Tentokrat to bezelo dlouho:-)
ComboFix 11-04-20.03 - BRAVE 21.04.2011 12:18:05.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.293 [GMT 2:00]
Spuštěný z: c:\documents and settings\BRAVE\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\BRAVE\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\audiograbber\audiograbber.exe
c:\documents and settings\BRAVE\WINDOWS
c:\documents and settings\Monika\WINDOWS
c:\documents and settings\Patrik\WINDOWS
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Shared\0005C76E.dat
c:\program files\FunWebProducts\Shared\00304B2A.dat
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\2.bin\MWSBAR(2).DLL
c:\program files\MyWebSearch\bar\2.bin\MWSBAR(3).DLL
c:\program files\MyWebSearch\bar\2.bin\MWSBAR(4).DLL
c:\program files\MyWebSearch\bar\2.bin\MWSBAR.DLL
c:\windows\d.ini
c:\windows\dia6vm2.bmp
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\FreeOffers.ini
c:\windows\serrv.s
c:\windows\serrv.wax
c:\windows\system32\dlh9jkd1q8.exe
c:\windows\system32\pfxzmtsmtspm.dll
c:\windows\system32\pfxzmtwbmail.dll
c:\windows\system32\sfxzmtsmtspm.dll
c:\windows\system32\sfxzmtwbmail.dll
c:\windows\system32\vx.tll
c:\windows\system32\wincom32.ini
c:\windows\system32\zlbw.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_POOF
-------\Legacy_WINCOM32
-------\Service_kprof
-------\Service_pe386
-------\Service_poof
-------\Service_wincom32
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-21 do 2011-04-21 )))))))))))))))))))))))))))))))
.
.
2011-04-21 08:52 . 2011-04-21 08:52 -------- d-----w- c:\program files\trend micro
2011-04-21 08:52 . 2011-04-21 08:53 -------- dc----w- C:\rsit
2011-04-20 10:45 . 2011-02-23 13:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-20 10:45 . 2011-02-23 13:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-20 10:45 . 2011-02-23 13:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-20 10:45 . 2011-02-23 13:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-20 10:45 . 2011-02-23 13:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-20 10:45 . 2011-02-23 13:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-20 10:45 . 2011-02-23 13:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-20 10:45 . 2011-02-23 13:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-20 10:45 . 2011-02-23 14:04 40648 ----a-w- c:\windows\avastSS.scr
2011-04-20 10:45 . 2011-02-23 14:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-20 10:45 . 2011-04-20 10:45 -------- d-----w- c:\program files\AVAST Software
2011-04-20 10:45 . 2011-04-20 10:45 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-04-20 10:37 . 2011-04-20 10:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG7
2011-04-20 09:41 . 2005-03-04 09:10 74496 ----a-w- c:\windows\system32\drivers\Rtlnicxp.sys
2011-04-20 09:40 . 2011-04-20 09:40 -------- d-----w- c:\documents and settings\BRAVE\Local Settings\Data aplikací\GHISLER
2011-04-20 09:40 . 2011-04-20 09:40 -------- d-----w- c:\program files\totalcmd
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\UC.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\RAR.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\LHA.PIF
2011-04-20 09:40 . 2010-12-17 05:56 545 ----a-w- c:\windows\ARJ.PIF
2011-04-20 08:50 . 2011-04-20 08:50 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
2011-04-20 08:50 . 2011-04-20 08:50 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2011-04-20 07:43 . 2008-04-14 06:52 9728 ------w- c:\windows\system32\ativdaxx.ax
2011-04-20 07:41 . 2011-04-20 07:41 -------- d-----w- c:\windows\ServicePackFiles
2011-04-20 07:38 . 2006-12-28 22:31 19569 ----a-w- c:\windows\002546_.tmp
2011-04-20 07:38 . 2007-08-10 18:43 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-04-20 07:34 . 2011-04-20 07:34 -------- d-----w- c:\windows\EHome
2011-04-19 19:07 . 2004-12-02 08:36 70144 ----a-r- c:\windows\system32\drivers\Rtlnic.sys
2011-04-19 18:50 . 2003-03-11 09:04 266240 ----a-w- c:\windows\system32\hpdj3500
2011-04-19 18:18 . 2011-04-19 18:18 -------- d-----w- c:\documents and settings\BRAVE\Local Settings\Data aplikací\Scansoft
2011-04-19 16:03 . 2011-04-19 16:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\CanonIJPLM
2011-04-19 15:59 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-04-19 15:59 . 2011-04-19 15:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\InstallShield
