Včera už jsem nechtěl čekat, jak vidím, odešel jsem dvě minuty před tvým příchodem... Firefox je RC1, tento týden by měla vyjít čtvrtá verze, pokud to není nutné, v používání bych pokračoval... Používám FF4 od jedenácté betaverze a z uživatelského pohledu bez problémů.
Tady je log:
ComboFix 11-03-14.04 - Petr Mach 15.03.2011 7:57.11.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2046.1484 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr Mach\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Petr Mach\Plocha\CFScript.txt
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{77B9B837-DEB7-4B30-9F0A-F06B0B9AA36E}\MpKsld24bdf81.sys"
"c:\windows\system32\drivers\Lbd.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\Norton
c:\documents and settings\All Users\Data aplikací\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
c:\program files\Common Files\Symantec Shared
c:\windows\system32\drivers\Lbd.sys
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_LBD
-------\Legacy_MPKSLD24BDF81
-------\Service_Lbd
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-15 do 2011-03-15 )))))))))))))))))))))))))))))))
.
.
2011-03-15 06:20 . 2011-03-15 06:20 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E60BEA4B-489F-4642-AF90-AD9998B99735}\MpKslf7117da9.sys
2011-03-14 20:20 . 2011-02-11 06:54 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E60BEA4B-489F-4642-AF90-AD9998B99735}\mpengine.dll
2011-03-14 12:53 . 2011-03-14 12:53 388096 ----a-r- c:\documents and settings\Petr Mach\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-13 18:55 . 2011-03-13 18:55 -------- d--h--w- c:\program files\InstallJammer Registry
2011-03-13 18:55 . 2011-03-13 18:55 -------- d-----w- c:\program files\Esmska
2011-03-10 10:35 . 2011-03-10 10:35 -------- d-----w- C:\VritualRoot
2011-03-06 10:15 . 2011-03-06 10:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NortonInstaller
2011-03-06 09:49 . 2011-03-06 09:49 -------- d-----w- c:\program files\Diar
2011-03-06 08:19 . 2011-03-06 08:19 -------- d-----w- c:\windows\IrfanView
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-03-06 08:15 . 2011-03-06 08:17 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-03-06 08:14 . 2011-03-06 08:17 -------- d-----w- c:\program files\QuickTime
2011-03-06 07:43 . 2011-03-06 07:43 -------- d-----w- c:\documents and settings\Petr Mach\Local Settings\Data aplikací\Secunia PSI
2011-03-06 07:43 . 2011-03-06 07:43 -------- d-----w- c:\program files\Secunia
2011-03-06 07:22 . 2011-03-06 07:22 -------- d-----w- c:\documents and settings\Petr Mach\Local Settings\Data aplikací\PicasaDownloader
2011-03-05 18:06 . 2011-03-05 18:14 -------- d-----w- c:\documents and settings\Petr Mach\Data aplikací\Efficient Diary
2011-03-05 17:43 . 2011-03-05 17:43 -------- d-----w- c:\program files\Planner
2011-02-27 16:18 . 2011-02-27 16:18 -------- d-----w- c:\program files\VideoLAN
2011-02-19 18:28 . 2011-02-19 18:28 -------- d-----w- c:\documents and settings\Petr Mach\Data aplikací\DDMSettings
2011-02-19 18:20 . 2011-02-19 18:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DivX
2011-02-17 10:52 . 2011-02-17 10:52 -------- d-----w- c:\program files\Sandboxie
2011-02-15 13:34 . 2011-02-15 13:34 -------- d-----w- c:\documents and settings\Petr Mach\Local Settings\Data aplikací\Installer3456
2011-02-15 13:26 . 2011-02-15 13:27 -------- d-----w- c:\documents and settings\Petr Mach\Local Settings\Data aplikací\Installer3072
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-06 08:34 . 2010-04-20 19:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-06 08:34 . 2009-10-09 12:59 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-11 06:54 . 2011-01-27 08:29 5943120 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2006-03-02 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-03-02 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-10-09 11:29 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-02-01 13:32 . 2011-02-01 13:32 34048 ----a-w- c:\windows\system32\eEmpty.exe
2011-01-27 11:57 . 2009-10-09 11:29 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2006-03-02 12:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-20 22:32 . 2010-09-10 22:41 285480 ----a-w- c:\windows\system32\guard32.dll
2011-01-20 22:32 . 2010-09-10 22:40 94784 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-01-20 22:32 . 2010-09-10 22:40 27576 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-01-20 22:32 . 2010-09-10 22:40 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-01-20 22:32 . 2010-09-10 22:40 239368 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-01-20 13:19 . 2011-01-20 13:19 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-01-20 13:19 . 2011-01-20 13:19 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-01-07 14:09 . 2006-03-02 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2006-03-02 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-27 09:29 . 2010-12-27 09:20 2377696 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2010-12-27 09:20 . 2010-12-27 09:20 18368 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-12-22 20:11 . 2010-12-22 20:11 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-12-22 12:34 . 2006-03-02 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2006-03-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2006-03-02 12:00 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2010-11-01 17:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-11-01 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-14_17.35.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-15 07:03 . 2011-03-15 07:03 16384 c:\windows\temp\Perflib_Perfdata_2a8.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" [2010-03-01 451224]
"Diar.exe"="c:\program files\Diar\Diar.exe" [2006-11-01 1523200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF32605.cfxxe" [X]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-20 8429568]
"nwiz"="nwiz.exe" [2007-04-20 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-20 81920]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-20 2548552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^Petr Mach^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
2007-03-20 06:36 36864 ------r- c:\windows\RaidTool\xInsIDE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-07-25 15:02 563984 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-07-25 15:06 2027792 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-10-17 22:42 404200 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\COMMON\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"c:\\Program Files\\Microsoft Research\\Microsoft WorldWide Telescope\\WWTExplorer.exe"=
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [3.2.2011 8:51 14776]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.12.2009 19:27 697328]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [10.9.2010 23:40 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [10.9.2010 23:40 27576]
R1 MpKslf7117da9;MpKslf7117da9;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E60BEA4B-489F-4642-AF90-AD9998B99735}\MpKslf7117da9.sys [15.3.2011 7:20 28752]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [15.5.2008 11:07 61424]
R2 Active@ Disk Monitor;Active@ Disk Monitor;c:\program files\LSoft Technologies Inc\Active@ Hard Disk Monitor\DiskMonitorService.exe [2.5.2010 16:37 1127944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [17.12.2009 21:37 135664]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [21.6.2007 16:21 30720]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11.7.2008 1:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10.7.2008 2:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11.7.2008 1:28 369688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 11:26]
.
.
------- Doplňkový sken -------
.
mSearch Bar =
hxxp://www.google.com/ieIE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {262E9174-1DB6-470F-A60D-66F7ED01E115} = 156.154.70.25,156.154.71.25
FF - ProfilePath - c:\documents and settings\Petr Mach\Data aplikací\Mozilla\Firefox\Profiles\8u6sadbv.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedie (cs)
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - prefs.js: keyword.URL -
hxxp://search.seznam.cz/?sourceid=undefined&q=FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-15 08:04
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-03-15 08:07:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-15 07:07
ComboFix2.txt 2011-03-14 20:20
ComboFix3.txt 2011-03-14 19:23
ComboFix4.txt 2011-03-14 18:56
ComboFix5.txt 2011-03-15 06:56
.
Před spuštěním: Volných bajtů: 58 908 758 016
Po spuštění: Volných bajtů: 58 776 236 032
.
- - End Of File - - 1E5A6E61A78DCCA34032A1E70AB1BCD9