ComboFix 09-10-08.04 - Zemish 10.10.2009 17:18.3.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1428 [GMT 2:00]
Spuštěný z: c:\documents and settings\Zemish\Plocha\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\ctfmon .exe
c:\windows\system32\ieuinit.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-10 do 2009-10-10 )))))))))))))))))))))))))))))))
.
2009-10-10 14:52 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-10 14:52 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-10 14:52 . 2009-10-10 14:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-07 18:37 . 2009-10-07 18:37 -------- d-sh--w- c:\documents and settings\Zemish\IECompatCache
2009-10-04 10:38 . 2009-10-04 10:38 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2009-10-04 10:38 . 2009-10-04 10:38 298104 ----a-w- c:\windows\system32\imon.dll
2009-10-04 10:38 . 2009-10-04 10:38 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2009-10-04 10:37 . 2009-10-04 10:47 -------- d-----w- c:\program files\Eset
2009-10-02 11:52 . 2009-10-02 11:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 11:47 . 2009-10-02 11:47 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-16 14:54 . 2009-09-16 14:54 -------- d-sh--w- c:\documents and settings\Zemish\PrivacIE
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-10 15:12 . 2009-05-30 17:45 -------- d-----w- c:\program files\Common Files\LightScribe
2009-10-10 14:46 . 2009-05-26 16:00 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-26 16:48 . 2009-08-22 17:40 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-08 14:55 . 2009-09-08 14:55 -------- d-----w- c:\program files\Bonjour
2009-09-08 14:55 . 2009-09-08 14:55 -------- d-----w- c:\program files\QuickTime
2009-09-01 12:34 . 2009-09-01 12:34 -------- d-----w- c:\program files\HP Wireless Keyboard
2009-08-21 12:49 . 2002-09-23 12:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2009-08-21 12:49 . 2002-09-23 12:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2009-08-06 17:24 . 2009-05-25 16:20 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2009-05-25 16:20 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2009-05-25 16:20 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2008-10-16 12:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2009-05-25 15:14 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2002-09-23 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2009-05-25 16:20 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2009-05-25 15:14 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2002-09-23 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-21 08:04 . 2009-07-21 08:04 98304 ----a-w- c:\windows\system32\qttask.exe
2009-07-20 16:42 . 2009-07-20 16:42 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-07-20 07:34 . 2009-07-20 07:34 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-07-17 19:04 . 2002-09-23 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2009-05-25 16:20 286208 ------w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-03_18.05.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2002-09-23 12:00 . 2009-06-25 08:27 54272 c:\windows\system32\wdigest.dll
+ 2002-09-23 12:00 . 2008-04-14 06:52 37888 c:\windows\system32\url.dll
+ 2009-10-07 14:07 . 2009-08-06 17:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2009-10-07 14:07 . 2009-08-06 17:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2002-09-23 12:00 . 2009-06-25 08:27 56832 c:\windows\system32\secur32.dll
- 2002-09-23 12:00 . 2009-02-03 19:58 56832 c:\windows\system32\secur32.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 39424 c:\windows\system32\pngfilt.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 96768 c:\windows\system32\occache.dll
+ 2002-09-23 12:00 . 2008-04-14 05:42 56832 c:\windows\system32\mshtmler.dll
+ 2002-09-23 12:00 . 2008-04-14 06:52 29184 c:\windows\system32\mshta.exe
+ 2002-09-23 12:00 . 2008-04-14 06:51 22016 c:\windows\system32\licmgr10.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 15872 c:\windows\system32\jsproxy.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 96768 c:\windows\system32\inseng.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 35840 c:\windows\system32\imgutil.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 62976 c:\windows\system32\iesetup.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 48128 c:\windows\system32\iernonce.dll
+ 2009-07-09 05:56 . 2009-06-26 16:51 81920 c:\windows\system32\ieencode.dll
+ 2002-09-23 12:00 . 2008-04-14 06:52 34304 c:\windows\system32\ie4uinit.exe
+ 2002-09-23 12:00 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys
+ 2009-05-25 16:20 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2009-05-25 15:14 . 2009-08-06 17:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2009-06-25 08:27 . 2009-06-25 08:27 54272 c:\windows\system32\dllcache\wdigest.dll
- 2009-02-03 19:58 . 2009-02-03 19:58 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-02-03 19:58 . 2009-06-25 08:27 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys
+ 2009-07-09 05:56 . 2009-06-26 16:51 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2002-09-23 12:00 . 2009-08-06 17:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 35328 c:\windows\system32\corpol.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 61440 c:\windows\system32\admparse.dll
+ 2009-10-04 09:33 . 2008-07-08 12:59 26488 c:\windows\$hf_mig$\KB968389\update\spcustom.dll
+ 2009-10-04 09:33 . 2008-07-08 12:59 18296 c:\windows\$hf_mig$\KB968389\spmsg.dll
