ComboFix 10-02-07.07 - franta 08/02/2010 16:46:00.4.1 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.482 [GMT 1:00]
Spuštěný z: c:\documents and settings\franta\Plocha\Potvora.com
Použité ovládací přepínače :: c:\docume~1\franta\Plocha\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Drivers\atapi.sys . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-08 do 2010-02-08 )))))))))))))))))))))))))))))))
.
2010-02-05 15:20 . 2010-02-05 15:20 -------- d-----w- c:\program files\trend micro
2010-02-02 15:32 . 2010-02-02 15:32 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-02 10:04 . 2010-02-02 10:04 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-01-27 17:40 . 2010-01-27 17:40 -------- d-----w- c:\windows\SHELLNEW
2010-01-27 17:40 . 2010-01-27 17:40 -------- d-----w- c:\program files\Microsoft.NET
2010-01-27 17:37 . 2010-01-27 17:37 -------- d-----r- C:\MSOCache
2010-01-27 17:02 . 2010-01-27 17:02 -------- d-----w- c:\program files\Disk Cleaner
2010-01-25 15:32 . 2010-01-25 15:32 -------- d-----w- c:\program files\Defraggler
2010-01-24 11:40 . 2010-01-24 11:40 -------- d-----w- c:\program files\DiskCheckerXP
2010-01-24 11:07 . 2010-01-24 11:07 -------- d-----w- c:\program files\IObit
2010-01-23 17:32 . 2010-01-23 17:32 -------- d-----w- c:\program files\Argente Software
2010-01-09 17:07 . 2010-01-09 17:07 -------- d-----w- c:\program files\Lark Anti-Spyware
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-22 17:06 . 2009-08-18 16:42 737280 ----a-w- c:\windows\iun6002.exe
2010-01-07 15:07 . 2009-05-05 16:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-05-05 16:16 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 17:20 . 2010-01-06 17:20 -------- d-----w- c:\program files\PhotoFiltre
2010-01-05 11:18 . 2010-01-05 11:18 -------- d-----w- c:\program files\Foxit Software
2010-01-04 15:56 . 2010-01-04 15:56 -------- d-----w- c:\program files\Free Window Registry Repair
2010-01-02 10:21 . 2010-01-02 10:21 -------- d-----w- c:\program files\Sunbelt Software
2010-01-01 16:42 . 2010-01-01 16:42 249592 ----a-w- c:\windows\system32\cssdll32.dll
2009-12-29 15:49 . 2009-07-26 18:16 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-28 15:48 . 2009-12-28 15:48 -------- d-----w- c:\program files\Avira
2009-12-22 10:15 . 2009-12-22 10:15 -------- d-----w- c:\program files\MSECache
2009-12-21 19:08 . 2001-10-25 11:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-18 15:20 . 2009-12-18 15:20 -------- d-----w- c:\program files\WebKeySoft
2009-12-18 11:08 . 2009-12-18 11:08 -------- d-----w- c:\program files\Quick Startup
2009-12-17 18:54 . 2001-10-25 11:00 92702 ----a-w- c:\windows\system32\perfc005.dat
2009-12-17 18:54 . 2001-10-25 11:00 457296 ----a-w- c:\windows\system32\perfh005.dat
2009-12-17 16:26 . 2006-01-25 18:22 33393 ----a-w- c:\windows\mozver.dat
2009-12-14 18:12 . 2009-12-14 18:12 -------- d-----w- c:\program files\Auslogics
2009-11-21 16:03 . 2001-10-25 11:00 471552 ----a-w- c:\windows\AppPatch\AcLayers.dll
2009-08-24 11:17 . 2009-08-24 11:13 80 --sh--r- c:\windows\system32\B722219E98.dll
2007-10-28 18:04 . 2007-10-28 18:04 274 --sha-w- c:\windows\system32\drivers\0261AF.DAT
2007-10-28 18:00 . 2007-10-28 18:00 200 --sha-w- c:\windows\system32\drivers\0261A4.DAT
2007-10-28 18:00 . 2007-10-28 18:00 200 --sha-w- c:\windows\system32\drivers\1201A5.DAT
2007-10-28 18:14 . 2007-10-28 18:14 200 --sha-w- c:\windows\system32\drivers\02635.DAT
2007-10-28 18:14 . 2007-10-28 18:14 200 --sha-w- c:\windows\system32\drivers\27f36.DAT
2007-10-28 18:14 . 2007-10-28 18:14 200 --sha-w- c:\windows\system32\drivers\ba137.DAT
2007-10-28 18:00 . 2007-10-28 18:00 200 --sha-w- c:\windows\system32\drivers\6e61A6.DAT
2007-10-28 18:04 . 2007-10-28 18:04 274 --sha-w- c:\windows\system32\drivers\5ae1B0.DAT
2007-10-28 18:04 . 2007-10-28 18:04 274 --sha-w- c:\windows\system32\drivers\0cb1B1.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SeaMonkey Quick Launch"="c:\program files\mozilla.org\SeaMonkey\SeaMonkey.exe" -turbo
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe"
"UnlockerAssistant"="d:\instalace\Unlocker\UnlockerAssistant.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 pxark;pxark;c:\windows\system32\drivers\pxark.sys [26/11/2008 19:28 26680]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28/12/2009 16:48 108289]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15/01/2010 17:28 135664]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 16:28]
2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 16:28]
.
