Takže tady je ten Log z Combofixu:
ComboFix 12-09-18.07 - Lukáš 20.09.2012 14:01:37.2.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.688 [GMT 2:00]
Spuštěný z: c:\documents and settings\Lukáš\Plocha\ComboFix.exe
FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\BasicScan
c:\program files\BasicScan\basicscan.dll
c:\program files\BasicScan\basicscan.exe
c:\program files\BasicScan\uninstall.exe
c:\program files\BFlix\BFLIx.dll
c:\program files\DealPly
c:\program files\DealPly\DealPly.crx
c:\program files\DealPly\DealPly.xpi
c:\program files\DealPly\DealPlyIE.dll
c:\program files\DealPly\DealPlyUpdate.exe
c:\program files\DealPly\DealPlyUpdateRun.exe
c:\program files\DealPly\icon.ico
c:\program files\DealPly\sqlite3.dll
c:\program files\DealPly\uninst.exe
c:\program files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}
c:\program files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\chrome\basicscan.jar
c:\program files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\install.rdf
c:\program files\MyTools\MyTOols.dll
c:\windows\system32\OLD388.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BASICSCAN_SERVICE
-------\Service_BasicScan Service
-------\Legacy_bProtector
-------\Service_bProtector
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-20 do 2012-09-20 )))))))))))))))))))))))))))))))
.
.
2012-09-20 07:53 . 2012-09-20 07:53 -------- dc----w- c:\documents and settings\Administrator
2012-09-19 13:24 . 2012-09-19 13:24 512 -c--a-w- C:\PhysicalMBR.bin
2012-09-19 09:33 . 2012-08-23 10:59 172464 ----a-w- c:\program files\4zres.dll
2012-09-19 09:33 . 2012-08-23 10:58 699536 ----a-w- c:\program files\4zUninstall VideoDownloadConverter.dll
2012-09-19 09:29 . 2012-06-09 18:50 172440 ----a-w- c:\program files\4wres.dll
2012-09-19 09:29 . 2012-06-09 18:50 699536 ----a-w- c:\program files\4wUninstall Retrogamer.dll
2012-09-19 09:09 . 2011-10-18 15:19 245760 ----a-w- c:\program files\Uninstall Ask Toolbar.dll
2012-09-18 17:34 . 2012-09-18 17:34 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Trymedia
2012-09-18 16:54 . 2012-09-19 10:37 -------- d-----w- c:\program files\trend micro
2012-09-18 16:54 . 2012-09-18 16:56 -------- dc----w- C:\rsit
2012-09-18 16:06 . 2012-09-18 16:06 -------- d-----w- c:\program files\CCleaner
2012-09-15 10:02 . 2012-09-15 10:32 -------- d-----w- c:\documents and settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
2012-08-31 08:41 . 2012-09-08 09:39 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-30 11:56 . 2005-04-03 20:59 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2012-08-29 11:05 . 2012-08-29 11:05 -------- d-----w- c:\documents and settings\Lukáš\Data aplikací\vlc
2012-08-29 10:54 . 2012-08-29 10:54 -------- d-----w- c:\program files\VideoLAN
2012-08-28 09:43 . 2012-08-28 09:43 -------- d-----w- c:\program files\Activision
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 10:01 . 2012-06-28 07:49 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 10:01 . 2011-10-18 18:15 70344 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-02 20:29 . 2011-11-11 07:20 22328 -c--a-w- c:\documents and settings\Lukáš\Data aplikací\PnkBstrK.sys
2012-07-02 20:29 . 2011-11-11 07:20 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-07-02 20:28 . 2011-11-11 07:20 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-07-02 20:28 . 2011-11-11 07:19 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-09-08 09:39 . 2012-06-07 16:52 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files\ICQ7.6\ICQ.exe" [2011-10-10 127040]
"EADM"="d:\hovno\Origin\Origin.exe" [2012-01-11 28201096]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17420464]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-07-20 847872]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Lukáš\Nabídka Start\Programy\Po spuštění\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Xfire.lnk - d:\hovno\Xfire\xfire.exe [2007-11-15 2836304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=protector.dll
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\Windows iLivid Toolbar\\Datamngr\\ToolBar\\dtUser.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"d:\\hovno\\iw3mp.exe"=
"d:\\FiFa 2011\\Game\\fifa.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\panúrstebu\\game.dat"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57462:TCP"= 57462:TCP:Pando Media Booster
"57462:UDP"= 57462:UDP:Pando Media Booster
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [30.12.2011 16:07 239168]
R2 IBUpdaterService;Updater Service;c:\documents and settings\All Users\Data aplikací\IBUpdaterService\ibsvc.exe [25.2.2012 13:28 397848]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [31.12.2011 12:35 2253120]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [23.12.2011 16:07 793048]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [13.8.2012 13:33 3064000]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [14.6.2012 11:37 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [28.6.2012 9:49 250056]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 EraserUtilDrv11220;EraserUtilDrv11220;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [18.8.2005 7168]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [7.6.2012 18:52 114144]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-28 10:01]
.
2012-09-20 c:\windows\Tasks\DriverScanner.job
- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2012-02-09 10:22]
.
2012-09-19 c:\windows\Tasks\Norton Security Scan for Lukáš.job
- c:\progra~1\NORTON~2\Engine\360~1.31\Nss.exe [2011-10-21 00:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=RGxdm652YYcz&ptb=DD6546C9-A33A-4250-8560-7DC0F2FDDDDF&si=gamesxite
mStart Page = hxxp://
www.bigseekpro.com/xilisoftdownloadyout ... 6BC0977554}
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: Interfaces\{322D9B46-694A-4DBB-97DC-616396B5B612}: NameServer = 85.93.160.254,85.93.160.118
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebPlayer.cab
FF - ProfilePath - c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BitTorrentBar Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://home.mywebsearch.com/index.jhtml?ptb=DD6546C9-A33A-4250-8560-7DC0F2FDDDDF&n=77edc33a&ptnrS=RGxdm652YYcz&si=gamesxite
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=
user_pref('extensions.dealply.partner', 'vn');
user_pref('extensions.dealply.channel', 'pcdealply');
user_pref('extensions.dealply.installId', 'v23600243599708270172582012052608410022');
user_pref('extensions.dealply.installIdSource', 'inst');
user_pref('extensions.dealply.sampleGroup', '2');
FF - user.js: extensions.BabylonToolbar_i.id - b80ca65f0000000000000018f38c59dd
FF - user.js: extensions.BabylonToolbar_i.hardId - b80ca65f0000000000000018f38c59dd
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15500
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babclient
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - std
FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic_i.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MON1200T01/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.hpOld - hxxp://home.mywebsearch.com/index.jhtml?ptb=DD6546C9-A33A-4250-8560-7DC0F2FDDDDF&n=77edc33a&ptnrS=RGxdm652YYcz&si=gamesxite
FF - user.js: extensions.Softonic.hpNew - hxxp://search.softonic.com/MON1200T01/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.keyWordUrl - hxxp://search.softonic.com/MON1200T01/tb_v1?SearchSource=2&cc=&q=
FF - user.js: extensions.Softonic.dspOld - BitTorrentBar Customized Web Search
FF - user.js: extensions.Softonic.dspNew - Search the web (Softonic)
FF - user.js: extensions.Softonic_i.dnsErr - true
FF - user.js: extensions.Softonic_i.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MON1200T01/tb_v1?SearchSource=15&cc=
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON1200T01/tb_v1?SearchSource=1&cc=&q=
FF - user.js: extensions.Softonic.id - b80ca65f0000000000000018f38c59dd
FF - user.js: extensions.Softonic.instlDay - 15551
FF - user.js: extensions.Softonic.vrsn - 1.6.4.3
FF - user.js: extensions.Softonic.vrsni - 1.6.4.3
FF - user.js: extensions.Softonic_i.vrsnTs - 1.6.4.37:59
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - SD
FF - user.js: extensions.Softonic_i.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - base
FF - user.js: extensions.Softonic.instlRef - MON1200T01
FF - user.js: extensions.Softonic.dfltLng -
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.admin - false
FF - user.js: extentions.y2layers.installId - f566d56d-c82c-435b-aeed-2901f345c8c3
FF - user.js: extentions.y2layers.defaultEnableAppsList - ezLooker,pagerage,buzzdock,toprelatedtopics,twittube
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=114278&tt=3412_2
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://
www.google.com/search?babsrc=TB_ggl&q=
FF - user.js: extensions.BabylonToolbar.id - b80ca65f0000000000000018f38c59dd
FF - user.js: extensions.BabylonToolbar.instlDay - 15573
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.611:09
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
Toolbar-10 - (no file)
Toolbar-!!{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
Toolbar-!!{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
Toolbar-!!{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-BasicScan - c:\program files\BasicScan\uninstall.exe
AddRemove-DealPly - c:\program files\DealPly\uninst.exe
AddRemove-Google Chrome - c:\documents and settings\Lukáš\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.163\Installer\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-09-20 14:07
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ICQ = "c:\program files\ICQ7.6\ICQ.exe" silent loginmode=4?C
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3636)
d:\hovno\Xfire\xfire_toucan_28888.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\Uniblue\DriverScanner\driverscanner.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-09-20 14:12:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-20 12:12
.
Před spuštěním: 6 813 069 312
Po spuštění: 6 779 015 168
.
- - End Of File - - 1A3CEAB3807A3C2FE82DCEE985313340