ComboFix 10-07-08.02 - Tomáš Jedno 09.07.2010 22:06:51.1.3 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2754 [GMT 2:00]
Spuštěný z: c:\documents and settings\Tomáš Jedno\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100709-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-09 do 2010-07-09 )))))))))))))))))))))))))))))))
.
2010-07-07 20:39 . 2010-07-07 20:39 -------- d-----w- c:\program files\Dobrý farmář
2010-07-05 22:08 . 2010-07-05 22:09 -------- d-----w- C:\rsit
2010-06-29 11:14 . 2010-06-29 11:14 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-06-29 11:13 . 2010-06-29 11:13 -------- d-----w- c:\program files\Common Files\Skype
2010-06-29 11:13 . 2010-07-06 22:42 -------- d-----r- c:\program files\Skype
2010-06-24 10:51 . 2010-07-08 18:43 -------- d-----w- c:\program files\The Sims 3 - Nástroj Tvoření světa
2010-06-20 11:28 . 2010-06-20 11:28 -------- d-----w- c:\program files\Essentials Codec Pack
2010-06-20 11:14 . 2010-06-20 11:14 -------- d-----w- c:\program files\Xvid
2010-06-20 11:14 . 2009-06-07 14:24 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-16 16:21 . 2010-06-16 16:21 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-13 08:40 . 2010-06-13 08:42 -------- d-----w- c:\program files\The Sims - 3 Povolání snů
2010-06-11 22:45 . 2010-05-06 10:35 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-09 20:09 . 2007-10-29 12:00 83630 ----a-w- c:\windows\system32\perfc005.dat
2010-07-09 20:09 . 2007-10-29 12:00 440310 ----a-w- c:\windows\system32\perfh005.dat
2010-07-08 18:42 . 2010-04-13 21:23 -------- d-----w- c:\program files\Ahead
2010-07-07 18:09 . 2010-05-04 15:31 -------- d-----w- c:\program files\trend micro
2010-07-04 19:31 . 2010-04-14 20:40 -------- d-----w- c:\program files\Mv2Player
2010-07-02 07:35 . 2010-04-23 13:04 7744384 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-06-24 10:52 . 2010-04-13 18:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-09 20:12 . 2010-04-13 19:27 -------- d-----w- c:\program files\ICQ7.1
2010-06-08 09:35 . 2010-06-08 09:35 -------- d-----w- c:\program files\BitLord
2010-06-05 11:19 . 2010-06-05 11:16 -------- d-----w- c:\program files\DRAKENSANG - The Dark Eye
2010-06-01 09:33 . 2010-05-08 18:16 -------- d-----w- c:\program files\Esmska
2010-05-31 15:44 . 2010-05-27 18:33 -------- d-----w- c:\program files\XnView
2010-05-31 12:59 . 2010-05-17 21:05 -------- d-----w- c:\program files\AGEIA Technologies
2010-05-31 12:59 . 2010-05-04 13:34 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-05-31 12:57 . 2010-05-27 20:20 -------- d-----w- c:\program files\Gallery Creator
2010-05-26 20:04 . 2010-05-26 20:04 -------- d-----w- c:\program files\IrfanView
2010-05-24 18:49 . 2010-05-24 18:49 -------- d-----w- c:\program files\Web Album Generator
2010-05-22 20:18 . 2010-05-22 20:03 104257 ----a-w- c:\windows\hpoins04.dat
2010-05-22 20:16 . 2010-05-22 20:04 -------- d-----w- c:\program files\HP
2010-05-22 20:15 . 2010-05-22 20:15 -------- d-----w- c:\program files\Common Files\HP
2010-05-22 20:13 . 2010-05-22 20:13 -------- d-----w- c:\program files\Hewlett-Packard
2010-05-22 20:12 . 2010-05-22 20:12 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-05-22 19:18 . 2010-05-22 19:17 -------- d-----w- c:\program files\DVD Decrypter
2010-05-22 11:00 . 2010-05-22 09:17 -------- d-----w- c:\program files\Grand Theft Auto IV - Episodes From Liberty City
2010-05-21 14:01 . 2010-05-21 14:01 -------- d-----w- c:\program files\nwps
2010-05-18 07:44 . 2010-05-17 21:36 -------- d-----w- c:\program files\Risen
2010-05-17 21:06 . 2010-05-17 21:06 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-05-17 21:06 . 2010-05-17 21:06 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-05-17 21:05 . 2010-05-17 21:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-15 09:25 . 2010-05-15 09:25 -------- d-----w- c:\program files\Spyware Terminator
2010-05-15 09:25 . 2010-05-15 09:25 141312 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-05-13 09:57 . 2010-05-13 09:57 -------- d-----w- c:\program files\MSXML 4.0
