Konečně jsem se ktomu dostal a vy až se dostanete od pípy se na to podívejte
ComboFix 09-09-18.02 - Petr 19.09.2009 22:58.8.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.247 [GMT 2:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-08-19 do 2009-09-19 )))))))))))))))))))))))))))))))
.
2009-09-18 18:07 . 2009-09-18 18:08 -------- d-----w- c:\program files\VirtualDJ
2009-09-16 19:25 . 2009-09-16 19:25 -------- d-----w- c:\program files\Meizu
2009-09-16 17:40 . 2009-09-16 17:57 -------- d-----w- c:\program files\WebSite X5 v8 - Evolution
2009-09-16 17:39 . 1997-01-15 22:00 29696 ----a-w- c:\windows\system32\VB5STKIT.DLL
2009-09-16 17:39 . 2009-03-15 15:35 207872 ----a-w- c:\windows\system32\iwpsetup.exe
2009-09-13 16:02 . 2001-08-23 16:58 462848 ----a-w- c:\windows\system32\ippcva611.dll
2009-09-13 16:02 . 2001-08-23 16:58 1359872 ----a-w- c:\windows\system32\ippsa611.dll
2009-09-13 16:02 . 2001-08-23 16:58 151552 ----a-w- c:\windows\system32\ippja611.dll
2009-09-13 16:02 . 2001-08-23 16:58 77824 ----a-w- c:\windows\system32\ippsr11.dll
2009-09-13 16:02 . 2001-08-23 16:58 184320 ----a-w- c:\windows\system32\ippsra611.dll
2009-09-13 16:02 . 2001-08-23 16:58 2428928 ----a-w- c:\windows\system32\ippia611.dll
2009-09-13 16:02 . 2001-08-23 16:58 176128 ----a-w- c:\windows\system32\ipps11.dll
2009-09-13 16:02 . 2001-08-23 16:58 65536 ----a-w- c:\windows\system32\ippj11.dll
2009-09-13 16:02 . 2001-08-23 16:58 225280 ----a-w- c:\windows\system32\ippi11.dll
2009-09-13 16:02 . 2001-08-23 16:58 94208 ----a-w- c:\windows\system32\ippcv11.dll
2009-09-13 16:02 . 2001-03-10 15:56 40960 ----a-w- c:\windows\system32\IPPCPUID.DLL
2009-09-13 15:59 . 1997-10-14 03:19 11776 ----a-w- c:\windows\system32\pmsbfn32.dll
2009-09-13 15:55 . 2009-09-13 16:00 -------- d-----w- c:\program files\Common Files\PDFView
2009-09-13 15:54 . 2009-09-13 15:54 -------- d-----w- c:\program files\NewSoft
2009-09-13 15:54 . 2009-09-13 15:54 -------- d-----w- c:\windows\system32\Color
2009-09-13 15:51 . 2009-09-13 15:51 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-09-13 15:49 . 2009-09-13 15:49 -------- d-----w- c:\program files\ScanSoft
2009-09-13 15:35 . 1995-07-31 11:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
2009-09-13 15:35 . 2009-09-13 15:35 -------- d-----w- c:\program files\ArcSoft
2009-09-13 14:56 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-09-13 14:56 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-09-07 16:05 . 2009-09-07 16:05 -------- d-----w- c:\program files\Free MP3 Sound Recorder
2009-09-04 21:07 . 2009-09-04 21:07 -------- d-----w- c:\program files\Darq Software
2009-08-30 14:39 . 2009-08-30 20:15 -------- d-----w- c:\program files\AV Vcs 7.0 DIAMOND
2009-08-25 20:12 . 2009-09-04 20:28 -------- d-----w- c:\program files\Opera
2009-08-25 19:16 . 2009-08-25 19:16 -------- d-----w- c:\program files\Aladdin Systems
2009-08-23 10:46 . 2009-08-23 10:46 -------- d-----w- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 19:25 . 2003-08-14 14:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-13 15:51 . 2009-03-23 14:02 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-13 15:30 . 2009-03-23 14:27 -------- d-----w- c:\program files\Canon
2009-09-13 15:29 . 2009-03-23 14:28 -------- d--h--w- c:\program files\CanonBJ
2009-09-11 18:03 . 2009-05-27 17:37 -------- d-----w- c:\program files\Steam
2009-08-24 21:44 . 2009-08-09 16:41 -------- d-----w- c:\program files\Net Profiles
2009-08-23 19:07 . 2009-07-11 17:16 -------- d-----w- c:\program files\QIP
2009-08-22 08:38 . 2009-05-21 17:10 -------- d-----w- c:\program files\McAfee
2009-08-14 10:45 . 2009-08-14 10:45 -------- d-----w- c:\program files\Common Files\Macromedia
