Re: Prosím o kontrolu
Napsal: 14 čer 2010 23:00
- scan combofix nerobil - ponúkol mi dokonca novú verziu
- musela som PC reštartovať - nejak zamrzol
- potom hláška - že sa systém obnovuje po vážnej chybe
- a nakoniec sa cobofix rozbehol:
ComboFix 10-06-13.04 - Admin 14.06.2010 23:48:19.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1588 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-14 23:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-14 23:51:42
ComboFix-quarantined-files.txt 2010-06-14 21:51
ComboFix2.txt 2010-06-14 17:01
Pre-Run: 72 546 258 944 bytes free
Post-Run: 72 536 178 688 bytes free
- - End Of File - - DEC4F7F551974DF41696EF0059C8C39B
- musela som PC reštartovať - nejak zamrzol
- potom hláška - že sa systém obnovuje po vážnej chybe
- a nakoniec sa cobofix rozbehol:
ComboFix 10-06-13.04 - Admin 14.06.2010 23:48:19.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1588 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-14 23:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-14 23:51:42
ComboFix-quarantined-files.txt 2010-06-14 21:51
ComboFix2.txt 2010-06-14 17:01
Pre-Run: 72 546 258 944 bytes free
Post-Run: 72 536 178 688 bytes free
- - End Of File - - DEC4F7F551974DF41696EF0059C8C39B