ComboFix 08-11-18.02 - liRik 2008-11-18 20:46:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1029.18.49 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
* Vytvořen nový Bod Obnovení
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system\msvbvm60.dll
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-10-18 do 2008-11-18 )))))))))))))))))))))))))))))))
.
2008-11-18 20:31 . 2008-11-18 20:33 3,968,900 -ra------ C:\ComboFix.exe
2008-11-18 20:02 . 2008-11-18 20:02 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-11-18 19:59 . 2008-11-18 20:00 <DIR> d-------- c:\windows\ERUNT
2008-11-18 19:53 . 2008-11-18 19:53 1,529,241 --a------ C:\SDFix.exe
2008-11-18 19:33 . 2008-11-18 19:33 <DIR> d-------- c:\program files\Trend Micro
2008-11-18 19:33 . 2008-11-18 19:33 812,344 --a------ C:\HJTInstall.exe
2008-11-18 18:49 . 2008-11-18 18:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-18 18:49 . 2008-11-18 18:49 <DIR> d-------- c:\documents and settings\liRik\Data aplikací\Malwarebytes
2008-11-18 18:49 . 2008-11-18 18:49 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2008-11-18 18:49 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-18 18:49 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-18 18:47 . 2008-11-18 18:47 2,372,472 --a------ C:\mbam-setup.exe
2008-11-18 16:21 . 2008-11-18 16:21 <DIR> d-a------ c:\windows\zts2.exe
2008-11-18 16:21 . 2008-11-18 16:21 <DIR> d-a------ c:\windows\system32\iifgfgf.dll
2008-11-18 16:21 . 2008-11-18 16:21 <DIR> d-a------ c:\windows\rundl132.dll
2008-11-18 16:19 . 2008-11-18 16:35 54 --a------ c:\windows\Lic.xxx
2008-11-18 16:18 . 2008-11-18 16:18 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\MicroWorld
2008-11-18 16:18 . 2008-11-18 16:18 626,688 --a------ c:\windows\system32\msvcr80.dll
2008-11-18 16:18 . 2008-11-18 16:18 548,864 --a------ c:\windows\system32\msvcp80.dll
2008-11-18 16:18 . 2008-04-14 07:52 147,968 --a------ c:\windows\R.COM
2008-11-18 16:18 . 2008-04-14 07:52 137,216 --a------ c:\windows\system32\T.COM
2008-11-18 16:18 . 2008-11-18 16:18 28,672 --a------ c:\windows\system32\eEmpty.exe
2008-11-18 16:18 . 2005-09-22 23:22 522 --a------ c:\windows\system32\Microsoft.VC80.CRT.manifest
2008-11-18 15:32 . 2008-11-18 15:42 45,561,232 --a------ C:\mwav.exe
2008-11-16 21:09 . 2008-11-16 21:09 119 --a------ c:\windows\MP3OGGC.ini
2008-11-16 21:07 . 2008-11-16 21:07 3,082 --a------ c:\windows\system32\affv14575p15now.sys
2008-11-16 20:47 . 2008-11-16 20:58 96 --a------ c:\windows\mp3wavcon.ini
2008-11-16 20:45 . 2003-12-15 12:43 1,871,872 --a------ c:\windows\system32\NCTAudioFile2.dll
2008-11-16 20:45 . 2003-12-08 12:19 425,984 --a------ c:\windows\system32\NCTAudioTransform2.dll
2008-11-16 20:45 . 2002-01-05 14:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-11-16 20:45 . 2004-12-01 14:43 315,392 --a------ c:\windows\system32\NCTAudioPlayer2.dll
2008-11-16 20:45 . 2003-08-07 14:01 237,568 --a------ c:\windows\system32\lame_enc.dll
2008-11-16 20:45 . 2008-11-16 21:09 5 --a------ c:\windows\system32\SySMP3OC.dat
2008-11-16 15:38 . 2008-11-16 16:04 84,087,242 --a------ C:\Kelly_Rowland_feat_Trina_-_Here_we_go.avi
2008-11-16 11:50 . 2002-08-29 18:33 319,488 -ra------ c:\windows\system32\MafiaSetup.exe
2008-11-13 15:10 . 2008-11-13 15:10 <DIR> d-------- c:\program files\Total Uninstall 4
2008-11-13 15:10 . 2008-11-13 15:10 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Martau
