ComboFix 11-03-19.01 - Administrator 20.03.2011 0:08.2.2 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1012.787 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-19 do 2011-03-19 )))))))))))))))))))))))))))))))
.
.
2011-03-19 21:56 . 2011-03-19 21:56 -------- d-----r- C:\MSOCache
2011-03-13 19:03 . 2011-03-13 19:04 -------- d-----w- C:\temp
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:53 . 2008-04-14 07:51 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 07:51 186880 ----a-w- c:\windows\system32\encdec.dll
2011-01-21 14:44 . 2008-04-14 07:51 440320 ----a-w- c:\windows\system32\shimgvw.dll
2010-12-31 14:04 . 2008-04-14 06:45 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-20 17:25 . 2008-04-14 07:51 729088 ----a-w- c:\windows\system32\lsasrv.dll
.
.
------- Sigcheck -------
.
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp3qfe\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp3gdr\tcpip.sys
[-] 2008-05-18 . 68F06FE0021B01E670AF37B8C5964FDF . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys
.
[-] 2008-05-18 . C71BB4782833750BF4C02AC30ED670B7 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-03-19_22.56.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-10-25 15:00 . 2011-03-19 22:55 40326 c:\windows\system32\perfc009.dat
+ 2001-10-25 15:00 . 2011-03-19 23:11 40326 c:\windows\system32\perfc009.dat
- 2001-10-25 15:00 . 2011-03-19 22:55 46394 c:\windows\system32\perfc005.dat
+ 2001-10-25 15:00 . 2011-03-19 23:11 46394 c:\windows\system32\perfc005.dat
+ 2001-10-25 15:00 . 2011-03-19 23:11 311938 c:\windows\system32\perfh009.dat
- 2001-10-25 15:00 . 2011-03-19 22:55 311938 c:\windows\system32\perfh009.dat
+ 2001-10-25 15:00 . 2011-03-19 23:11 310228 c:\windows\system32\perfh005.dat
- 2001-10-25 15:00 . 2011-03-19 22:55 310228 c:\windows\system32\perfh005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2011-03-19 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"M3000Mnt"="M3000Rmv.dll " [X]
"RTHDCPL"="RTHDCPL.EXE" [2009-12-22 18789920]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2009-12-11 59936]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
R0 ffire;FlashFire;c:\windows\system32\drivers\ffire.sys [15.7.2009 20:39 10624]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [13.3.2011 19:57 254976]
S1 MpKsl8807db29;MpKsl8807db29;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKsl8807db29.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKsl8807db29.sys [?]
S1 MpKslbe5f094c;MpKslbe5f094c;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKslbe5f094c.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKslbe5f094c.sys [?]
S1 MpKsld7a40cd5;MpKsld7a40cd5;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKsld7a40cd5.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{6309375B-5D40-4E4E-AAF5-57FA9D34517A}\MpKsld7a40cd5.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [13.3.2011 19:46 1691480]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [13.3.2011 19:47 96856]
.
.
------- Doplňkový sken -------
.
uStart Page = my.daemon-search.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-20 00:13
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3364)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Celkový čas: 2011-03-20 00:14:41
ComboFix-quarantined-files.txt 2011-03-19 23:14
.
Před spuštěním: 3 174 416 384
Po spuštění: 3 172 880 384
.
- - End Of File - - 0828CFB1673C357A1307333C19DBD2E4
Díky za každou pomoc!
