Projel jsem to programem MWAV a ten napsal: 1.
Potom jsem dal Combofix a log je tady: 2.
Je tam ještě něco? (případně co s tím?
Díky moc
1.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svcd\svchost.exe je infikovaný virem Trojan-Proxy.Win32.Fackemo.g !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\alt.exe.exe je infikovaný virem Trojan.Win32.Agent.dvv !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\alt.exe.exe je infikovaný virem Trojan.Win32.Agent.dvv !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\System32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\System32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\system32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
Soubor C:\WINDOWS\System32\svchost.exe:ext.exe je infikovaný virem Trojan.Win32.Agent.dur !! Provedené akce: Nic nebylo provedeno.
2.
ComboFix 08-01-09.2 - david 2008-01-13 15:15:14.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1628 [GMT 1:00]
Running from: C:\Documents and Settings\david\Plocha\ComboFix.exe
.
ADS - svchost.exe: deleted 25600 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1.tmp
C:\7.tmp
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\alt.exe.exe
C:\WINDOWS\system32\drivers\LEL36.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\shift.exe.exe
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tmp32.tmp
C:\WINDOWS\system32\winsub.xml
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FCI
-------\LEGACY_LEL36
-------\LEGACY_PROTECT
-------\LEGACY_SYMAVC32
-------\LEGACY_SYSLIBRARY
-------\FCI
-------\protect
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 15:14 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 11:25 . 2004-08-17 14:49 147,968 --a------ C:\WINDOWS\R.COM
2008-01-13 11:25 . 2004-08-17 14:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-01-13 11:25 . 2008-01-13 11:30 50 --a------ C:\WINDOWS\Lic.xxx
2008-01-12 09:50 . 2008-01-12 09:50 29 --a------ C:\WINDOWS\system32\idaufuqd.tmp
2008-01-12 09:48 . 2008-01-12 09:48 540 --a------ C:\9.tmp
2008-01-12 09:48 . 2008-01-12 09:48 0 --a------ C:\E.tmp
2008-01-12 09:48 . 2008-01-12 09:48 0 --a------ C:\D.tmp
2008-01-12 09:48 . 2008-01-12 09:48 0 --a------ C:\C.tmp
2008-01-12 09:48 . 2008-01-12 09:48 0 --a------ C:\B.tmp
2008-01-12 09:48 . 2008-01-12 09:48 0 --a------ C:\A.tmp
2008-01-11 22:17 . 2008-01-11 22:17 <DIR> d-------- C:\WINDOWS\system32\svcd
2008-01-11 22:17 . 2008-01-11 22:17 34,816 --a------ C:\winwwhc.exe
2008-01-11 22:17 . 2008-01-13 15:06 114 --a------ C:\WINDOWS\system32\url3
2008-01-11 22:17 . 2008-01-13 15:06 102 --a------ C:\WINDOWS\system32\url2
2008-01-11 22:17 . 2008-01-13 15:06 102 --a------ C:\WINDOWS\system32\url1
2008-01-11 22:17 . 2008-01-13 15:06 8 --a------ C:\WINDOWS\system32\CID
2008-01-11 22:17 . 2008-01-11 22:17 4 --a------ C:\WINDOWS\system32\SvcNm
2008-01-11 22:03 . 2008-01-11 22:12 <DIR> d-------- C:\Program Files\ICQ6
2008-01-11 17:20 . 2008-01-11 17:20 <DIR> d-------- C:\Program Files\Rockstar Games
2008-01-09 21:22 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-01-09 19:38 . 2008-01-09 19:38 <DIR> d---s---- C:\Documents and Settings\david\UserData
2008-01-09 19:05 . 2005-04-06 03:22 100,096 --a------ C:\WINDOWS\system32\nvtcp.sys
2008-01-09 19:04 . 2008-01-09 19:04 <DIR> d-------- C:\Program Files\AMD
2008-01-07 23:19 . 2008-01-09 20:51 <DIR> d-------- C:\Program Files\OpenAL
2008-01-07 23:15 . 2008-01-07 23:15 <DIR> d-------- C:\Program Files\Bohemia Interactive
2008-01-06 19:37 . 2008-01-07 21:45 <DIR> d-------- C:\Program Files\TrackMania Nations ESWC
2008-01-06 17:14 . 2008-01-12 13:53 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-06 12:53 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-06 12:45 . 2008-01-05 17:12 <DIR> d--h----- C:\Documents and Settings\martin\ćablony
2008-01-06 12:45 . 2008-01-11 22:27 <DIR> d-------- C:\Documents and Settings\martin\Plocha
2008-01-06 12:45 . 2008-01-05 18:04 <DIR> d--h----- C:\Documents and Settings\martin\Okolnˇ tisk rny
2008-01-06 12:45 . 2008-01-05 18:04 <DIR> d--h----- C:\Documents and Settings\martin\Okolnˇ sˇś
2008-01-06 12:45 . 2008-01-06 12:45 <DIR> dr------- C:\Documents and Settings\martin\Oblˇben‚ polo§ky
2008-01-06 12:45 . 2008-01-05 18:04 <DIR> dr------- C:\Documents and Settings\martin\Nabˇdka Start
2008-01-06 12:45 . 2008-01-11 22:42 <DIR> dr------- C:\Documents and Settings\martin\Dokumenty
2008-01-06 12:45 . 2008-01-12 20:07 <DIR> dr-h----- C:\Documents and Settings\martin\Data aplikacˇ
2008-01-06 12:41 . 2008-01-06 12:41 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2008-01-06 12:41 . 2008-01-06 12:40 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-01-06 12:13 . 2008-01-06 12:14 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-01-06 10:59 . 2008-01-06 10:59 <DIR> d-------- C:\Program Files\Nero