2008-11-12 14:16 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 14:16 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-08 16:24 . 2003-05-23 13:28 1,060,864 --a------ c:\windows\system32\mfc71.dll
2008-11-08 15:54 . 2008-11-08 15:54 <DIR> d-------- c:\windows\mp2_screensaver_1600x1200 dir
2008-11-08 15:54 . 2008-11-08 15:54 12,288 --a------ c:\windows\impborl.dll
2008-11-08 09:13 . 2008-11-08 09:13 <DIR> d-------- c:\documents and settings\liRik\Data aplikací\ESET
2008-11-08 09:10 . 2008-11-08 09:10 <DIR> d-------- c:\program files\ESET
2008-11-08 09:10 . 2008-11-08 09:10 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\ESET
2008-10-25 00:32 . 2008-11-17 16:27 <DIR> d-------- c:\documents and settings\liRik\Data aplikací\FileZilla
2008-10-23 18:12 . 2008-10-15 17:38 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 17:56 . 2008-10-23 17:56 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\vsosdk
2008-10-21 21:06 . 2008-10-21 21:06 <DIR> d--hs---- C:\found.000
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 15:15 --------- d-----w c:\documents and settings\liRik\Data aplikací\uTorrent
2008-11-18 15:08 --------- d-----w c:\program files\PeerGuardian2
2008-11-17 15:30 --------- d-----w c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-11-17 15:07 --------- d-----w c:\documents and settings\liRik\Data aplikací\gtk-2.0
2008-11-15 14:45 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 13:49 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-14 13:08 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-12 21:38 --------- d-----w c:\documents and settings\All Users\Data aplikací\Microsoft Help
2008-11-08 19:11 --------- d-----w c:\documents and settings\liRik\Data aplikací\SUPERAntiSpyware.com
2008-11-08 17:10 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-02 17:13 --------- d-----w c:\program files\RocketDock
2008-11-02 16:14 --------- d-----w c:\program files\QIP Infium
2008-11-02 12:56 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-01 17:57 --------- d-----w c:\documents and settings\liRik\Data aplikací\Zoner
2008-11-01 17:52 --------- d-----w c:\program files\Zoner
2008-11-01 09:22 --------- d-----w c:\program files\Reference Assemblies
2008-11-01 09:09 --------- d-----w c:\program files\DAEMON Tools Lite
2008-10-30 12:43 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-10-30 12:43 --------- d-----w c:\program files\Java
2008-10-30 12:19 --------- d-----w c:\program files\Opera
2008-10-28 17:55 239,863 ----a-w c:\windows\system32\ati2sgav.exe
2008-10-25 21:49 --------- d-----w c:\program files\Codec Pack - All In 1
2008-10-25 21:48 737,280 ----a-w c:\windows\iun6002.exe
2008-10-24 23:32 --------- d-----w c:\program files\FileZilla FTP Client
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 05:22 --------- d-----w c:\program files\MagicISO
2008-10-23 17:17 --------- d-----w c:\program files\DVDFab 5
2008-10-19 17:06 --------- d-----w c:\documents and settings\liRik\Data aplikací\Skype
2008-10-19 16:42 --------- d-----w c:\documents and settings\liRik\Data aplikací\skypePM
2008-10-18 07:23 505,128 ----a-w c:\windows\system32\msvcp71.dll
2008-10-18 07:23 353,576 ----a-w c:\windows\system32\msvcr71.dll
2008-10-18 07:23 29,480 ----a-w c:\windows\system32\msxml3a.dll
2008-10-18 06:46 --------- d---a-w c:\documents and settings\All Users\Data aplikací\TEMP
2008-10-15 21:05 --------- d-----w c:\program files\MSXML 4.0
2008-10-15 12:20 --------- d-----w c:\documents and settings\All Users\Data aplikací\LightScribe