+ 2009-06-25 08:42 . 2009-06-25 08:42 54272 c:\windows\$hf_mig$\KB968389\SP3QFE\wdigest.dll
+ 2009-06-25 08:42 . 2009-06-25 08:42 56832 c:\windows\$hf_mig$\KB968389\SP3QFE\secur32.dll
+ 2009-06-24 10:28 . 2009-06-24 10:28 92928 c:\windows\$hf_mig$\KB968389\SP3QFE\ksecdd.sys
+ 2002-09-23 12:00 . 2009-06-26 16:51 667648 c:\windows\system32\wininet.dll
+ 2002-09-23 12:00 . 2008-04-14 06:52 278528 c:\windows\system32\webcheck.dll
+ 2002-09-23 12:00 . 2008-05-09 10:56 430080 c:\windows\system32\vbscript.dll
+ 2002-09-23 12:00 . 2009-06-26 16:51 619520 c:\windows\system32\urlmon.dll
+ 2002-09-23 12:00 . 2009-06-25 08:27 147456 c:\windows\system32\schannel.dll
+ 2002-09-23 12:00 . 2009-06-25 08:27 136192 c:\windows\system32\msv1_0.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 532480 c:\windows\system32\mstime.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 146432 c:\windows\system32\msrating.dll
+ 2002-09-23 12:00 . 2002-09-23 12:00 146432 c:\windows\system32\msls31.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 449024 c:\windows\system32\mshtmled.dll
+ 2002-09-23 12:00 . 2009-06-25 08:27 729088 c:\windows\system32\lsasrv.dll
+ 2002-09-23 12:00 . 2009-06-25 08:27 301568 c:\windows\system32\kerberos.dll
+ 2002-09-23 12:00 . 2009-08-13 15:24 512000 c:\windows\system32\jscript.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 251904 c:\windows\system32\iepeers.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 323584 c:\windows\system32\iedkcs32.dll
+ 2002-09-23 12:00 . 2002-09-23 12:00 225280 c:\windows\system32\ieakui.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 219136 c:\windows\system32\ieaksie.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 143360 c:\windows\system32\ieakeng.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 205312 c:\windows\system32\dxtrans.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 357888 c:\windows\system32\dxtmsft.dll
+ 2009-05-25 16:20 . 2009-08-06 17:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2009-05-25 16:20 . 2009-08-06 17:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2009-05-25 16:20 . 2009-08-06 17:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2009-02-20 08:12 . 2009-06-26 16:51 667648 c:\windows\system32\dllcache\wininet.dll
+ 2008-05-09 10:56 . 2008-05-09 10:56 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2009-02-20 08:12 . 2009-06-26 16:51 619520 c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-05 06:57 . 2009-06-25 08:27 147456 c:\windows\system32\dllcache\schannel.dll
+ 2009-06-25 08:27 . 2009-06-25 08:27 136192 c:\windows\system32\dllcache\msv1_0.dll
+ 2002-09-23 12:00 . 2002-09-23 12:00 146432 c:\windows\system32\dllcache\msls31.dll
+ 2009-05-25 17:04 . 2009-06-25 08:27 729088 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-06-25 08:27 . 2009-06-25 08:27 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2008-05-09 10:56 . 2009-08-13 15:24 512000 c:\windows\system32\dllcache\jscript.dll
+ 2002-09-23 12:00 . 2002-09-23 12:00 225280 c:\windows\system32\dllcache\ieakui.dll
+ 2002-09-23 12:00 . 2008-04-14 06:51 100352 c:\windows\system32\advpack.dll
+ 2009-10-04 09:33 . 2009-05-26 11:40 391032 c:\windows\$hf_mig$\KB968389\update\updspapi.dll
+ 2009-10-04 09:33 . 2009-05-26 11:40 759160 c:\windows\$hf_mig$\KB968389\update\update.exe
+ 2009-10-04 09:33 . 2008-07-08 12:59 233848 c:\windows\$hf_mig$\KB968389\spuninst.exe
+ 2009-06-25 08:42 . 2009-06-25 08:42 147456 c:\windows\$hf_mig$\KB968389\SP3QFE\schannel.dll
+ 2009-06-25 08:42 . 2009-06-25 08:42 136704 c:\windows\$hf_mig$\KB968389\SP3QFE\msv1_0.dll
+ 2009-06-26 09:42 . 2009-06-26 09:42 729088 c:\windows\$hf_mig$\KB968389\SP3QFE\lsasrv.dll
+ 2009-06-25 08:42 . 2009-06-25 08:42 301568 c:\windows\$hf_mig$\KB968389\SP3QFE\kerberos.dll
+ 2002-09-23 12:00 . 2009-07-18 16:05 1510400 c:\windows\system32\shdocvw.dll
+ 2002-09-23 12:00 . 2009-07-18 16:05 3090432 c:\windows\system32\mshtml.dll
+ 2009-05-25 15:14 . 2009-08-06 17:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2009-03-02 23:11 . 2009-07-18 16:05 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-02-20 08:12 . 2009-07-18 16:05 3090432 c:\windows\system32\dllcache\mshtml.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"BtcMaestro"="c:\program files\HP Wireless Keyboard\KMaestro.exe" [2007-11-15 348160]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-10-04 949376]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-26 18081280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Zemish\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WinFast\\WFDTV\\DVBTAP.exe"=
"c:\\Program Files\\WinFast\\WFDTV\\LiveUpdate\\LiveUpdate.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [25.5.2009 20:03 17640]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [4.10.2009 12:38 15424]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [1.4.2009 13:28 93184]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [27.5.2009 15:56 9446]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [26.5.2009 14:39 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Doplňkový sken -------
.
TCP: {196A49A4-B71C-4F59-9789-1BC2C22A022D} = 213.180.36.130,213.180.36.131
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-10 17:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(528)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(584)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
.
Celkový čas: 2009-10-10 17:21
ComboFix-quarantined-files.txt 2009-10-10 15:21
Před spuštěním: Volných bajtů: 42 486 276 096
Po spuštění: Volných bajtů: 42 777 833 472
201 --- E O F --- 2009-10-10 11:34