Tak zde je log po druhém kole s CF
ComboFix 10-08-21.06 - Emanek 22.08.2010 23:28:35.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.766.363 [GMT 2:00]
Spuštěný z: c:\documents and settings\Emanek\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Emanek\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\program files\BS_Player\tbBS_1.dll"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Emanek\LOCALS~1\Temp
c:\docume~1\Emanek\LOCALS~1\Temp\_iu14D2N.tmp
c:\docume~1\Emanek\LOCALS~1\Temp\AdobeARM.log
c:\docume~1\Emanek\LOCALS~1\Temp\Arabic.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Av-test.txt
c:\docume~1\Emanek\LOCALS~1\Temp\Czech.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Danish.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Dutch.bin
c:\docume~1\Emanek\LOCALS~1\Temp\English.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Finnish.bin
c:\docume~1\Emanek\LOCALS~1\Temp\French.bin
c:\docume~1\Emanek\LOCALS~1\Temp\German.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Greek.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Hebrew.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Hungarian.bin
c:\docume~1\Emanek\LOCALS~1\Temp\IMT10.xml
c:\docume~1\Emanek\LOCALS~1\Temp\IMT9.xml
c:\docume~1\Emanek\LOCALS~1\Temp\IMTA.xml
c:\docume~1\Emanek\LOCALS~1\Temp\IMTB.xml
c:\docume~1\Emanek\LOCALS~1\Temp\IMTE.xml
c:\docume~1\Emanek\LOCALS~1\Temp\IMTF.xml
c:\docume~1\Emanek\LOCALS~1\Temp\Italian.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Japanese.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Korean.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Norwegian.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Polish.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Portuguese(Brazil).bin
c:\docume~1\Emanek\LOCALS~1\Temp\Portuguese.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Russian.bin
c:\docume~1\Emanek\LOCALS~1\Temp\SimChin.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Spanish.bin
c:\docume~1\Emanek\LOCALS~1\Temp\SWEDISH.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Thai.bin
c:\docume~1\Emanek\LOCALS~1\Temp\TradChin.bin
c:\docume~1\Emanek\LOCALS~1\Temp\Turkish.bin
c:\program files\BS_Player\tbBS_1.dll
c:\program files\CentrumczToolbar\IEToolbar.dll
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MCHINJDRV
-------\Service_mchInjDrv
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-22 do 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-22 19:21 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-22 19:21 . 2010-08-22 19:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-22 19:21 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-22 18:49 . 2010-08-22 18:49 -------- d-----w- c:\program files\CCleaner
2010-08-22 04:30 . 2010-08-22 04:30 -------- d-----w- c:\program files\trend micro
2010-08-22 04:30 . 2010-08-22 04:30 -------- d-----w- C:\rsit
2010-08-21 20:35 . 2010-08-21 20:35 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-08-21 20:16 . 2010-08-22 21:14 -------- d-----w- c:\program files\TrojanHunter 4.2
2010-08-20 19:24 . 2008-04-13 17:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-08-20 19:24 . 2008-04-13 17:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-08-20 19:24 . 2008-04-13 17:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-08-20 19:24 . 2008-04-13 17:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-08-20 19:23 . 2008-04-13 17:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-08-20 19:23 . 2008-04-13 17:40 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-08-07 20:04 . 2010-08-07 20:05 -------- d-----w- c:\program files\Essentials Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 21:36 . 2010-02-02 21:45 -------- d-----w- c:\program files\CentrumczToolbar
2010-08-22 21:36 . 2010-02-01 07:21 -------- d-----w- c:\program files\BS_Player
2010-08-16 13:44 . 2010-02-05 15:40 -------- d-----w- c:\program files\JDownloader
2010-08-12 17:39 . 2010-06-16 14:58 -------- d-----w- c:\program files\ICQ7.2
2010-08-10 22:21 . 2001-10-25 12:00 79440 ----a-w- c:\windows\system32\perfc005.dat
2010-08-10 22:21 . 2001-10-25 12:00 432516 ----a-w- c:\windows\system32\perfh005.dat
2010-08-05 13:31 . 2010-02-01 02:40 -------- d-----w- c:\program files\Google
2010-07-05 09:02 . 2010-07-02 19:18 -------- d-----w- c:\program files\rajce
2010-06-30 12:33 . 2004-08-17 14:49 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 20:57 . 2010-06-29 16:00 38848 ----a-w- c:\windows\avastSS.scr
2010-06-28 20:57 . 2010-02-18 19:29 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-02-18 19:29 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-02-18 19:29 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-02-18 19:29 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-02-18 19:29 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-02-18 19:29 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-02-18 19:29 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-02-18 19:29 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-24 12:27 . 2004-08-17 14:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2004-08-17 14:44 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-03 22:14 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-17 14:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2010-02-01 01:10 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 14:49 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
.
((((((((((((((((((((((((((((( SnapShot@2010-08-22_20.41.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-22 21:40 . 2010-08-22 21:40 16384 c:\windows\temp\Perflib_Perfdata_c64.dat
+ 2010-08-22 21:03 . 2010-08-22 21:03 16384 c:\windows\temp\Perflib_Perfdata_b7c.dat
+ 2010-08-22 21:39 . 2010-08-22 21:39 16384 c:\windows\temp\Perflib_Perfdata_874.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-11-11 1236992]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-15 53248]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-06-23 602112]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"PsaStart"="c:\applic\ddc\bin\psastart.exe" [2009-02-26 40960]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-06 1848648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Emanek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2010-2-1 45056]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\APPLIC\\Portail\\mozilla.exe"=
"c:\\APP\\PPS\\mozilla.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [18.2.2010 21:29 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18.2.2010 21:29 17744]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\applic\FIREBIRD\bin\fbguard.exe -s --> c:\applic\FIREBIRD\bin\fbguard.exe -s [?]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [1.2.2010 7:33 246520]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\applic\FIREBIRD\bin\fbserver.exe -s --> c:\applic\FIREBIRD\bin\fbserver.exe -s [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5.8.2010 15:28 136176]
.
Obsah adresáře 'Naplánované úlohy'
2010-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-05 13:28]
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-05 13:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Emanek\Data aplikací\Mozilla\Firefox\Profiles\vgwaw1rq.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.6&q=
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-22 23:40
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(464)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'Explorer.EXE'(1276)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\applic\ddc\bin\psaagent.exe
c:\applic\FIREBIRD\bin\fbguard.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\applic\FIREBIRD\bin\fbserver.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-08-22 23:44:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-22 21:44
ComboFix2.txt 2010-08-22 20:47
Před spuštěním: 6 704 201 728
Po spuštění: 6 687 739 904
- - End Of File - - 722F4AEB57E263AA9017C88A4912E711