2008-01-06 00:47 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-01-06 00:47 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-01-06 00:46 . 2004-06-15 07:00 116,736 --a------ C:\WINDOWS\system32\CNMLM61.DLL
2008-01-06 00:46 . 2004-06-04 17:34 86,016 -ra------ C:\WINDOWS\system32\CNMCP61.exe
2008-01-06 00:46 . 2004-06-15 07:00 7,680 --a------ C:\WINDOWS\system32\CNMVS61.DLL
2008-01-06 00:45 . 2008-01-06 00:47 <DIR> d-------- C:\Program Files\Canon
2008-01-06 00:41 . 2008-01-06 12:53 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-06 00:41 . 2005-10-21 02:47 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-01-06 00:41 . 2005-10-21 02:47 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2008-01-06 00:30 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-01-06 00:30 . 2008-01-06 00:30 390 --a------ C:\WINDOWS\ODBC.INI
2008-01-06 00:29 . 2008-01-06 00:30 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-06 00:16 . 2005-08-18 17:52 289,792 --a------ C:\WINDOWS\system32\idecoins.dll
2008-01-06 00:16 . 2005-08-18 10:52 289,792 --a------ C:\WINDOWS\system32\idecoi.dll
2008-01-06 00:16 . 2005-09-28 11:08 176,128 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-01-06 00:16 . 2005-09-28 11:08 176,128 --------- C:\WINDOWS\system32\nvuide.exe
2008-01-06 00:16 . 2005-08-18 17:52 93,568 --a------ C:\WINDOWS\system32\drivers\nvata.sys
2008-01-06 00:16 . 2005-08-03 07:52 33,280 --a------ C:\WINDOWS\system32\NVCOI.DLL
2008-01-06 00:16 . 2005-06-30 00:26 1,537 --------- C:\WINDOWS\system32\nvide.nvu
2008-01-06 00:16 . 2005-09-22 16:29 1,391 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-01-06 00:14 . 2004-01-03 12:45 635,094 --a------ C:\WINDOWS\system32\MS7125.bmp
2008-01-06 00:14 . 2005-03-09 15:53 42,496 --a------ C:\WINDOWS\system32\drivers\AmdK8.sys
2008-01-06 00:14 . 2004-01-03 13:39 258 --a------ C:\WINDOWS\system32\raidmgmt.ini
2008-01-06 00:01 . 2008-01-06 00:01 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-01-06 00:01 . 2008-01-06 00:01 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-01-06 00:01 . 2008-01-06 00:01 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-01-06 00:01 . 2008-01-07 13:53 60,416 --a------ C:\WINDOWS\ALCFDRTM.VER
2008-01-06 00:01 . 2008-01-06 00:01 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2008-01-05 23:57 . 2008-01-05 23:57 <DIR> d-------- C:\Program Files\Realtek AC97
2008-01-05 23:57 . 2008-01-11 22:07 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-01-05 23:02 . 2008-01-05 23:02 <DIR> d-------- C:\Program Files\Eraser
2008-01-05 23:02 . 2008-01-05 23:02 155,648 --a------ C:\WINDOWS\system32\stuninstall.exe
2008-01-05 22:25 . 2005-07-14 20:37 217,159 --a------ C:\WINDOWS\Grassy.jpg
2008-01-05 22:19 . 2008-01-05 22:19 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-01-05 22:19 . 2008-01-05 22:19 <DIR> d-------- C:\Program Files\ACD Systems
2008-01-05 22:17 . 2008-01-05 22:17 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-01-05 21:58 . 2008-01-09 19:03 <DIR> d-------- C:\ovladaźe
2008-01-05 21:51 . 2008-01-05 21:51 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-05 21:50 . 2008-01-05 21:50 <DIR> d-------- C:\WINDOWS\nview
2008-01-05 21:50 . 2008-01-05 21:50 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-01-05 21:50 . 2008-01-05 21:50 <DIR> d-------- C:\NVIDIA
2008-01-05 21:50 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-01-05 21:50 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-01-05 21:50 . 2008-01-05 22:06 163,353 --a------ C:\WINDOWS\system32\nvapps.xml
2008-01-05 21:50 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-01-05 18:31 . 2008-01-05 18:31 512 --a------ C:\WINDOWS\system32\DcppOLBS.dat
2008-01-05 18:07 . 2004-08-17 16:49 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-01-05 18:07 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-01-05 18:06 . 2004-08-17 16:49 75,264 --a------ C:\WINDOWS\system32\usbui.dll
2008-01-05 18:06 . 2004-08-17 16:43 58,240 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-01-05 18:06 . 2001-08-17 22:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-01-05 18:04 . 2008-01-12 13:37 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-01-05 18:04 . 2008-01-05 17:12 <DIR> d--h----- C:\Documents and Settings\Default User\ćablony
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> d-------- C:\Documents and Settings\Default User\Plocha
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> d--h----- C:\Documents and Settings\Default User\Okolnˇ tisk rny
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> d--h----- C:\Documents and Settings\Default User\Okolnˇ sˇś
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> d-------- C:\Documents and Settings\Default User\Oblˇben‚ polo§ky
