prosim pomoc,jak na vir:win32.backdoor,win32trpack,win32zbot
Napsal: pát 5. pro 2008, 15:26
zdravim,prosim pomohl by mi nekdo s odvirovanim kompu? nemam s tim žádne zkušenosti a nevím si rady, dekuju...
avast mi našel několik typu:
win32.backdoor.agent
win32.backdoor.bedincks
win32.trpack
win32.zbot-aud
win32.trojan-gen
dal sem je smazat,ale po připojení k síti avast zase hlásil napadení...
Už sem si četl nějaké diskuze, a tak přikládám log z combofixu:
ComboFix 08-12-04.05 - Oem 2008-12-05 14:55:23.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.80 [GMT 1:00]
Spuštěný z: E:\ComboFix.exe
* Vytvořen nový Bod Obnovení
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Oem\Nabídka Start\Programy\Po spuštění\userinit.exe
C:\userinit.exe
c:\windows\system32\1025j.exe
c:\windows\system32\1664672363.dll
c:\windows\system32\drivers\services.exe
c:\windows\system32\TDSScfub.dll
c:\windows\system32\TDSSfpmp.dll
c:\windows\system32\TDSSosvn.dat
c:\windows\system32\TDSStkdv.log
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DMADMINSWPRV
-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_PROTECTEDSTORAGETHEMES
-------\Service_dmadminSwPrv
-------\Service_ProtectedStorageThemes
((((((((((((((((((((((((( Soubory vytvořené od 2008-11-05 do 2008-12-05 )))))))))))))))))))))))))))))))
.
2008-11-29 21:15 . 2008-11-29 21:15 172 --a------ c:\windows\wininit.ini
2008-11-29 18:43 . 2008-11-29 18:43 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-29 18:43 . 2008-11-29 21:16 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-11-29 13:35 . 2008-11-29 13:35 <DIR> d-------- c:\program files\Lavasoft
2008-11-29 13:35 . 2008-11-29 13:38 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Lavasoft
2008-11-29 13:33 . 2008-11-29 13:33 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-28 20:36 . 2001-08-17 20:11 66,591 --a------ c:\windows\system32\drivers\el90xbc5.sys
2008-11-28 20:36 . 2001-08-17 20:11 66,591 --a--c--- c:\windows\system32\dllcache\el90xbc5.sys
2008-11-26 23:17 . 2008-11-29 18:38 288 --a-s---- c:\windows\system32\2214465269.dat
2008-11-26 23:15 . 2008-11-26 23:17 190 --a-s---- c:\windows\system32\4007493141.dat
2008-11-16 18:54 . 2008-11-16 18:54 <DIR> d-------- c:\program files\Microsoft Games
2008-11-16 18:51 . 2008-11-16 18:51 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-11-16 18:51 . 2008-11-16 18:51 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-16 18:44 . 2008-11-16 18:44 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-14 16:08 . 2008-11-14 16:08 582 --a------ c:\windows\eReg.dat
2008-11-14 16:01 . 2008-11-15 21:32 <DIR> d-------- c:\program files\1503 AD
2008-11-11 15:49 . 2008-11-11 15:49 <DIR> d-------- c:\program files\Oko
2008-11-11 15:49 . 1997-07-20 01:01 75,536 --a------ c:\windows\system32\PICCLP32.OCX
2008-11-07 14:34 . 2008-11-07 14:36 <DIR> d-------- c:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 20:57 14,336 ----a-w c:\windows\system32\svchost.exe.tmp
2008-11-16 11:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-04 13:52 --------- d-----w c:\program files\Marias
2008-11-02 14:18 --------- d-----w c:\program files\The KMPlayer
2008-10-24 12:39 --------- d-----w c:\program files\Medicopter 4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-16 17:34 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-07 15:05 --------- d-----w c:\program files\Codemasters
2008-10-06 14:30 --------- d-----w c:\program files\Electronic Arts
2008-09-21 08:30 737,280 ----a-w c:\windows\iun6002.exe
.
