:13 -------- d-----w- c:\users\David\AppData\Roaming\Nokia Ovi Suite
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\users\David\AppData\Roaming\AnvSoft
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\program files\AnvSoft
2010-09-22 17:29 . 2010-09-22 17:32 -------- d-----w- c:\users\David\AppData\Local\Video Converter
2010-09-22 17:28 . 2010-09-22 17:28 -------- d-----w- c:\programdata\VideoConverter
2010-09-22 16:21 . 2010-09-22 16:21 -------- d-----w- c:\program files\Ultra Video Joiner
2010-09-22 14:44 . 2010-09-22 14:44 -------- d-----w- c:\program files\FreeTime
2010-09-22 14:41 . 2010-09-22 14:41 -------- d-----w- c:\users\David\AppData\Local\Broad Intelligence
2010-09-22 09:54 . 2010-09-22 09:54 -------- d--h--w- c:\windows\PIF
2010-09-21 08:06 . 2010-09-22 10:01 -------- d-----w- c:\program files\Windows Update
2010-09-20 14:06 . 2010-09-20 14:13 -------- d-----w- c:\program files\ReviverSoft
2010-09-20 14:05 . 2010-09-20 14:05 -------- d-----w- c:\programdata\ReviverSoft
2010-09-20 14:04 . 2010-09-20 14:05 12343104 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\p1v1_AFIRegistryReviver_w.exe
2010-09-20 14:04 . 2010-09-20 14:06 -------- d-----w- c:\users\David\AppData\Local\OpenCandy
2010-09-20 14:04 . 2010-09-20 14:04 349296 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\DLMgr_3_1.6.87.exe
2010-09-20 14:03 . 2010-09-22 14:19 -------- d-----w- c:\users\David\AppData\Roaming\Broad Intelligence
2010-09-20 06:08 . 2010-09-20 06:29 -------- d-----w- c:\program files\uTorrent
2010-09-19 18:33 . 2010-09-19 18:33 310208 ----a-w- c:\users\David\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
2010-09-19 18:33 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\Azureus
2010-09-18 06:53 . 2010-09-18 06:54 -------- d-----w- c:\program files\Ask.com
2010-09-18 06:52 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2010-09-18 05:48 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-17 18:56 . 2010-09-17 18:56 12212040 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 13930312 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 61440 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-09-17 18:56 . 2010-09-17 18:56 58880 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-09-17 18:56 . 2010-09-17 18:56 50000 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\pcswpc.exe
2010-09-17 18:56 . 2009-01-01 10:00 93326608 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Nokia_Ovi_Suite_2_0_0_8_ALL.exe
2010-09-17 18:56 . 2010-09-18 05:47 -------- d-----w- c:\program files\Nokia
2010-09-17 18:56 . 2010-09-17 18:56 -------- d-----w- c:\programdata\OviInstallerCache
2010-09-15 02:44 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 07:10 . 2010-03-20 18:01 -------- d-----w- c:\users\David\AppData\Roaming\EPSON
2010-10-06 07:10 . 2009-11-26 18:37 -------- d-----w- c:\users\David\AppData\Roaming\GRETECH
2010-10-06 07:10 . 2010-04-10 08:48 -------- d-----w- c:\users\David\AppData\Roaming\OpenCandy
2010-10-06 07:10 . 2009-11-27 09:09 -------- d-----w- c:\users\David\AppData\Roaming\Skype
2010-10-06 07:10 . 2010-03-21 18:33 -------- d-----w- c:\users\David\AppData\Roaming\Ulead Systems
2010-10-06 06:08 . 2009-07-14 08:44 579238 ----a-w- c:\windows\system32\perfh005.dat
2010-10-06 06:08 . 2009-07-14 08:44 107134 ----a-w- c:\windows\system32\perfc005.dat
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-10-05 08:18 . 2009-11-26 18:43 -------- d-----w- c:\program files\Alwil Software
2010-10-05 07:17 . 2010-01-05 17:21 -------- d-----w- c:\programdata\Microsoft Help
2010-09-30 07:12 . 2009-11-26 20:25 -------- d-----w- c:\program files\CAPCOM
2010-09-27 07:25 . 2010-03-17 10:45 -------- d-----w- c:\program files\Windows Live
2010-09-24 12:27 . 2010-08-30 14:43 -------- d-----w- c:\users\David\AppData\Roaming\Vso
2010-09-23 14:02 . 2009-11-27 09:23 -------- d-----w- c:\users\David\AppData\Roaming\skypePM
2010-09-23 09:13 . 2010-09-17 19:00 -------- d-----w- c:\users\David\AppData\Roaming\Nokia
2010-09-23 07:44 . 2010-01-23 20:01 -------- d-----w- c:\users\David\AppData\Roaming\AVI ReComp
2010-09-22 04:54 . 2010-09-17 19:00 -------- d-----w- c:\programdata\PC Suite
2010-09-22 04:38 . 2010-01-05 17:23 -------- d-----w- c:\program files\Microsoft.NET
2010-09-18 07:59 . 2010-09-18 07:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-09-18 05:51 . 2010-09-17 18:58 -------- d-----w- c:\program files\Common Files\Nokia
2010-09-18 05:48 . 2010-09-18 05:48 -------- d-----w- c:\program files\PC Connectivity Solution
2010-09-08 10:00 . 2010-09-08 10:00 72940376 ----a-w- c:\users\David\AppData\Roaming\Nokia\Ovi Suite\Software Updater\Nokia_Ovi_Suite_webupgrade_ALL.exe
2010-09-08 07:09 . 2010-03-20 12:03 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-07 15:11 . 2009-11-26 18:43 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2009-11-26 18:43 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2009-11-26 18:43 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2009-11-26 18:43 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2009-11-26 18:43 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 17:04 . 2010-08-30 17:04 -------- d-----w- c:\programdata\vsosdk
