menší majetkové -

Magazine
Go Back   Počítačové Juice > Computer Software > Virus, spyware a bezpečnost

Register


 Default 

Nakaženi MultiPacked.Multi.Generic Malware!




Reply
 
Thread Nástroje
  #1  
Old 23. června 2009, 10:38
Člen Skupina
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Nedávno jsem se stáhli téma aplikace. Po instalaci, Kaspersky výzva záznamu říká počítač napaden MultiPacked.Multi.Generic malware. Moje Kaspersky přestal pracovat a moje okna téma je pryč-jsem uvízl s okny klasika. Pomozte, prosím!
  #2  
Old 23. června 2009, 11:25
Moderátor skupiny
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Zkuste mi získat některou z logů můžete zde. http://www.computer-juice.com/forums...-posting-7476/
__________________

  #3  
Old 24. června 2009, 11:44
Moderátor skupiny
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Vypadá to, že ve fóru měli závada. Prosím, po těchto DDS logs.

Stáhnout z DDS | TADY | nebo | TADY | nebo | TADY | a uložit do počítače.

Vista uživatele Klikněte pravým tlačítkem na DDS a zvolte Spustit jako správce (obdržíte UAC prompt, prosím umožní ji)

* XP uživatelů Dvojitým kliknutím na DDS spusťte.
* Pokud je váš antivirový program nebo firewall pokusí zablokovat DDS pak prosím tomu, aby mohla spustit.
* Po skončení DDS otevřou dva (2) logy.

1) DDS.txt
2) Attach.txt

* Uložit oba logy na vaší pracovní ploše.
* Prosím, zkopírujte a vložte celý obsah oba záznamy v příští odpověď.

Poznámka: DDS Vás poučí, na post Attach.txt přihlásit jako přílohu.
Prosím jen post jako byste jakékoliv jiné log by kopírovat a vložit jej do odpovědi.
__________________

  #4  
Old 24. června 2009, 13:55
Člen Skupina
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

DDS (Ver_09-05 - 14.01) - NTFSx86
Úcastníku myši na 16:53:23.36 na středu 06.24.2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1294 [GMT -4:00]

AV: Kaspersky Internet Security * On-skenování přístup zdravotně postižených * (Aktualizováno) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security * zapnuto * (2C4D4BC6-0793-4956-A9F9-E252435469C0)

============== Spuštěných procesů ===============

C: \ WINDOWS \ system32 \ Svchost-k DcomLaunch
svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe-k netsvcs
C: \ WINDOWS \ system32 \ svchost.exe-k WudfServiceGroup
svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ Creative \ Sdílené Files \ CTAudSvc.exe
C: \ WINDOWS \ Explorer.exe
C: \ WINDOWS \ system32 \ CTHELPER.EXE
C: \ WINDOWS \ system32 \ CTXFIHLP.EXE
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE
C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Svazek Panel \ VolPanlu.exe
C: \ WINDOWS \ system32 \ RUNDLL32.EXE
C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ WINDOWS \ SYSTEM32 \ CTXFISPI.EXE
C: \ WINDOWS \ system32 \ Program Ctfmon.exe
C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe
C: \ PROGRA ~ 1 \ miliontin ~ 4 \ rapimgr.exe
svchost.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
C: \ WINDOWS \ system32 \ nvsvc32.exe
C: \ WINDOWS \ system32 \ PnkBstrA.exe
C: \ WINDOWS \ system32 \ svchost.exe-k imgsvc
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Zábava Center \ EAXLoadr.exe
C: \ Program Files \ hlediska \ Common \ ViewpointService.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ WINDOWS \ system32 \ svchost.exe-k HTTPFilter
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ LimeWire \ LimeWire.exe
C: \ Documents and Settings \ Mouse \ Desktop \ dds.com

============== Pseudo HJT Zpráva ===============

uStart Page = hxxp: / / google.com /
uInternet Nastavení, ProxyOverride = *. místní
BHO: Adobe PDF Reader Link Helper: (06849e9f-c8d7-4d59-b87d-784b7d6be0b3) - c: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
BHO: Skype add-on (génius): (22bf413b-c6d2-4d91-82a9-a0f997ba588c) - C: \ Program Files \ Skype \ toolbary \ Internet Explorer \ SkypeIEPlugin.dll
BHO: IEVkbdBHO třídy: (59273ab4-e7d3-40f9-a1a8-6fa9cca1862c) - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ievkbd.dll
BHO: Java (tm) Plug-In 2 SSV Helper: (dbc80044-a445-435b-bc74-9c25c1c588a9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
BHO: JQSIEStartDetectorImpl třídy: (e7e6f031-17ce-4c07-bc86-eabfe594f69c) - C: \ Program Files \ Java \ jre6 \ lib \ nasadit \ jqs \ tj \ jqs_plugin.dll
TB: Veoh Browser Plug-in: (d0943516-5076-4020-a3b5-aefaf26ab263) - C: \ Program Files \ veoh sítě \ veoh \ plugins \ reg \ VeohToolbar.dll
EB: (32683183-48a0-441b-a342-7c2a440a9478) - Ne souboru
uRun: [program Ctfmon.exe] c: \ windows \ system32 \ Program Ctfmon.exe
uRun: [H / PC připojení Agent] "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE C: \ windows \ system32 \ NvCpl.dll, NvStartup
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [CTDVDDET] "C: \ Program Files \ tvůrčí \ Sound Blaster X-Fi \ dvdaudio \ CTDVDDET.EXE"
mRun: [RCSystem] "C: \ Program Files \ tvůrčí \ sdílené soubory \ module loader \ DLLML.exe" RCSystem *-spuštění
mRun: [AudioDrvEmulator] "C: \ Program Files \ tvůrčí \ sdílené soubory \ module loader \ dllml.exe" -1 audiodrvemulator "C: \ Program Files \ tvůrčí \ sdílené soubory \ module loader \ audio emulátor \ AudDrvEm.dll"
mRun: [VolPanel] "C: \ Program Files \ tvůrčí \ Sound Blaster X-Fi \ objemu panel \ VolPanlu.exe" / r
mRun: [NvMediaCenter] RUNDLL32.EXE C: \ windows \ system32 \ NvMcTray.dll, NvTaskbarInit
mRun: [AVP] "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe"
mRun: [QuickTime Úkol] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
mRun: [AppleSyncNotifier] c: \ Program Files \ Common Files \ jablko \ mobilní přístroj Support \ bin \ AppleSyncNotifier.exe
mRun: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
IE: Přidat do Banner ad Blocker - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportovat do aplikace Microsoft Excel - c: \ progra ~ 1 \ miliontin ~ 2 \ office10 \ EXCEL.EXE/3000
IE: (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostické \ xpnetdiag.exe
IE: (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
IE: (1F460357-8A94-4D71-9CA3-AA4ACF32ED8E) - (85E0B171-04FA-11D1-B7DA-00A0C90348D6) - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ SCIEPlgn.dll
IE: (2EAF5BB1-070F-11D3-9307-00C04FAE2D4F) - (2EAF5BB0-070F-11D3-9307-00C04FAE2D4F) - c: \ progra ~ 1 \ miliontin ~ 4 \ INetRepl.dll
IE: (2EAF5BB2-070F-11D3-9307-00C04FAE2D4F) - (2EAF5BB0-070F-11D3-9307-00C04FAE2D4F) - c: \ progra ~ 1 \ miliontin ~ 4 \ INetRepl.dll
IE: (77BF5300-1474-4EC7-9980-D32B190E9B07) - (77BF5300-1474-4EC7-9980-D32B190E9B07) - C: \ Program Files \ Skype \ toolbary \ Internet Explorer \ SkypeIEPlugin.dll
DPF: Microsoft XML Parser Java - file: / / c: \ windows \ Java \ Classes \ xmldso.cab
DPF: (17492023-C23A-453E-A040-C7C580BBF700) - hxxp: / / go.microsoft.com / fwlink /? Linkid = 39204
DPF: (45B69029-F3AB-4204-92DE-D5140C3E8E74) - hxxps: / / portal.apogentech.com / vdesk / terminálu / InstallerControl.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
DPF: (57C76689-F052-487B-A19F-855AFDDF28EE) - hxxps: / / portal.apogentech.com/vdesk/terminal/f5InspectionHost.cab # version = 6030,2008,0904,1939
DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D) - hxxps: / / portal.apogentech.com/policy/download_binary.php/win32/f5syschk.cab # Version = 6030,2008,0904,1947
Handler: cdo - (CD00020A-8B95-11D1-82DB-00C04FB1625D) - c: \ Program Files \ Common Files \ Microsoft Shared \ web složky \ PKMCDO.DLL
Handler: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - c: \ progra ~ 1 \ Common ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
Informujte:! SASWinLogon - C: \ Program Files \ superantispyware \ SASWINLO.DLL
Informujte: klogon - c: \ windows \ system32 \ klogon.dll
AppInit_DLLs: c: \ progra ~ 1 \ Kasper ~ 1 \ Kasper ~ 1 \ mzvkbd.dll, c: \ progra ~ 1 \ Kasper ~ 1 \ Kasper ~ 1 \ adialhk.dll, c: \ progra ~ 1 \ kaspe r ~ 1 \ Kasper ~ 1 \ kloehk.dll
SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - c: \ windows \ system32 \ WPDShServiceObj.dll
SEH: SABShellExecuteHook třídy: (5ae067d3-9afb-48e0-853a-ebb7f4a000da) - C: \ Program Files \ superantispyware \ SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath --

