Re: key-logger
Napsal: 07 pro 2010 18:50
Tak je tady ten log z kombofix, ale nic jsem tam nenalezl, tak opravdu nevim. Treba je to pouze logo ktere se tam zobrazuje, ale...
ComboFix 10-12-06.04 - Lipickovi 07.12.2010 18:05:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2048.1541 [GMT 1:00]
Spuštěný z: c:\documents and settings\Lipickovi\Plocha\ComboFix.exe
AV: avast! Internet Security *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lipickovi\Data aplikací\PriceGong
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\z.xml
c:\windows\XSxS
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-07 do 2010-12-07 )))))))))))))))))))))))))))))))
.
2010-12-06 15:37 . 2010-12-07 00:15 -------- d-----w- c:\program files\FreeRapid-0.85
2010-12-04 23:04 . 2007-06-27 01:58 2303488 -c--a-w- c:\windows\system32\dllcache\ati2mtag.sys
2010-12-04 23:04 . 2007-06-27 01:58 2303488 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-12-04 22:49 . 2010-12-04 22:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2010-12-04 22:48 . 2010-12-04 22:48 0 ----a-w- c:\windows\ativpsrm.bin
2010-12-04 22:24 . 2010-12-04 22:24 -------- d-----w- c:\program files\DIFX
2010-12-04 22:24 . 2010-12-05 13:54 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-04 22:22 . 2010-12-04 22:22 -------- d-----w- C:\ATI
2010-12-04 18:11 . 2010-12-04 18:11 -------- d-----w- c:\program files\Common Files\DirectX
2010-12-04 17:56 . 2010-12-04 17:56 -------- d-----w- c:\program files\SCi Games
2010-12-04 17:56 . 2002-12-05 13:12 692224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2010-12-04 17:56 . 2002-12-05 13:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2010-12-04 17:56 . 2002-12-02 14:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2010-12-04 17:56 . 2002-12-02 12:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2010-12-04 17:56 . 2002-12-02 12:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2010-12-04 17:56 . 2010-12-04 17:56 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2010-12-04 17:56 . 2010-12-04 17:56 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2010-12-04 15:50 . 2010-12-04 16:04 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-12-04 15:37 . 2010-12-04 16:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
2010-12-04 15:37 . 2010-12-04 15:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Symantec
2010-12-04 15:34 . 2010-12-04 15:53 -------- d-----w- c:\windows\system32\Adobe
2010-12-04 10:54 . 2010-12-04 10:54 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-04 07:28 . 2010-12-04 11:55 -------- d-----w- c:\program files\trend micro
2010-12-04 07:28 . 2010-12-04 07:29 -------- d-----w- C:\rsit
2010-12-04 06:34 . 2010-12-04 06:34 -------- d-----w- c:\documents and settings\Lipickovi\Local Settings\Data aplikací\ConduitEngine
2010-12-04 06:33 . 2010-12-04 06:34 -------- d-----w- c:\program files\ConduitEngine
2010-12-04 06:33 . 2010-12-04 06:33 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-12-03 21:19 . 2003-07-06 12:07 372736 ----a-w- c:\windows\system32\IJL_11.DLL
2010-11-16 16:29 . 2010-11-16 16:33 -------- d-----w- c:\program files\ICQ7.2
2010-11-12 17:49 . 2010-11-12 18:38 -------- d-----w- c:\documents and settings\Lipickovi\Data aplikací\avidemux
2010-11-12 17:48 . 2010-11-12 17:49 -------- d-----w- c:\program files\Avidemux 2.5
2010-11-12 17:47 . 2010-11-12 17:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SiComponents
2010-11-10 21:06 . 2010-11-10 21:06 -------- d-----w- c:\documents and settings\Lipickovi\Data aplikací\HandBrake
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 11:49 . 2010-09-28 11:49 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-27 10:29 . 2010-10-07 18:29 563952 ----a-w- C:\WindowsXP-KB893056-x86-CSY.exe
2010-09-27 10:29 . 2010-10-07 18:29 194800 ----a-w- C:\WindowsXP-KB893056-x86-Symbols-CSY.exe
2010-09-26 13:38 . 2010-09-12 06:57 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-09-18 10:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 05:50 . 2010-09-18 05:50 87608 ----a-w- c:\documents and settings\Lipickovi\Data aplikací\inst.exe
2010-09-18 05:50 . 2010-09-18 05:50 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-09-18 05:50 . 2010-09-18 05:50 47360 ----a-w- c:\documents and settings\Lipickovi\Data aplikací\pcouffin.sys
2010-09-18 04:35 . 2010-09-18 04:35 1409 ----a-w- c:\windows\QTFont.for
