ComboFix 10-07-16.02 - Admin 18.07.2010 18:19:48.9.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1652 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\etc\lmhosts
.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.
2010-07-18 15:36 . 2010-07-18 15:36 -------- d--h--w- c:\windows\PIF
2010-07-10 10:44 . 2010-06-08 21:00 52224 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
2010-07-10 10:44 . 2010-06-08 21:00 101376 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
2010-07-10 10:40 . 2010-06-23 11:51 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-07-10 10:40 . 2010-06-23 11:51 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-07-10 10:40 . 2010-06-23 11:51 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-07-10 09:39 . 2010-07-10 10:26 46899712 ----a-w- c:\program files\zaSetup_92_057_000_en.exe
2010-07-03 08:12 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-06-26 20:22 . 2010-06-26 20:22 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\FarmvilleMagicTools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 16:14 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-07-18 14:46 . 2010-07-18 14:47 24576 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2010-07-18 14:46 . 2010-07-18 14:47 2077184 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2010-07-18 11:33 . 2010-07-13 09:12 3125335 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-07-18 11:16 . 2010-07-18 11:33 2316288 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2010-07-18 11:16 . 2010-07-18 11:33 2074624 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2010-07-18 08:59 . 2010-07-18 09:15 2074112 ----a-w- c:\windows\Internet Logs\xDB3.tmp
2010-07-15 19:42 . 2010-06-11 09:30 -------- d-----w- c:\program files\trend micro
2010-07-15 14:44 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-07-14 21:59 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-07-14 08:30 . 2010-07-14 12:50 2042880 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2010-07-14 08:30 . 2010-07-14 12:50 2792448 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2010-07-12 19:35 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-07-10 10:40 . 2010-03-31 15:49 -------- d-----w- c:\program files\CheckPoint
2010-07-10 10:40 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-06-28 20:57 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2009-03-20 21:42 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2009-03-20 21:42 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2009-03-20 21:42 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2009-03-20 21:42 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-25 19:57 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-16 14:26 . 2010-06-16 14:26 -------- d-----w- c:\program files\Zone Labs
2010-06-15 21:02 . 2010-06-15 20:06 33952648 ----a-w- c:\program files\zaZA_Setup_en.exe
2010-06-15 15:59 . 2010-06-15 15:59 -------- d-----w- c:\program files\CCleaner
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\HRY\\CALL OF DUTY MODERN WARFARE 2\\Modern Warfare 2\\iw4mp.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 165456]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 17744]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-07-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\
xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-18 18:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
Completion time: 2010-07-18 18:23:42
ComboFix-quarantined-files.txt 2010-07-18 16:23
Pre-Run: 69 547 819 008 bytes free
Post-Run: 69 704 278 016 bytes free
- - End Of File - - 2D01F4475F3B7F61CFD919148F4CFE74