2010-08-30 15:20 . 2010-03-21 18:30 -------- d-----w- c:\program files\SmartSound Software
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 -------- d-----w- c:\program files\VSO
2010-08-20 23:16 . 2010-08-20 23:16 12284672 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\AFIRegistryReviverSetup.exe
2010-07-29 11:31 . 2010-07-29 11:31 96920 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2010-07-29 11:31 . 2010-07-29 11:31 136632 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-07-29 11:31 . 2010-07-29 11:31 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-07-29 06:30 . 2010-08-29 15:17 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-29 15:17 82944 ----a-w- c:\windows\system32\iccvid.dll
2009-11-27 09:43 . 2009-11-27 09:42 16742712 ----a-w- c:\program files\install_icq65.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-09-07 15:14 152160 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:Czech /KBD:2
R1 aswSnx;aswSnx; [x]
R1 aswSP;avast! Self Protection; [x]
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-08-17 53328]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 96920]
R3 AllShare;SAMSUNG AllShare Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-04-23 9241088]
R3 GarenaPEngine;GarenaPEngine;c:\users\David\AppData\Local\Temp\LCK6FB4.tmp [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-26 691696]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:25392
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
HKCU-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-Metropolis - c:\windows\system32\sshnas21.dll
HKCU-Run-JCFSE7V7Z1 - c:\users\David\AppData\Local\Temp\Ec1.exe
HKCU-Run-Smart Security - c:\programdata\642fa8\SM642_231.exe
HKLM-Run-AGEIA PhysX SysTray - c:\program files\AGEIA Technologies\bin\TrayIcon.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Standby - c:\program files\Common Files\Corel\Standby\Standby.exe
HKLM-RunOnce-<NO NAME> - (no file)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GarenaPEngine]
"ImagePath"="\??\c:\users\David\AppData\Local\Temp\LCK6FB4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:de,ac,79,38,6b,79,a2,73,68,53,3e,3a,54,10,12,21,11,00,95,cc,a8,18,2e,
1f,56,1e,8d,4a,ad,41,c4,bc,62,a8,a8,1a,07,3b,02,4f,27,ac,b3,b7,6f,36,8a,b2,\
"??"=hex:a8,1c,b6,38,2c,97,76,a6,1a,67,78,8c,e9,b9,85,9d
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\License information*]
"datasecu"=hex:8d,6c,8d,31,c7,67,4b,25,da,73,61,f1,a9,75,bb,2e,ba,9c,f4,69,5e,
70,6a,65,9c,a2,d3,c2,22,d8,ea,59,69,6f,04,ea,43,3b,6e,77,1c,8d,35,61,85,4a,\
"rkeysecu"=hex:0e,6d,fb,82,c6,22,85,20,77,b0,39,2f,0c,e8,f1,2f
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-10-09 12:44:52
ComboFix-quarantined-files.txt 2010-10-09 10:44
Před spuštěním: Volných bajtů: 94 303 567 872
Po spuštění: Volných bajtů: 96 768 667 648
- - End Of File - - AC7EA55B1D278DD39BB2B2310BAE3726
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1498 [GMT 2:00]
Spuštěný z: c:\users\Davidek\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\page
c:\programdata\page\page.ico
c:\programdata\page\page.URL
c:\users\David\AppData\Roaming\inst.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\dudl.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\gid.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\SM.drv
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\David\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\windows\system32\skinboxer43.dll
c:\windows\TEMP\catchme.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-09 do 2010-10-09 )))))))))))))))))))))))))))))))
.
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Davidek\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\David\AppData\Local\temp
2010-10-09 10:42 . 2010-10-09 10:42 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-09 09:31 . 2010-10-09 09:31 -------- d-----w- c:\users\Davidek\DoctorWeb
2010-10-09 08:26 . 2010-10-09 08:26 -------- d-----w- c:\users\Davidek\AppData\Roaming\Malwarebytes
2010-10-08 16:18 . 2010-10-08 16:18 -------- d-----w- c:\users\Guest\AppData\Local\Opera
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\programdata\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-08 13:56 . 2010-10-08 13:56 -------- d-----w- C:\rsit
2010-10-08 06:53 . 2010-10-08 06:53 388096 ----a-r- c:\users\Davidek\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-07 16:20 . 2010-10-07 16:20 -------- d-----w- c:\program files\Trend Micro
2010-10-07 07:11 . 2010-10-07 07:11 119776 ----a-w- c:\users\Davidek\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-05 20:31 . 2010-10-09 05:48 -------- d-----w- c:\users\Davidek\AppData\Local\Diagnostics
2010-10-05 20:14 . 2010-10-05 20:14 -------- d-----w- c:\users\David\AppData\Local\ESET
2010-10-05 19:08 . 2010-10-06 07:10 -------- d-----w- c:\programdata\MFAData
2010-10-05 10:20 . 2010-10-05 10:20 -------- d-----w- c:\users\Davidek\AppData\Roaming\PC Suite
2010-10-05 09:19 . 2010-10-05 09:19 -------- d-----w- c:\users\Davidek\AppData\Local\ESET
2010-10-05 09:02 . 2010-10-05 09:02 -------- d-----w- c:\program files\ESET
2010-10-05 08:19 . 2009-08-17 16:05 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-10-05 07:29 . 2010-09-07 14:53 340048 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2010-10-05 07:29 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-10-05 07:29 . 2010-10-05 07:29 -------- d-----w- c:\programdata\Alwil Software
