ComboFix 09-07-25.06 - Owner 26.07.2009 16:58.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.289 [GMT 2:00]
Spuštěný z: c:\documents and settings\Owner\Dokumenty\Downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\27d8f8e.msp
c:\windows\Installer\43787.msp
c:\windows\system32\Drivers\jixgun.sys
c:\windows\system32\mdm.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_tlnc
((((((((((((((((((((((((( Soubory vytvořené od 2009-06-26 do 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 14:10 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 14:10 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-26 14:10 . 2009-07-26 14:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 13:42 . 2009-07-26 13:42 -------- d-----w- c:\program files\Trend Micro
2009-07-24 17:16 . 2007-09-04 16:56 164352 ----a-w- c:\windows\system32\unrar.dll
2009-07-24 17:16 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-24 17:16 . 2008-01-10 12:16 159839 ----a-w- c:\windows\system32\xvidvfw.dll
2009-07-24 17:16 . 2008-01-10 12:15 755027 ----a-w- c:\windows\system32\xvidcore.dll
2009-07-24 17:16 . 2008-03-21 20:30 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-07-24 17:16 . 2008-03-21 20:28 81920 ----a-w- c:\windows\system32\dpl100.dll
2009-07-24 17:16 . 2008-03-31 21:25 682496 ----a-w- c:\windows\system32\divx.dll
2009-07-24 17:15 . 2008-03-28 17:41 7680 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-24 17:15 . 2009-07-24 17:16 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-07-23 12:33 . 2009-07-23 12:33 -------- d-sh--w- C:\found.000
2009-07-23 12:11 . 2009-07-23 12:11 -------- d-----w- c:\documents and settings\Admin
2009-07-05 15:27 . 2009-07-26 15:07 -------- d-----w- c:\documents and settings\Owner\Tracing
2009-07-05 15:25 . 2009-07-05 15:25 -------- d-----w- c:\program files\Microsoft
2009-07-05 15:24 . 2009-07-05 15:24 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-05 15:24 . 2009-07-05 15:25 -------- d-----w- c:\program files\Windows Live
2009-07-05 15:20 . 2009-07-05 15:20 -------- d-----w- c:\program files\Common Files\Windows Live
2009-07-05 08:59 . 2009-07-12 17:03 -------- d-----w- c:\program files\QIP Infium
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 14:50 . 2008-07-30 10:29 -------- d-----w- c:\program files\ICQToolbar
2009-07-24 17:14 . 2008-08-06 07:47 -------- d-----w- c:\program files\Codec Pack - All In 1
2009-07-21 18:25 . 2009-02-02 12:00 -------- d-----w- c:\program files\VirtualDJ
2009-07-21 09:29 . 2008-10-18 12:34 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 09:19 . 2008-08-29 14:49 -------- d-----w- c:\program files\Sony
2009-07-21 09:19 . 2008-08-29 14:52 -------- d-----w- c:\program files\VSTplugins
2009-07-21 09:17 . 2008-07-30 10:36 -------- d-----w- c:\program files\BitComet
2009-07-20 14:24 . 2008-08-29 14:48 -------- d-----w- c:\program files\Sony Setup
2009-07-12 10:06 . 2008-07-30 10:49 -------- d-----w- c:\program files\ESET
2009-07-10 13:08 . 2008-07-30 10:30 -------- d-----w- c:\program files\QIP
2009-07-06 14:02 . 2008-07-30 14:35 -------- d-----w- c:\program files\LimeWire
2009-07-01 09:40 . 2009-06-09 07:53 -------- d-----w- c:\program files\JetAudio
2009-06-24 06:35 . 2009-02-05 14:38 -------- d-----w- c:\program files\7-Zip
2009-06-23 15:34 . 2008-08-01 12:55 -------- d-----w- c:\program files\EA Sports
2009-06-23 15:34 . 2009-06-11 16:58 -------- d-----w- c:\program files\ICQ6Toolbar
2009-06-23 14:58 . 2009-06-14 12:08 -------- d-----w- c:\program files\Common Files\Real
2009-06-23 14:48 . 2008-11-10 12:47 -------- d-----w- c:\program files\Czech Soccer Manager 2002 FE
2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-14 12:08 . 2009-06-14 12:08 -------- d-----w- c:\program files\Real
2009-06-14 12:08 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-11 17:09 . 2009-06-11 16:54 -------- d-----w- c:\program files\ICQ6.5
2009-06-11 16:56 . 2008-07-30 10:27 -------- d-----w- c:\program files\ICQ6
2009-06-09 07:54 . 2009-06-09 07:53 -------- d-----w- c:\program files\Common Files\COWON
