ComboFix 12-08-08.03 - 1 09.08.2012 8:49.1.4 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3070.1844 [GMT 2:00]
Spuštěný z: c:\users\1\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\1\AppData\Local\assembly\tmp
c:\users\Public\sdelevURL.tmp
c:\windows\iun6002.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-09 do 2012-08-09 )))))))))))))))))))))))))))))))
.
.
2012-08-08 20:03 . 2012-08-08 20:03 -------- d-----w- C:\rsit
2012-08-08 19:18 . 2012-08-08 19:26 -------- d-----w- C:\!KillBox
2012-08-08 08:55 . 2012-08-08 08:55 -------- d-----w- c:\users\1\AppData\Roaming\Avira
2012-08-08 08:49 . 2012-07-18 16:05 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-08-08 08:49 . 2012-07-18 16:05 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-08-08 08:49 . 2012-07-18 16:05 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-08-08 08:48 . 2012-08-08 08:48 -------- d-----w- c:\programdata\Avira
2012-08-08 07:24 . 2012-08-08 20:09 -------- d-----w- c:\program files\trend micro
2012-08-08 07:21 . 2012-07-16 00:41 6891424 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B15742C7-7790-48FC-A8BF-319605E09B36}\mpengine.dll
2012-08-07 19:28 . 2012-08-07 19:28 -------- d-----w- c:\program files\Enigma Software Group
2012-08-07 19:27 . 2012-08-07 19:27 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-08-07 16:28 . 2012-08-07 16:28 304 ----a-w- C:\user.js
2012-08-02 07:43 . 2012-08-02 07:43 -------- d-----w- c:\users\1\AppData\Roaming\daypo
2012-07-15 08:23 . 2012-07-15 08:23 -------- d--h--r- c:\users\1\AppData\Roaming\SecuROM
2012-07-15 08:22 . 2012-07-15 09:09 -------- d-----w- c:\users\1\AppData\Local\Rockstar Games
2012-07-14 14:03 . 2012-06-13 13:40 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-14 11:54 . 2012-06-05 16:47 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-14 11:54 . 2012-06-05 16:47 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-14 11:54 . 2012-06-05 16:47 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-14 11:54 . 2012-06-04 15:26 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-14 11:54 . 2012-06-02 00:04 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-14 11:54 . 2012-06-02 00:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-03 12:13 . 2012-05-07 12:09 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-03 12:13 . 2011-05-23 06:29 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-15 08:21 . 2012-02-16 21:46 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-07-06 16:34 . 2012-07-06 16:34 476936 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-07-06 16:34 . 2010-05-10 06:39 472840 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-27 02:14 . 2012-06-27 02:14 4472832 ----a-w- c:\windows\system32\GPhotos.scr
2012-06-02 22:19 . 2012-06-21 06:30 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 06:30 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 06:30 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 06:30 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-21 06:30 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-21 06:30 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-21 06:30 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 06:29 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-21 06:29 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-14 11:54 278528 ----a-w- c:\windows\system32\schannel.dll
2012-05-31 10:25 . 2009-10-03 07:04 237072 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\1\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\1\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\1\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-13 6711840]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
"avgnt"="d:\avira\AntiVir Desktop\avgnt.exe" [2012-07-18 348664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SlimStar 250.lnk - c:\program files\SlimStar 250\MagicKey.exe [2010-2-13 172032]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezGOSvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.com/
mStart Page = about:blank
IE: &Download All by FlashGet - d:\program files\FlashGet universal\ComDlls\Bhoall.htm
IE: &Download by FlashGet - d:\program files\FlashGet universal\ComDlls\Bholink.htm
IE: &Stáhnout s FlashGetem - d:\program files\FlashGet universal\ComDlls\Bholink.htm
IE: &Stáhnout vše s FlashGetem - d:\program files\FlashGet universal\ComDlls\Bhoall.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Save YouTube Video as MP3
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-BsScanner
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-GamePlayLabs Plugin - c:\users\1\AppData\Local\GamePlayLabs Plugin\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-09 08:55
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{25515A79-C1C7-4B97-97F8-31A711694487}"=hex:51,66,7a,6c,4c,1d,38,12,17,59,42,
21,f5,8f,f9,0e,e8,ee,72,e7,14,37,00,93
"{687578B9-7132-4A7A-80E4-30EE31099E03}"=hex:51,66,7a,6c,4c,1d,38,12,d7,7b,66,
6c,00,3f,14,0f,ff,f2,73,ae,34,57,da,17
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{26A7CA19-7D58-411D-B2DA-F1B0324CBFFC}"=hex:51,66,7a,6c,4c,1d,38,12,77,c9,b4,
22,6a,33,73,04,cd,cc,b2,f0,37,12,fb,e8
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:2f,28,0e,91,3c,26,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ec,18,d1,cf,d9,ea,c5,4c,9b,4d,4e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ec,18,d1,cf,d9,ea,c5,4c,9b,4d,4e,\
.
[HKEY_USERS\S-1-5-21-2462328225-3109948575-47500355-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A8D0E82-5F27-23FE-1BEF-F1B91A2F27CE}*]
"namecdealdeahppekfcleghhkleo"=hex:69,61,6b,63,64,65,67,62,6e,6f,68,67,67,61,
6c,70,6c,64,00,00
"oaoepbpkjhdglonmccgnceogkbidlb"=hex:69,61,6b,63,64,65,67,62,6e,6f,68,67,67,61,
6c,70,6c,64,00,00
.
[HKEY_USERS\S-1-5-21-2462328225-3109948575-47500355-1000\Software\SecuROM\License information*]
"datasecu"=hex:90,1e,a6,0a,68,b8,28,76,16,35,08,9e,b8,e4,9b,bc,68,b7,a0,b9,8b,
2e,e3,26,bb,e1,70,b3,7e,82,58,a3,d6,6e,ab,d5,75,c7,71,68,02,41,b6,1e,d5,8d,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
Celkový čas: 2012-08-09 08:56:29
ComboFix-quarantined-files.txt 2012-08-09 06:56
.
Před spuštěním: Volných bajtů: 10 321 391 616
Po spuštění: Volných bajtů: 10 305 372 160
.
- - End Of File - - 3DF445633281F25EE832AA9E9905A712