ComboFix 11-05-02.04 - Miroslav 03.05.2011 17:04:20.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.867 [GMT 2:00]
Spuštěný z: c:\documents and settings\Miroslav\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Miroslav\Plocha\CFScript.txt
.
FILE ::
"c:\documents and settings\Miroslav\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll"
"c:\windows\system32\sysconfig.exe"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1214440339-1364589140-725345543-1003.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1214440339-1364589140-725345543-1003.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\aports.dll
c:\program files\Spybot - Search & Destroy\Plugins\Fennel.dll
c:\program files\Spybot - Search & Destroy\Plugins\Chai.dll
c:\program files\Spybot - Search & Destroy\Plugins\Mate.dll
c:\program files\Spybot - Search & Destroy\Plugins\TCPIPAddress.dll
c:\program files\Spybot - Search & Destroy\SpybotSD.exe
c:\program files\Spybot - Search & Destroy\sqlite3.dll
c:\program files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\Spybot - Search & Destroy\Tools.dll
c:\windows\system32\sysconfig.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1214440339-1364589140-725345543-1003.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1214440339-1364589140-725345543-1003.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ICQ_SERVICE
-------\Service_ICQ Service
-------\Service_VMMDriver
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-03 do 2011-05-03 )))))))))))))))))))))))))))))))
.
.
2011-05-02 14:33 . 2011-05-03 14:06 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\TEMP
2011-05-02 14:24 . 2011-05-02 14:24 -------- d-----w- c:\windows\Sun
2011-04-29 13:35 . 2010-09-01 15:32 140752 ----a-w- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-04-29 13:35 . 2011-05-03 12:59 -------- d-----w- c:\program files\QIP Infium
2011-04-29 13:03 . 2011-04-29 13:03 -------- d-----w- c:\program files\ACQPR
2011-04-29 12:40 . 2011-04-29 12:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ICQ
2011-04-29 12:39 . 2011-04-29 12:40 -------- d-----w- c:\program files\ICQ FORCE
2011-04-29 12:36 . 2011-04-29 12:36 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Miranda
2011-04-29 12:36 . 2011-04-29 12:36 -------- d-----w- c:\program files\Miranda IM
2011-04-29 12:31 . 2011-04-29 12:31 -------- d-----w- c:\program files\WinPcap
2011-04-28 15:37 . 2011-04-28 15:37 -------- d-----w- c:\documents and settings\Miroslav\VirtualBox VMs
2011-04-28 15:37 . 2011-04-28 15:40 -------- d-----w- c:\documents and settings\Miroslav\.VirtualBox
2011-04-28 15:37 . 2011-04-28 15:37 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Thinstall
2011-04-28 15:37 . 2011-04-28 15:37 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Thinstall
2011-04-16 07:13 . 2011-04-16 07:13 -------- d-----w- c:\program files\Common Files\Java
2011-04-16 07:12 . 2011-04-16 07:12 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-16 07:12 . 2011-04-16 07:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-16 07:12 . 2011-04-16 07:12 -------- d-----w- c:\program files\Java
2011-04-13 15:00 . 2011-04-13 15:00 -------- d-----w- c:\documents and settings\Bláňa\Data aplikací\PC Suite
2011-04-12 18:54 . 2011-04-12 18:55 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\PC Suite
2011-04-12 18:54 . 2011-04-12 18:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PC Suite
2011-04-12 18:54 . 2011-04-12 18:54 -------- d-----w- c:\program files\Common Files\PCSuite
2011-04-12 18:53 . 2008-08-26 07:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2011-04-12 18:53 . 2011-04-12 18:53 -------- d-----w- c:\program files\PC Connectivity Solution
2011-04-12 18:53 . 2010-07-30 12:16 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2011-04-12 18:53 . 2010-07-30 12:16 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2011-04-12 18:53 . 2010-07-30 12:16 23040 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2011-04-12 18:53 . 2010-07-30 12:16 18048 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2011-04-12 18:53 . 2010-07-30 12:17 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2011-04-12 13:44 . 2011-04-12 13:44 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nokia
2011-04-12 13:31 . 2011-04-12 18:59 -------- d-----w- c:\program files\Common Files\Nokia
2011-04-04 18:13 . 2011-04-04 18:13 162816 ----a-w- c:\windows\system32\fmod.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-16 15:03 . 2011-03-16 15:03 388096 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-19 09:54 . 2011-02-19 09:54 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2011-02-18 20:46 . 2011-02-18 20:46 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2011-02-17 11:20 . 2011-02-17 11:20 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-02-13 16:25 . 2011-02-13 16:25 71680 ----a-w- c:\windows\system32\drivers\nhcDriver.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-03_14.26.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-03 15:10 . 2011-05-03 15:10 16384 c:\windows\temp\Perflib_Perfdata_24c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2011-01-22 202256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Ralink Wireless Utility.lnk - d:\ralink\RT7x Wireless LAN Card\Installer\WINXP\RaUI.exe [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Miroslav^Nabídka Start^Programy^Po spuštění^MagicDisc.lnk]
path=c:\documents and settings\Miroslav\Nabídka Start\Programy\Po spuštění\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Miroslav^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\Miroslav\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-15 20:02 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 07:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-01-31 10:16 703360 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-26 16:05 15026056 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-01-22 17:14 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2005-03-08 02:33 53248 ----a-w- c:\windows\system32\VTTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServiceLayer"=3 (0x3)
"idsvc"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3.4.2011 9:23 136176]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [19.2.2011 11:54 23456]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2.8.2005 23:10 32512]
.
.
------- Doplňkový sken -------
.
uSearchAssistant =
hxxp://search.qip.ru/ieIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-03 17:12
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(4060)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\windows\system32\devldr32.exe
c:\progra~1\MICROS~2\rapimgr.exe
.
**************************************************************************
.
Celkový čas: 2011-05-03 17:15:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-03 15:15
ComboFix2.txt 2011-05-03 14:28
.
Před spuštěním: 7 019 171 840
Po spuštění: 6 959 968 256
.
- - End Of File - - E0EF9C635E0BADD61A6F0F7D532DDCF5