2009-06-09 07:53 . 2008-07-29 14:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-06 10:09 . 2008-07-30 12:11 -------- d-----w- c:\program files\Lexmark X1100 Series
2009-06-03 19:11 . 2006-03-02 12:00 1293824 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:33 . 2006-03-02 12:00 346624 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:47 . 2008-09-21 14:52 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-29 04:35 . 2006-03-02 12:00 667648 ----a-w- c:\windows\system32\wininet.dll
2009-07-23 08:07 . 2009-07-21 09:30 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-31 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\Owner\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-07-20 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008]
"DT ACR"="c:\program files\Acer Display\eDisplay Management\DTHtml.exe" [2007-09-20 305664]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-03 116040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-21 148888]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-03-27 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Instant Wireless LAN Monitor.lnk - c:\program files\WUSB11 WLAN Monitor\Wlan_cfg.exe [2008-8-7 2833920]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Software Kodak EasyShare.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Software Kodak EasyShare.lnk
backup=c:\windows\pss\Software Kodak EasyShare.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\VirtualDJ\\virtualdj.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [11.6.2009 18:58 222968]
R3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [20.2.2002 2:34 72576]
S3 PLUsbbc2;Hi-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [30.7.2008 14:15 7936]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - PCANDIS5
.
Obsah adresáře 'Naplánované úlohy'
2009-07-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{95289393-33EA-4F8D-B952-483415B9C955} - (no file)
HKCU-Run-OEXPRESS - (no file)
HKCU-Run-WEBTRAN - (no file)
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKLM-Run-realteks - c:\documents and settings\Owner\Data aplikací\Google\edpgz16420882.exe
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://google.atcomet.com/b/uSearch Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SHCN
uDefault_Search_URL =
hxxp://search.qip.ruuSearch Bar =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {74DCDCC7-AFC0-42CD-979D-B6064EE7FB43} = 89.235.4.2,82.100.63.254
TCP: {F9EDEDE8-33BC-4BA8-BCF7-AEE920663399} = 89.235.4.2,82.100.63.254
FF - ProfilePath - c:\documents and settings\Owner\Data aplikací\Mozilla\Firefox\Profiles\iuix268f.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://slirsredirect.search.aol.com/sli ... ie7&query=FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - prefs.js: keyword.URL -
hxxp://slirsredirect.search.aol.com/sli ... pab&query=---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-26 17:07
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\ACPI\PNP0F13\3&13c0b0c5&0\LogConf]
@DACL=(02 0000)
"BasicConfigVector"=hex(a):48,00,00,00,0f,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,01,00,01,00,01,00,00,00,00,02,\
"BootConfig"=hex(8):01,00,00,00,0f,00,00,00,00,00,00,00,01,00,01,00,01,00,00,
00,02,01,01,00,0c,00,00,00,0c,00,00,00,ff,ff,ff,ff
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2756)
c:\program files\Portrait Displays\Pivot Software\winphook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\documents and settings\Owner\Local Settings\Data aplikací\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Portrait Displays\Pivot Software\Floater.exe
.
**************************************************************************
.
Celkový čas: 2009-07-26 17:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-07-26 15:14
Před spuštěním: Volných bajtů: 38 706 774 016
Po spuštění: Volných bajtů: 39 492 993 024
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
200 --- E O F --- 2009-07-23 07:21