============= SLUŽBY / STROJVEDOUCÍM ===============

R0 kl1; Kl1, c: \ windows \ system32 \ drivers \ kl1.sys [2007-10-31 112144]
R0 klbg; Kaspersky Lab Zavádecí stráže Driver; c: \ windows \ system32 \ drivers \ klbg.sys [2008-1-29 33808]
R1 klif; Kaspersky Lab Driver; c: \ windows \ system32 \ drivers \ klif.sys [2008-4-18 213520]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ superantispyware \ SASKUTIL.SYS [2008-2-29 55024]
R1 UGURU; UGURU, c: \ windows \ system32 \ drivers \ uGuru.sys [2008-5-12 14592]
R2 AVP; Kaspersky Internet Security, C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe-r -> C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe-r [? ]
R2 hlediska Manager Service; hlediska Manager Service; C: \ Program Files \ hlediska \ Common \ ViewpointService.exe [2008-12-7 24652]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, c: \ windows \ system32 \ drivers \ klfltdev.sys [2008-3-13 26640]
R3 klim5, Kaspersky Anti-Virus NDIS filtr, c: \ windows \ system32 \ drivers \ klim5.sys [2007-12-13 24592]
R3 SASENUM; SASENUM, C: \ Program Files \ superantispyware \ SASENUM.SYS [2006-2-16 4096]
S1 SASDIFSV; SASDIFSV, C: \ Program Files \ superantispyware \ SASDIFSV.SYS [2008-2-29 9968]
S2 Cubase32; Cubase32, c: \ windows \ system32 \ drivers \ Kuba se32.sys [2009-4-5 11808]
S3 IlvMoneyDRIVER53; IlvMoneyDRIVER53, c: \ windows \ syste M32 \ drivers \ IlvMoney1215.sys [2008-8-21 30080]

=============== Vytvořeno Poslední 30 ================

2009-06-17 13:58 <dir> - d ----- C: \ Program Files \ LSoft Technologie
2009-06-13 12:32 <dir> - d ----- C: \ Program Files \ iPod
2009-06-13 12:32 <dir> - d ----- C: \ Program Files \ iTunes

==================== Find3M ====================


============= FINISH: 16:54:12.42 ===============


Pokud to není výslovně poučen, DON'T POST tento záznam.
Pokud o to požádá, ZIP IT UP & ATTACH IT

DDS (Ver_09-05 - 14.01)

Microsoft Windows XP Professional
Zaváděcího zařízení: \ Device \ HarddiskVolume1
Instalace Date: 5/12/2008 2:38:20 PM
Systém Uptime: 6.24.2009 12:33:35 (4 hodiny)

Základní deska: http://www.abit.com.tw/ | | IP35 PRO (P35 + ICH9R)
Procesor: Intel (R) Pentium (R) 4 CPU 2.80GHz | Socket 775 | 3024/216mhz

==== Disku =========================

A: je Vyměnitelná
C: je FIXNÍHO (NTFS) - 128 GIB celkem 60.146 GIB zdarma.
D: je FIXNÍHO (NTFS) - 69 GIB celkem 60.479 GIB zdarma.
E: is CDROM (CDFS)
F: is CDROM (CDFS)
G: je stanovena (NTFS) - 245 GIB celkem 138.326 GIB zdarma.
H: is CDROM ()
I: je CD-ROM ()
J: is CDROM ()
K: je CD-ROM ()

==== Zakázáno Device Manager Zboľí =============

Třída GUID: (4D36E972-E325-11CE-BFC1-08002BE10318)
Popis: Realtek RTL8169/8110 rodinu Gigabit Ethernet NIC
Zařízení ID: PCI \ VEN_10EC & DEV_8167 & SUBSYS_1083147B & REV_10 \ 4 & BB2 9FA6 & 0 & 00F0
Výrobce: Realtek Semiconductor Corp.
Jméno: Realtek RTL8169/8110 Rodinné Gigabit Ethernet NIC # 3
PNP Zařízení ID: PCI \ VEN_10EC & DEV_8167 & SUBSYS_1083147B & REV_10 \ 4 & BB2 9FA6 & 0 & 00F0
Servis: RTL8023xp

Třída GUID: (4D36E972-E325-11CE-BFC1-08002BE10318)
Popis: Miniport mostu MAC
Zařízení ID: ROOT \ MS_BRIDGEMP \ 0000
Výrobce: Microsoft
Jméno: Miniport mostu MAC
PNP Zařízení ID: ROOT \ MS_BRIDGEMP \ 0000
Servis: BridgeMP