2010-10-05 07:22 . 2010-10-05 07:22 -------- d-----w- c:\users\Davidek\AppData\Local\Opera
2010-10-04 06:56 . 2010-10-06 08:10 -------- d-----w- c:\users\David\AppData\Local\Diagnostics
2010-10-04 06:39 . 2010-10-05 07:17 -------- d-sh--w- c:\programdata\SMNGRS
2010-10-04 06:39 . 2010-10-05 10:11 -------- d-sh--w- c:\programdata\642fa8
2010-09-29 05:38 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 05:38 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 02:33 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft
2010-09-27 07:25 . 2010-09-27 07:25 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-27 06:59 . 2010-09-29 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-27 06:58 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-27 06:58 . 2009-10-10 02:31 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-09-27 06:58 . 2010-09-27 06:58 -------- d-----w- c:\program files\CONEXANT
2010-09-26 07:49 . 2010-10-04 19:43 -------- d-----w- c:\users\David\AppData\Local\Deployment
2010-09-23 09:13 . 2010-09-23 09:13 -------- d-----w- c:\users\David\AppData\Roaming\Nokia Ovi Suite
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\users\David\AppData\Roaming\AnvSoft
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\program files\AnvSoft
2010-09-22 17:29 . 2010-09-22 17:32 -------- d-----w- c:\users\David\AppData\Local\Video Converter
2010-09-22 17:28 . 2010-09-22 17:28 -------- d-----w- c:\programdata\VideoConverter
2010-09-22 16:21 . 2010-09-22 16:21 -------- d-----w- c:\program files\Ultra Video Joiner
2010-09-22 14:44 . 2010-09-22 14:44 -------- d-----w- c:\program files\FreeTime
2010-09-22 14:41 . 2010-09-22 14:41 -------- d-----w- c:\users\David\AppData\Local\Broad Intelligence
2010-09-22 09:54 . 2010-09-22 09:54 -------- d--h--w- c:\windows\PIF
2010-09-21 08:06 . 2010-09-22 10:01 -------- d-----w- c:\program files\Windows Update
2010-09-20 14:06 . 2010-09-20 14:13 -------- d-----w- c:\program files\ReviverSoft
2010-09-20 14:05 . 2010-09-20 14:05 -------- d-----w- c:\programdata\ReviverSoft
2010-09-20 14:04 . 2010-09-20 14:05 12343104 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\p1v1_AFIRegistryReviver_w.exe
2010-09-20 14:04 . 2010-09-20 14:06 -------- d-----w- c:\users\David\AppData\Local\OpenCandy
2010-09-20 14:04 . 2010-09-20 14:04 349296 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\DLMgr_3_1.6.87.exe
2010-09-20 14:03 . 2010-09-22 14:19 -------- d-----w- c:\users\David\AppData\Roaming\Broad Intelligence
2010-09-20 06:08 . 2010-09-20 06:29 -------- d-----w- c:\program files\uTorrent
2010-09-19 18:33 . 2010-09-19 18:33 310208 ----a-w- c:\users\David\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
2010-09-19 18:33 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\Azureus
2010-09-18 06:53 . 2010-09-18 06:54 -------- d-----w- c:\program files\Ask.com
2010-09-18 06:52 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2010-09-18 05:48 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-17 18:56 . 2010-09-17 18:56 12212040 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 13930312 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 61440 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-09-17 18:56 . 2010-09-17 18:56 58880 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-09-17 18:56 . 2010-09-17 18:56 50000 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\pcswpc.exe
2010-09-17 18:56 . 2009-01-01 10:00 93326608 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Nokia_Ovi_Suite_2_0_0_8_ALL.exe
2010-09-17 18:56 . 2010-09-18 05:47 -------- d-----w- c:\program files\Nokia
2010-09-17 18:56 . 2010-09-17 18:56 -------- d-----w- c:\programdata\OviInstallerCache
2010-09-15 02:44 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 07:10 . 2010-03-20 18:01 -------- d-----w- c:\users\David\AppData\Roaming\EPSON
2010-10-06 07:10 . 2009-11-26 18:37 -------- d-----w- c:\users\David\AppData\Roaming\GRETECH
2010-10-06 07:10 . 2010-04-10 08:48 -------- d-----w- c:\users\David\AppData\Roaming\OpenCandy
2010-10-06 07:10 . 2009-11-27 09:09 -------- d-----w- c:\users\David\AppData\Roaming\Skype
2010-10-06 07:10 . 2010-03-21 18:33 -------- d-----w- c:\users\David\AppData\Roaming\Ulead Systems
2010-10-06 06:08 . 2009-07-14 08:44 579238 ----a-w- c:\windows\system32\perfh005.dat
2010-10-06 06:08 . 2009-07-14 08:44 107134 ----a-w- c:\windows\system32\perfc005.dat
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-10-05 08:18 . 2009-11-26 18:43 -------- d-----w- c:\program files\Alwil Software
2010-10-05 07:17 . 2010-01-05 17:21 -------- d-----w- c:\programdata\Microsoft Help
2010-09-30 07:12 . 2009-11-26 20:25 -------- d-----w- c:\program files\CAPCOM
2010-09-27 07:25 . 2010-03-17 10:45 -------- d-----w- c:\program files\Windows Live
2010-09-24 12:27 . 2010-08-30 14:43 -------- d-----w- c:\users\David\AppData\Roaming\Vso
2010-09-23 14:02 . 2009-11-27 09:23 -------- d-----w- c:\users\David\AppData\Roaming\skypePM
2010-09-23 09:13 . 2010-09-17 19:00 -------- d-----w- c:\users\David\AppData\Roaming\Nokia
