z MbAM:Malwarebytes' Anti-Malware 1.45
http://www.malwarebytes.orgVerze databáze: 3930
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
20.3.2011 11:35:16
mbam-log-2011-03-20 (11-35-16).txt
Typ skenu: Rychlý sken
Skenované objekty: 132551
Uplynulý čas: 20 minuta(y), 17 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 3
Infikované hodnoty registru: 0
Infikované datové položky registru: 3
Infikované složky: 0
Infikované soubory: 3
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe pgsb.lto csxyfxr) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
C:\DelUS.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\s32.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\ws386.ini (Malware.Trace) -> Quarantined and deleted successfully.
z ComboFix:ComboFix 11-03-19.03 - Administrator 20.03.2011 12:12:34.1.1 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.318 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Norton AntiVirus 2005 *Disabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Jirka\Data aplikací\PriceGong
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Jirka\Data aplikací\PriceGong\Data\z.xml
c:\documents and settings\Jirka\WALKMAN NWZ-B135 .lnk
c:\documents and settings\Ucetni\Data aplikací\PriceGong
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Ucetni\Data aplikací\PriceGong\Data\z.xml
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\g32.txt
c:\windows\ST6UNST.000
c:\windows\system32\569569569569
c:\windows\system32\569569569569\2898.15449
c:\windows\system32\569569569569\adresy.txt
c:\windows\system32\drivers\imfojji.sys
c:\windows\system32\Filters
c:\windows\system32\Filters\AviSplitter.ax
c:\windows\system32\Filters\ffdshow\ffdshow.ax
c:\windows\system32\Filters\FLVSplitter.ax
c:\windows\system32\Filters\MatroskaSplitter.ax
c:\windows\system32\Filters\MP4Splitter.ax
c:\windows\system32\Filters\RealMediaSplitter.ax
c:\windows\system32\Filters\VSFilter.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ASPIMGR
-------\Service_lvwqy
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-20 do 2011-03-20 )))))))))))))))))))))))))))))))
.
.
2011-03-20 09:26 . 2010-03-29 14:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-20 09:26 . 2011-03-20 09:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-20 09:26 . 2011-03-20 09:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-03-20 09:26 . 2010-03-29 14:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-19 17:24 . 2011-03-20 11:32 -------- d-----w- c:\documents and settings\Administrator
2011-03-10 22:27 . 2011-03-10 22:27 -------- d-----w- c:\program files\Google
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-03 15:51 . 2011-01-03 15:51 1409 ----a-w- c:\windows\QTFont.for
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\DVDVideoSoftTB\tbDVD0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-02-22 58984]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-09-16 100056]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"wcmdmgr"="c:\windows\wt\updater\wcmdmgrl.exe" [2002-09-27 20480]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SchedulingAgent"="mstinit.exe" [2004-08-18 12288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-03-29 1086856]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HD Writer AE 1.0.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HD Writer AE 1.0.lnk
backup=c:\windows\pss\HD Writer AE 1.0.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
2002-12-04 00:24 184800 ----a-w- c:\program files\WildTangent\Apps\GameChannel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Jirka\\Data aplikací\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\\Documents and Settings\\All Users\\Dokumenty\\hry\\bulanci.exe"=
"c:\\Program Files\\Atari\\Deer Hunter 2005\\DH2005.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7281:TCP"= 7281:TCP:lhkuzjs
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-04 691696]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 wkveytxc;Microsoft Installer;c:\windows\system32\svchost.exe [2004-08-18 14336]
R3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;c:\windows\system32\DRIVERS\RTL8150.SYS [2002-02-22 26505]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wkveytxc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-18 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-09-22 11:26]
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\www
TCP: {49CDC4BE-A308-49AB-8307-AB978DA64830} = 10.0.1.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {50E43D86-A74D-11D0-98CE-004005249458} -
hxxps://www.mojebanka.cz/jars/confwiz/MVSGif.cabFF - ProfilePath -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe
AddRemove-Any Flv Player_is1 - c:\program files\Any Flv Player\unins000.exe
AddRemove-Defense Commander - c:\program files\Defense Commander\Uninst.isu
AddRemove-Easy GIF Animator_is1 - c:\documents and settings\Jirka\Plocha\Prezantace_ministerstvo pro mistni rozvoj\Easy GIF Animator\unins000.exe
AddRemove-Worm Wars - c:\program files\Jacobs\Worm Wars\DeIsL1.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-20 12:38
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wkveytxc]
"ServiceDll"="c:\windows\system32\jawmh.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2011-03-20 12:47:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-20 11:47
.
Před spuštěním: Volných bajtů: 10 294 382 592
Po spuštění: Volných bajtů: 10 751 098 880
.
- - End Of File - - 035CA0FD55320E2A594973A0E5DC60DE