ComboFix 12-12-22.01 - jirik 22.12.2012 12:00:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.894.369 [GMT 1:00]
Spuštěný z: c:\documents and settings\jirik\Plocha\ComboFix.exe\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
c:\windows\system32\SET184.tmp
c:\windows\system32\SET18E.tmp
c:\windows\system32\SET1A9.tmp
c:\windows\system32\SET1AB.tmp
c:\windows\system32\SET1B9.tmp
c:\windows\system32\SET1D9.tmp
c:\windows\system32\SET1DA.tmp
c:\windows\system32\SET2AB.tmp
c:\windows\system32\SET2BE.tmp
c:\windows\system32\SET2CE.tmp
c:\windows\system32\SET2D4.tmp
c:\windows\system32\SET2D6.tmp
c:\windows\system32\SET2DB.tmp
c:\windows\system32\SET305.tmp
c:\windows\system32\SET30A.tmp
c:\windows\system32\SET30D.tmp
c:\windows\system32\SET314.tmp
c:\windows\system32\SET32A.tmp
c:\windows\system32\SET32C.tmp
c:\windows\system32\SET363.tmp
c:\windows\system32\SET365.tmp
c:\windows\system32\SET3E.tmp
c:\windows\system32\SET47.tmp
c:\windows\system32\SET4A.tmp
c:\windows\system32\SET54.tmp
c:\windows\system32\SET89.tmp
c:\windows\system32\SET8D.tmp
c:\windows\system32\SET92.tmp
c:\windows\system32\SET95.tmp
c:\windows\system32\SET97.tmp
c:\windows\system32\SET9C.tmp
c:\windows\system32\SETA2.tmp
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
E:\AUTORUN.INF
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-22 do 2012-12-22 )))))))))))))))))))))))))))))))
.
.
2012-12-21 16:17 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-21 16:17 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-21 16:17 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-21 16:17 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-12-21 16:17 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-21 16:17 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-12-21 16:17 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-12-21 16:17 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-12-21 16:15 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-21 16:15 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-21 16:15 . 2012-12-21 16:15 -------- d-----w- c:\program files\AVAST Software
2012-12-21 16:15 . 2012-12-21 16:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-12-21 16:09 . 2012-12-22 08:33 -------- d-----w- c:\documents and settings\pavla\Data aplikací\vlc
2012-12-21 13:35 . 2012-12-21 13:35 -------- d-----w- c:\documents and settings\pavla\Local Settings\Data aplikací\Google
2012-12-21 13:21 . 2012-12-21 13:22 -------- d-----w- c:\program files\RegCleaner
2012-12-21 13:12 . 2012-12-21 13:12 -------- d-----w- c:\program files\CCleaner
2012-12-21 13:02 . 2012-12-21 13:02 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2012-12-21 13:02 . 2012-12-21 13:02 -------- d-----w- c:\program files\Google
2012-12-21 13:02 . 2012-12-21 13:02 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-21 13:02 . 2012-12-21 13:02 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-21 11:47 . 2012-12-21 11:47 388096 ----a-r- c:\documents and settings\jirik\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-12-21 10:04 . 2012-12-21 10:04 -------- d-----w- c:\documents and settings\jirik\Data aplikací\TeamViewer
2012-12-21 10:04 . 2012-12-21 10:04 -------- d-----w- c:\program files\TeamViewer
2012-12-21 10:00 . 2012-12-21 10:00 -------- d-----w- c:\documents and settings\jirik\Data aplikací\FastStone
2012-12-21 10:00 . 2012-12-21 10:00 -------- d-----w- c:\program files\FastStone Capture
2012-12-21 05:16 . 2012-12-21 05:16 -------- d-----w- c:\documents and settings\jirik\Data aplikací\Malwarebytes
2012-12-21 05:16 . 2012-12-21 05:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-12-21 05:16 . 2012-12-21 05:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-12-21 05:16 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-20 20:26 . 2012-12-20 20:26 -------- d-----w- c:\documents and settings\jirik\Doctor Web
2012-12-20 20:13 . 2012-12-21 16:27 -------- d-----w- c:\documents and settings\jirik\Data aplikací\vlc
2012-12-20 20:12 . 2012-12-20 20:12 -------- d-----w- c:\program files\VideoLAN
2012-12-17 20:01 . 2012-12-21 11:47 -------- d-----w- c:\program files\trend micro
2012-12-17 20:01 . 2012-12-17 20:02 -------- d-----w- C:\rsit
2012-12-13 09:05 . 2012-12-14 05:09 -------- d-----w- c:\program files\Microsoft LifeCam
2012-12-13 09:04 . 2005-05-26 14:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2012-12-13 09:03 . 2008-04-14 04:21 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-12-13 09:03 . 2008-04-14 04:21 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2012-12-13 09:03 . 2008-04-14 03:29 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-12-13 09:03 . 2008-04-14 03:29 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2012-12-13 06:50 . 2008-04-13 19:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2012-12-13 06:50 . 2008-04-13 19:45 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2012-12-13 06:49 . 2012-12-13 06:49 -------- d-----w- c:\program files\Skype
2012-12-13 06:47 . 2008-04-13 19:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-12-13 06:47 . 2008-04-13 19:45 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-16 12:23 . 2005-07-05 14:51 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 11:55 . 2005-07-05 14:52 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-02 02:03 . 2005-07-05 14:52 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:12 . 2005-07-05 14:52 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:12 . 2005-07-05 14:52 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 12:12 . 2005-07-05 14:52 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2005-07-05 14:52 385024 ------w- c:\windows\system32\html.iec
2012-10-02 18:04 . 2005-07-05 14:52 58368 ----a-w- c:\windows\system32\synceng.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\apps\SMP\SmpSys.exe" [2005-12-08 975360]
"ICQ"="c:\program files\ICQ7.4\ICQ.exe" [2011-03-07 119608]
"Skype"="c:\apps\skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-28 766041]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 36975]
"DetectorApp"="c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe" [2005-10-20 102400]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2006-10-12 147456]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-03-06 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-06-29 269104]
"VX1000"="c:\windows\vVX1000.exe" [2006-06-29 707376]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\APPS\\skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [21.12.2012 17:17 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [21.12.2012 17:17 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.12.2012 17:17 21256]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [21.12.2012 6:16 676936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [21.12.2012 6:16 22856]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [13.12.2012 14:26 3290896]
S2 SkypeUpdate;Skype Updater;c:\apps\skype\Updater\Updater.exe [13.7.2012 12:28 160944]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-22 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-12-21 22:50]
.
2012-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-21 13:02]
.
2012-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-21 13:02]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.google.com/uInternet Connection Wizard,ShellNext = iexplore
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-12-22 12:10
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2012-12-22 12:12:54
ComboFix-quarantined-files.txt 2012-12-22 11:12
.
Před spuštěním: Volných bajtů: 18 056 359 936
Po spuštění: Volných bajtů: 18 440 630 272
.
- - End Of File - - 178FAC117611A5EFAF3711BE13D160B0