ComboFix 10-04-20.01 - admin 21.04.2010 8:28.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.91 [GMT 2:00]
Spuštěný z: c:\documents and settings\admin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\admin\Plocha\CFScript.txt
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\drivers\beep.sys . . . je infikován!!
c:\windows\system32\drivers\tcpip.sys . . . je infikován!!
c:\windows\System32\regsvc.dll . . . je infikován!!
c:\windows\System32\wscntfy.exe . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-21 do 2010-04-21 )))))))))))))))))))))))))))))))
.
2010-04-21 06:25 . 2009-04-01 19:47 1683968 ----a-w- C:\HxD.exe
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\windows\system32\wbem\snmp
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\windows\system32\xircom
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\windows\system32\oobe
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\windows\srchasst
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\windows\msagent
2010-04-20 07:06 . 2010-04-20 07:06 -------- d-----w- c:\program files\microsoft frontpage
2010-04-17 17:57 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-17 17:57 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-17 17:57 . 2010-04-17 17:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-16 18:44 . 2010-04-17 17:52 -------- d-----w- c:\program files\trend micro
2010-04-16 18:43 . 2010-04-16 18:44 -------- d-----w- C:\rsit
2010-04-14 12:32 . 2010-03-10 06:17 420352 ------w- c:\windows\system32\dllcache\vbscript.dll
2010-04-10 14:33 . 2010-04-10 14:33 10 ----a-w- c:\windows\popcinfo.dat
2010-04-10 08:51 . 2010-04-10 08:51 -------- d-----w- c:\windows\system32\LogFiles
2010-04-10 08:49 . 2008-04-13 20:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2010-04-10 08:49 . 2008-03-21 11:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-04-10 08:42 . 2010-04-10 08:42 -------- d-----w- c:\program files\Common Files\PCSuite
2010-04-06 22:59 . 2010-04-06 22:59 -------- d--h--w- c:\windows\PIF
2010-04-06 20:47 . 2010-04-06 20:47 -------- d-----w- c:\program files\TomTom International B.V
2010-04-06 20:46 . 2010-04-06 20:47 -------- d-----w- c:\program files\TomTom HOME 2
2010-04-05 18:31 . 2010-04-05 18:31 -------- d-----w- c:\program files\4shared Desktop
2010-04-01 08:53 . 2010-04-01 08:53 -------- d-sh--w- c:\documents and settings\admin\PrivacIE
2010-03-31 09:56 . 2010-02-25 06:12 611840 ------w- c:\windows\system32\dllcache\mstime.dll
2010-03-30 19:21 . 2010-03-30 19:21 -------- d-----w- c:\program files\Common Files\Java
2010-03-30 14:06 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-30 07:39 . 2010-03-30 07:39 -------- d-----w- c:\program files\CBS Software
2010-03-28 12:39 . 2010-03-28 12:39 -------- d-----w- c:\program files\Defraggler
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-16 19:53 . 2010-03-04 10:17 -------- d-----w- c:\program files\CCleaner
2010-04-15 15:30 . 2001-10-25 12:00 82440 ----a-w- c:\windows\system32\perfc005.dat
2010-04-15 15:30 . 2001-10-25 12:00 437056 ----a-w- c:\windows\system32\perfh005.dat
2010-04-10 08:49 . 2010-04-10 08:49 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-04-10 08:49 . 2010-04-10 08:49 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-04-10 08:42 . 2010-04-10 08:42 -------- d-----w- c:\program files\Common Files\Nokia
2010-04-10 08:42 . 2010-04-10 08:40 -------- d-----w- c:\program files\Nokia
2010-04-10 08:41 . 2010-04-10 08:41 -------- d-----w- c:\program files\DIFX
2010-04-10 08:40 . 2010-04-10 08:40 -------- d-----w- c:\program files\PC Connectivity Solution
2010-04-01 09:07 . 2010-03-04 11:15 -------- d-----w- c:\program files\Winamp
2010-03-30 19:20 . 2010-03-04 10:23 -------- d-----w- c:\program files\Java
2010-03-30 07:47 . 2010-03-04 10:24 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-10 15:29 . 2010-03-09 20:24 -------- d-----w- c:\program files\Anti Trojan Elite
2010-03-10 06:17 . 2009-06-04 00:30 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 02:28 . 2010-03-04 10:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 13:32 . 2010-03-04 10:33 -------- d-----w- c:\program files\totalcmd
2010-03-05 11:58 . 2010-03-04 10:00 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-05 11:58 . 2010-03-04 10:00 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-05 11:57 . 2010-03-04 10:00 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-03-04 11:39 . 2010-03-04 11:36 -------- d-----w- c:\program files\Common Files\Nero
2010-03-04 11:36 . 2010-03-04 11:36 -------- d-----w- c:\program files\Nero
2010-03-04 11:25 . 2010-03-04 10:34 -------- d-----w- c:\program files\nLite
2010-03-04 11:22 . 2010-03-04 11:21 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-03-04 11:19 . 2010-03-04 11:19 0 ----a-w- c:\windows\nsreg.dat