.
------- Doplňkový sken -------
.
uSearchMigratedDefaultURL = hxxp://
www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = localhost
IE: E&xportovat do aplikace Microsoft Excel - d:\instal~1\MICROS~1\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - d:\instalace\Verdict free\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - d:\instalace\Verdict free\etnxp.dll
DPF: {3190CE28-0B6E-4133-A7D3-87D29CB92120}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-08 16:54
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="AE5B94BEBC99FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407A6171C11EC38DE3D5D575E7D6A3B98083A045C20E5BA7D111FC2C827A92CA8FA6D6B0FA2A199A95C7160B9E7E190E3CD1E9C50EB67036F5ED0732AC7999F72F8A014D37E6F0514984364061D1241FBCE7DA92E259D275C16A98105CBE3E692F5C4A5B283CE07D67C148C0559C51C77FA5ACAB823AAE12E9E124FCE78639473D74AE9F103F2A679897FA6ED99283E221096F1B7ACD3058F155815FE80154EC23607FCDABEB2FECDF405D37CCC89560B01FB657600017771C72D5F13101B4F715C3850BB6D0A416329860AEE58DD2A0475B741C5CDC0B008BB260D8CC4BBE4344CF9A866BB95AD91C14D1307133D12A6465873F7BA42BECB27BC516EB06071843A4F9D2FC69A9D7112038D8C49E3794C03D33FE561DB4477F54E354158976B1F8E9E1EF0A2FDFB629EB86A493AB0E194ED813B6BCC05730D471C1413B793DD85E433E88856CC488522DFEF8C9BA75DE27D1F5166FEDB98506FCB9D74BCA8E57D8FB91358DCB314420952372914F116DD5CCBC23B6D218EC875E656F8C7D1360F13458545A40789C0F4C92E74BFD9C7F0688C9F538038C8C2945B153AB02D9587264C7E3912BD6171BC6617C9305143CB35C8CF1715AB4BCDBD7885D441FC5E78B6AA8CA2FAF16C85E72B8789E7696C6009CE0EF9FBA82FBF1375A7E8B5A4FDB7E31C16722A630D72357F6892DEDCBA675E4D686C7BFEA1AEECEBCF1A42B176DC8445539EDEF33A7215AE79CF02063C5B63D9C2674BA36578D5D7A5938B4F5F461FAA519F4D2B0106AE68CA2931658F7AFAEC54661A304EBC0E9CA4802DCF621570B86FF49BB3FE6BDA40C20D3F1D6949BA61A6E907E0465F88FD9B91B32ABDAD693DE49EE4DC68AC272D1BEF75F7120EEEF8977428964A086E25AFFB21F7C339AF68B82338190491D38BE1488FDF66541557DC0D85D6EBA499A0D8776CF65A251BD3480C987F2DA85819F70FBDE556EADF06FA429D4BD0E299E16241FD88FCA336784467FBCBD2445EF9934324BCE665B4EF4E21E0BE31B9333DEB9AB633382844B4B1C6CF5BF8FAC1B63FE9DA3EAE1A30E6833DB3A3DA5FDB6DE8476521AF6D38CAE7BEF0B237A693B858866CE3D9A6209D1EAFEF0E2FCF428EA28F521F18EE3C61956A33F6B6E41C5190A65ACE2B6685AEF61362B7234CC2A2B241B6203EEEA903BA66DD74B9985233ECD698C2F4FE9894B608CBFB41D8F20F8AAC40B9FDF2159E2CD42C9891676574C8A98E28A0D743315CB1E1DDA4BC191E6DA512254B43BF0513DACB78A53BB6925037980A299A25C7BA374D81008431FAF1064142AB6C246DEA2360C971435A6C861A871920B78F8179452A2E99816BB806"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(772)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ScsiAccess.EXE
c:\windows\system32\wscntfy.exe
c:\progra~1\MOZILLA.ORG\SEAMON~1\SEAMON~1.EXE
.
**************************************************************************
.
Celkový čas: 2010-02-08 16:59:49 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-08 15:59
ComboFix2.txt 2010-02-08 14:26
ComboFix3.txt 2010-02-08 11:06
ComboFix4.txt 2010-02-08 10:21
Před spuštěním: Volných bajtů: 50 357 436 416
Po spuštění: Volných bajtů: 50 313 330 688
- - End Of File - - C55F63942AFCFC9F267C5D98C5CA03E6