==== Obnovení systému Body ===================

RP202: 3/26/2009 6:14:01 PM - Systém Checkpoint
RP203: 3/27/2009 9:06:08 PM - Systém Checkpoint
RP204: 3.30.2009 12:43:20 - Systém Checkpoint
RP205: 4/1/2009 5:11:23 PM - Systém Checkpoint
RP206: 4/3/2009 3:31:49 PM - Systém Checkpoint
RP207: 4.6.2009 11:30:33 - Systém Checkpoint
RP208: 4/8/2009 1:48:55 AM - Odstraněno MapleStory GL.
RP209: 4/8/2009 1:49:05 AM - Instalovaný MapleStory.
RP210: 4/8/2009 2:00:33 AM - Odstraněno MapleStory.
RP211: 4/8/2009 2:12:11 AM - Instalovaný MapleStory.
RP212: 4/9/2009 1:53:58 PM - Systém Checkpoint
RP213: 4/11/2009 6:22:36 AM - Systém Checkpoint
RP214: 4.14.2009 11:18:28 - Systém Checkpoint
RP215: 4/15/2009 5:50:23 PM - Software Distribution Service 3.0
RP216: 4/18/2009 1:32:37 AM - Systém Checkpoint
RP217: 4/21/2009 2:37:36 PM - Systém Checkpoint
RP218: 4/22/2009 5:07:27 PM - Systém Checkpoint
RP219: 4/24/2009 2:41:28 PM - Systém Checkpoint
RP220: 4/25/2009 10:07:27 PM - Systém Checkpoint
RP221: 4/28/2009 6:48:10 AM - Instalovaný Java (TM) 6 Update 13
RP222: 5/2/2009 7:23:06 PM - Systém Checkpoint
RP223: 5/3/2009 11:36:18 PM - Systém Checkpoint
RP224: 5/5/2009 2:29:10 PM - Systém Checkpoint
RP225: 5/6/2009 8:29:33 PM - Systém Checkpoint
RP226: 5/7/2009 3:00:17 AM - Software Distribution Service 3.0
RP227: 5.7.2009 11:16:03 - Instalovaný Windows XP WgaNotify.
RP228: 5.9.2009 11:12:42 - Systém Checkpoint
RP229: 5/10/2009 5:10:12 PM - Systém Checkpoint
RP230: 5/11/2009 9:02:07 PM - Systém Checkpoint
RP231: 5/13/2009 12:26:07 AM - Software Distribution Service 3.0
RP232: 5/14/2009 2:28:00 PM - Odstraněno ZU-ONLINE
RP233: 5/15/2009 2:47:49 PM - Systém Checkpoint
RP234: 5/17/2009 1:28:31 AM - Systém Checkpoint
RP235: 5/17/2009 4:58:00 PM - LG Instalovaný ovladač USB modemu
RP236: 5.19.2009 11:34:48 - Systém Checkpoint
RP237: 5.20.2009 12:47:48 - Systém Checkpoint
RP238: 5.23.2009 10:08:08 - Systém Checkpoint
RP239: 6.1.2009 10:03:10 - Systém Checkpoint
RP240: 6.2.2009 10:03:30 - Systém Checkpoint
RP241: 6.3.2009 11:47:56 - Systém Checkpoint
RP242: 6/5/2009 11:10:53 PM - Systém Checkpoint
RP243: 6/7/2009 2:46:24 PM - Systém Checkpoint
RP244: 6.9.2009 11:32:41 - Systém Checkpoint
RP245: 6/10/2009 5:52:30 PM - Systém Checkpoint
RP246: 6/10/2009 11:00:09 PM - Software Distribution Service 3.0
RP247: 6.12.2009 12:14:34 - Systém Checkpoint
RP248: 6/13/2009 1:12:33 PM - Systém Checkpoint
RP249: 6/14/2009 9:20:14 PM - Systém Checkpoint
RP250: 6/15/2009 9:53:46 PM - Systém Checkpoint
RP251: 6/17/2009 12:27:01 AM - Systém Checkpoint
RP252: 6/21/2009 7:28:06 PM - Systém Checkpoint
RP253: 6/22/2009 8:08:50 PM - Systém Checkpoint
RP254: 6/23/2009 2:54:41 PM - Odstraněno Garmin City Navigator Severní Amerika NT 2009 Update
RP255: 6/23/2009 2:58:20 PM - Odstraněno palmOne
RP256: 6/24/2009 3:58:18 PM - Systém Checkpoint

==== Nainstalovaných programů ======================


==== Prohlížeči událostí Zprávy z minulého týdne ========


==== Konec souboru ===========================
  #5  
Old 24. června 2009, 14:05
Moderátor skupiny
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Stáhněte ComboFix © subs z jednoho z níže uvedených odkazů. Jistěže top uložit do Desktop.

Link # 1
Link # 2

** Poznámka: Je důležité, že je uložen přímo na váš Desktop

DON'T spustit ještě!

Poznámka: níže uvedených pokynů byly vytvořeny speciálně pro tohoto uživatele. Pokud si nejste tímto uživatelem DON'T postupujte podle těchto pokynů, které by mohly poškodit chod vašeho systému

Odstranit tyto soubory / adresáře, takto:

1. Přejít na Začít > Běžet > Typ Notepad.exe a klikněte OK otevřete Poznámkový blok.
To muset třeba Poznámkový blok, WordPad není.
2. Zkopírujte text v níže kód do kolonky zvýraznění celý text a stisknutím Ctrl + C

Kód:
Killall:: DDS:: uInternet Nastavení, ProxyOverride = *. místní EB: (32683183-48a0-441b-a342-7c2a440a9478) - Ne souboru IE: (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ messenger \ msmsgs.exe DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll Driver:: hlediska Manager Service Folder:: C: \ Program Files \ hlediska
3. Jdi do okna Poznámkového bloku a klikněte Upravit > Vložit
4. Potom klikněte na Soubor > Uložit
5. Název souboru CFScript.txt - Uložte soubor do počítače
6. Poté přesuneme CFScript (držte levé tlačítko myši a zároveň přetažením souboru) a pusť ji (uvolněte levé tlačítko myši) do ComboFix.exe, jak vidíte na obrázku níže. Důležité upozornění: Provede instrukce pozorně!



ComboFix začne provádět, stačí sledovat pokyny.
Po restartu (v případě, že požádá o restart systému), bude produkovat záznam pro vás.
Posta, že log (Combofix.txt) ve své příští odpověď.

Poznámka: Don't mouseclick ComboFix okna, pokud je v chodu. To může způsobit váš systém zmrazit
__________________

  #6  
Old 25. června 2009, 08:45
Člen Skupina
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Myš 06/24/2009 17:18.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1452 [GMT -4:00]
Spuštění z: c: \ Documents and Settings \ Mouse \ Desktop \ ComboFix.exe
Command přepínačů používá:: c: \ Documents and Settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-skenování přístup zdravotně postižených * (Aktualizováno) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security * zapnuto * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

((((((((((((((((((((((((((((((((((((((( Ostatní Vymazání ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

C: \ Program Files \ hlediska
c: \ recyklátor \ S-1-5-21-1957994488-1801674531-1177238915-1004
c: \ recyklátor \ S-1-5-21-789336058-2025429265-1644491937-1003
c: \ windows \ system32 \ drivers \ kl1.sys
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ Program Files \ hlediska \ Common \ ViewpointService.exe
C: \ Program Files \ hlediska \ Common \ VistaBoot.sdll
C: \ Program Files \ hlediska \ hlediska Media Player \ AxMetaStream.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ ClassIDs.ini
C: \ Program Files \ hlediska \ hlediska Media Player \ ComponentMgr.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ MetaStreamID.ini
C: \ Program Files \ hlediska \ hlediska Media Player \ MtsAxInstaller.exe
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ AOLUserShell.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ Cursors.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ JpegReader.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ Mts3Reader.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ SceneComponent.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ SreeDMMX.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ SWFView.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ VETScriptInterpreter.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ VMPSpeech.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ NewComponents \ VMPVideo2.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ npViewpoint.dll
C: \ Program Files \ hlediska \ hlediska Media Player \ npViewpoint.xpt
c: \ recyklátor \ S-1-5-21-1957994488-1801674531-1177238915-1004 \ Desktop.ini
c: \ recyklátor \ S-1-5-21-1957994488-1801674531-1177238915-1004 \ INFO2
c: \ recyklátor \ S-1-5-21-789336058-2025429265-1644491937-1003 \ Desktop.ini
c: \ recyklátor \ S-1-5-21-789336058-2025429265-1644491937-1003 \ INFO2
c: \ windows \ emMON.exe
c: \ windows \ system32 \ Kodeky \ 7zAES.dll
c: \ windows \ system32 \ Kodeky \ AES.dll
c: \ windows \ system32 \ Kodeky \ Branch.dll
c: \ windows \ system32 \ Kodeky \ BZip2.dll
c: \ windows \ system32 \ Kodeky \ Copy.dll
c: \ windows \ system32 \ Kodeky \ Deflate.dll
c: \ windows \ system32 \ Kodeky \ LZMA.dll
c: \ windows \ system32 \ Kodeky \ PPMd.dll
c: \ windows \ system32 \ Kodeky \ Rar29.dll
c: \ windows \ system32 \ Kodeky \ Swap.dll
c: \ windows \ system32 \ drivers \ ctoss2k.sys
c: \ windows \ system32 \ formáty \ 7z.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače / Služby )))))))) )))))))))))))))))))))))))))))))))))))))))
.

------- \ Legacy_ILVMONEYDRIVER53
------- \ Legacy_VIEWPOINT_MANAGER_SERVICE
------- \ Service_IlvMoneyDRIVER53
------- \ Service_Viewpoint Service Manager
------- \ Legacy_ossrv
------- \ Service_ossrv


((((((((((((((((((((((((( Soubory vytvořené od 2009-05-24 do 2009-06-24 ))))))))))) ))))))))))))))))))))
.

