ComboFix 10-12-03.03 - Spravce 04.12.2010 14:40:55.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.536 [GMT 1:00]
Spuštěný z: d:\documents and settings\Spravce\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
d:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Možné infikované stránky -----
hxxp://client.updatestar.com.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-04 do 2010-12-04 )))))))))))))))))))))))))))))))
.
2010-11-25 09:41 . 2010-11-25 09:41 -------- d-----w- d:\documents and settings\Spravce\Data aplikací\AnvSoft
2010-11-25 09:41 . 2010-11-25 09:41 -------- d-----w- d:\program files\AnvSoft
2010-11-20 18:49 . 2010-11-20 18:49 -------- d-----w- d:\documents and settings\Spravce\Data aplikací\skypePM
2010-11-07 09:41 . 2010-11-07 09:41 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 16:42 . 2010-07-21 08:08 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 16:42 . 2010-07-21 08:08 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-10-09 14:34 . 2010-10-09 14:34 752128 ----a-w- d:\windows\system32\drivers\tdrpm273.sys
2010-10-09 14:34 . 2010-10-09 14:34 600928 ----a-w- d:\windows\system32\drivers\timntr.sys
2010-10-02 08:39 . 2010-10-02 08:39 691696 ----a-w- d:\windows\system32\drivers\sptd.sys
2010-09-18 10:23 . 2007-04-03 06:44 974848 ----a-w- d:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 06:51 974848 ----a-w- d:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 06:51 953856 ----a-w- d:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2004-08-18 12:00 954368 ----a-w- d:\windows\system32\mfc40.dll
2010-09-15 02:50 . 2010-07-12 20:12 472808 ----a-w- d:\windows\system32\deployJava1.dll
2010-09-15 00:29 . 2010-07-12 20:12 73728 ----a-w- d:\windows\system32\javacpl.cpl
2010-09-10 05:50 . 2010-07-12 19:14 919552 ----a-w- d:\windows\system32\wininet.dll
2010-09-10 05:50 . 2010-07-12 19:13 43520 ----a-w- d:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2010-07-12 19:13 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2010-09-07 15:12 . 2010-07-12 20:28 38848 ----a-w- d:\windows\avastSS.scr
2010-09-07 15:11 . 2010-07-12 20:28 167592 ----a-w- d:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2010-07-12 20:28 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2010-07-12 20:28 165584 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2010-07-12 20:28 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2010-07-12 20:28 100176 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-09-07 14:47 . 2010-07-12 20:28 94544 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-09-07 14:47 . 2010-07-12 20:28 17744 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-09-07 14:46 . 2010-07-12 20:28 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
.
------- Sigcheck -------
[-] 2010-07-12 . B84B22372D6170FFA7858C3B405B1A16 . 1571840 . . [5.1.2600.5512] . . d:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EVEREST AutoStart"="d:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe" [2009-02-04 2350176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2010-07-12 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 ----a-w- d:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2010-10-27 12:20 133432 ----a-w- d:\program files\ICQ7.2\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- d:\program files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\ICQ7.2\\ICQ.exe"=
"d:\\Program Files\\ICQ7.2\\aolload.exe"=
"d:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"d:\\Program Files\\Nero\\Nero 7\\Core\\nero.exe"=
"d:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"g:\\Nainstalováný Softwéry\\track mania national forever\\TmNationsForever\\TmForever.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"h:\\Miranda IM\\miranda32.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [2.10.2010 9:39 691696]
R1 AsUpIO;AsUpIO;d:\windows\system32\drivers\AsUpIO.sys [18.7.2010 2:10 11448]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [12.7.2010 21:28 165584]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [12.7.2010 21:28 17744]
S2 VRAID Log Service;VRAID Log Service;d:\program files\VIA\RAID\vialogsv.exe [18.7.2010 4:24 52888]
S3 cpudrv;cpudrv;d:\program files\SystemRequirementsLab\cpudrv.sys [18.12.2009 9:58 11336]
S3 Start BT in service;Start BT in service;d:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 13:54 52080]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - EverestDriver
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.google.com/IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\2d718ojg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Locale Switcher: {338e0b96-2285-4424-b4c8-e25560750fa3} - d:\documents and settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\2d718ojg.default\extensions\{338e0b96-2285-4424-b4c8-e25560750fa3}
FF - Extension: Czech (CZ) Language Pack:
langpack-cs@firefox.mozilla.org - d:\documents and settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\2d718ojg.default\extensions\langpack-cs@firefox.mozilla.org
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\documents and settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\2d718ojg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: ÄŚeskĂ© slovnĂky pro kontrolu pravopisu:
cs@dictionaries.addons.mozilla.org - d:\documents and settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\2d718ojg.default\extensions\cs@dictionaries.addons.mozilla.org
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-04 14:44
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2010-12-04 14:46:11
ComboFix-quarantined-files.txt 2010-12-04 13:46
Před spuštěním: Volných bajtů: 17 014 751 232
Po spuštění: Volných bajtů: 17 394 831 360
- - End Of File - - 8CC592A51F6839BC2AE6425BF9626C80