2010-09-15 03:50 . 2010-09-27 09:55 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 01:29 . 2010-09-27 09:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-12 06:56 . 2010-09-12 06:57 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-12 06:56 . 2010-09-12 06:57 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-09-10 05:52 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1392b8d2-5c05-419f-a8f6-b9f15a596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2010-10-20 19:52 2735200 ----a-w- c:\program files\Freecorder\tbFre1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1392b8d2-5c05-419f-a8f6-b9f15a596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{1392B8D2-5C05-419F-A8F6-B9F15A596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-04-14 16:33 140288 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-12-05 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BDARemote.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk
backup=c:\windows\pss\BDARemote.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
2010-09-07 15:50 2176512 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"WebClient"=2 (0x2)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SSDPSRV"=3 (0x3)
"xmlprov"=3 (0x3)
"ImapiService"=3 (0x3)
"Browser"=2 (0x2)
"Schedule"=2 (0x2)
"UPS"=3 (0x3)
"Themes"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"upnphost"=3 (0x3)
"wscsvc"=2 (0x2)
"SharedAccess"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"CLMLServer"="c:\program files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
"PCMAgent"="c:\program files\CyberLink\PowerCinema\PCMAgent.exe"
"PlayMovie"="c:\program files\CyberLink\PlayMovie\PMVService.exe"
"TVEService"="c:\program files\CyberLink\TV Enhance\TVEService.exe"
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe"
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe"
"BDRegion"=c:\program files\Cyberlink\Shared files\brs.exe
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" /run
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"c:\\Program Files\\CyberLink\\TV Enhance\\TVEnhance.exe"=
"c:\\Program Files\\CyberLink\\TV Enhance\\TVEService.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [8.9.2010 18:55 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [8.9.2010 18:56 196048]
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31.7.2008 19:45 20616]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.9.2010 12:49 691696]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [8.9.2010 18:56 102736]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [8.9.2010 18:56 297552]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.9.2010 18:56 162768]
R1 scrambler;scrambler;c:\windows\system32\drivers\scrambler.sys [14.2.2005 11:17 206336]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [7.9.2010 16:50 142592]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/09/26 15:43];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [13.3.2010 11:58 87536]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\CyberLink\PlayMovie\000.fcl [12.9.2010 8:16 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.9.2010 18:56 19024]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [15.12.2008 13:31 143467]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [7.10.2010 20:52 20328]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [12.9.2010 8:18 364635]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [12.9.2010 8:18 172121]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [6.9.2010 18:19 2829696]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [7.12.2008 11:44 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 13:58 26248]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 20:37 4640000]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [8.9.2010 18:55 119200]
.
Obsah adresáře 'Naplánované úlohy'
2010-10-29 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-10-29 19:55]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Lipickovi\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Lipickovi\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-07 18:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\CyberLink\PlayMovie\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1068)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-12-07 18:25:01
ComboFix-quarantined-files.txt 2010-12-07 17:24
Před spuštěním: Volných bajtů: 21 495 214 080
Po spuštění: Volných bajtů: 21 478 932 480
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=signature(eb2787fd)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
signature(eb2787fd)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 2DD2C286BAA2534CF97BDC8D4B025CCA
ComboFix 10-12-06.04 - Lipickovi 07.12.2010 18:05:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2048.1541 [GMT 1:00]
Spuštěný z: c:\documents and settings\Lipickovi\Plocha\ComboFix.exe
AV: avast! Internet Security *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lipickovi\Data aplikací\PriceGong
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Lipickovi\Data aplikací\PriceGong\Data\z.xml
c:\windows\XSxS
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-07 do 2010-12-07 )))))))))))))))))))))))))))))))
.