2010-09-23 07:44 . 2010-01-23 20:01 -------- d-----w- c:\users\David\AppData\Roaming\AVI ReComp
2010-09-22 04:54 . 2010-09-17 19:00 -------- d-----w- c:\programdata\PC Suite
2010-09-22 04:38 . 2010-01-05 17:23 -------- d-----w- c:\program files\Microsoft.NET
2010-09-18 07:59 . 2010-09-18 07:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-09-18 05:51 . 2010-09-17 18:58 -------- d-----w- c:\program files\Common Files\Nokia
2010-09-18 05:48 . 2010-09-18 05:48 -------- d-----w- c:\program files\PC Connectivity Solution
2010-09-08 10:00 . 2010-09-08 10:00 72940376 ----a-w- c:\users\David\AppData\Roaming\Nokia\Ovi Suite\Software Updater\Nokia_Ovi_Suite_webupgrade_ALL.exe
2010-09-08 07:09 . 2010-03-20 12:03 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-07 15:11 . 2009-11-26 18:43 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2009-11-26 18:43 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2009-11-26 18:43 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2009-11-26 18:43 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2009-11-26 18:43 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 17:04 . 2010-08-30 17:04 -------- d-----w- c:\programdata\vsosdk
2010-08-30 15:20 . 2010-03-21 18:30 -------- d-----w- c:\program files\SmartSound Software
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 -------- d-----w- c:\program files\VSO
2010-08-20 23:16 . 2010-08-20 23:16 12284672 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\AFIRegistryReviverSetup.exe
2010-07-29 11:31 . 2010-07-29 11:31 96920 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2010-07-29 11:31 . 2010-07-29 11:31 136632 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-07-29 11:31 . 2010-07-29 11:31 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-07-29 06:30 . 2010-08-29 15:17 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-29 15:17 82944 ----a-w- c:\windows\system32\iccvid.dll
2009-11-27 09:43 . 2009-11-27 09:42 16742712 ----a-w- c:\program files\install_icq65.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-09-07 15:14 152160 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:Czech /KBD:2
R1 aswSnx;aswSnx; [x]
R1 aswSP;avast! Self Protection; [x]
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-08-17 53328]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 96920]
R3 AllShare;SAMSUNG AllShare Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-04-23 9241088]
R3 GarenaPEngine;GarenaPEngine;c:\users\David\AppData\Local\Temp\LCK6FB4.tmp [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-26 691696]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:25392
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
HKCU-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-Metropolis - c:\windows\system32\sshnas21.dll
HKCU-Run-JCFSE7V7Z1 - c:\users\David\AppData\Local\Temp\Ec1.exe
HKCU-Run-Smart Security - c:\programdata\642fa8\SM642_231.exe
HKLM-Run-AGEIA PhysX SysTray - c:\program files\AGEIA Technologies\bin\TrayIcon.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Standby - c:\program files\Common Files\Corel\Standby\Standby.exe
HKLM-RunOnce-<NO NAME> - (no file)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GarenaPEngine]
"ImagePath"="\??\c:\users\David\AppData\Local\Temp\LCK6FB4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:de,ac,79,38,6b,79,a2,73,68,53,3e,3a,54,10,12,21,11,00,95,cc,a8,18,2e,
1f,56,1e,8d,4a,ad,41,c4,bc,62,a8,a8,1a,07,3b,02,4f,27,ac,b3,b7,6f,36,8a,b2,\
"??"=hex:a8,1c,b6,38,2c,97,76,a6,1a,67,78,8c,e9,b9,85,9d
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\License information*]
"datasecu"=hex:8d,6c,8d,31,c7,67,4b,25,da,73,61,f1,a9,75,bb,2e,ba,9c,f4,69,5e,
70,6a,65,9c,a2,d3,c2,22,d8,ea,59,69,6f,04,ea,43,3b,6e,77,1c,8d,35,61,85,4a,\
"rkeysecu"=hex:0e,6d,fb,82,c6,22,85,20,77,b0,39,2f,0c,e8,f1,2f
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-10-09 12:44:52
ComboFix-quarantined-files.txt 2010-10-09 10:44
Před spuštěním: Volných bajtů: 94 303 567 872
Po spuštění: Volných bajtů: 96 768 667 648
- - End Of File - - AC7EA55B1D278DD39BB2B2310BAE3726
Re: napadeni pocitace virem
Tak jak to vypada,co dal?
Re: napadeni pocitace virem
Co mam delat dal?
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43292
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: napadeni pocitace virem
V logu máš stále dva antiviry , ESET NOD32 a AVAST , jeden odinstaluj a udělej znovu sken Combofixem.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: napadeni pocitace virem
ten eset mi nejde odsinstalovat,mam tam k nabidce v ovladacich panelech jen zmenit.Kdyz dam v nabidce start vsechny programy a dam eset odinstalovat,tak mi vyskoci hlaska pri prepisovani informaci na disk doslo k chybe.Presvedcte se ze je na disku dost mista.A u toho avastu mi to trva nejak dlouho,ja tam mam totiz dve verze,Avast a Avast ProAntivirus.Tak co ted?
Re: napadeni pocitace virem
tak se mi to povedlo,ted sem hodim ten sken.
Re: napadeni pocitace virem
ComboFix 10-10-08.01 - David 10.10.2010 13:01:09.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1324 [GMT 2:00]
Spuštěný z: c:\users\Davidek\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\catchme.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-10 do 2010-10-10 )))))))))))))))))))))))))))))))
.