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> dr------- C:\Documents and Settings\Default User\Nabˇdka Start
2008-01-05 18:04 . 2008-01-05 18:04 <DIR> d-------- C:\Documents and Settings\Default User\Dokumenty
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 08:48 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-01-09 20:22 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-01-09 20:22 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-01-05 16:23 --------- d-----w C:\Program Files\DIFX
2008-01-05 16:23 --------- d-----w C:\Program Files\AnyDATA
2008-01-05 16:16 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-05 00:41 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 00:41 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 00:41 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 00:41 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 00:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 00:41 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 00:41 6,549,504 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 00:41 5,773,568 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 00:41 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 00:41 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 00:41 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 00:41 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 00:41 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 00:41 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 00:41 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 00:41 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 00:41 3,710,976 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 00:41 3,420,160 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 00:41 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 00:41 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 00:41 2,498,560 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 00:41 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 00:41 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 00:41 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 00:41 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 00:41 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-12-05 00:41 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll
2007-12-05 00:41 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 00:41 1,228,800 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 00:41 1,089,536 ----a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 00:41 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 16:50 1289000]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 15:55 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 15:55 1057328]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 14:49 15360]
R0 pe3agmlb;Armed Assault Environment Driver (pe3agmlb);C:\WINDOWS\system32\drivers\pe3agmlb.sys [2007-06-04 20:01]
R0 ps6agmlb;Armed Assault Synchronization Driver (ps6agmlb);C:\WINDOWS\system32\drivers\ps6agmlb.sys [2007-06-04 20:01]
R0 sfdrv02;FrontLine Environment Driver (v2);C:\WINDOWS\system32\drivers\sfdrv02.sys [2006-09-11 12:57]
R0 sfsync05;FrontLine Synchronization Driver (v5);C:\WINDOWS\system32\drivers\sfsync05.sys [2006-08-11 17:09]
R2 FGQM;Security Service;C:\WINDOWS\system32\svcd\svchost.exe [2008-01-11 22:17]
R3 adusbser;AnyDATA USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 02:36]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 22:04]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 23:08]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 22:08]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
S2 pr2agmlb;Armed Assault Drivers Auto Removal (pr2agmlb);C:\WINDOWS\system32\pr2agmlb.exe svc []
S2 sfrem02;FrontLine Drivers Auto Removal (v2);C:\WINDOWS\system32\sfrem02.exe svc []
S3 SetupNTGLM7X;SetupNTGLM7X;H:\NTGLM7X.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-13 15:18:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\lrito.ini 32493 bytes
C:\WINDOWS\system32\lrito6e56-2f5f.sys 129792 bytes executable
C:\WINDOWS\system32\drivers\ntio922.sys 37632 bytes executable
C:\WINDOWS\system32\drivers\ndisaluo.sys 7040 bytes executable
scan completed successfully
hidden files: 4
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\lrito6e56-2f5f]
"ImagePath"="\??\C:\WINDOWS\system32\lrito6e56-2f5f.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NDIS]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ndisaluo]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\ndisaluo.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ntio922]
"ImagePath"="system32\Drivers\ntio922.sys"
.
Completion time: 2008-01-13 15:19:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-13 14:19:09