2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w-C: \ Program Files \ LSoft Technologie
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w-C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-c - aw-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw-c: \ windows \ system32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w-C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w-C: \ Hry
2009-06-10 20:13. 2009-05-07 15:32 345600-c ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-c ---- w-c: \ windows \ system32 \ dllcache \ Rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Zpráva )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 23:25. 2008-05-16 03:35 -------- d ----- w-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab
2009-06-24 21:26. 2008-05-16 03:35 761888 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.dat
2009-06-24 21:26. 2008-05-16 03:35 64388 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.idx
2009-06-24 21:26. 2008-05-16 03:35 4571424 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.dat
2009-06-24 21:26. 2008-05-16 03:35 29696 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.idx
2009-06-24 21:09. 2008-05-17 00:25 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w-C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w-C: \ Program Files \ Pando Sítě
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w-C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw-c: \ windows \ system32 \ drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw-c: \ windows \ system32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w-C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w-C: \ Program Files \ Common Files \ Apple
2009-05-20 16:16. 2008-05-16 03:36 94643 ---- aw-c: \ windows \ system32 \ drivers \ klick.dat
2009-05-20 16:16. 2008-05-16 03:36 105395 ---- aw-c: \ windows \ system32 \ drivers \ klin.dat
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w-C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w-C: \ Program Files \ InstallShield Informace o instalaci
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w-C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw-c: \ windows \ system32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw-c: \ windows \ system32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w-c: \ windows \ system32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w-C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ neděli \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-26 01:13. 2009-04-26 00:43 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ Přesun Sítě
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw-c: \ windows \ system32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw-c: \ windows \ system32 \ Rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw-c: \ Documents and Settings \ Mouse \ Local Settings \ Data aplikací \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw-c: \ windows \ system32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg. Načítám Body )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Poznámka * prázdné záznamy & důvěryhodně výchozí údaje nejsou zobrazeny
REGEDIT4

[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Program Ctfmon.exe" = "c: \ windows \ system32 \ Program Ctfmon.exe" [2008-04-14 15360]
"H / PC připojení Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "c: \ windows \ system32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Svazek Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "c: \ windows \ system32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Úkol" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - c: \ windows \ system32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - c: \ windows \ system32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ oznámit \! SASWinLogon]
2009-01-01 04:29 356352----- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ safeboot \ Minimální \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Adobe Gamma Loader.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = c: \ windows \ PSS \ Adobe Gamma Loader.lnkCommon Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ HOTSYNCSHORTCUTNAME.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = c: \ windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Microsoft Office.lnk]
path = c: \ Documents and Settings \ All Users \ Nabídka Start \ Programy \ Po spuštění \ Microsoft Office.lnk
backup = c: \ windows \ PSS \ Microsoft Office.lnkCommon Spuštění

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ sdílené tools \ msconfig \ services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp Plánovac 3" = 2 (0x2)
"MDM" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center \ Sledování \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ system32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh sítě \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Data aplikací \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ English \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Povoleno: Aplikace ActiveSync
"% windir% \ \ Network Diagnostické \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Telefon \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Service
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Zavádecí stráže Driver; c: \ windows \ system32 \ drivers \ klbg.sys [1/29/2008 6:29 AM 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 AM 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 AM 55024]
R1 UGURU; UGURU, c: \ windows \ system32 \ drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, c: \ windows \ system32 \ drivers \ klfltdev.sys [3/13/2008 7:02 AM 26640]
R3 klim5, Kaspersky Anti-Virus NDIS filtr, c: \ windows \ system32 \ drivers \ klim5.sys [12/13/2007 1:28 PM 24592]
S2 Cubase32; Cubase32, c: \ windows \ system32 \ drivers \ Kuba se32.sys [4/5/2009 7:02 PM 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 AM 4096]

--- Ostatní služby / Řidiči v paměti ---

* * NewlyCreated - SASDIFSV
.
Obsah této 'Naplánované úlohy' složce

2009-06-13 C: \ Windows \ Úkoly \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009-06-24 C: \ Windows \ Úkoly \ Malwarebytes' Anti-Malware.job
- C: \ progra ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
- - - - SIROTKY ODSTRANĚNY - - - --

Safeboot-AVG Anti-Spyware Driver
Safeboot-AVG Anti-Spyware stráže


.
------- Doplňkový Scan -------
.
uStart Page = hxxp: / / google.com /
IE: Přidat do Banner ad Blocker - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportovat do aplikace Microsoft Excel - c: \ progra ~ 1 \ miliontin ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: Microsoft XML Parser Java - file: / / c: \ windows \ Java \ Classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

catchme 0.3.1398 W2K/XP/Vista - rootkit / stealth malware detektor by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 19:25
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek autostart ...

skenování skrytých souborů ...

scan úspěšně dokončena
skryté soubory: 0

************************************************** ************************
.
--------------------- Kryté klíčů registru ---------------------

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, E8, e1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, d1,
34, d2, D9, c8, 28,51, af, b0, 29, a3, 98, a9, c3, A8, 8a, 5e, d3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, c2, c2, DC, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8, 42, 2f, c4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, dfk, 4f, 25,
c2, 62,83,25, da, ec, 7e, 55,20, C9, 26, a3, f2, 65, ed, 80,3 e, e4, f6, ff, 7c, 85, E0, 43, d4, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, E0, 57,5 a, 93,61, f2, a1, b4, 61,82,
bb, ab, d5, 3e, 1e, 9e, E0, 57,5 a, 93,61,6 f, 0e, 5c, ae, ec, 4f, e7, 8d, 86,8 c, 21,01, třeba, 91, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, B9, a6, 33,6 c, cd, 91, d7, 7a, 29,97,
C7, 40,4 b, cd, 44, cd, B9, a6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4f, 73, A8, 13, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: dfk, 20,58,62, 78,6 b, cf, c8, 7e, 4a, d5, 24,8 d,
3a, 49, c4, b0, 18, ed, A7, 3f, 8f, 37, a4, 29, b5, 53,9 a, d3, 4a, 02,51, dfk, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, ba, b1, f8, 68,02,09, d4, 0B, f3, 53,
bc, 62,26,31,77, e1, ba, b1, f8, 68,02,77, c3, de, C6, 98,79, 54,2 c, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 a, 48, fc, E8, 04,4 a, f1, DF, 00, d5, 43, ff,
f8, 0f, f3, 83,6 c, 56,8 b, A0, 85,96, ab, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, E8, 04, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, ea, f8, c4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, C6, F6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3d, ce, ea, 26, 2d, 45, aa, 78,0 b, ba, 41,78,8 a,
C9, 90,04, b1, cd, 45,5 a, A8, c4, f8, B9, 6b, C6, a2, 44,8 d, 59, a6, F5, 3d, ce, ea, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, b7, cc, B5, B9, 7f, 41, e7, 5d, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, d5, eb, bc, 2f, 6b, e1, 69,31, ac, dd, ba, 7f, 02,2 a, b7, cc, B5, B9, 7f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, ea, 66,7 f, d4, 3b, 6b, 70, a5, 97,0 a, 6e, 8a,
cf, 52,73, fa, ea, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7b, 08,64,6 c, 43,2 d, 1e, aa, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ h-€ | "rrrr" ¤ • € | U • A ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLL Nabito pod tekoucí procesy ---------------------

- - - - - - -> 'Winlogon.exe' (1028)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ windows \ system32 \ klogon.dll

- - - - - - -> 'Explorer.exe' (3748)
c: \ windows \ system32 \ WPDShServiceObj.dll
c: \ windows \ system32 \ PortableDeviceTypes.dll
c: \ windows \ system32 \ PortableDeviceApi.dll
.
------------------------ Jiné spuštěných procesů ----------------------- --
.
C: \ Program Files \ Creative \ Sdílené Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ windows \ system32 \ nvsvc32.exe
c: \ windows \ system32 \ PnkBstrA.exe
c: \ windows \ system32 \ rundll32.exe
c: \ progra ~ 1 \ miliontin ~ 4 \ rapimgr.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Zábava Center \ EAXLoadr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ windows \ system32 \ wscntfy.exe
c: \ windows \ system32 \ CTxfispi.exe
.
************************************************** ************************
.
Dokončení čas: 2009-06-24 19:29 - stroj byl restartován
ComboFix-karantény-files.txt 2009-06-24 23:29
ComboFix2.txt 2008-05-20 17:05