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Davidek\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\David\AppData\Local\temp
2010-10-09 09:31 . 2010-10-09 09:31 -------- d-----w- c:\users\Davidek\DoctorWeb
2010-10-09 08:26 . 2010-10-09 08:26 -------- d-----w- c:\users\Davidek\AppData\Roaming\Malwarebytes
2010-10-08 16:18 . 2010-10-08 16:18 -------- d-----w- c:\users\Guest\AppData\Local\Opera
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\programdata\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-08 13:56 . 2010-10-08 13:56 -------- d-----w- C:\rsit
2010-10-08 06:53 . 2010-10-08 06:53 388096 ----a-r- c:\users\Davidek\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-07 16:20 . 2010-10-07 16:20 -------- d-----w- c:\program files\Trend Micro
2010-10-07 07:11 . 2010-10-07 07:11 119776 ----a-w- c:\users\Davidek\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-05 20:31 . 2010-10-09 05:48 -------- d-----w- c:\users\Davidek\AppData\Local\Diagnostics
2010-10-05 20:14 . 2010-10-05 20:14 -------- d-----w- c:\users\David\AppData\Local\ESET
2010-10-05 19:08 . 2010-10-06 07:10 -------- d-----w- c:\programdata\MFAData
2010-10-05 10:20 . 2010-10-05 10:20 -------- d-----w- c:\users\Davidek\AppData\Roaming\PC Suite
2010-10-05 09:19 . 2010-10-05 09:19 -------- d-----w- c:\users\Davidek\AppData\Local\ESET
2010-10-05 08:19 . 2009-08-17 16:05 53328 ------w- c:\windows\system32\drivers\aswMonFlt.sys
2010-10-05 07:29 . 2010-10-10 10:56 -------- d-----w- c:\programdata\Alwil Software
2010-10-05 07:22 . 2010-10-05 07:22 -------- d-----w- c:\users\Davidek\AppData\Local\Opera
2010-10-04 06:56 . 2010-10-06 08:10 -------- d-----w- c:\users\David\AppData\Local\Diagnostics
2010-10-04 06:39 . 2010-10-05 07:17 -------- d-sh--w- c:\programdata\SMNGRS
2010-10-04 06:39 . 2010-10-05 10:11 -------- d-sh--w- c:\programdata\642fa8
2010-09-29 05:38 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 05:38 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 02:33 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft
2010-09-27 07:25 . 2010-09-27 07:25 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-27 06:59 . 2010-09-29 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-27 06:58 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-27 06:58 . 2009-10-10 02:31 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-09-27 06:58 . 2010-09-27 06:58 -------- d-----w- c:\program files\CONEXANT
2010-09-26 07:49 . 2010-10-04 19:43 -------- d-----w- c:\users\David\AppData\Local\Deployment
2010-09-23 09:13 . 2010-09-23 09:13 -------- d-----w- c:\users\David\AppData\Roaming\Nokia Ovi Suite
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\users\David\AppData\Roaming\AnvSoft
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\program files\AnvSoft
2010-09-22 17:29 . 2010-09-22 17:32 -------- d-----w- c:\users\David\AppData\Local\Video Converter
2010-09-22 17:28 . 2010-09-22 17:28 -------- d-----w- c:\programdata\VideoConverter
2010-09-22 16:21 . 2010-09-22 16:21 -------- d-----w- c:\program files\Ultra Video Joiner
2010-09-22 14:44 . 2010-09-22 14:44 -------- d-----w- c:\program files\FreeTime
2010-09-22 14:41 . 2010-09-22 14:41 -------- d-----w- c:\users\David\AppData\Local\Broad Intelligence
2010-09-22 09:54 . 2010-09-22 09:54 -------- d--h--w- c:\windows\PIF
2010-09-21 08:06 . 2010-09-22 10:01 -------- d-----w- c:\program files\Windows Update
2010-09-20 14:06 . 2010-09-20 14:13 -------- d-----w- c:\program files\ReviverSoft
2010-09-20 14:05 . 2010-09-20 14:05 -------- d-----w- c:\programdata\ReviverSoft
2010-09-20 14:04 . 2010-09-20 14:05 12343104 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\p1v1_AFIRegistryReviver_w.exe
2010-09-20 14:04 . 2010-09-20 14:06 -------- d-----w- c:\users\David\AppData\Local\OpenCandy
2010-09-20 14:04 . 2010-09-20 14:04 349296 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\DLMgr_3_1.6.87.exe
2010-09-20 14:03 . 2010-09-22 14:19 -------- d-----w- c:\users\David\AppData\Roaming\Broad Intelligence
2010-09-20 06:08 . 2010-09-20 06:29 -------- d-----w- c:\program files\uTorrent
2010-09-19 18:33 . 2010-09-19 18:33 310208 ----a-w- c:\users\David\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
2010-09-19 18:33 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\Azureus
2010-09-18 06:53 . 2010-09-18 06:54 -------- d-----w- c:\program files\Ask.com
2010-09-18 06:52 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2010-09-18 05:48 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-17 18:56 . 2010-09-17 18:56 12212040 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 13930312 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 61440 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-09-17 18:56 . 2010-09-17 18:56 58880 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-09-17 18:56 . 2010-09-17 18:56 50000 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\pcswpc.exe