2010-12-06 15:37 . 2010-12-07 00:15 -------- d-----w- c:\program files\FreeRapid-0.85
2010-12-04 23:04 . 2007-06-27 01:58 2303488 -c--a-w- c:\windows\system32\dllcache\ati2mtag.sys
2010-12-04 23:04 . 2007-06-27 01:58 2303488 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-12-04 22:49 . 2010-12-04 22:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ATI
2010-12-04 22:48 . 2010-12-04 22:48 0 ----a-w- c:\windows\ativpsrm.bin
2010-12-04 22:24 . 2010-12-04 22:24 -------- d-----w- c:\program files\DIFX
2010-12-04 22:24 . 2010-12-05 13:54 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-04 22:22 . 2010-12-04 22:22 -------- d-----w- C:\ATI
2010-12-04 18:11 . 2010-12-04 18:11 -------- d-----w- c:\program files\Common Files\DirectX
2010-12-04 17:56 . 2010-12-04 17:56 -------- d-----w- c:\program files\SCi Games
2010-12-04 17:56 . 2002-12-05 13:12 692224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2010-12-04 17:56 . 2002-12-05 13:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2010-12-04 17:56 . 2002-12-02 14:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2010-12-04 17:56 . 2002-12-02 12:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2010-12-04 17:56 . 2002-12-02 12:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2010-12-04 17:56 . 2010-12-04 17:56 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2010-12-04 17:56 . 2010-12-04 17:56 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2010-12-04 15:50 . 2010-12-04 16:04 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-12-04 15:37 . 2010-12-04 16:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
2010-12-04 15:37 . 2010-12-04 15:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Symantec
2010-12-04 15:34 . 2010-12-04 15:53 -------- d-----w- c:\windows\system32\Adobe
2010-12-04 10:54 . 2010-12-04 10:54 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-04 07:28 . 2010-12-04 11:55 -------- d-----w- c:\program files\trend micro
2010-12-04 07:28 . 2010-12-04 07:29 -------- d-----w- C:\rsit
2010-12-04 06:34 . 2010-12-04 06:34 -------- d-----w- c:\documents and settings\Lipickovi\Local Settings\Data aplikací\ConduitEngine
2010-12-04 06:33 . 2010-12-04 06:34 -------- d-----w- c:\program files\ConduitEngine
2010-12-04 06:33 . 2010-12-04 06:33 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-12-03 21:19 . 2003-07-06 12:07 372736 ----a-w- c:\windows\system32\IJL_11.DLL
2010-11-16 16:29 . 2010-11-16 16:33 -------- d-----w- c:\program files\ICQ7.2
2010-11-12 17:49 . 2010-11-12 18:38 -------- d-----w- c:\documents and settings\Lipickovi\Data aplikací\avidemux
2010-11-12 17:48 . 2010-11-12 17:49 -------- d-----w- c:\program files\Avidemux 2.5
2010-11-12 17:47 . 2010-11-12 17:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SiComponents
2010-11-10 21:06 . 2010-11-10 21:06 -------- d-----w- c:\documents and settings\Lipickovi\Data aplikací\HandBrake
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 11:49 . 2010-09-28 11:49 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-27 10:29 . 2010-10-07 18:29 563952 ----a-w- C:\WindowsXP-KB893056-x86-CSY.exe
2010-09-27 10:29 . 2010-10-07 18:29 194800 ----a-w- C:\WindowsXP-KB893056-x86-Symbols-CSY.exe
2010-09-26 13:38 . 2010-09-12 06:57 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-09-18 10:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 05:50 . 2010-09-18 05:50 87608 ----a-w- c:\documents and settings\Lipickovi\Data aplikací\inst.exe
2010-09-18 05:50 . 2010-09-18 05:50 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-09-18 05:50 . 2010-09-18 05:50 47360 ----a-w- c:\documents and settings\Lipickovi\Data aplikací\pcouffin.sys
2010-09-18 04:35 . 2010-09-18 04:35 1409 ----a-w- c:\windows\QTFont.for
2010-09-15 03:50 . 2010-09-27 09:55 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 01:29 . 2010-09-27 09:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-12 06:56 . 2010-09-12 06:57 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-12 06:56 . 2010-09-12 06:57 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-09-10 05:52 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1392b8d2-5c05-419f-a8f6-b9f15a596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2010-10-20 19:52 2735200 ----a-w- c:\program files\Freecorder\tbFre1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1392b8d2-5c05-419f-a8f6-b9f15a596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{1392B8D2-5C05-419F-A8F6-B9F15A596612}"= "c:\program files\Freecorder\tbFre1.dll" [2010-10-20 2735200]