2009-08-14 10:44 . 2009-08-14 10:44 -------- d-----w- c:\program files\Macromedia
2009-08-13 07:27 . 2009-05-02 17:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-13 07:27 . 2009-08-13 07:27 -------- d-----w- c:\program files\Java
2009-08-11 10:55 . 2009-08-11 10:55 -------- d-----w- c:\program files\AmitySource
2009-08-11 10:23 . 2003-08-14 14:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-11 10:14 . 2009-08-11 10:14 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-08-03 22:57 . 2009-07-18 16:17 -------- d-----w- c:\program files\Image-Line
2009-08-03 22:57 . 2009-06-02 18:22 -------- d-----w- c:\program files\VSTplugins
2009-07-30 18:31 . 2009-07-30 18:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-30 16:49 . 2009-07-30 16:49 -------- d-----w- c:\program files\FLVPlayer
2009-07-25 19:17 . 2009-07-25 19:17 -------- d-----w- c:\program files\Common Files\DirectX
2009-07-16 10:32 . 2009-05-21 17:12 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-13 11:36 . 2009-07-30 18:31 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2009-07-30 18:31 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-08 11:44 . 2009-05-21 17:12 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-08 11:44 . 2009-05-21 17:12 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-08 11:44 . 2009-05-21 17:12 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-08 11:44 . 2009-05-21 17:12 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-08 11:43 . 2009-05-21 17:09 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-07-05 20:16 . 2009-07-05 20:16 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-23 3367424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WireLessMouse"="c:\program files\Trust\Trust R-series Mouse And Keyboard\StartAutorun.exe" [2007-03-06 212992]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2006-10-17 398944]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-07 1176808]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Petr\Nabˇdka Start\Programy\Po spuçtŘnˇ\
DragStrip.lnk - c:\program files\Aladdin Systems\DragStrip\DragStrip.exe [2009-8-25 323584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\NexonEU\\NGM\\NGM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\crayon physics deluxe demo\\launcher.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 lladrv;LLAdrv;c:\windows\system32\drivers\lladrv.sys [13.7.2009 9:15 32544]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [21.5.2009 19:17 206112]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Obsah adresáře 'Naplánované úlohy'
2009-05-21 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-05-21 19:26]
2009-05-21 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-05-21 19:26]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: {DC68A5C9-D3CA-49C1-B0C5-217A29AD9FCC} = 79.127.160.2,192.168.0.1
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\83lymd7x.default\
FF - prefs.js: browser.startup.homepage -
www.seznam.czFF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-WrtMon.exe - c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-19 23:06
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2616)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Microsoft Office\Office12\1029\GrooveIntlResource.dll
c:\windows\system32\nvcpl.dll
c:\windows\system32\nvapi.dll
c:\windows\system32\nvshell.dll
.
Celkový čas: 2009-09-19 23:10
ComboFix-quarantined-files.txt 2009-09-19 21:10
ComboFix2.txt 2009-08-03 16:57
Před spuštěním: Volných bajtů: 12 706 750 464
Po spuštění: Volných bajtů: 12 661 514 240
Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
171