2010-09-17 18:56 . 2009-01-01 10:00 93326608 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Nokia_Ovi_Suite_2_0_0_8_ALL.exe
2010-09-17 18:56 . 2010-09-18 05:47 -------- d-----w- c:\program files\Nokia
2010-09-17 18:56 . 2010-09-17 18:56 -------- d-----w- c:\programdata\OviInstallerCache
2010-09-15 02:44 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 07:10 . 2010-03-20 18:01 -------- d-----w- c:\users\David\AppData\Roaming\EPSON
2010-10-06 07:10 . 2009-11-26 18:37 -------- d-----w- c:\users\David\AppData\Roaming\GRETECH
2010-10-06 07:10 . 2010-04-10 08:48 -------- d-----w- c:\users\David\AppData\Roaming\OpenCandy
2010-10-06 07:10 . 2009-11-27 09:09 -------- d-----w- c:\users\David\AppData\Roaming\Skype
2010-10-06 07:10 . 2010-03-21 18:33 -------- d-----w- c:\users\David\AppData\Roaming\Ulead Systems
2010-10-06 06:08 . 2009-07-14 08:44 579238 ----a-w- c:\windows\system32\perfh005.dat
2010-10-06 06:08 . 2009-07-14 08:44 107134 ----a-w- c:\windows\system32\perfc005.dat
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-10-05 08:18 . 2009-11-26 18:43 -------- d-----w- c:\program files\Alwil Software
2010-10-05 07:17 . 2010-01-05 17:21 -------- d-----w- c:\programdata\Microsoft Help
2010-09-30 07:12 . 2009-11-26 20:25 -------- d-----w- c:\program files\CAPCOM
2010-09-27 07:25 . 2010-03-17 10:45 -------- d-----w- c:\program files\Windows Live
2010-09-24 12:27 . 2010-08-30 14:43 -------- d-----w- c:\users\David\AppData\Roaming\Vso
2010-09-23 14:02 . 2009-11-27 09:23 -------- d-----w- c:\users\David\AppData\Roaming\skypePM
2010-09-23 09:13 . 2010-09-17 19:00 -------- d-----w- c:\users\David\AppData\Roaming\Nokia
2010-09-23 07:44 . 2010-01-23 20:01 -------- d-----w- c:\users\David\AppData\Roaming\AVI ReComp
2010-09-22 04:54 . 2010-09-17 19:00 -------- d-----w- c:\programdata\PC Suite
2010-09-22 04:38 . 2010-01-05 17:23 -------- d-----w- c:\program files\Microsoft.NET
2010-09-18 07:59 . 2010-09-18 07:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-09-18 05:51 . 2010-09-17 18:58 -------- d-----w- c:\program files\Common Files\Nokia
2010-09-18 05:48 . 2010-09-18 05:48 -------- d-----w- c:\program files\PC Connectivity Solution
2010-09-08 10:00 . 2010-09-08 10:00 72940376 ----a-w- c:\users\David\AppData\Roaming\Nokia\Ovi Suite\Software Updater\Nokia_Ovi_Suite_webupgrade_ALL.exe
2010-09-08 07:09 . 2010-03-20 12:03 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-08-30 17:04 . 2010-08-30 17:04 -------- d-----w- c:\programdata\vsosdk
2010-08-30 15:20 . 2010-03-21 18:30 -------- d-----w- c:\program files\SmartSound Software
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 -------- d-----w- c:\program files\VSO
2010-08-20 23:16 . 2010-08-20 23:16 12284672 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\AFIRegistryReviverSetup.exe
2010-07-29 06:30 . 2010-08-29 15:17 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-29 15:17 82944 ----a-w- c:\windows\system32\iccvid.dll
2009-11-27 09:43 . 2009-11-27 09:42 16742712 ----a-w- c:\program files\install_icq65.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1324 [GMT 2:00]
Spuštěný z: c:\users\Davidek\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\catchme.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-10 do 2010-10-10 )))))))))))))))))))))))))))))))
.
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\Davidek\AppData\Local\temp
2010-10-10 11:08 . 2010-10-10 11:08 -------- d-----w- c:\users\David\AppData\Local\temp
2010-10-09 09:31 . 2010-10-09 09:31 -------- d-----w- c:\users\Davidek\DoctorWeb
2010-10-09 08:26 . 2010-10-09 08:26 -------- d-----w- c:\users\Davidek\AppData\Roaming\Malwarebytes
2010-10-08 16:18 . 2010-10-08 16:18 -------- d-----w- c:\users\Guest\AppData\Local\Opera
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\programdata\Malwarebytes
2010-10-08 14:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 14:29 . 2010-10-08 14:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-08 13:56 . 2010-10-08 13:56 -------- d-----w- C:\rsit
2010-10-08 06:53 . 2010-10-08 06:53 388096 ----a-r- c:\users\Davidek\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-07 16:20 . 2010-10-07 16:20 -------- d-----w- c:\program files\Trend Micro
2010-10-07 07:11 . 2010-10-07 07:11 119776 ----a-w- c:\users\Davidek\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-05 20:31 . 2010-10-09 05:48 -------- d-----w- c:\users\Davidek\AppData\Local\Diagnostics
2010-10-05 20:14 . 2010-10-05 20:14 -------- d-----w- c:\users\David\AppData\Local\ESET
2010-10-05 19:08 . 2010-10-06 07:10 -------- d-----w- c:\programdata\MFAData
2010-10-05 10:20 . 2010-10-05 10:20 -------- d-----w- c:\users\Davidek\AppData\Roaming\PC Suite
2010-10-05 09:19 . 2010-10-05 09:19 -------- d-----w- c:\users\Davidek\AppData\Local\ESET
2010-10-05 08:19 . 2009-08-17 16:05 53328 ------w- c:\windows\system32\drivers\aswMonFlt.sys
2010-10-05 07:29 . 2010-10-10 10:56 -------- d-----w- c:\programdata\Alwil Software
