tadyje tn log a kdyz jsem vypl residentni ochranu a spy bot tak mi vyskocila hlaska z windouws defendru ze nasel Trojan:Win32/Agent.gen!D
a pak cesta C:\32788R22FWJFW\EXEreg.exe
ComboFix 09-10-27.08 - Petr 28.10.2009 17:23.9.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.1526.961 [GMT 0:00]
Spuštěný z: c:\documents and settings\Petr\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 091028-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-28 do 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-28 16:37 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-28 16:37 . 2009-10-28 16:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-28 16:37 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 16:35 . 2009-10-28 16:35 -------- d-----w- c:\windows\LastGood
2009-10-27 22:27 . 2009-10-27 22:27 -------- d-----w- C:\FOUND.044
2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\documents and settings\Petr\Application Data\WinPatrol
2009-10-27 21:09 . 2009-10-27 21:09 -------- d-----w- c:\program files\BillP Studios
2009-10-27 19:05 . 2009-10-27 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Temp
2009-10-26 10:27 . 2009-10-26 10:27 -------- d-----w- c:\program files\Landi2003
2009-10-17 15:12 . 2009-10-17 15:12 -------- d-----w- c:\program files\Common Files\Skype
2009-10-11 14:33 . 2009-10-11 14:33 -------- d-----w- c:\program files\IKEA HomePlanner
2009-10-03 08:51 . 2009-10-01 10:29 195440 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 22:34 . 2006-08-22 06:12 12 ----a-w- c:\windows\bthservsdp.dat
2009-10-26 10:27 . 2009-07-29 19:09 475136 ------w- c:\windows\Setup1.exe
2009-10-26 10:27 . 2009-07-29 19:09 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-09-24 17:41 . 2007-03-10 12:34 46944 ----a-w- c:\documents and settings\Petr\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-19 13:07 . 2009-09-19 13:07 -------- d-----w- c:\documents and settings\Petr\Application Data\jabbim
2009-09-12 13:03 . 2009-09-12 13:03 -------- d--h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-09-11 15:18 . 2004-08-04 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 20:44 . 2009-09-10 20:44 -------- d-----w- c:\documents and settings\Petr\Application Data\vlc
2009-09-06 16:51 . 2009-09-06 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2009-09-04 22:03 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 09:08 . 2006-01-09 11:08 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 09:00 . 2004-08-04 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 17:10 . 2008-05-15 18:11 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 17:06 . 2008-05-15 18:11 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 17:06 . 2008-05-15 18:11 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 17:05 . 2008-05-15 18:31 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 17:05 . 2008-05-15 18:31 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 17:04 . 2008-05-15 18:11 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 17:04 . 2008-05-15 18:11 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 17:03 . 2008-05-15 18:11 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 17:02 . 2008-05-15 18:11 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-06 19:24 . 2004-08-04 05:00 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 19:24 . 2004-08-04 05:00 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 19:24 . 2005-05-26 04:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 19:24 . 2004-08-04 05:00 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 19:24 . 2004-08-04 05:00 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 19:24 . 2004-08-04 05:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 19:23 . 2004-08-04 05:00 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 19:23 . 2007-05-12 19:35 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 19:23 . 2005-05-26 04:19 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 19:23 . 2004-08-04 05:00 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 10:01 . 2004-08-04 05:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 16:13 . 2005-09-28 17:02 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 15:20 . 2005-09-28 16:35 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2004-12-07 09:13 . 2004-12-07 09:13 976020 ----a-w- c:\program files\BDAXP.cab
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Svátky a výročí"="c:\program files\OKsoftware\Svátky a výročí\Vyroci.exe" [2002-11-29 4749824]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 352256]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-21 520024]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Task Catcher"="c:\program files\BillP Studios\Task Catcher\tasktrap.exe" [2005-11-14 136760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"ntiMUI"=c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
"tsnp2std"=c:\windows\tsnp2std.exe
"PCSuiteTrayApplication"=c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"snp2std"=c:\windows\vsnp2std.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"d:\\HRY\\NFS U2\\SPEED2.EXE"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16.3.2009 18:24 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [15.5.2008 18:31 114768]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [12.1.2008 16:25 12856]
R1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [30.3.2008 10:55 115968]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [4.4.2009 17:10 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.5.2008 18:31 20560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 20:06 1028432]
R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [21.4.2006 8:22 70912]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [11.1.2009 22:44 603904]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [4.4.2009 17:10 65576]
S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [6.7.2007 17:28 31768]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - MBR
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-10-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:24]
2009-10-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 21:36]
2009-10-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://seznam.cz/uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/def ... earch.htmluSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.comIE: &ICQ Toolbar Search
IE: ÓA±EIO3«ÁéIÂÔO(&B)
TCP: {F30B0D9C-6DBF-4F30-BA7A-265D561B5F4C} = 10.0.0.4,10.0.0.2
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cabFF - ProfilePath - c:\documents and settings\Petr\Application Data\Mozilla\Firefox\Profiles\bhw1u3w5.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
hxxp://seznam.cz/FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-28 17:33
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-4193024368-3511700768-2906882624-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(532)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Microsoft Private Folder 1.0\ShellExt.dll
c:\windows\system32\PFLib.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2009-10-28 17:37
ComboFix-quarantined-files.txt 2009-10-28 17:37
Před spuštěním: 956 628 992 bytes free
Po spuštění: 1 208 778 752 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - B3FAC78278B891496D4D896E29C8E996