ComboFix 10-05-10.03 - Shodar87 11.05.2010 12:49:08.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2045.1132 [GMT 2:00]
Spuštěný z: c:\users\Shodar87\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Shodar87\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Anti-Virus *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\windows\system32\DRIVERS\eamonm.sys"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EAMONM
-------\Service_eamonm
-------\Service_rlxptqcd
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-11 do 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-11 10:57 . 2010-05-11 10:59 -------- d-----w- c:\users\Shodar87\AppData\Local\temp
2010-05-11 10:57 . 2010-05-11 10:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-05-10 20:49 . 2010-05-10 20:49 -------- d-----w- C:\_OTM
2010-05-10 15:08 . 2010-05-10 15:08 -------- d-----w- C:\rsit
2010-05-10 11:23 . 2010-05-10 15:08 -------- d-----w- c:\program files\trend micro
2010-05-10 08:30 . 2010-05-10 08:44 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-05-10 08:30 . 2010-05-10 08:44 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-10 08:29 . 2010-05-11 10:58 4626976 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-05-10 08:29 . 2010-05-11 10:58 253984 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-05-10 08:29 . 2010-05-10 20:55 -------- d-----w- c:\programdata\Kaspersky Lab
2010-05-10 08:29 . 2010-05-10 08:29 -------- d-----w- c:\program files\Kaspersky Lab
2010-05-10 08:27 . 2010-05-10 08:27 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-05-10 08:16 . 2010-05-10 08:16 -------- d-----w- c:\programdata\WindowsSearch
2010-05-09 21:29 . 2010-05-02 20:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-05-04 20:27 . 2010-05-04 20:27 -------- d-----w- c:\program files\WinPcap
2010-04-20 21:05 . 2010-04-21 14:30 -------- d-----w- c:\users\Shodar87\AppData\Roaming\DivX
2010-04-20 21:04 . 2010-05-05 07:37 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-04-20 21:02 . 2010-04-20 21:03 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-04-20 20:53 . 2010-05-05 07:38 -------- d-----w- c:\program files\DivX
2010-04-19 19:28 . 2010-04-19 19:28 -------- d-----w- c:\users\Shodar87\AppData\Local\Mumble
2010-04-17 19:40 . 2010-05-05 07:42 -------- d-----w- c:\programdata\DivX
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 10:59 . 2010-02-23 18:10 32156 ----a-w- c:\programdata\nvModes.dat
2010-05-11 10:58 . 2010-05-10 08:29 37228 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-05-11 10:58 . 2010-05-10 08:29 1948 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-05-11 10:57 . 2010-03-01 12:26 12 ----a-w- c:\windows\bthservsdp.dat
2010-05-10 08:44 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2010-05-10 08:44 . 2010-05-10 08:44 33808 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2010-05-10 08:44 . 2010-05-10 08:44 224272 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\Vista\klif.sys
2010-05-10 08:44 . 2010-05-10 08:44 21256 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2010-05-10 08:44 . 2010-05-10 08:44 861448 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2010-05-10 08:43 . 2010-05-10 08:43 83208 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2010-05-10 08:43 . 2010-05-10 08:43 62728 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2010-05-10 08:43 . 2010-05-10 08:43 43784 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2010-05-10 08:43 . 2010-05-10 08:43 365832 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2010-05-10 08:43 . 2010-05-10 08:43 201992 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2010-05-10 07:23 . 2010-02-23 16:46 53832 ----a-w- c:\users\Shodar87\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-09 11:13 . 2010-03-27 12:59 1 ----a-w- c:\users\Shodar87\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-09 08:41 . 2010-02-24 08:24 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 10:04 . 2010-02-24 01:32 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-05-08 10:04 . 2010-02-24 01:32 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-05-05 22:40 . 2010-03-20 17:25 -------- d-----w- c:\users\Shodar87\AppData\Roaming\Mumble
2010-05-05 12:57 . 2010-02-24 08:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-05 07:42 . 2010-04-20 21:08 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-05 07:38 . 2010-05-05 07:38 56766 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-05 07:38 . 2010-05-05 07:38 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-05-05 07:38 . 2010-05-05 07:38 57679 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-05-05 07:37 . 2010-05-05 07:37 84040 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-05-05 07:37 . 2010-05-05 07:37 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-05-05 07:37 . 2010-05-05 07:37 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-05-05 07:37 . 2010-05-05 07:37 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-05-05 07:17 . 2010-04-20 20:49 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-05 07:17 . 2010-04-20 21:05 754984 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-05-05 07:17 . 2010-04-20 21:05 1180952 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-05-04 09:30 . 2010-02-27 08:31 -------- d-----w- c:\users\Shodar87\AppData\Roaming\ICQ