Pre-Spustit: 65511231488 bytes zdarma
Post-Spustit: 67799437312 bytes zdarma

WindowsXP-KB310994-SP2-Pro-bootdisk-CSY.exe
[boot loader]
timeout = 2
default = multi (0) disk (0) rdisk (1) partition (1) \ OKNO S
[operating systems]
c: \ cmdcons \ BOOTSECT.DAT = "Microsoft Windows konzolu pro zotavení" / cmdcons
multi (0) disk (0) rdisk (1) partition (1) \ WINDOWS = "Micro soft Windows XP Professional" / noexecute = OptIn / fastdetect
multi (0) disk (0) rdisk (0) partition (1) \ WINDOWS = "Micro soft Windows XP Professional" / fastdetect / noexecute = OptIn

Aktuální = 3 Default = 3 Nepodařilo = 1 LastKnownGood = 4 sad = 1,2,3,4
335 --- EOF --- 2009-06-11 03:03
  #7  
Old 25. června 2009, 09:58
Moderátor skupiny
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Odstranit tyto soubory / adresáře, takto:

1. Přejít na Začít > Běžet > Typ Notepad.exe a klikněte OK otevřete Poznámkový blok.
To muset třeba Poznámkový blok, WordPad není.
2. Zkopírujte text v níže kód do kolonky zvýraznění celý text a stisknutím Ctrl + C

Kód:
Killall:: RegLock:: [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C - D8D3582C741C) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98 - D0152D08C8B9) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B - 3E52D94DB145) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B - 37E957082D6D) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073 - C02FF9619B6F) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D - 1411304BCD84) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ h-€ | "rrrr" ¤ • € | U • A ~ *]
3. Jdi do okna Poznámkového bloku a klikněte Upravit > Vložit
4. Potom klikněte na Soubor > Uložit
5. Název souboru CFScript.txt - Uložte soubor do počítače
6. Poté přesuneme CFScript (držte levé tlačítko myši a zároveň přetažením souboru) a pusť ji (uvolněte levé tlačítko myši) do ComboFix.exe, jak vidíte na obrázku níže. Důležité upozornění: Provede instrukce pozorně!



ComboFix začne provádět, stačí sledovat pokyny.
Po restartu (v případě, že požádá o restart systému), bude produkovat záznam pro vás.
Posta, že log (Combofix.txt) ve své příští odpověď.

Poznámka: Don't mouseclick ComboFix okna, pokud je v chodu. To může způsobit váš systém zmrazit

----------

Také dejte mi vědět, jak počítač běží nyní.

.
__________________

  #8  
Old 25. června 2009, 16:17
Člen Skupina
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Myš 06/25/2009 19:04.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1597 [GMT -4:00]
Spuštění z: c: \ Documents and Settings \ Mouse \ Desktop \ ComboFix.exe
Command přepínačů používá:: c: \ Documents and Settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-skenování přístup zdravotně postižených * (Aktualizováno) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security postižené * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

((((((((((((((((((((((((((((((((((((((( Ostatní Vymazání ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

c: \ windows \ system32 \ drivers \ kl1.sys

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-25 do 2009-06-25 ))))))))))) ))))))))))))))))))))
.

2009-06-24 23:28. 2009-06-24 23:28 -------- dc ---- w-c: \ windows \ system32 \ dllcache \ cache
2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w-C: \ Program Files \ LSoft Technologie
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w-C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-c - aw-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw-c: \ windows \ system32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w-C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w-C: \ Hry
2009-06-10 20:13. 2009-05-07 15:32 345600-c ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-c ---- w-c: \ windows \ system32 \ dllcache \ Rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Zpráva )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 23:11. 2008-05-16 03:35 -------- d ----- w-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab
2009-06-25 23:09. 2008-05-16 03:35 761888 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.dat
2009-06-25 23:09. 2008-05-16 03:35 64388 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.idx
2009-06-25 23:09. 2008-05-16 03:35 4571424 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.dat
2009-06-25 23:09. 2008-05-16 03:35 29696 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.idx
2009-06-24 23:59. 2008-01-29 22:29 33808 ---- aw-c: \ windows \ system32 \ drivers \ klbg.sys
2009-06-24 23:59. 2009-02-05 00:58 33808 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ klbg.sys
2009-06-24 23:59. 2008-05-16 03:36 94643 ---- aw-c: \ windows \ system32 \ drivers \ klick.dat
2009-06-24 23:59. 2008-05-16 03:36 105395 ---- aw-c: \ windows \ system32 \ drivers \ klin.dat
2009-06-24 23:59. 2008-07-17 23:08 213520 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ XP \ klif.sys
2009-06-24 23:59. 2008-07-17 23:08 861448 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ updater.dll
2009-06-24 21:09. 2008-05-17 00:25 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w-C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w-C: \ Program Files \ Pando Sítě
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w-C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw-c: \ windows \ system32 \ drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw-c: \ windows \ system32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w-C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w-C: \ Program Files \ Common Files \ Apple
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w-C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w-C: \ Program Files \ InstallShield Informace o instalaci
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w-C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw-c: \ windows \ system32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw-c: \ windows \ system32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w-c: \ windows \ system32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w-C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ neděli \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw-c: \ windows \ system32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw-c: \ windows \ system32 \ Rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw-c: \ Documents and Settings \ Mouse \ Local Settings \ Data aplikací \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw-c: \ windows \ system32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-24_23.25.37 )))))))))))) )))))))))))))))))))))))))))))
.
+ 2008-03-26 00:07. 2008-03-26 00:07 24592 c: \ windows \ system32 \ drivers \ klim5.sys
- 2007-12-13 17:28. 2008-03-26 00:07 24592 c: \ windows \ system32 \ drivers \ klim5.sys
+ 2009-06-24 23:28. 2008-10-16 19:09 51224 c: \ windows \ system32 \ dllcache \ cache \ wuauclt.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 82432 c: \ windows \ system32 \ dllcache \ cache \ ws2_32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 26112 c: \ windows \ system32 \ dllcache \ cache \ userinit.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 14336 c: \ windows \ system32 \ dllcache \ cache \ svchost.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 57856 c: \ windows \ system32 \ dllcache \ cache \ spoolsv.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 17408 c: \ windows \ system32 \ dllcache \ cache \ powrprof.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 13312 c: \ windows \ system32 \ dllcache \ cache \ lsass.exe
+ 2009-06-24 23:28. 2008-04-13 18:39 24576 c: \ windows \ system32 \ dllcache \ cache \ Kbdclass.sys
+ 2009-06-24 23:28. 2008-04-13 18:53 36608 c: \ windows \ system32 \ dllcache \ cache \ ip6fw.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 15360 c: \ windows \ system32 \ dllcache \ cache \ Program Ctfmon.exe
- 2008-04-18 17:53. 2009-02-05 00:58 213520 C: \ windows \ system32 \ drivers \ klif.sys
+ 2008-04-18 17:53. 2009-06-24 23:59 213520 C: \ windows \ system32 \ drivers \ klif.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 507904 C: \ windows \ system32 \ dllcache \ cache \ winlogon.exe
+ 2009-06-24 23:28. 2009-04-29 04:46 666624 C: \ windows \ system32 \ dllcache \ cache \ Wininet.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 578560 C: \ windows \ system32 \ dllcache \ cache \ user32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 295424 C: \ windows \ system32 \ dllcache \ cache \ termsrv.dll
+ 2009-06-24 23:28. 2008-06-20 11:51 361600 C: \ windows \ system32 \ dllcache \ cache \ Tcpip.sys
+ 2009-06-24 23:28. 2009-02-06 11:11 110592 C: \ windows \ system32 \ dllcache \ cache \ SERVICES.EXE
+ 2009-06-24 23:28. 2008-04-13 19:20 182656 C: \ windows \ system32 \ dllcache \ cache \ ndis.sys
+ 2009-06-24 23:28. 2009-03-21 14:06 989696 C: \ windows \ system32 \ dllcache \ cache \ kernel32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 110080 C: \ windows \ system32 \ dllcache \ cache \ imm32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 167936 C: \ windows \ system32 \ dllcache \ cache \ appmgmts.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 1614848 C: \ windows \ system32 \ dllcache \ cache \ sfcfiles.dll
+ 2009-06-24 23:28. 2009-02-06 11:06 2145280 C: \ windows \ system32 \ dllcache \ cache \ ntoskrnl.exe
+ 2009-06-24 23:28. 2009-02-06 10:32 2023936 C: \ windows \ system32 \ dllcache \ cache \ ntkrnlpa.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 1033728 C: \ windows \ system32 \ dllcache \ cache \ explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg. Načítám Body )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Poznámka * prázdné záznamy & důvěryhodně výchozí údaje nejsou zobrazeny
REGEDIT4