------- Sigcheck -------
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\tcpip.sys
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AtiPTA"="atiptaxx.exe" [2001-09-27 c:\windows\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1glxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1osxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1puxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2lqxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2wbxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3eixx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3fkxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3puxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4hlxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4xcxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5uyxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6hlxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7xcxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8lpxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8mrxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8uaxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Codemasters\\Operation Flashpoint\\FlashpointResistance.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Codemasters\\Operation Flashpoint\\OperationFlashpoint.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Valve\\hl.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\EA SPORTS\\NHL 2001\\nhl2001.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Oem\\Plocha\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Valve\\hlds.exe"=
"c:\\Program Files\\Microsoft Games\\Midtown Madness 2\\Midtown2.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-09-21 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-09-21 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-09-28 222456]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
S0 ati1glxx;ati1glxx;c:\windows\system32\Drivers\ati1glxx.sys []
S0 ati1osxx;ati1osxx;c:\windows\system32\Drivers\ati1osxx.sys []
S0 ati1puxx;ati1puxx;c:\windows\system32\Drivers\ati1puxx.sys []
S0 ati2lqxx;ati2lqxx;c:\windows\system32\Drivers\ati2lqxx.sys []
S0 ati2wbxx;ati2wbxx;c:\windows\system32\Drivers\ati2wbxx.sys []
S0 ati3eixx;ati3eixx;c:\windows\system32\Drivers\ati3eixx.sys []
S0 ati3fkxx;ati3fkxx;c:\windows\system32\Drivers\ati3fkxx.sys []
S0 ati3puxx;ati3puxx;c:\windows\system32\Drivers\ati3puxx.sys []
S0 ati4hlxx;ati4hlxx;c:\windows\system32\Drivers\ati4hlxx.sys []
S0 ati4xcxx;ati4xcxx;c:\windows\system32\Drivers\ati4xcxx.sys []
S0 ati5uyxx;ati5uyxx;c:\windows\system32\Drivers\ati5uyxx.sys []
S0 ati6hlxx;ati6hlxx;c:\windows\system32\Drivers\ati6hlxx.sys []
S0 ati7xcxx;ati7xcxx;c:\windows\system32\Drivers\ati7xcxx.sys []
S0 ati8lpxx;ati8lpxx;c:\windows\system32\Drivers\ati8lpxx.sys []
S0 ati8mrxx;ati8mrxx;c:\windows\system32\Drivers\ati8mrxx.sys []
S0 ati8uaxx;ati8uaxx;c:\windows\system32\Drivers\ati8uaxx.sys []
S2 rrssqqrr;rrssqqrr;\??\c:\windows\system32\drivers\rrssqqrr.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23025a74-87b3-11dd-b3e6-0000b4bc3f31}]
\Shell\AutoRun\command - E:\tcmdr703.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
BHO-{9F094E37-833C-401E-AA6B-F14C62CE8C90} - c:\windows\system32\1664672363.dll
HKU-Default-Run-[system] - c:\windows\system32\drivers\services.exe
HKU-Default-Run-winlogon - c:\documents and settings\LocalService\svchost.exe
Notify-gzbpjx - gzbpjx.dll
SafeBoot-ati0joxx.sys
SafeBoot-ati2puxx.sys
SafeBoot-ati2uyxx.sys
SafeBoot-ati3osxx.sys
SafeBoot-ati6xcxx.sys
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FireFox -: Profile - c:\documents and settings\Oem\Data aplikací\Mozilla\Firefox\Profiles\wvhvhr3w.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.atlas.cz/?from=icqhp
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 15:00:45
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2008-12-05 15:05:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2008-12-05 14:04:57
Před spuštěním: 3 067 228 160
Po spuštění: 3,941,109,760
201
avast mi našel několik typu:
win32.backdoor.agent
win32.backdoor.bedincks
win32.trpack
win32.zbot-aud
win32.trojan-gen
dal sem je smazat,ale po připojení k síti avast zase hlásil napadení...
Už sem si četl nějaké diskuze, a tak přikládám log z combofixu:
ComboFix 08-12-04.05 - Oem 2008-12-05 14:55:23.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.80 [GMT 1:00]
Spuštěný z: E:\ComboFix.exe
* Vytvořen nový Bod Obnovení
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Oem\Nabídka Start\Programy\Po spuštění\userinit.exe
C:\userinit.exe
c:\windows\system32\1025j.exe
c:\windows\system32\1664672363.dll
c:\windows\system32\drivers\services.exe
c:\windows\system32\TDSScfub.dll
c:\windows\system32\TDSSfpmp.dll
c:\windows\system32\TDSSosvn.dat
c:\windows\system32\TDSStkdv.log
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DMADMINSWPRV
-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_PROTECTEDSTORAGETHEMES
-------\Service_dmadminSwPrv
-------\Service_ProtectedStorageThemes
((((((((((((((((((((((((( Soubory vytvořené od 2008-11-05 do 2008-12-05 )))))))))))))))))))))))))))))))
.