2010-04-20 21:05 . 2010-04-20 21:05 56978 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-04-20 21:04 . 2010-04-20 21:04 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-04-20 21:04 . 2010-04-20 21:04 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-04-20 21:04 . 2010-04-20 21:04 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-04-20 21:04 . 2010-04-20 21:04 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-04-20 21:04 . 2010-04-20 21:04 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-04-20 21:03 . 2010-04-20 21:03 54629 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-04-20 21:03 . 2010-04-20 21:03 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-04-20 21:03 . 2010-04-20 21:03 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-04-20 21:03 . 2010-04-20 21:03 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-04-20 21:02 . 2010-04-20 21:02 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-04-11 10:57 . 2010-04-11 10:56 -------- d-----w- c:\users\Shodar87\AppData\Roaming\Youtube Downloader HD
2010-04-11 10:46 . 2010-04-11 10:46 -------- d-----w- c:\users\Shodar87\AppData\Roaming\AnvSoft
2010-04-08 11:24 . 2010-04-08 11:24 -------- d-----w- c:\program files\Common Files\BioWare
2010-04-08 10:11 . 2010-04-07 11:09 -------- d-----w- c:\programdata\Media Center Programs
2010-04-07 08:48 . 2010-04-07 08:48 -------- d-----w- c:\program files\Microsoft Silverlight
2010-04-06 12:54 . 2010-03-20 21:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-06 12:53 . 2010-03-20 21:44 -------- d-----w- c:\program files\AGEIA Technologies
2010-04-05 09:58 . 2010-04-05 09:58 -------- d-----w- c:\users\Shodar87\AppData\Roaming\GHISLER
2010-04-04 18:03 . 2010-02-27 08:31 -------- d-----w- c:\program files\ICQ7.0
2010-03-31 20:12 . 2010-03-31 20:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-27 13:03 . 2010-02-23 16:52 -------- d-----w- c:\program files\Opera
2010-03-27 12:58 . 2010-03-27 12:58 -------- d-----w- c:\users\Shodar87\AppData\Roaming\OpenOffice.org
2010-03-26 11:33 . 2010-03-26 11:33 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-03-23 17:17 . 2010-03-23 17:10 -------- d--h--w- c:\program files\Zero G Registry
2010-03-23 17:08 . 2010-03-23 17:08 -------- d-----w- c:\users\Shodar87\AppData\Roaming\Sports Interactive
2010-03-22 10:51 . 2010-03-22 10:51 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-03-22 07:29 . 2010-03-22 06:37 -------- d-----w- c:\program files\ESET
2010-03-21 21:10 . 2010-03-21 21:06 -------- d-----w- c:\programdata\Lavasoft
2010-03-21 21:07 . 2010-03-21 21:06 -------- d-----w- c:\program files\Lavasoft
2010-03-21 21:07 . 2010-03-21 21:07 -------- dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-03-21 20:51 . 2010-03-21 20:51 -------- d-----w- c:\programdata\Alwil Software
2010-03-21 20:51 . 2010-03-21 20:51 -------- d-----w- c:\program files\Alwil Software
2010-03-21 19:20 . 2010-03-21 19:20 4096 ----a-w- c:\windows\system32\08748.tmp
2010-03-21 19:20 . 2010-02-28 08:35 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-03-21 14:55 . 2010-03-21 14:55 -------- d-----w- c:\programdata\Age of Empires 3
2010-03-20 17:25 . 2010-03-20 17:25 -------- d-----w- c:\program files\Mumble
2010-03-19 15:34 . 2010-03-19 15:34 -------- d-----w- c:\users\Shodar87\AppData\Roaming\InstallShield
2010-03-18 06:36 . 2010-03-18 06:36 -------- d-----w- c:\program files\RADVideo
2010-03-09 12:09 . 2010-03-09 12:09 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-03-09 12:09 . 2010-03-09 12:09 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-08 13:14 . 2010-03-08 13:14 4096 ----a-w- c:\windows\system32\09548.tmp
2010-03-06 15:02 . 2010-03-06 15:02 4096 ----a-w- c:\windows\system32\drivers\nocashio.sys
2010-02-24 01:31 . 2010-02-24 01:32 34724 ----a-w- c:\windows\system32\perfd005.dat
2010-02-24 01:31 . 2010-02-24 01:32 286912 ----a-w- c:\windows\system32\perfi005.dat
2010-02-24 01:31 . 2010-02-24 01:31 34724 ----a-w- c:\windows\inf\PERFLIB\0405\perfd.dat
2010-02-24 01:31 . 2010-02-24 01:31 34724 ----a-w- c:\windows\inf\PERFLIB\0405\perfc.dat
2010-02-24 01:31 . 2010-02-24 01:31 286912 ----a-w- c:\windows\inf\PERFLIB\0405\perfi.dat
2010-02-24 01:31 . 2010-02-24 01:31 286912 ----a-w- c:\windows\inf\PERFLIB\0405\perfh.dat
2010-02-23 20:46 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-02-23 19:57 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-02-23 19:57 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-02-23 18:23 . 2010-02-23 18:24 737280 ----a-w- c:\windows\iun6002.exe
2010-02-23 16:49 . 2010-02-23 16:45 680 ----a-w- c:\users\Shodar87\AppData\Local\d3d9caps.dat
2010-02-19 19:27 . 2010-02-19 19:27 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27 . 2010-02-19 19:27 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27 . 2010-02-19 19:27 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27 . 2010-02-19 19:27 839680 ----a-w- c:\windows\system32\divx_xx11.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\games\steam\steam.exe" [2010-05-07 1238352]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2010-03-28 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-01 13797992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2010-05-10 201992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):66,8e,fb,23,ca,b4,ca,01
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2010-05-10 33808]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2008-03-26 20496]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-02 1285864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
2010-05-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 20:11]
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-11 13:03
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2010-05-11 13:07:46 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-05-11 11:07
ComboFix2.txt 2010-05-10 21:14
Před spuštěním: Volných bajtů: 20 215 472 128
Po spuštění: Volných bajtů: 19 947 331 584
- - End Of File - - 5D2A8EF8D29A03C563B1DD8015B250EC