ComboFix 11-03-15.03 - Miroslav 16.03.2011 17:36:14.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.1027 [GMT 1:00]
Spuštěný z: c:\documents and settings\Miroslav\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\winhelp.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-16 do 2011-03-16 )))))))))))))))))))))))))))))))
.
.
2011-03-16 15:48 . 2011-03-16 15:48 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Malwarebytes
2011-03-16 15:47 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-16 15:47 . 2011-03-16 15:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-03-16 15:47 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-16 15:47 . 2011-03-16 15:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-16 15:36 . 2011-03-16 15:36 -------- d-----w- c:\documents and settings\Miroslav\DoctorWeb
2011-03-16 15:03 . 2011-03-16 15:03 388096 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-16 15:03 . 2011-03-16 15:03 -------- d-----w- c:\program files\Trend Micro
2011-03-16 14:57 . 2011-03-16 15:36 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-03-16 14:57 . 2011-03-16 14:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-16 14:34 . 2011-03-16 16:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-03-16 14:34 . 2011-03-16 14:34 -------- d-----w- c:\program files\AVAST Software
2011-03-16 09:39 . 2011-03-16 15:57 -------- d-----w- C:\LFS
2011-03-15 14:03 . 2001-05-11 12:18 420240 ----a-w- c:\windows\system32\mpg4c32.dll
2011-03-15 14:03 . 2001-03-26 03:41 245760 ----a-w- c:\windows\system32\mp4sds32.ax
2011-03-15 14:01 . 2011-03-16 11:07 -------- d-----w- c:\program files\Codemasters
2011-03-14 16:14 . 2000-08-14 14:41 283648 ----a-w- c:\windows\uninst.exe
2011-03-14 16:13 . 2011-03-14 16:13 -------- d-----w- c:\program files\Handmark
2011-03-14 16:07 . 2011-03-14 16:07 -------- d-----w- c:\program files\Jamdat
2011-03-14 16:05 . 2011-03-14 16:05 -------- d-----w- c:\program files\ZIO
2011-03-14 15:59 . 1999-12-17 09:13 86016 ----a-w- c:\windows\unvise32.exe
2011-03-14 15:59 . 2011-03-14 15:59 -------- d-----w- c:\program files\Hexacto Games
2011-03-14 15:53 . 2011-03-14 15:53 -------- d-----w- c:\program files\ZIO Interactive
2011-03-14 08:47 . 2011-03-14 08:47 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Google
2011-03-14 08:37 . 2011-03-14 08:37 -------- d-----w- c:\program files\Google
2011-03-10 10:55 . 2011-03-10 10:55 -------- d-----w- c:\program files\Astraware
2011-03-10 07:53 . 2003-07-12 17:35 231936 ----a-w- c:\windows\epsuninst.exe
2011-03-07 14:58 . 2011-03-07 15:07 -------- d-----w- c:\program files\MDM
2011-03-07 14:58 . 2002-08-05 09:46 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2011-03-07 14:58 . 2002-08-02 01:20 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2011-03-07 14:58 . 2002-08-02 01:20 151552 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2011-03-07 14:58 . 2011-03-07 14:58 270468 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2011-03-07 14:58 . 2011-03-07 14:58 159876 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2011-03-07 14:58 . 2002-08-02 02:10 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2011-03-07 14:58 . 2002-08-02 01:20 634880 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2011-03-07 14:50 . 2011-03-14 16:14 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-03-01 16:57 . 2011-03-01 16:57 -------- d-----w- C:\DRIVERS
2011-02-27 12:38 . 2007-12-18 20:46 165232 ---ha-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Virtual PC\VPCKeyboard.dll
2011-02-27 12:38 . 2007-08-02 03:45 144800 ----a-r- c:\windows\system32\VMNetSrv.dll
2011-02-27 12:38 . 2007-08-02 03:40 59280 ----a-r- c:\windows\system32\drivers\VMNetSrv.sys
2011-02-25 11:50 . 2011-03-16 15:03 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\skypePM
2011-02-25 11:47 . 2011-02-25 11:47 -------- d-----w- c:\program files\Common Files\Skype
2011-02-25 11:47 . 2011-02-25 11:47 -------- d-----r- c:\program files\Skype
2011-02-25 11:47 . 2011-03-16 14:54 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Skype
2011-02-25 11:47 . 2011-02-25 11:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-02-22 16:58 . 2011-02-22 16:58 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\OpenOffice.org
2011-02-22 16:50 . 2011-02-22 16:50 -------- d-----w- c:\program files\OpenOffice.org 3
2011-02-19 13:32 . 2011-02-19 13:32 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Temp
2011-02-19 13:32 . 2011-02-19 13:32 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Adobe
2011-02-19 10:26 . 2005-05-26 14:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2011-02-19 10:24 . 2011-02-19 10:26 -------- d--h--w- c:\windows\msdownld.tmp