2008-11-29 21:15 . 2008-11-29 21:15 172 --a------ c:\windows\wininit.ini
2008-11-29 18:43 . 2008-11-29 18:43 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-29 18:43 . 2008-11-29 21:16 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-11-29 13:35 . 2008-11-29 13:35 <DIR> d-------- c:\program files\Lavasoft
2008-11-29 13:35 . 2008-11-29 13:38 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Lavasoft
2008-11-29 13:33 . 2008-11-29 13:33 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-28 20:36 . 2001-08-17 20:11 66,591 --a------ c:\windows\system32\drivers\el90xbc5.sys
2008-11-28 20:36 . 2001-08-17 20:11 66,591 --a--c--- c:\windows\system32\dllcache\el90xbc5.sys
2008-11-26 23:17 . 2008-11-29 18:38 288 --a-s---- c:\windows\system32\2214465269.dat
2008-11-26 23:15 . 2008-11-26 23:17 190 --a-s---- c:\windows\system32\4007493141.dat
2008-11-16 18:54 . 2008-11-16 18:54 <DIR> d-------- c:\program files\Microsoft Games
2008-11-16 18:51 . 2008-11-16 18:51 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-11-16 18:51 . 2008-11-16 18:51 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-16 18:44 . 2008-11-16 18:44 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-16 18:43 . 2008-11-16 18:43 <DIR> d-------- c:\documents and settings\Oem\Data aplikací\DAEMON Tools
2008-11-14 16:08 . 2008-11-14 16:08 582 --a------ c:\windows\eReg.dat
2008-11-14 16:01 . 2008-11-15 21:32 <DIR> d-------- c:\program files\1503 AD
2008-11-11 15:49 . 2008-11-11 15:49 <DIR> d-------- c:\program files\Oko
2008-11-11 15:49 . 1997-07-20 01:01 75,536 --a------ c:\windows\system32\PICCLP32.OCX
2008-11-07 14:34 . 2008-11-07 14:36 <DIR> d-------- c:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 20:57 14,336 ----a-w c:\windows\system32\svchost.exe.tmp
2008-11-16 11:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-04 13:52 --------- d-----w c:\program files\Marias
2008-11-02 14:18 --------- d-----w c:\program files\The KMPlayer
2008-10-24 12:39 --------- d-----w c:\program files\Medicopter 4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-24 12:39 --------- d-----w c:\documents and settings\Oem\Data aplikací\Medicopter4
2008-10-16 17:34 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-07 15:05 --------- d-----w c:\program files\Codemasters
2008-10-06 14:30 --------- d-----w c:\program files\Electronic Arts
2008-09-21 08:30 737,280 ----a-w c:\windows\iun6002.exe
.
------- Sigcheck -------
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\tcpip.sys
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AtiPTA"="atiptaxx.exe" [2001-09-27 c:\windows\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1glxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1osxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1puxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2lqxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2wbxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3eixx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3fkxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3puxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4hlxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4xcxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5uyxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6hlxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7xcxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8lpxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8mrxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8uaxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Codemasters\\Operation Flashpoint\\FlashpointResistance.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Codemasters\\Operation Flashpoint\\OperationFlashpoint.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Valve\\hl.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\EA SPORTS\\NHL 2001\\nhl2001.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Oem\\Plocha\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Valve\\hlds.exe"=
"c:\\Program Files\\Microsoft Games\\Midtown Madness 2\\Midtown2.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-09-21 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-09-21 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-09-28 222456]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
S0 ati1glxx;ati1glxx;c:\windows\system32\Drivers\ati1glxx.sys []
S0 ati1osxx;ati1osxx;c:\windows\system32\Drivers\ati1osxx.sys []
S0 ati1puxx;ati1puxx;c:\windows\system32\Drivers\ati1puxx.sys []
S0 ati2lqxx;ati2lqxx;c:\windows\system32\Drivers\ati2lqxx.sys []
S0 ati2wbxx;ati2wbxx;c:\windows\system32\Drivers\ati2wbxx.sys []
S0 ati3eixx;ati3eixx;c:\windows\system32\Drivers\ati3eixx.sys []
S0 ati3fkxx;ati3fkxx;c:\windows\system32\Drivers\ati3fkxx.sys []
S0 ati3puxx;ati3puxx;c:\windows\system32\Drivers\ati3puxx.sys []
S0 ati4hlxx;ati4hlxx;c:\windows\system32\Drivers\ati4hlxx.sys []
S0 ati4xcxx;ati4xcxx;c:\windows\system32\Drivers\ati4xcxx.sys []
S0 ati5uyxx;ati5uyxx;c:\windows\system32\Drivers\ati5uyxx.sys []
S0 ati6hlxx;ati6hlxx;c:\windows\system32\Drivers\ati6hlxx.sys []
S0 ati7xcxx;ati7xcxx;c:\windows\system32\Drivers\ati7xcxx.sys []
S0 ati8lpxx;ati8lpxx;c:\windows\system32\Drivers\ati8lpxx.sys []
S0 ati8mrxx;ati8mrxx;c:\windows\system32\Drivers\ati8mrxx.sys []
S0 ati8uaxx;ati8uaxx;c:\windows\system32\Drivers\ati8uaxx.sys []
S2 rrssqqrr;rrssqqrr;\??\c:\windows\system32\drivers\rrssqqrr.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23025a74-87b3-11dd-b3e6-0000b4bc3f31}]
\Shell\AutoRun\command - E:\tcmdr703.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
BHO-{9F094E37-833C-401E-AA6B-F14C62CE8C90} - c:\windows\system32\1664672363.dll
HKU-Default-Run-[system] - c:\windows\system32\drivers\services.exe
HKU-Default-Run-winlogon - c:\documents and settings\LocalService\svchost.exe
Notify-gzbpjx - gzbpjx.dll
SafeBoot-ati0joxx.sys
SafeBoot-ati2puxx.sys
SafeBoot-ati2uyxx.sys
SafeBoot-ati3osxx.sys
SafeBoot-ati6xcxx.sys
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FireFox -: Profile - c:\documents and settings\Oem\Data aplikací\Mozilla\Firefox\Profiles\wvhvhr3w.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.atlas.cz/?from=icqhp
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 15:00:45
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2008-12-05 15:05:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2008-12-05 14:04:57
Před spuštěním: 3 067 228 160
Po spuštění: 3,941,109,760
201