[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Program Ctfmon.exe" = "c: \ windows \ system32 \ Program Ctfmon.exe" [2008-04-14 15360]
"H / PC připojení Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "c: \ windows \ system32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Svazek Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "c: \ windows \ system32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Úkol" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - c: \ windows \ system32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - c: \ windows \ system32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ oznámit \! SASWinLogon]
2009-01-01 04:29 356352----- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ safeboot \ Minimální \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Adobe Gamma Loader.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = c: \ windows \ PSS \ Adobe Gamma Loader.lnkCommon Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ HOTSYNCSHORTCUTNAME.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = c: \ windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Microsoft Office.lnk]
path = c: \ Documents and Settings \ All Users \ Nabídka Start \ Programy \ Po spuštění \ Microsoft Office.lnk
backup = c: \ windows \ PSS \ Microsoft Office.lnkCommon Spuštění

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ sdílené tools \ msconfig \ services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp Plánovac 3" = 2 (0x2)
"MDM" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center \ Sledování \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ system32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh sítě \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Data aplikací \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ English \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Povoleno: Aplikace ActiveSync
"% windir% \ \ Network Diagnostické \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Telefon \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Service
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Zavádecí stráže Driver; c: \ windows \ system32 \ drivers \ klbg.sys [1/29/2008 6:29 AM 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 AM 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 AM 55024]
R1 UGURU; UGURU, c: \ windows \ system32 \ drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, c: \ windows \ system32 \ drivers \ klfltdev.sys [3/13/2008 7:02 AM 26640]
R3 klim5, Kaspersky Anti-Virus NDIS filtr, c: \ windows \ system32 \ drivers \ klim5.sys [3/25/2008 8:07 AM 24592]
S2 Cubase32; Cubase32, c: \ windows \ system32 \ drivers \ Kuba se32.sys [4/5/2009 7:02 PM 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 AM 4096]
.
Obsah této 'Naplánované úlohy' složce

2009-06-13 C: \ Windows \ Úkoly \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009-06-25 C: \ Windows \ Úkoly \ Malwarebytes' Anti-Malware.job
- C: \ progra ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
.
------- Doplňkový Scan -------
.
uStart Page = hxxp: / / google.com /
IE: Přidat do Banner ad Blocker - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportovat do aplikace Microsoft Excel - c: \ progra ~ 1 \ miliontin ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: Microsoft XML Parser Java - file: / / c: \ windows \ Java \ Classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

catchme 0.3.1398 W2K/XP/Vista - rootkit / stealth malware detektor by Gmer, http://www.gmer.net
Rootkit scan 2009-06-25 19:11
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek autostart ...

skenování skrytých souborů ...

scan úspěšně dokončena
skryté soubory: 0

************************************************** ************************
.
--------------------- Kryté klíčů registru ---------------------

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, E8, e1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, d1,
34, d2, D9, c8, 28,51, af, b0, 29, a3, 98, a9, c3, A8, 8a, 5e, d3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, c2, c2, DC, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8, 42, 2f, c4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, dfk, 4f, 25,
c2, 62,83,25, da, ec, 7e, 55,20, C9, 26, a3, f2, 65, ed, 80,3 e, e4, f6, ff, 7c, 85, E0, 43, d4, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, E0, 57,5 a, 93,61, f2, a1, b4, 61,82,
bb, ab, d5, 3e, 1e, 9e, E0, 57,5 a, 93,61,6 f, 0e, 5c, ae, ec, 4f, e7, 8d, 86,8 c, 21,01, třeba, 91, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, B9, a6, 33,6 c, cd, 91, d7, 7a, 29,97,
C7, 40,4 b, cd, 44, cd, B9, a6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4f, 73, A8, 13, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: dfk, 20,58,62, 78,6 b, cf, c8, 7e, 4a, d5, 24,8 d,
3a, 49, c4, b0, 18, ed, A7, 3f, 8f, 37, a4, 29, b5, 53,9 a, d3, 4a, 02,51, dfk, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, ba, b1, f8, 68,02,09, d4, 0B, f3, 53,
bc, 62,26,31,77, e1, ba, b1, f8, 68,02,77, c3, de, C6, 98,79, 54,2 c, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 a, 48, fc, E8, 04,4 a, f1, DF, 00, d5, 43, ff,
f8, 0f, f3, 83,6 c, 56,8 b, A0, 85,96, ab, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, E8, 04, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, ea, f8, c4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, C6, F6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3d, ce, ea, 26, 2d, 45, aa, 78,0 b, ba, 41,78,8 a,
C9, 90,04, b1, cd, 45,5 a, A8, c4, f8, B9, 6b, C6, a2, 44,8 d, 59, a6, F5, 3d, ce, ea, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, b7, cc, B5, B9, 7f, 41, e7, 5d, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, d5, eb, bc, 2f, 6b, e1, 69,31, ac, dd, ba, 7f, 02,2 a, b7, cc, B5, B9, 7f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, ea, 66,7 f, d4, 3b, 6b, 70, a5, 97,0 a, 6e, 8a,
cf, 52,73, fa, ea, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7b, 08,64,6 c, 43,2 d, 1e, aa, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ h-€ | "rrrr" ¤ • € | U • A ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLL Nabito pod tekoucí procesy ---------------------

- - - - - - -> 'Winlogon.exe' (1028)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ windows \ system32 \ klogon.dll

- - - - - - -> 'Explorer.exe' (212)
c: \ windows \ system32 \ WPDShServiceObj.dll
c: \ windows \ system32 \ PortableDeviceTypes.dll
c: \ windows \ system32 \ PortableDeviceApi.dll
.
------------------------ Jiné spuštěných procesů ----------------------- --
.
C: \ Program Files \ Creative \ Sdílené Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ windows \ system32 \ nvsvc32.exe
c: \ windows \ system32 \ PnkBstrA.exe
c: \ windows \ system32 \ rundll32.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Zábava Center \ EAXLoadr.exe
c: \ progra ~ 1 \ miliontin ~ 4 \ rapimgr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ windows \ system32 \ CTxfispi.exe
c: \ windows \ system32 \ wscntfy.exe
.
************************************************** ************************
.
Dokončení čas: 2009-06-25 19:14 - stroj byl restartován
ComboFix-karantény-files.txt 2009-06-25 23:14
ComboFix2.txt 2009-06-24 23:29
ComboFix3.txt 2008-05-20 17:05

Pre-Spustit: 67819319296 bytes zdarma
Post-Spustit: 67883995136 bytes zdarma

Aktuální = 3 Default = 3 Nepodařilo = 1 LastKnownGood = 4 sad = 1,2,3,4
310 --- EOF --- 2009-06-11 03:03
  #9  
Old 25. června 2009, 18:13
Moderátor skupiny
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

Promiň, že jsem něco přehlížet.