2010-10-05 07:22 . 2010-10-05 07:22 -------- d-----w- c:\users\Davidek\AppData\Local\Opera
2010-10-04 06:56 . 2010-10-06 08:10 -------- d-----w- c:\users\David\AppData\Local\Diagnostics
2010-10-04 06:39 . 2010-10-05 07:17 -------- d-sh--w- c:\programdata\SMNGRS
2010-10-04 06:39 . 2010-10-05 10:11 -------- d-sh--w- c:\programdata\642fa8
2010-09-29 05:38 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 05:38 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 02:33 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-09-27 07:26 . 2010-09-27 07:26 -------- d-----w- c:\program files\Microsoft
2010-09-27 07:25 . 2010-09-27 07:25 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-27 06:59 . 2010-09-29 05:38 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-27 06:58 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-27 06:58 . 2009-10-10 02:31 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-09-27 06:58 . 2010-09-27 06:58 -------- d-----w- c:\program files\CONEXANT
2010-09-26 07:49 . 2010-10-04 19:43 -------- d-----w- c:\users\David\AppData\Local\Deployment
2010-09-23 09:13 . 2010-09-23 09:13 -------- d-----w- c:\users\David\AppData\Roaming\Nokia Ovi Suite
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\users\David\AppData\Roaming\AnvSoft
2010-09-22 19:41 . 2010-09-22 19:41 -------- d-----w- c:\program files\AnvSoft
2010-09-22 17:29 . 2010-09-22 17:32 -------- d-----w- c:\users\David\AppData\Local\Video Converter
2010-09-22 17:28 . 2010-09-22 17:28 -------- d-----w- c:\programdata\VideoConverter
2010-09-22 16:21 . 2010-09-22 16:21 -------- d-----w- c:\program files\Ultra Video Joiner
2010-09-22 14:44 . 2010-09-22 14:44 -------- d-----w- c:\program files\FreeTime
2010-09-22 14:41 . 2010-09-22 14:41 -------- d-----w- c:\users\David\AppData\Local\Broad Intelligence
2010-09-22 09:54 . 2010-09-22 09:54 -------- d--h--w- c:\windows\PIF
2010-09-21 08:06 . 2010-09-22 10:01 -------- d-----w- c:\program files\Windows Update
2010-09-20 14:06 . 2010-09-20 14:13 -------- d-----w- c:\program files\ReviverSoft
2010-09-20 14:05 . 2010-09-20 14:05 -------- d-----w- c:\programdata\ReviverSoft
2010-09-20 14:04 . 2010-09-20 14:05 12343104 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\p1v1_AFIRegistryReviver_w.exe
2010-09-20 14:04 . 2010-09-20 14:06 -------- d-----w- c:\users\David\AppData\Local\OpenCandy
2010-09-20 14:04 . 2010-09-20 14:04 349296 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\DLMgr_3_1.6.87.exe
2010-09-20 14:03 . 2010-09-22 14:19 -------- d-----w- c:\users\David\AppData\Roaming\Broad Intelligence
2010-09-20 06:08 . 2010-09-20 06:29 -------- d-----w- c:\program files\uTorrent
2010-09-19 18:33 . 2010-09-19 18:33 310208 ----a-w- c:\users\David\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
2010-09-19 18:33 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\Azureus
2010-09-18 06:53 . 2010-09-18 06:54 -------- d-----w- c:\program files\Ask.com
2010-09-18 06:52 . 2010-10-06 07:10 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2010-09-18 05:48 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-17 18:56 . 2010-09-17 18:56 12212040 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 13930312 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-09-17 18:56 . 2010-09-17 18:56 61440 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-09-17 18:56 . 2010-09-17 18:56 58880 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-09-17 18:56 . 2010-09-17 18:56 50000 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Installer\CommonCustomActions\pcswpc.exe
2010-09-17 18:56 . 2009-01-01 10:00 93326608 ----a-w- c:\programdata\OviInstallerCache\{EC6BCADF-AA21-428B-B5DE-CB91C94053BE}\Nokia_Ovi_Suite_2_0_0_8_ALL.exe
2010-09-17 18:56 . 2010-09-18 05:47 -------- d-----w- c:\program files\Nokia
2010-09-17 18:56 . 2010-09-17 18:56 -------- d-----w- c:\programdata\OviInstallerCache
2010-09-15 02:44 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 07:10 . 2010-03-20 18:01 -------- d-----w- c:\users\David\AppData\Roaming\EPSON
2010-10-06 07:10 . 2009-11-26 18:37 -------- d-----w- c:\users\David\AppData\Roaming\GRETECH
2010-10-06 07:10 . 2010-04-10 08:48 -------- d-----w- c:\users\David\AppData\Roaming\OpenCandy
2010-10-06 07:10 . 2009-11-27 09:09 -------- d-----w- c:\users\David\AppData\Roaming\Skype
2010-10-06 07:10 . 2010-03-21 18:33 -------- d-----w- c:\users\David\AppData\Roaming\Ulead Systems
2010-10-06 06:08 . 2009-07-14 08:44 579238 ----a-w- c:\windows\system32\perfh005.dat
2010-10-06 06:08 . 2009-07-14 08:44 107134 ----a-w- c:\windows\system32\perfc005.dat
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-10-06 06:06 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-10-05 08:18 . 2009-11-26 18:43 -------- d-----w- c:\program files\Alwil Software
2010-10-05 07:17 . 2010-01-05 17:21 -------- d-----w- c:\programdata\Microsoft Help
2010-09-30 07:12 . 2009-11-26 20:25 -------- d-----w- c:\program files\CAPCOM
