ComboFix 09-02-12.03 - User 2009-02-13 12:03:03.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.2046.1554 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090212-0] *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\A360
c:\program files\A360\av360.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-13 to 2009-02-13 )))))))))))))))))))))))))))))))
.
2009-02-13 10:41 . 2009-02-13 10:41 <DIR> d-------- c:\program files\Trend Micro
2009-02-12 20:27 . 2009-02-12 20:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2009-02-12 20:26 . 2009-02-12 20:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-02-12 20:25 . 2009-02-12 20:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-12 20:22 . 2009-02-12 20:22 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-12 19:24 . 2009-02-12 19:29 <DIR> d-------- c:\program files\Lavasoft
2009-02-12 19:07 . 2009-02-12 20:10 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-12 17:44 . 2009-02-12 17:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2009-02-12 17:07 . 2009-02-12 19:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-12 16:35 . 2009-02-12 16:35 298,496 --a------ c:\windows\system32\winconfig.dll
2009-02-10 18:31 . 2009-02-10 18:32 <DIR> d-------- c:\documents and settings\User\Application Data\U3
2009-02-08 13:15 . 2009-02-08 13:15 <DIR> d-------- c:\documents and settings\User\OngameNetwork
2009-02-08 13:14 . 2009-02-08 13:14 <DIR> d-------- c:\windows\Sun
2009-02-08 13:09 . 2009-02-08 13:09 <DIR> d-------- c:\program files\Java
2009-02-08 13:09 . 2009-02-08 13:09 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-08 13:09 . 2009-02-08 13:09 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-07 16:53 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-07 16:53 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-02-07 16:52 . 2008-04-13 19:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-07 16:52 . 2008-04-13 19:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 10:55 --------- d-----w c:\documents and settings\User\Application Data\Skype
2009-02-13 10:43 --------- d-----w c:\documents and settings\User\Application Data\skypePM
2009-01-16 17:15 --------- d-----w c:\documents and settings\User\Application Data\MSN6
2009-01-11 18:37 --------- d-----w c:\documents and settings\All Users\Application Data\MSN6
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-18 22:30 --------- d-----w c:\documents and settings\User\Application Data\DivX
2008-12-18 18:11 --------- d-----w c:\program files\Opera
2008-12-17 15:22 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-17 15:22 --------- d-----w c:\program files\ViaVoiceTTS
2008-12-17 15:20 --------- d-----w c:\program files\Commercial Service
2008-12-17 11:55 --------- d-----w c:\program files\Nero
2008-12-17 11:55 --------- d-----w c:\program files\Common Files\Ahead
2008-12-17 11:55 --------- d-----w c:\documents and settings\User\Application Data\Ahead
2008-12-17 10:36 --------- d-----w c:\program files\iTunes
2008-12-17 10:36 --------- d-----w c:\program files\iPod
2008-12-17 10:36 --------- d-----w c:\program files\Common Files\Apple
2008-12-17 10:36 --------- d-----w c:\documents and settings\User\Application Data\Apple Computer
2008-12-17 10:36 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-17 10:36 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-17 10:35 --------- d-----w c:\program files\QuickTime
2008-12-17 10:35 --------- d-----w c:\program files\Bonjour
2008-12-17 10:34 --------- d-----w c:\program files\Apple Software Update
2008-12-17 10:34 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-12-17 10:13 --------- d-----w c:\documents and settings\User\Application Data\Windows Search
2008-12-17 10:00 --------- d-----w c:\program files\Mobility Manager
2008-12-17 09:33 --------- d-----w c:\documents and settings\User\Application Data\Windows Desktop Search
2008-12-17 09:32 --------- d-----w c:\program files\Windows Desktop Search
2008-12-17 09:13 --------- d--h--w c:\program files\Zero G Registry
2008-12-17 08:57 --------- d-----w c:\program files\Skype
2008-12-17 08:57 --------- d-----w c:\program files\Common Files\Skype
2008-12-17 08:57 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-12-17 08:08 --------- d-----w c:\program files\MSXML 4.0
2008-12-16 14:52 --------- d-----w c:\program files\Microsoft Works
2008-12-16 14:52 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-16 14:41 --------- d-----w c:\program files\Common Files\Logitech
2008-12-16 14:40 --------- d-----w c:\program files\Common Files\Acer
2008-12-16 14:40 --------- d-----w c:\program files\Acer
2008-12-16 14:20 --------- d-----w c:\program files\WIDCOMM
2008-12-16 14:19 --------- d-----w c:\program files\CyberLink
2008-12-16 14:19 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-12-16 14:18 --------- d-----w c:\program files\CONEXANT
2008-12-16 14:09 --------- d-----w c:\program files\Realtek
2008-12-16 13:59 --------- d-----w c:\documents and settings\User\Application Data\Acer
2008-12-16 13:52 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-16 13:51 --------- d-----w c:\program files\DivX
2008-12-16 13:46 --------- d-----w c:\program files\Gabest
2008-12-16 13:43 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-16 13:42 --------- d-----w c:\program files\Common Files\Adobe
2008-12-16 13:38 --------- d-----w c:\program files\Alwil Software
2008-12-16 12:58 --------- d-----w c:\program files\Intel
2008-12-16 12:31 --------- d-----w c:\program files\microsoft frontpage
2008-12-16 12:30 558,142 ----a-w c:\windows\java\Packages\2U0OTBVP.ZIP
2008-12-16 12:30 155,995 ----a-w c:\windows\java\Packages\PF5JBLZT.ZIP
2008-11-21 21:47 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-11-21 21:47 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-11-21 21:47 129,784 ------w c:\windows\system32\pxafs.dll
2008-11-21 21:47 120,056 ------w c:\windows\system32\pxcpyi64.exe
2008-11-21 21:47 118,520 ------w c:\windows\system32\pxinsi64.exe
2008-11-21 21:46 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-11-21 21:46 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-11-21 21:44 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-11-21 21:44 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}]
2009-02-12 16:35 298496 --a------ c:\windows\system32\winconfig.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-25 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-21 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-21 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-08-16 53248]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 304664]
"AcerOrbicamRibbon"="c:\program files\Acer\OrbiCam10\OrbiCam.exe" [2006-11-28 754712]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 244512]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-08 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"nwiz"="nwiz.exe" [2006-07-21 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-16 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-08-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 618557]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-12 20560]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [2008-12-16 847392]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2002-08-29 69120]
S3 FlrnUSB;Leadtek USB Network Interface;c:\windows\system32\DRIVERS\LtkUSB.sys --> c:\windows\system32\DRIVERS\LtkUSB.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3877d73a-f74b-11dd-8edb-0018de269146}]
\Shell\AutoRun\command - G:\f.exe
\Shell\explore\Command - G:\f.exe
\Shell\open\Command - G:\f.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-197F68A42D8C97991BFB963C9CEE5B1F - c:\program files\A360\av360.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.sk/uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\zjcpysn3.default\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-13 12:04:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-13 12:05:32
ComboFix-quarantined-files.txt 2009-02-13 11:05:30
Pre-Run: 57 813 471 232 bytes free
Post-Run: 8 adresárov, 58,030,108,672 voľných bajtov
195 --- E O F --- 2009-02-11 22:56:20