2008-10-14 20:59 --------- d-----w c:\program files\PSPad editor
2008-10-14 15:50 --------- d-----w c:\documents and settings\liRik\Data aplikací\Nero
2008-10-14 15:47 --------- d-----w c:\program files\Common Files\Nero
2008-10-14 15:40 --------- d-----w c:\program files\Nero
2008-10-14 15:35 --------- d-----w c:\documents and settings\All Users\Data aplikací\Nero
2008-10-14 15:34 --------- d-----w c:\program files\Common Files\LightScribe
2008-10-12 09:31 --------- d-----w c:\program files\Common Files\Adobe
2008-10-11 22:25 --------- d-----w c:\documents and settings\All Users\Data aplikací\IsolatedStorage
2008-10-11 15:47 --------- d-----w c:\program files\Common Files\wsm
2008-10-08 19:17 --------- d-----w c:\program files\uTorrent
2008-10-03 22:17 --------- d-----w c:\program files\GIMP-2.0
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 21:01 --------- d-----w c:\program files\Miranda IM
2008-09-29 15:28 --------- d-----w c:\program files\Mozilla Thunderbird
2008-09-20 11:58 --------- d-----w c:\program files\Total Commander 7.04
2008-09-20 08:38 --------- d-----w c:\program files\CCleaner
2008-09-20 06:54 --------- d-----w c:\program files\Internet Cell Boost
2008-09-19 21:59 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2008-09-18 22:07 --------- d-----w c:\program files\OO Software
2008-09-15 15:27 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:16 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 04:02 730,368 ----a-w c:\windows\system32\oodsvct.exe
2008-09-04 04:02 1,295,616 ----a-w c:\windows\system32\oodag.exe
2008-09-04 04:01 2,524,416 ----a-w c:\windows\system32\oodtray.exe
2008-09-04 04:01 194,816 ----a-w c:\windows\system32\oodbs.exe
2008-09-04 03:58 9,984 ----a-w c:\windows\system32\oodbsrs.dll
2008-09-04 03:58 894,208 ----a-w c:\windows\system32\oodtrrs.dll
2008-09-04 03:58 8,448 ----a-w c:\windows\system32\oodagrs.dll
2008-09-04 03:58 15,616 ----a-w c:\windows\system32\oodagmg.dll
2008-08-30 03:20 15,104 ----a-w c:\windows\system32\ootmapi.dll
2008-08-29 23:53 151,552 ----a-w c:\windows\system32\securenet.dll
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-06-21 126976]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-09-04 2524416]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-10 1447168]
"SoundMan"="SOUNDMAN.EXE" [2004-03-10 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
DSLMON.lnk - c:\program files\ADSL\ADSL USB MODEM\dslmon.exe [2008-06-12 929889]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2008-06-09 09:16 2363392 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\QIP\\qip.exe"=
"d:\\Program Files\\Counter-Strike 1.5\\hl.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Obsah adresáře 'Naplánované úlohy'
2008-11-18 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe []
.
.
------- Doplňkový sken -------
.
FireFox -: Profile - c:\documents and settings\liRik\Data aplikací\Mozilla\Firefox\Profiles\gzvh124a.default\
FF -: plugin - c:\documents and settings\liRik\Local Settings\Data aplikacĂ\Google\Update\1.2.131.25\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Opera\program\plugins\NPOFF12.DLL
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-18 20:49:17
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2008-11-18 20:58:07
ComboFix-quarantined-files.txt 2008-11-18 19:57:53
Před spuštěním: Volných bajtů: 21 295 673 344
Po spuštění: Volných bajtů: 21,283,540,992
202 --- E O F --- 2008-11-16 00:10:02