2010-09-27 07:25 . 2010-03-17 10:45 -------- d-----w- c:\program files\Windows Live
2010-09-24 12:27 . 2010-08-30 14:43 -------- d-----w- c:\users\David\AppData\Roaming\Vso
2010-09-23 14:02 . 2009-11-27 09:23 -------- d-----w- c:\users\David\AppData\Roaming\skypePM
2010-09-23 09:13 . 2010-09-17 19:00 -------- d-----w- c:\users\David\AppData\Roaming\Nokia
2010-09-23 07:44 . 2010-01-23 20:01 -------- d-----w- c:\users\David\AppData\Roaming\AVI ReComp
2010-09-22 04:54 . 2010-09-17 19:00 -------- d-----w- c:\programdata\PC Suite
2010-09-22 04:38 . 2010-01-05 17:23 -------- d-----w- c:\program files\Microsoft.NET
2010-09-18 07:59 . 2010-09-18 07:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-09-18 05:51 . 2010-09-17 18:58 -------- d-----w- c:\program files\Common Files\Nokia
2010-09-18 05:48 . 2010-09-18 05:48 -------- d-----w- c:\program files\PC Connectivity Solution
2010-09-08 10:00 . 2010-09-08 10:00 72940376 ----a-w- c:\users\David\AppData\Roaming\Nokia\Ovi Suite\Software Updater\Nokia_Ovi_Suite_webupgrade_ALL.exe
2010-09-08 07:09 . 2010-03-20 12:03 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-08-30 17:04 . 2010-08-30 17:04 -------- d-----w- c:\programdata\vsosdk
2010-08-30 15:20 . 2010-03-21 18:30 -------- d-----w- c:\program files\SmartSound Software
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 47360 ----a-w- c:\users\David\AppData\Roaming\pcouffin.sys
2010-08-30 14:43 . 2010-08-30 14:43 -------- d-----w- c:\program files\VSO
2010-08-20 23:16 . 2010-08-20 23:16 12284672 ----a-w- c:\users\David\AppData\Roaming\OpenCandy\OpenCandy_7AC158BD3B894D3391C5A229613C164C\AFIRegistryReviverSetup.exe
2010-07-29 06:30 . 2010-08-29 15:17 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-29 15:17 82944 ----a-w- c:\windows\system32\iccvid.dll
2009-11-27 09:43 . 2009-11-27 09:42 16742712 ----a-w- c:\program files\install_icq65.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
Re: napadeni pocitace virem
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AllShare;SAMSUNG AllShare Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-04-23 9241088]
R3 GarenaPEngine;GarenaPEngine;c:\users\David\AppData\Local\Temp\LCK6FB4.tmp [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-26 691696]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:25392
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GarenaPEngine]
"ImagePath"="\??\c:\users\David\AppData\Local\Temp\LCK6FB4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:de,ac,79,38,6b,79,a2,73,68,53,3e,3a,54,10,12,21,11,00,95,cc,a8,18,2e,
1f,56,1e,8d,4a,ad,41,c4,bc,62,a8,a8,1a,07,3b,02,4f,27,ac,b3,b7,6f,36,8a,b2,\
"??"=hex:a8,1c,b6,38,2c,97,76,a6,1a,67,78,8c,e9,b9,85,9d
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\License information*]
"datasecu"=hex:8d,6c,8d,31,c7,67,4b,25,da,73,61,f1,a9,75,bb,2e,ba,9c,f4,69,5e,
70,6a,65,9c,a2,d3,c2,22,d8,ea,59,69,6f,04,ea,43,3b,6e,77,1c,8d,35,61,85,4a,\
"rkeysecu"=hex:0e,6d,fb,82,c6,22,85,20,77,b0,39,2f,0c,e8,f1,2f
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-10-10 13:10:35
ComboFix-quarantined-files.txt 2010-10-10 11:10
ComboFix2.txt 2010-10-09 10:44
Před spuštěním: Volných bajtů: 104 797 560 832
Po spuštění: Volných bajtů: 104 803 913 728
- - End Of File - - B4153B3B6428BF7E918AA8E8C194FE09
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AllShare;SAMSUNG AllShare Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-04-23 9241088]
R3 GarenaPEngine;GarenaPEngine;c:\users\David\AppData\Local\Temp\LCK6FB4.tmp [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-11-26 691696]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:25392
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GarenaPEngine]
"ImagePath"="\??\c:\users\David\AppData\Local\Temp\LCK6FB4.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:de,ac,79,38,6b,79,a2,73,68,53,3e,3a,54,10,12,21,11,00,95,cc,a8,18,2e,
1f,56,1e,8d,4a,ad,41,c4,bc,62,a8,a8,1a,07,3b,02,4f,27,ac,b3,b7,6f,36,8a,b2,\
"??"=hex:a8,1c,b6,38,2c,97,76,a6,1a,67,78,8c,e9,b9,85,9d
[HKEY_USERS\S-1-5-21-163937605-4191390367-3994013808-1001\Software\SecuROM\License information*]
"datasecu"=hex:8d,6c,8d,31,c7,67,4b,25,da,73,61,f1,a9,75,bb,2e,ba,9c,f4,69,5e,
70,6a,65,9c,a2,d3,c2,22,d8,ea,59,69,6f,04,ea,43,3b,6e,77,1c,8d,35,61,85,4a,\
"rkeysecu"=hex:0e,6d,fb,82,c6,22,85,20,77,b0,39,2f,0c,e8,f1,2f
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-10-10 13:10:35
ComboFix-quarantined-files.txt 2010-10-10 11:10
ComboFix2.txt 2010-10-09 10:44
Před spuštěním: Volných bajtů: 104 797 560 832
Po spuštění: Volných bajtů: 104 803 913 728
- - End Of File - - B4153B3B6428BF7E918AA8E8C194FE09
Re: napadeni pocitace virem
Tak mi to skoukni a napis co dal:popripade mi porad co s tim puvodnim Avastem,jestli si ho mam nechat,nebo odinstalovat a zvolit jinou antivirovou ochranu,popripade,jaky program by jsi mi doporucil.
Zpět na “Viry, antiviry, firewally…”
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti