Tu to je vsetko.
http://www.virustotal.com/cs/analisis/5 ... 1263186946
ComboFix 10-01-13.04 - Miro . 01. 2010 18:43:08.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1650 [GMT 1:00]
Running from: c:\documents and settings\All Users\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Miro\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\system32\dllcache\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-15 08:59 . 2010-01-15 08:59 -------- d-----w- c:\program files\ESET
2010-01-13 16:44 . 2010-01-13 16:44 -------- d-----w- c:\documents and settings\Miro\Application Data\Malwarebytes
2010-01-13 16:44 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-13 16:44 . 2010-01-13 16:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-13 16:44 . 2010-01-13 16:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-13 16:44 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-13 15:04 . 2010-01-13 15:58 -------- d-----w- c:\program files\trend micro
2010-01-13 15:03 . 2010-01-13 15:58 -------- d-----w- C:\rsit
2010-01-06 21:24 . 2010-01-06 21:24 -------- d-----w- c:\documents and settings\Miro\Application Data\Winamp
2010-01-06 14:48 . 2010-01-06 14:48 -------- d-----w- c:\program files\MP3 Cutter
2010-01-06 14:48 . 2004-11-14 04:27 212992 ----a-w- c:\windows\system32\sql.dll
2010-01-04 08:19 . 2010-01-13 19:14 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-01 20:06 . 2010-01-01 20:53 -------- d-----w- c:\documents and settings\Miro\Application Data\GanymedeNet
2010-01-01 20:05 . 2010-01-01 20:05 -------- d-----w- c:\program files\Ganymede
2009-12-29 00:21 . 2009-12-29 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-28 15:10 . 2009-12-28 15:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-12-24 10:31 . 2009-12-24 10:31 -------- d-----w- c:\program files\123 DVD Clone
2009-12-24 10:17 . 2009-12-24 10:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2009-12-24 10:16 . 2009-09-28 19:57 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-12-24 10:16 . 2009-12-24 17:51 -------- d-----w- c:\program files\CDBurnerXP
2009-12-23 16:04 . 2009-12-23 16:04 -------- d-----w- c:\program files\Common Files\DirectX
2009-12-20 09:28 . 2009-12-20 10:12 -------- d-----w- c:\program files\Free YouTube Downloader Converter
2009-12-20 09:26 . 2009-12-20 09:26 -------- d-----w- c:\program files\YouTube Downloader
2009-12-18 23:33 . 2009-12-18 23:33 -------- d-----w- c:\documents and settings\Miro\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-15 17:49 . 2009-10-15 07:45 140577 ----a-w- c:\windows\hpoins14.dat
2010-01-15 12:25 . 2009-11-04 12:24 -------- d-----w- c:\documents and settings\Miro\Application Data\HP
2010-01-15 12:25 . 2009-11-04 12:14 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-01-14 19:02 . 2009-09-28 18:22 -------- d-----w- c:\program files\ICQ6.5
2010-01-06 21:16 . 2009-10-08 07:44 -------- d-----w- c:\program files\BitComet
2010-01-06 15:17 . 2010-01-06 15:16 -------- d-----w- c:\program files\Winamp
2010-01-05 16:21 . 2009-10-06 12:46 -------- d-----w- c:\documents and settings\Miro\Application Data\ICQ
2009-12-29 00:25 . 2009-12-29 00:25 56 ---ha-w- c:\documents and settings\All Users\Application Data\ezsidmv.dat
2009-12-22 13:04 . 2009-09-26 13:20 -------- d-----w- c:\program files\Google
2009-12-15 12:45 . 2009-12-15 12:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-13 13:37 . 2009-12-13 13:37 -------- d-----w- c:\program files\ShrinkTo5
2009-12-08 21:40 . 2009-09-27 11:06 24736 ----a-w- c:\documents and settings\Miro\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-08 20:53 . 2009-09-26 12:41 24736 ----a-w- c:\documents and settings\Peto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-08 17:20 . 2009-10-07 19:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-08 15:06 . 2009-09-26 20:40 25128 ----a-w- c:\documents and settings\Mammi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-08 13:47 . 2009-12-08 13:47 -------- d-----w- c:\documents and settings\Mammi\Application Data\HPAppData
2009-12-07 16:39 . 2009-12-07 16:39 -------- d-----w- c:\documents and settings\Miro\Application Data\Apple Computer
2009-12-03 20:59 . 2009-12-02 17:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-30 23:03 . 2009-11-30 23:03 79488 ----a-w- c:\documents and settings\Peto\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-29 11:10 . 2009-11-28 16:27 -------- d-----w- c:\program files\Any Video Converter
2009-11-29 11:09 . 2009-11-24 14:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-11-29 11:09 . 2009-11-24 14:58 -------- d-----w- c:\program files\Common Files\Nero
2009-11-29 11:09 . 2009-11-24 14:58 -------- d-----w- c:\program files\Nero
2009-11-28 20:23 . 2009-11-28 20:13 -------- d-----w- c:\documents and settings\Miro\Application Data\DeepBurner
2009-11-28 19:45 . 2009-11-28 19:45 -------- d-----w- c:\program files\Astonsoft
2009-11-28 16:51 . 2009-11-28 16:51 -------- d-----w- c:\program files\Digiarty
2009-11-28 16:35 . 2009-11-28 16:33 -------- d-----w- c:\program files\Next Video Converter
2009-11-26 19:25 . 2009-09-27 14:48 -------- d-----w- c:\program files\rFactor
2009-11-25 12:03 . 2009-11-25 12:03 -------- d-----w- c:\documents and settings\Miro\Application Data\Nero
2009-11-24 17:42 . 2009-11-24 17:42 -------- d-----w- c:\documents and settings\Peto\Application Data\Nero
2009-11-24 15:08 . 2009-11-24 15:08 -------- d-----w- c:\program files\Windows Sidebar
2009-11-07 22:49 . 2009-11-07 22:49 86016 ----a-w- c:\windows\system32\frapsvid.dll
2009-10-26 12:53 . 2001-08-23 13:00 14336 ------w- c:\windows\system32\svchost.exe
2009-10-26 10:35 . 2009-10-26 10:28 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-26 10:24 . 2009-10-26 10:24 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-26 10:24 . 2009-10-26 10:24 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-26 10:24 . 2009-10-26 10:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-26 10:24 . 2009-10-26 10:24 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-22 19:42 . 2009-10-22 19:42 411368 ----a-w- c:\windows\system32\deploytk.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-14_19.04.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-15 17:48 . 2010-01-15 17:48 16384 c:\windows\temp\Perflib_Perfdata_79c.dat
+ 2009-09-26 06:21 . 2010-01-15 16:51 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-09-26 06:21 . 2010-01-14 12:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-15 16:51 . 2010-01-15 16:51 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-09-26 06:21 . 2010-01-14 12:47 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2002-08-29 02:58 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
- 2008-06-20 11:51 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-26 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-25 13680640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
S2 FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe;FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe;c:\program files\Ubisoft\Far Cry 2\bin\FAH.exe -svcstart --> c:\program files\Ubisoft\Far Cry 2\bin\FAH.exe -svcstart [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8. 10. 2009 8:18 133104]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [16. 10. 2009 15:02 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [16. 10. 2009 15:02 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [16. 10. 2009 15:02 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [16. 10. 2009 15:12 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [16. 10. 2009 15:12 83344]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\i:\ntglm7x.sys --> i:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-08 07:18]
2010-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-08 07:18]
2010-01-15 c:\windows\Tasks\WebReg Deskjet F2100 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-11 20:27]
2010-01-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-09-27 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.atcomet.com/b/
uSearch Page = hxxp://
www.google.com
uSearch Bar = hxxp://
www.google.com/ie
mDefault_Search_URL = hxxp://
www.google.com/ie
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
mSearchAssistant = hxxp://
www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Stiahnuť &všetky odkazy pomocou BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Stiahnuť odkaz &pomocou BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stiahnuť všetky v&ideá pomocou BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Miro\Application Data\Mozilla\Firefox\Profiles\y9bwhm8r.default\
FF - component: c:\documents and settings\Miro\Application Data\Mozilla\Firefox\Profiles\y9bwhm8r.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-15 18:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ServiceDll"="c:\windows\System32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe]
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-01-15 18:51:55 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 17:51
ComboFix2.txt 2010-01-14 19:07
Pre-Run: 99 785 818 112 bytes free
Post-Run: 99 740 651 520 bytes free
- - End Of File - - 122D488F6063798FE0D7EE6027E57DA3