ComboFix 10-08-03.02 - Sulcar 04.08.2010 16:00:43.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1358 [GMT 2:00]
Spuštěný z: c:\documents and settings\Sulcar\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Sulcar\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FILE ::
"c:\windows\iun6002.exe"
"c:\windows\system32\KGyGaAvL.sys"
"c:\windows\system32\perfc005.dat"
"c:\windows\system32\perfh005.dat"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\iun6002.exe
c:\windows\system32\KGyGaAvL.sys
c:\windows\system32\perfc005.dat
c:\windows\system32\perfh005.dat
Nakažená kopie c:\windows\system32\kernel32.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\$NtServicePackUninstall$\kernel32.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-04 do 2010-08-04 )))))))))))))))))))))))))))))))
.
2010-08-04 06:16 . 2010-08-04 06:16 -------- d-----w- c:\program files\Recuva
2010-08-03 13:30 . 2010-08-03 13:30 -------- d-----w- c:\program files\TrendMicro
2010-08-03 06:08 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-03 06:08 . 2010-08-03 06:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-03 06:08 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-03 05:57 . 2010-08-03 05:57 -------- d-----w- c:\windows\system32\NtmsData
2010-08-02 07:12 . 2010-08-02 07:14 -------- d-----w- c:\program files\QuickTime
2010-08-02 07:11 . 2010-08-02 07:11 -------- d-----w- c:\program files\Common Files\Apple
2010-08-02 07:10 . 2010-08-02 07:10 -------- d-----w- c:\program files\Apple Software Update
2010-07-27 15:40 . 2007-04-24 17:36 41856 ----a-w- c:\windows\system32\drivers\tosrfusb.sys
2010-07-27 15:40 . 2007-04-24 11:20 113920 ----a-w- c:\windows\system32\drivers\tosrfbd.sys
2010-07-27 15:40 . 2007-03-01 14:53 73728 ----a-w- c:\windows\system32\drivers\Tosrfhid.sys
2010-07-27 15:40 . 2006-11-20 15:55 36480 ----a-w- c:\windows\system32\drivers\tosrfbnp.sys
2010-07-27 15:40 . 2007-01-22 08:43 53376 ----a-w- c:\windows\system32\drivers\TosRfSnd.sys
2010-07-27 15:40 . 2005-08-01 14:45 64896 ----a-w- c:\windows\system32\drivers\tosrfcom.sys
2010-07-27 15:40 . 2005-01-06 11:42 18612 ----a-w- c:\windows\system32\drivers\tosrfnds.sys
2010-07-27 15:40 . 2006-10-10 17:33 41600 ----a-w- c:\windows\system32\drivers\tosporte.sys
2010-07-27 15:39 . 2010-07-27 15:39 -------- d-----w- c:\program files\Toshiba
2010-07-14 04:00 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-12 11:00 . 2010-07-12 13:23 -------- d-----w- c:\program files\Radio Decoder
2010-07-08 06:43 . 2010-07-08 13:12 -------- d-----w- C:\TECDOC_CD
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-04 13:59 . 2010-04-12 11:23 -------- d-----w- c:\program files\GoQ - NetRadio
2010-08-04 13:55 . 2010-04-13 07:39 -------- d-----w- c:\program files\AUTOSERVIS
2010-08-04 10:49 . 2010-04-13 12:57 4 ----a-w- c:\windows\vx86036.dat
2010-08-04 07:49 . 2010-01-30 07:05 -------- d-----w- c:\program files\Lexmark X1100 Series
2010-08-03 14:06 . 2010-04-11 22:57 -------- d-----w- c:\program files\AIDA32 - Enterprise System Information
2010-07-26 17:39 . 2010-04-12 11:55 397312 ----a-w- c:\windows\esi_kl01.dat
2010-07-07 18:08 . 2010-04-12 08:46 120 ---ha-r- c:\windows\ssystda.dat
2010-07-02 10:43 . 2010-07-02 10:43 95896 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-07-02 10:43 . 2010-07-02 10:43 140752 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-06-28 12:12 . 2010-04-13 13:19 -------- d-----w- c:\program files\eTECH
2010-06-17 07:36 . 2006-11-22 06:01 180480 ----a-w- c:\windows\system32\drivers\yk51x86.sys
2010-06-14 14:31 . 2010-04-11 22:41 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-10 04:28 . 2010-04-12 10:43 -------- d-----w- c:\program files\ICQ7.1
2010-06-07 15:51 . 2010-04-11 22:42 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-06-07 15:51 . 2010-04-11 22:42 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-06-07 12:22 . 2010-06-07 12:22 -------- d-----w- c:\program files\ESET
2010-04-22 14:13 . 2010-04-22 14:13 7153319 ----a-w- c:\program files\AUTOSERVIS.zip
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Sulcar\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-04-12 136176]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-17 17508864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2009-12-11 614400]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-07-30 98304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-07-02 2202704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2010-06-08 11:39 133368 ----a-w- c:\program files\ICQ7.1\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
2003-08-19 14:36 57344 ----a-w- c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.4.2010 13:50 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [28.4.2010 8:17 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2.7.2010 12:43 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2.7.2010 12:43 810144]
R2 hlemu;hlemu;c:\windows\system32\drivers\hlemu.sys [12.4.2010 18:38 97792]
R2 SBS_GM_TOMCAT6;SBS_GM_TOMCAT6;c:\program files\Snap-on Business Solutions\Global EPC\GM\Tomcat\bin\tomcat6.exe [5.5.2007 2:42 57344]
R2 SBS_GM_TRANSBASE;SBS_GM_TRANSBASE;c:\program files\Snap-on Business Solutions\Global EPC\GM\Transbase\tbmux32.exe [27.11.2007 12:33 417792]
R2 Transbase TECDOC CD 3_2010 Service;Transbase TECDOC CD 3_2010 Service;c:\tecdoc_cd\3_2010\db\tbmux32.exe [4.6.2010 13:30 356352]
R2 WorkshopDBService;WorkshopDBService;c:\progra~1\eTECH\ORGANI~1.EXE -zglaxservice WorkshopDBService --> c:\progra~1\eTECH\ORGANI~1.EXE -zglaxservice WorkshopDBService [?]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29.9.2009 8:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29.9.2009 8:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29.9.2009 8:11 12928]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [12.4.2010 17:48 97792]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [12.4.2010 1:20 1684736]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\axtmvflt.sys [12.4.2010 9:41 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\axtmvmdm.sys [12.4.2010 9:41 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\axtmvprt.sys [12.4.2010 9:41 38784]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
FF - ProfilePath - c:\documents and settings\Sulcar\Data aplikací\Mozilla\Firefox\Profiles\0cohzxm4.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Radio Decoder - c:\windows\iun6002.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-04 16:12
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spks.sys >>UNKNOWN [0x8A638938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e74cb8
\Driver\atapi -> atapi.sys @ 0xb9e09b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9d12bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d1fa21
SendHandler -> NDIS.sys @ 0xb9cfd87b
user & kernel MBR OK
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\eTECH\ORGANI~1.EXE
c:\program files\eTECH\jre\bin\java.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Snap-on Business Solutions\Global EPC\GM\Transbase\tbkern32.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Snap-on Business Solutions\Global EPC\GM\Transbase\tbkern32.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-08-04 16:22:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-04 14:22
ComboFix2.txt 2010-08-04 07:09
Před spuštěním: Volných bajtů: 53 175 681 024
Po spuštění: Volných bajtů: 53 357 199 360
- - End Of File - - 5C451FF699E66D3E460C928B7260DAC7