Odstranit tyto soubory / adresáře, takto:

1. Přejít na Začít > Běžet > Typ Notepad.exe a klikněte OK otevřete Poznámkový blok.
To muset třeba Poznámkový blok, WordPad není.
2. Zkopírujte text v níže kód do kolonky zvýraznění celý text a stisknutím Ctrl + C

Kód:
Killall:: RegLock:: [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (47629D4B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (604BB98A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (684373FB-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (74554CCD-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (7EB537F9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (948395E8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (DE5654CA-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (EACAFCE5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ software \ Classes \ CLSID \ (F8F02ADD-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (FEE45DE2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Installer \ UserData \ LocalSystem \ Components \ h-€ | "rrrr" ¤ • € | U • A ~ *]
3. Jdi do okna Poznámkového bloku a klikněte Upravit > Vložit
4. Potom klikněte na Soubor > Uložit
5. Název souboru CFScript.txt - Uložte soubor do počítače
6. Poté přesuneme CFScript (držte levé tlačítko myši a zároveň přetažením souboru) a pusť ji (uvolněte levé tlačítko myši) do ComboFix.exe, jak vidíte na obrázku níže. Důležité upozornění: Provede instrukce pozorně!



ComboFix začne provádět, stačí sledovat pokyny.
Po restartu (v případě, že požádá o restart systému), bude produkovat záznam pro vás.
Posta, že log (Combofix.txt) ve své příští odpověď.

Poznámka: Don't mouseclick ComboFix okna, pokud je v chodu. To může způsobit váš systém zmrazit

----------

Také dejte mi vědět, jak počítač běží nyní.

.
__________________

  #10  
Old 26. června 2009, 00:59
Člen Skupina
 
Default Nakaženi MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Myš 06/26/2009 3:47.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1564 [GMT -4:00]
Spuštění z: c: \ Documents and Settings \ Mouse \ Desktop \ ComboFix.exe
Command přepínačů používá:: c: \ Documents and Settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-skenování přístup zdravotně postižených * (Aktualizováno) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security postižené * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

((((((((((((((((((((((((((((((((((((((( Ostatní Vymazání ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

c: \ windows \ system32 \ drivers \ kl1.sys

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-26 do 2009-06-26 ))))))))))) ))))))))))))))))))))
.

2009-06-24 23:28. 2009-06-24 23:28 -------- dc ---- w-c: \ windows \ system32 \ dllcache \ cache
2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w-C: \ Program Files \ LSoft Technologie
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w-C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w-C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-c - aw-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw-c: \ windows \ system32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w-C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w-C: \ Hry
2009-06-10 20:13. 2009-05-07 15:32 345600-c ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-c ---- w-c: \ windows \ system32 \ dllcache \ Rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Zpráva )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 07:54. 2008-05-16 03:35 -------- d ----- w-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab
2009-06-26 07:52. 2008-05-16 03:35 761888 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.dat
2009-06-26 07:52. 2008-05-16 03:35 64388 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.idx
2009-06-26 07:52. 2008-05-16 03:35 4571424 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox.dat
2009-06-26 07:52. 2008-05-16 03:35 29696 - SHA-w-c: \ windows \ system32 \ drivers \ fidbox2.idx
2009-06-25 23:24. 2008-01-29 22:29 33808 ---- aw-c: \ windows \ system32 \ drivers \ klbg.sys
2009-06-25 23:24. 2008-05-16 03:36 94643 ---- aw-c: \ windows \ system32 \ drivers \ klick.dat
2009-06-25 23:24. 2008-05-16 03:36 105395 ---- aw-c: \ windows \ system32 \ drivers \ klin.dat
2009-06-25 23:24. 2009-02-05 00:58 33808 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ klbg.sys
2009-06-25 23:24. 2008-07-17 23:08 213520 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ XP \ klif.sys
2009-06-25 23:24. 2008-07-17 23:08 861448 ---- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Dočasný Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ updater.dll
2009-06-24 21:09. 2008-05-17 00:25 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w-C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w-C: \ Program Files \ Pando Sítě
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w-C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw-c: \ windows \ system32 \ drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw-c: \ windows \ system32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w-C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw-c: \ Documents and Settings \ All Users \ Data aplikací \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 -------- d ----- w-c: \ Documents and Settings \ Mouse \ Data aplikací \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w-C: \ Program Files \ Common Files \ Apple
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w-C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w-C: \ Program Files \ InstallShield Informace o instalaci
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w-C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw-c: \ windows \ system32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw-c: \ windows \ system32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w-c: \ windows \ system32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w-C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw-c: \ Documents and Settings \ Mouse \ Data aplikací \ neděli \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw-c: \ windows \ system32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw-c: \ windows \ system32 \ Rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ Documents and Settings \ Mouse \ Data aplikací \ Microsoft \ Installer \ (B5F7ED63-4BE6-E4D5-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw-c: \ Documents and Settings \ Mouse \ Local Settings \ Data aplikací \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw-c: \ windows \ system32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-24_23.25.37 )))))))))))) )))))))))))))))))))))))))))))
.
+ 2008-03-26 00:07. 2008-03-26 00:07 24592 c: \ windows \ system32 \ drivers \ klim5.sys
- 2007-12-13 17:28. 2008-03-26 00:07 24592 c: \ windows \ system32 \ drivers \ klim5.sys
+ 2009-06-24 23:28. 2008-10-16 19:09 51224 c: \ windows \ system32 \ dllcache \ cache \ wuauclt.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 82432 c: \ windows \ system32 \ dllcache \ cache \ ws2_32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 26112 c: \ windows \ system32 \ dllcache \ cache \ userinit.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 14336 c: \ windows \ system32 \ dllcache \ cache \ svchost.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 57856 c: \ windows \ system32 \ dllcache \ cache \ spoolsv.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 17408 c: \ windows \ system32 \ dllcache \ cache \ powrprof.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 13312 c: \ windows \ system32 \ dllcache \ cache \ lsass.exe
+ 2009-06-24 23:28. 2008-04-13 18:39 24576 c: \ windows \ system32 \ dllcache \ cache \ Kbdclass.sys
+ 2009-06-24 23:28. 2008-04-13 18:53 36608 c: \ windows \ system32 \ dllcache \ cache \ ip6fw.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 15360 c: \ windows \ system32 \ dllcache \ cache \ Program Ctfmon.exe
- 2008-04-18 17:53. 2009-02-05 00:58 213520 C: \ windows \ system32 \ drivers \ klif.sys
+ 2008-04-18 17:53. 2009-06-25 23:24 213520 C: \ windows \ system32 \ drivers \ klif.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 507904 C: \ windows \ system32 \ dllcache \ cache \ winlogon.exe
+ 2009-06-24 23:28. 2009-04-29 04:46 666624 C: \ windows \ system32 \ dllcache \ cache \ Wininet.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 578560 C: \ windows \ system32 \ dllcache \ cache \ user32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 295424 C: \ windows \ system32 \ dllcache \ cache \ termsrv.dll
+ 2009-06-24 23:28. 2008-06-20 11:51 361600 C: \ windows \ system32 \ dllcache \ cache \ Tcpip.sys
+ 2009-06-24 23:28. 2009-02-06 11:11 110592 C: \ windows \ system32 \ dllcache \ cache \ SERVICES.EXE
+ 2009-06-24 23:28. 2008-04-13 19:20 182656 C: \ windows \ system32 \ dllcache \ cache \ ndis.sys
+ 2009-06-24 23:28. 2009-03-21 14:06 989696 C: \ windows \ system32 \ dllcache \ cache \ kernel32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 110080 C: \ windows \ system32 \ dllcache \ cache \ imm32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 167936 C: \ windows \ system32 \ dllcache \ cache \ appmgmts.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 1614848 C: \ windows \ system32 \ dllcache \ cache \ sfcfiles.dll
+ 2009-06-24 23:28. 2009-02-06 11:06 2145280 C: \ windows \ system32 \ dllcache \ cache \ ntoskrnl.exe
+ 2009-06-24 23:28. 2009-02-06 10:32 2023936 C: \ windows \ system32 \ dllcache \ cache \ ntkrnlpa.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 1033728 C: \ windows \ system32 \ dllcache \ cache \ explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg. Načítám Body )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Poznámka * prázdné záznamy & důvěryhodně výchozí údaje nejsou zobrazeny
REGEDIT4