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-04-14 16:33 140288 ----a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-12-05 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BDARemote.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\BDARemote.lnk
backup=c:\windows\pss\BDARemote.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
2010-09-07 15:50 2176512 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"WebClient"=2 (0x2)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SSDPSRV"=3 (0x3)
"xmlprov"=3 (0x3)
"ImapiService"=3 (0x3)
"Browser"=2 (0x2)
"Schedule"=2 (0x2)
"UPS"=3 (0x3)
"Themes"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"upnphost"=3 (0x3)
"wscsvc"=2 (0x2)
"SharedAccess"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"CLMLServer"="c:\program files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
"PCMAgent"="c:\program files\CyberLink\PowerCinema\PCMAgent.exe"
"PlayMovie"="c:\program files\CyberLink\PlayMovie\PMVService.exe"
"TVEService"="c:\program files\CyberLink\TV Enhance\TVEService.exe"
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe"
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe"
"BDRegion"=c:\program files\Cyberlink\Shared files\brs.exe
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" /run
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"c:\\Program Files\\CyberLink\\TV Enhance\\TVEnhance.exe"=
"c:\\Program Files\\CyberLink\\TV Enhance\\TVEService.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [8.9.2010 18:55 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [8.9.2010 18:56 196048]
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31.7.2008 19:45 20616]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.9.2010 12:49 691696]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [8.9.2010 18:56 102736]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [8.9.2010 18:56 297552]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.9.2010 18:56 162768]
R1 scrambler;scrambler;c:\windows\system32\drivers\scrambler.sys [14.2.2005 11:17 206336]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [7.9.2010 16:50 142592]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/09/26 15:43];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [13.3.2010 11:58 87536]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\CyberLink\PlayMovie\000.fcl [12.9.2010 8:16 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.9.2010 18:56 19024]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [15.12.2008 13:31 143467]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [7.10.2010 20:52 20328]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [12.9.2010 8:18 364635]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [12.9.2010 8:18 172121]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [6.9.2010 18:19 2829696]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [7.12.2008 11:44 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 13:58 26248]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 20:37 4640000]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [8.9.2010 18:55 119200]
.
Obsah adresáře 'Naplánované úlohy'
2010-10-29 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-10-29 19:55]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Lipickovi\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Lipickovi\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-07 18:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\CyberLink\PlayMovie\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1068)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-12-07 18:25:01
ComboFix-quarantined-files.txt 2010-12-07 17:24
Před spuštěním: Volných bajtů: 21 495 214 080
Po spuštění: Volných bajtů: 21 478 932 480
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=signature(eb2787fd)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
signature(eb2787fd)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 2DD2C286BAA2534CF97BDC8D4B025CCA