2011-02-19 10:24 . 2011-02-19 10:24 -------- d-----w- c:\windows\Logs
2011-02-19 10:20 . 2005-03-08 09:52 1871872 ----a-w- c:\windows\system32\vticd.dll
2011-02-19 10:20 . 2005-03-08 09:50 172544 ----a-w- c:\windows\system32\drivers\vtmini.sys
2011-02-19 10:20 . 2005-03-08 09:50 3453824 ----a-w- c:\windows\system32\vtdisp.dll
2011-02-19 10:20 . 2005-03-08 02:33 53248 ----a-w- c:\windows\system32\VTTimer.exe
2011-02-19 10:20 . 2005-01-11 05:34 360448 ----a-w- c:\windows\system32\VTGamma2.dll
2011-02-19 10:20 . 2005-01-11 02:29 487424 ----a-w- c:\windows\system32\VTDisply.dll
2011-02-19 10:20 . 2005-01-11 02:24 389120 ----a-w- c:\windows\system32\VTovrlay.dll
2011-02-19 10:20 . 2004-12-08 08:03 253952 ----a-w- c:\windows\system32\VTInfo2.dll
2011-02-19 10:02 . 2003-08-05 13:14 77056 ----a-r- c:\windows\system32\drivers\viasraid.sys
2011-02-19 09:54 . 2011-02-19 09:54 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2011-02-19 09:38 . 2006-02-23 10:38 9728 ----a-r- c:\windows\system32\drivers\videX32.sys
2011-02-19 09:37 . 2011-02-19 09:38 -------- d-----w- c:\program files\VIA
2011-02-19 09:37 . 2006-03-31 01:18 100992 ----a-w- c:\windows\system32\drivers\viamraid.sys
2011-02-19 09:15 . 2011-02-19 09:15 -------- d-----w- c:\windows\nview
2011-02-19 09:15 . 2011-02-19 09:15 -------- d-----w- C:\NVIDIA
2011-02-18 20:46 . 2011-02-18 20:46 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2011-02-18 20:38 . 2011-02-18 20:38 -------- d-----w- c:\program files\TDK
2011-02-17 18:00 . 2011-02-17 18:00 -------- d-----w- c:\documents and settings\Administrator
2011-02-17 17:16 . 2011-02-17 17:16 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Mael
2011-02-17 17:12 . 2011-02-17 17:12 -------- d-----w- c:\program files\HxD
2011-02-17 16:44 . 2011-02-17 16:44 -------- d-----w- c:\program files\Common Files\Adobe
2011-02-17 11:20 . 2011-02-17 11:20 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-02-17 11:20 . 2006-08-15 10:42 200704 ----a-w- c:\windows\system32\UpdateDriver.exe
2011-02-17 11:20 . 2011-02-17 11:20 -------- d-----w- c:\program files\Belkin
2011-02-17 11:20 . 2011-02-17 11:20 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\InstallShield
2011-02-15 10:45 . 2011-02-15 10:45 -------- d-----w- c:\program files\XP Codec Pack
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-13 16:25 . 2011-02-13 16:25 71680 ----a-w- c:\windows\system32\drivers\nhcDriver.sys
2011-01-22 17:14 . 2011-01-22 17:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-01-22 17:14 . 2011-01-22 17:14 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-01-22 17:13 . 2011-01-22 17:13 737280 ----a-w- c:\windows\iun6002.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Miroslav\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Ralink Wireless Utility.lnk - d:\ralink\RT7x Wireless LAN Card\Installer\WINXP\RaUI.exe [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-15 20:02 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 07:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-01-22 17:14 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2005-03-08 02:33 53248 ----a-w- c:\windows\system32\VTTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServiceLayer"=3 (0x3)
"idsvc"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [19.2.2011 10:54 23456]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [27.1.2011 20:22 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [27.1.2011 20:22 8576]
S3 S3chipid;S3chipid;\??\c:\docume~1\Miroslav\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys --> c:\docume~1\Miroslav\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys [?]
S3 VMMDriver;VMM Driver;\??\c:\documents and settings\Miroslav\Plocha\Microsoft Virtual PC - Portable\Microsoft Virtual PC - Portable\Portable Microsoft Virtual Pc 2007\Appdata\bin\VMM\VMM.sys --> c:\documents and settings\Miroslav\Plocha\Microsoft Virtual PC - Portable\Microsoft Virtual PC - Portable\Portable Microsoft Virtual Pc 2007\Appdata\bin\VMM\VMM.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1214440339-1364589140-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
.
2011-03-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1214440339-1364589140-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-16 17:45
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2011-03-16 17:47:26
ComboFix-quarantined-files.txt 2011-03-16 16:47
.
Před spuštěním: 4 948 135 936
Po spuštění: 4 921 311 232
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 5FC76077D1A98894BC59228E47A3A09A