2010-03-04 11:13 . 2010-03-04 11:13 -------- d-----w- c:\program files\VertrigoServ
2010-03-04 10:50 . 2010-03-04 10:50 -------- d-----w- c:\program files\Agnitum
2010-03-04 10:48 . 2010-03-04 10:48 -------- d-----w- c:\program files\MSECache
2010-03-04 10:44 . 2010-03-04 10:44 -------- d-----w- c:\program files\Microsoft Works
2010-03-04 10:43 . 2010-03-04 10:43 -------- d-----w- c:\program files\Microsoft.NET
2010-03-04 10:41 . 2010-03-04 10:41 -------- d-----w- c:\program files\ESET
2010-03-04 10:35 . 2010-03-04 10:35 0 ----a-w- c:\windows\ativpsrm.bin
2010-03-04 10:33 . 2010-03-04 10:33 -------- d-----w- c:\program files\AV-Kodeky
2010-03-04 10:21 . 2010-03-04 10:21 -------- d-----w- c:\program files\Microsoft Silverlight
2010-03-04 10:20 . 2010-03-04 10:20 -------- d-----w- c:\program files\Opera
2010-03-04 10:17 . 2010-03-04 10:17 -------- d-----w- c:\program files\NWD2007
2010-03-04 10:17 . 2010-03-04 10:17 -------- d-----w- c:\program files\mpc
2010-03-04 10:17 . 2010-03-04 10:17 -------- d-----w- c:\program files\HD Tune
2010-03-04 10:07 . 2010-03-04 10:07 -------- d-----w- c:\program files\MSBuild
2010-03-04 10:07 . 2010-03-04 10:07 -------- d-----w- c:\program files\Reference Assemblies
2010-03-04 10:02 . 2010-03-04 10:02 -------- d-----w- c:\program files\MSXML 4.0
2010-03-04 09:58 . 2010-03-04 09:58 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-04 09:56 . 2010-03-04 09:56 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-25 06:12 . 2009-06-28 17:48 919040 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 11:57 . 2009-05-05 07:07 457216 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:02 . 2009-02-09 11:19 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 19:02 . 2009-05-05 07:07 2192256 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-12 04:29 . 2008-04-14 06:51 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 11:36 . 2009-05-05 07:06 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-02 11:24 . 2010-03-04 11:21 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-02-02 11:18 . 2010-03-04 11:21 30024 ----a-w- c:\windows\system32\uxtuneup.dll
.
------- Sigcheck -------
[-] 2009-05-05 . 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
c:\windows\System32\drivers\beep.sys ... chybí !!
c:\windows\System32\wscntfy.exe ... chybí !!
c:\windows\System32\regsvc.dll ... chybí !!
.
((((((((((((((((((((((((((((( SnapShot@2010-04-20_07.07.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-21 06:35 . 2010-04-21 06:35 16384 c:\windows\Temp\Perflib_Perfdata_60c.dat
+ 2010-04-21 05:37 . 2010-04-21 05:37 16384 c:\windows\Temp\Perflib_Perfdata_568.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-06-09 1227080]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [13.3.2008 17:52 33800]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [4.3.2010 13:02 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [4.3.2010 12:50 1268040]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [13.3.2008 17:49 472320]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13.11.2009 13:31 92008]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2.2.2010 13:21 1043784]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [4.3.2010 13:00 31128]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 8:24 10064]
S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [25.10.2001 14:00 3584]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [4.3.2010 13:02 33920]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Everest\kerneld.wnt [4.3.2010 12:34 26736]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2010-04-21 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2010-02-02 11:28]
.
.
------- Doplňkový sken -------
.
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: &Download using 4shared Desktop - c:\program files\4shared Desktop\down_link.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\o8nr1fdx.default\
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-21 08:36
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Everest\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-527237240-920026266-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,45,6c,b5,50,95,34,f0,4e,98,5f,42,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,45,6c,b5,50,95,34,f0,4e,98,5f,42,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1660)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3356)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\devldr32.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Celkový čas: 2010-04-21 08:38:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-04-21 06:38
ComboFix2.txt 2010-04-20 07:09
Před spuštěním: Volných bajtů: 24 564 428 800
Po spuštění: Volných bajtů: 24 532 090 880
- - End Of File - - 25F81A5BF1A060CFE6BA5EA34CF686D7