ComboFix 09-09-11.03 - Karel 12.09.2009 15:15.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1022.552 [GMT 2:00]
Spuštěný z: c:\documents and settings\Karel\Plocha\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2121369621-421504385-2192427132-1000
c:\program files\Mozilla Firefox\plc4.dll
c:\windows\Installer\151aa98.msi
c:\windows\Installer\1932f.msi
c:\windows\Installer\2be341e.msi
c:\windows\Installer\558350.msi
c:\windows\system32\3899482004.dat
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Soubory vytvořené od 2009-08-12 do 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-09 19:13 . 2009-08-22 06:32 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-09-09 19:13 . 2009-09-11 11:39 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-09-09 19:13 . 2009-09-11 11:39 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-09 19:13 . 2009-09-11 11:40 -------- d-----w- c:\program files\Symantec
2009-09-09 19:12 . 2009-09-12 10:03 -------- d-----w- c:\windows\system32\drivers\NAV
2009-09-09 19:12 . 2009-09-09 19:12 -------- d-----w- c:\program files\Norton AntiVirus
2009-09-09 19:12 . 2009-09-09 19:12 -------- d-----w- c:\program files\Windows Sidebar
2009-09-09 19:12 . 2009-09-09 19:12 -------- d-----w- c:\program files\NortonInstaller
2009-09-07 19:44 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-07 19:44 . 2009-09-07 19:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-07 19:44 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-05 18:08 . 2009-09-05 18:08 -------- d-----w- c:\program files\PowerISO
2009-08-31 20:18 . 2009-08-31 20:18 -------- d-----w- c:\program files\Trend Micro
2009-08-31 10:23 . 2009-08-31 10:23 -------- d-----w- c:\program files\Smart Port Forwarding
2009-08-29 20:22 . 2009-08-29 20:29 -------- d-----w- c:\program files\ICQ6.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 12:19 . 2007-12-11 18:38 -------- d-----w- c:\program files\Winamp Remote
2009-09-11 11:39 . 2009-09-09 19:13 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-11 11:39 . 2009-09-09 19:13 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-09 19:20 . 2008-05-29 20:41 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-07 19:40 . 2007-12-11 18:38 -------- d-----w- c:\program files\Winamp Toolbar
2009-09-07 19:40 . 2007-11-02 22:47 -------- d-----w- c:\program files\MegauploadToolbar
2009-09-04 15:12 . 2007-07-05 19:12 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-04 15:12 . 2007-05-13 16:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-29 20:22 . 2008-03-06 19:52 -------- d-----w- c:\program files\ICQ6
2009-07-27 02:43 . 2009-07-27 02:43 58908 ----a-w- c:\windows\system32\drivers\scdemu.sys
2009-06-27 20:46 . 2008-09-10 20:37 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-27 20:46 . 2008-09-10 20:37 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-24 18:34 . 2008-09-10 20:37 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-06-14 17:50 . 2007-05-22 13:39 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 495616]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2008-02-01 2194744]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 220544]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
"PowerArchiver Tray"="c:\program files\PowerArchiver\PASTARTER.EXE" [2008-01-24 141352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="c:\windows\TBPanel.exe" [2006-09-14 2162688]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"IPAnonymizer"="c:\program files\IP Anonymizer\IP Anonymizer.exe" [2006-01-06 5177344]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-03 16876032]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-03-09 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Pandion\\Pandion.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\BugReport\\BugReport.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\hry\\Supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"d:\\hry\\Supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"d:\\hry\\Neverwinter nights 2\\nwn2main.exe"=
"d:\\hry\\Neverwinter nights 2\\nwn2main_amdxp.exe"=
"d:\\hry\\Neverwinter nights 2\\nwupdate.exe"=
"d:\\hry\\Neverwinter nights 2\\nwn2server.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18896:TCP"= 18896:TCP:BitComet 18896 TCP
"18896:UDP"= 18896:UDP:BitComet 18896 UDP
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [5.7.2007 19:00 16640]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1007020.00B\SymEFA.sys [10.9.2009 15:34 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1007020.00B\BHDrvx86.sys [10.9.2009 15:34 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1007020.00B\cchpx86.sys [10.9.2009 15:32 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090910.003\IDSXpx86.sys [11.9.2009 13:40 276344]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe [10.9.2009 15:33 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9.9.2009 10:00 102448]
R3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [21.6.2007 17:21 30720]
S3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [13.3.2008 14:55 391688]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyServer = socks=
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Stáhnout Free Download Managerem -
file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout video Free Download Managerem -
file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem -
file://c:\program files\Free Download Manager\dlall.htm
IE: Stáhnout všechna videa s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\program files\translator 2005\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\program files\translator 2005\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\program files\translator 2005\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\program files\translator 2005\WEBIE.DLL
FF - ProfilePath - c:\documents and settings\Karel\Data aplikací\Mozilla\Firefox\Profiles\4ngb7jx2.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.daemon-search.com/startpage| ... google.cz/FF - prefs.js: keyword.URL -
hxxp://search.icq.com/search/afe_result ... id=afex&q=FF - component: c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-ICQ - c:\program files\ICQ6\ICQ.exe
HKLM-Run-Mirabilis ICQ - c:\program files\ICQ6\ICQ.exe
HKLM-Run-NWEReboot - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-12 15:29
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@?Y????????????
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.7.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1454471165-1085031214-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1454471165-1085031214-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:54,50,d4,1e,0b,02,5d,33,5b,79,e2,53,15,3b,36,10,ae,a1,89,99,ff,7a,d8,
39,74,42,c3,cf,ea,ed,bc,6f,6a,7e,f7,e9,05,49,f7,4a,3b,b3,31,92,0a,4a,b1,13,\
"??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d
[HKEY_USERS\S-1-5-21-1454471165-1085031214-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:9d,56,8c,45,cb,5f,5c,5c,39,22,9e,f8,7e,38,c8,da,6e,dd,ae,64,7d,
da,a2,d5,5e,63,bb,7c,f2,3f,50,52,34,ef,ad,f9,c3,e9,73,55,37,b9,8f,a2,8b,3c,\
"rkeysecu"=hex:d4,63,68,f0,81,86,bf,ea,d6,fd,32,45,e6,a1,09,b9
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2728)
c:\program files\Microsoft Office\Office10\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Winamp Remote\bin\Orb.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
.
**************************************************************************
.
Celkový čas: 2009-09-12 15:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-09-12 13:36
Před spuštěním: 855 400 448
Po spuštění: 1 763 160 064
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn /usepmtimer
222 --- E O F --- 2009-05-13 22:53