2010-05-12 14:01 . 2010-04-13 18:14 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-11 09:32 . 2010-04-14 14:24 -------- d-----w- c:\program files\Common Files\Real
2010-05-11 09:32 . 2010-04-14 14:24 -------- d-----w- c:\program files\Real
2010-05-06 10:35 . 2007-10-29 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 13:33 . 2010-04-13 18:10 737280 ----a-w- c:\windows\iun6002.exe
2010-05-02 08:09 . 2007-10-29 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 13:39 . 2010-05-05 20:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-05-05 20:28 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:32 . 2007-10-29 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-15 17:56 . 2010-04-15 17:56 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-15 12:12 . 2010-04-15 12:12 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-04-13 20:28 . 2010-04-13 20:28 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-04-13 16:16 . 2010-04-13 16:16 0 ----a-w- c:\windows\nsreg.dat
2010-04-13 13:50 . 2010-04-13 09:39 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-13 13:50 . 2010-04-13 09:39 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-04-13 13:38 . 2010-04-13 13:38 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-04-13 12:28 . 2010-04-13 12:28 0 ----a-w- c:\windows\ativpsrm.bin
2010-04-13 12:01 . 2010-04-13 09:39 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-04-13 09:37 . 2010-04-13 09:37 21812 ----a-w- c:\windows\system32\emptyregdb.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 16876032]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"avast!"="c:\program files\Alwil Software\Avast4\ashDisp.exe" [2009-11-24 81000]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-05-11 202256]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2010-4-13 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-05-11 09:31 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\HRY\\Age Of Empires 3\\age3x.exe"=
"c:\\HRY\\Age Of Empires 3\\age3y.exe"=
"c:\\Program Files\\Grand Theft Auto IV - Episodes From Liberty City\\EFLC.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [13.4.2010 23:12 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [15.5.2010 11:25 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13.4.2010 23:12 20560]
S2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;c:\windows\system32\drivers\wf88vcap.sys [13.4.2010 19:07 208467]
S2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;c:\windows\system32\drivers\WF88XBAR.sys [13.4.2010 19:09 9284]
S2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;c:\windows\system32\drivers\wf88tune.sys [13.4.2010 19:08 36261]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.4.2010 15:38 691696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
2010-07-09 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-1303643608-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-07-09 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-1303643608-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\Tomáš Jedno\Data aplikací\Mozilla\Firefox\Profiles\kbmxn01r.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - component: c:\documents and settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\Tomáš Jedno\Data aplikací\Mozilla\Firefox\Profiles\kbmxn01r.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}\components\nsWebFF15.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-09 22:11
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1708537768-1303643608-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:3b,32,7d,b6,8c,35,2b,5d,ab,48,e8,13,9d,e5,0a,ac,87,1e,db,4e,c3,
d6,2d,4c,06,7c,de,38,94,53,b8,d4,1d,29,a6,62,6b,96,21,04,39,6e,0c,42,61,e1,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-07-09 22:12:14
ComboFix-quarantined-files.txt 2010-07-09 20:12
Před spuštěním: Volných bajtů: 69 535 125 504
Po spuštění: Volných bajtů: 69 491 998 720
- - End Of File - - D805FB0B432C019FD140CA247EFF09E6