2011-04-19 15:59 . 2011-04-19 15:59 -------- d-----w- c:\documents and settings\Monika\Data aplikací\ScanSoft
2011-04-19 15:58 . 2011-04-19 15:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ScanSoft
2011-04-19 15:58 . 2011-04-19 15:58 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2011-04-19 15:58 . 2011-04-19 15:58 -------- d-----w- c:\program files\ScanSoft
2011-04-19 15:55 . 2011-04-19 15:55 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\CanonBJ
2011-04-19 15:55 . 2006-12-25 20:00 69632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8R.DLL
2011-04-19 15:55 . 2006-12-25 20:00 27136 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8R.DLL
2011-04-19 15:55 . 2006-12-25 20:00 198656 ----a-w- c:\windows\system32\CNMLM8R.DLL
2011-04-19 15:55 . 2011-04-19 15:55 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-04-19 15:55 . 2006-11-10 01:59 57344 ----a-w- c:\windows\system32\CNCI140.DLL
2011-04-19 15:55 . 2006-06-29 05:29 106496 ----a-w- c:\windows\system32\cnco140.dll
2011-04-19 15:55 . 2006-05-26 01:54 135168 ----a-w- c:\windows\system32\CNCL140.DLL
2011-04-19 15:55 . 2006-11-10 02:00 1314816 ----a-w- c:\windows\system32\CNCC140.DLL
2011-04-19 15:54 . 2011-04-19 16:03 -------- d-----w- c:\program files\Canon
2011-04-19 06:43 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-04-16 07:56 . 2008-04-14 06:52 75264 ----a-w- c:\windows\system32\usbui.dll
2011-04-16 07:56 . 2008-04-13 22:15 143872 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-04-16 07:56 . 2008-04-13 22:15 30208 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-04-16 07:56 . 2008-04-13 22:15 59520 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-04-16 07:56 . 2008-04-13 22:15 20608 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-04-16 07:56 . 2008-04-13 22:10 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2011-04-16 07:56 . 2008-04-13 22:10 24960 ----a-w- c:\windows\system32\drivers\pciidex.sys
2011-04-16 07:56 . 2001-10-24 09:52 3328 ----a-w- c:\windows\system32\drivers\pciide.sys
2011-04-16 07:56 . 2001-10-24 09:52 3328 ----a-w- c:\windows\system32\dllcache\pciide.sys
2011-04-16 07:55 . 2008-04-14 05:57 37248 ----a-w- c:\windows\system32\drivers\isapnp.sys
2011-04-16 07:55 . 2008-04-14 06:10 68736 ----a-w- c:\windows\system32\drivers\pci.sys
2011-04-16 07:55 . 2008-04-13 22:06 42368 ----a-w- c:\windows\system32\drivers\agp440.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-21 11:02 . 2007-04-01 14:46 1409 ----a-w- c:\windows\QTFont.for
.
.
------- Sigcheck -------
.
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2002-09-23 . 244A2F9816BC9B593957281EF577D976 . 332928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
c:\windows\System32\drivers\tcpip.sys ... chybí !!
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 14:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"nwiz"="nwiz.exe" [2002-07-16 372736]
"AGRSMMSG"="AGRSMMSG.exe" [2002-09-25 87751]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 172032]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-01-09 77824]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20.4.2011 12:45 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.4.2011 12:45 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.4.2011 12:45 19544]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
HKU-Default-Run-adirka - c:\windows\System32\adirka.exe
AddRemove-DesetiPrsty5 - c:\program files\DesetiPrsty\pmqUnInstall.exe
AddRemove-Indeo® Software - c:\program files\Ligos\Indeo\Uninst.isu
AddRemove-UWFX_5_is1 - c:\program files\WinFixer 2005\unins000.exe
AddRemove-wcmdmgr.exe - c:\windows\wt\updater\wcmdmgr.exe
AddRemove-wtwebdriver - c:\windows\wt\updater\wcmdmgr.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-04-21 13:09
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(492)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\RunDll32.exe
.
**************************************************************************
.
Celkový čas: 2011-04-21 13:22:41 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-04-21 11:22
.
Před spuštěním: Volných bajtů: 31 836 618 752
Po spuštění: Volných bajtů: 32 551 567 360
.
- - End Of File - - 8649000520C865686F9EFFB049AA634E