[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Program Ctfmon.exe" = "c: \ windows \ system32 \ Program Ctfmon.exe" [2008-04-14 15360]
"H / PC připojení Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "c: \ windows \ system32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Sdílené Files \ Modul Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Svazek Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "c: \ windows \ system32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Úkol" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - c: \ windows \ system32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - c: \ windows \ system32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ oznámit \! SASWinLogon]
2009-01-01 04:29 356352----- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ safeboot \ Minimální \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Adobe Gamma Loader.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = c: \ windows \ PSS \ Adobe Gamma Loader.lnkCommon Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ HOTSYNCSHORTCUTNAME.lnk]
path = c: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = c: \ windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Spuštění

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Nabídka Start ^ Programy ^ Po spuštění ^ Microsoft Office.lnk]
path = c: \ Documents and Settings \ All Users \ Nabídka Start \ Programy \ Po spuštění \ Microsoft Office.lnk
backup = c: \ windows \ PSS \ Microsoft Office.lnkCommon Spuštění

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ sdílené tools \ msconfig \ services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp Plánovac 3" = 2 (0x2)
"MDM" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ security center \ Sledování \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ system32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh sítě \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin Creed je \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Data aplikací \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ English \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Povoleno: Aplikace ActiveSync
"% windir% \ \ Network Diagnostické \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Telefon \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ services \ sharedaccess \ Parameters \ firewallpo antonny \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Povoleno: ActiveSync Service
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Zavádecí stráže Driver; c: \ windows \ system32 \ drivers \ klbg.sys [1/29/2008 6:29 AM 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 AM 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 AM 55024]
R1 UGURU; UGURU, c: \ windows \ system32 \ drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, c: \ windows \ system32 \ drivers \ klfltdev.sys [3/13/2008 7:02 AM 26640]
R3 klim5, Kaspersky Anti-Virus NDIS filtr, c: \ windows \ system32 \ drivers \ klim5.sys [3/25/2008 8:07 AM 24592]
S2 Cubase32; Cubase32, c: \ windows \ system32 \ drivers \ Kuba se32.sys [4/5/2009 7:02 PM 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 AM 4096]
.
Obsah této 'Naplánované úlohy' složce

2009-06-13 C: \ Windows \ Úkoly \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009-06-26 C: \ Windows \ Úkoly \ Malwarebytes' Anti-Malware.job
- C: \ progra ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
.
------- Doplňkový Scan -------
.
uStart Page = hxxp: / / google.com /
IE: Přidat do Banner ad Blocker - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportovat do aplikace Microsoft Excel - c: \ progra ~ 1 \ miliontin ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: Microsoft XML Parser Java - file: / / c: \ windows \ Java \ Classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

catchme 0.3.1398 W2K/XP/Vista - rootkit / stealth malware detektor by Gmer, http://www.gmer.net
Rootkit scan 2009-06-26 03:54
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek autostart ...

skenování skrytých souborů ...

scan úspěšně dokončena
skryté soubory: 0

************************************************** ************************
.
--------------------- Kryté klíčů registru ---------------------

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, E8, e1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, d1,
34, d2, D9, c8, 28,51, af, b0, 29, a3, 98, a9, c3, A8, 8a, 5e, d3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, c2, c2, DC, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8, 42, 2f, c4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, dfk, 4f, 25,
c2, 62,83,25, da, ec, 7e, 55,20, C9, 26, a3, f2, 65, ed, 80,3 e, e4, f6, ff, 7c, 85, E0, 43, d4, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, E0, 57,5 a, 93,61, f2, a1, b4, 61,82,
bb, ab, d5, 3e, 1e, 9e, E0, 57,5 a, 93,61,6 f, 0e, 5c, ae, ec, 4f, e7, 8d, 86,8 c, 21,01, třeba, 91, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, B9, a6, 33,6 c, cd, 91, d7, 7a, 29,97,
C7, 40,4 b, cd, 44, cd, B9, a6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4f, 73, A8, 13, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: dfk, 20,58,62, 78,6 b, cf, c8, 7e, 4a, d5, 24,8 d,
3a, 49, c4, b0, 18, ed, A7, 3f, 8f, 37, a4, 29, b5, 53,9 a, d3, 4a, 02,51, dfk, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, ba, b1, f8, 68,02,09, d4, 0B, f3, 53,
bc, 62,26,31,77, e1, ba, b1, f8, 68,02,77, c3, de, C6, 98,79, 54,2 c, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 a, 48, fc, E8, 04,4 a, f1, DF, 00, d5, 43, ff,
f8, 0f, f3, 83,6 c, 56,8 b, A0, 85,96, ab, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, E8, 04, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, ea, f8, c4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, C6, F6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3d, ce, ea, 26, 2d, 45, aa, 78,0 b, ba, 41,78,8 a,
C9, 90,04, b1, cd, 45,5 a, A8, c4, f8, B9, 6b, C6, a2, 44,8 d, 59, a6, F5, 3d, ce, ea, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, b7, cc, B5, B9, 7f, 41, e7, 5d, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, d5, eb, bc, 2f, 6b, e1, 69,31, ac, dd, ba, 7f, 02,2 a, b7, cc, B5, B9, 7f, \

[HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartment"
@ = "c: \ \ WINDOWS \ \ system32 \ \ Ole32.dll"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, ea, 66,7 f, d4, 3b, 6b, 70, a5, 97,0 a, 6e, 8a,
cf, 52,73, fa, ea, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7b, 08,64,6 c, 43,2 d, 1e, aa, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ h-€ | "rrrr" ¤ • € | U • A ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLL Nabito pod tekoucí procesy ---------------------

- - - - - - -> 'Winlogon.exe' (672)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ windows \ system32 \ klogon.dll

- - - - - - -> 'Explorer.exe' (288)
c: \ windows \ system32 \ WPDShServiceObj.dll
c: \ windows \ system32 \ PortableDeviceTypes.dll
c: \ windows \ system32 \ PortableDeviceApi.dll
.
------------------------ Jiné spuštěných procesů ----------------------- --
.
C: \ Program Files \ Creative \ Sdílené Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ windows \ system32 \ nvsvc32.exe
c: \ windows \ system32 \ PnkBstrA.exe
c: \ windows \ system32 \ rundll32.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Zábava Center \ EAXLoadr.exe
c: \ progra ~ 1 \ miliontin ~ 4 \ rapimgr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ windows \ system32 \ wscntfy.exe
c: \ windows \ system32 \ CTxfispi.exe
.
************************************************** ************************
.
Dokončení čas: 2009-06-26 3:57 - stroj byl restartován
ComboFix-karantény-files.txt 2009-06-26 07:57
ComboFix2.txt 2009-06-25 23:14
ComboFix3.txt 2009-06-24 23:29
ComboFix4.txt 2008-05-20 17:05

Pre-Spustit: 67824807936 bytes zdarma
Post-Spustit: 67888648192 bytes zdarma

Aktuální = 3 Default = 3 Nepodařilo = 1 LastKnownGood = 4 sad = 1,2,3,4
311 --- EOF --- 2009-06-11 03:03
Reply

Register

Záložky

Podobná témata
Nitka Thread Začátečnickou Fórum Odpovědi Poslední příspěvek
Problém s trojským koněm Downloader Generic 9 OGB Virus, spyware a bezpečnost 7 21.listopadu 2009 13:06
Multi Desktop aplikací? Haun Obecné Software Chat 6 31. března 2009 01:30
HEUR Trojan Generic kathymer Virus, spyware a bezpečnost 10 29. listopad 2008 12:58
Nakaženi Heur.trojan.generic Prosím Nápověda ruffryder2k7 Virus, spyware a bezpečnost 17 6. listopadu 2008 10:39
Jste schopni synch generikem mp3 přehrávač [není iPod] s iTunes? reyrey_angulo Zvuk, Reproduktory & MP3 přehrávače 1 18. března 2007 15:39
Thread Nástroje




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Počítačová Juice.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO by vBSEO © 2009, Crawlability, Inc