Toto?ComboFix 08-12-26.03 - Zedník 2008-12-27 19:17:25.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.511.254 [GMT 1:00]
Spuštěný z: c:\documents and settings\Zedník\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 080930-0] *On-access scanning disabled* (Outdated)
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Zedník\Local Settings\Temporary Internet Files\_tmB4.tmp
c:\documents and settings\Zedník\Local Settings\Temporary Internet Files\_tmC7.tmp
c:\documents and settings\Zedník\Local Settings\Temporary Internet Files\stb06759.tmp
c:\windows\Downloaded Program Files\setup.inf
c:\windows\IE4 Error Log.txt
c:\windows\system32\bpk.exe
c:\windows\system32\inst.dat
c:\windows\system32\kw.dat
c:\windows\system32\pk.bin
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-11-27 do 2008-12-27 )))))))))))))))))))))))))))))))
.
2008-12-27 18:14 . 2008-12-27 18:14 <DIR> d-------- c:\program files\Trend Micro
2008-12-21 11:48 . 2008-12-21 11:48 <DIR> d-------- c:\windows\system32\chrome
2008-12-15 19:25 . 2008-12-15 19:25 <DIR> d-------- c:\program files\Legion
2008-12-09 20:24 . 2008-12-09 20:24 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\PC Tools
2008-12-08 17:27 . 2008-12-12 19:11 <DIR> d-a------ c:\documents and settings\All Users\Data aplikací\TEMP
2008-12-08 17:16 . 2008-12-08 17:16 <DIR> d-------- c:\documents and settings\Zedník\Data aplikací\Simply Super Software
2008-12-08 17:16 . 2008-12-08 17:16 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Simply Super Software
2008-12-08 17:16 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2008-12-08 17:16 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2008-12-08 17:16 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2008-12-08 17:16 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2008-12-08 17:16 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2008-11-29 23:21 . 2008-11-29 23:21 291 --a------ c:\windows\STEditor.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-26 19:39 --------- d-----w c:\program files\ICQToolbar
2008-12-25 10:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-28 19:36 --------- d-----w c:\program files\LucasArts
2008-11-25 12:57 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-11-24 15:34 --------- d-----w c:\program files\Network Optimizer
2008-11-24 15:33 --------- d-----w c:\program files\DoubleD
2008-11-14 02:02 --------- d-----w c:\documents and settings\All Users\Data aplikací\Blizzard
2008-11-11 21:45 278,984 ----a-w c:\windows\system32\drivers\atksgt.sys
2008-11-11 21:45 25,416 ----a-w c:\windows\system32\drivers\lirsgt.sys
2008-11-11 21:35 --------- d-----w c:\program files\Atari
2008-10-29 19:55 --------- d-----w c:\program files\EA GAMES
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-06 18:06 126,976 ----a-w c:\windows\system32\UAService7.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-07-19 57344]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-14 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="c:\program files\ICQLite\ICQLite.exe" [2006-07-27 3142236]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-12 196608]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-07-19 40960]
"VirtualCloneDrive"="d:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"CloneCDTray"="d:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"ICQ Lite"="c:\program files\ICQLite\ICQLite.exe" [2006-07-27 3142236]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TrojanScanner"="d:\program files\Trojan Remover\Trjscan.exe" [2008-12-08 1231752]
"C-Media Mixer"="Mixer.exe" [2001-12-07 c:\windows\Mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\Zednˇk\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ubisoft register.lnk - c:\program files\Ubisoft\Register\schedule.exe [2007-03-03 28672]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-03-02 962663]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQLite\\ICQLite.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\Program Files\\Team17\\Worms2\\frontend.exe"=
"d:\\SIERRA\\Empire Earth\\Empire Earth.exe"=
"d:\\Program Files\\FlatOut\\flatout.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"d:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"d:\\Program Files\\FlatOut2\\FlatOut2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Program Files\\Simon a Schuster\\Skutečná Válka\\REALWAR.EXE"=
"d:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"d:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\Call of Duty\\The Call of Duty\\CoDMP.exe"=
"d:\\Program Files\\Ubisoft\\Heroes of Might and Magic V Collector Edition\\bin\\H5_Game.exe"=
"d:\\Program Files\\Cypron Studios\\State of War\\State of War.exe"=
"d:\\Program Files\\THE HISTORY CHANNEL Great Battles of Rome\\THCGBoR.exe"=
"d:\\Program Files\\Graffiti Studio 2.0\\Graffiti Studio.exe"=
"d:\\Program Files\\battle\\GameData\\battlefront.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25479:TCP"= 25479:TCP:BitComet 25479 TCP
"25479:UDP"= 25479:UDP:BitComet 25479 UDP
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-02 78416]
R1 prodrv04;Star Force copy protection driver v4;c:\windows\system32\drivers\prodrv04.sys [2007-03-02 114496]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-02 20560]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
*Newly Created Service* - PROCEXP90
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-bpk - c:\windows\system32\bpk.exe
HKLM-Run-bvhholqtyjdwviy - c:\windows\system32\tpkmovqbgs.dll
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/uSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/ieuInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: Download all links using BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all videos using BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Download link using &BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Poslat jako MMS - c:\program files\O2\SMSender\SMSender.E.143.dll/1003
IE: Poslat jako SMS - c:\program files\O2\SMSender\SMSender.E.143.dll/1001
IE: Poslat MMS na - c:\program files\O2\SMSender\SMSender.E.143.dll/1002
IE: Poslat SMS na - c:\program files\O2\SMSender\SMSender.E.143.dll/1000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Zedník\Data aplikací\Mozilla\Firefox\Profiles\9tvezutg.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - plugin: d:\program files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
ATTENTION: FIREFOX POLICES IS IN FORCE c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-27 19:20:01
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(600)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2008-12-27 19:21:55
ComboFix-quarantined-files.txt 2008-12-27 18:20:54
Před spuštěním: Volných bajtů: 12 547 141 632
Po spuštění: Volných bajtů: 15,311,372,288
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
182 --- E O F --- 2008-11-12 16:06:05