Re: Problém s javou a flash playerem
Napsal: 15 pro 2010 22:12
Tady je loq z ComboFixu s CFScriptem:
ComboFix 10-12-15.03 - Ales 15.12.2010 21:21:02.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2831 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ales\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Ales\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA281
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-15 do 2010-12-15 )))))))))))))))))))))))))))))))
.
2010-12-14 19:46 . 2010-12-14 19:57 -------- d-----w- C:\UsbFix
2010-12-14 18:09 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-14 18:09 . 2010-12-14 18:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-14 18:09 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 17:29 . 2010-12-14 17:29 -------- d-----w- C:\_OTL
2010-12-12 15:56 . 2010-12-12 15:56 -------- d-----w- c:\program files\PopCap Games
2010-12-12 14:27 . 2010-12-12 14:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PopCap Games
2010-12-09 21:00 . 2010-12-12 19:58 -------- d-----w- c:\program files\CCleaner
2010-12-09 20:59 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-09 20:59 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-09 20:59 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-09 20:58 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-09 20:58 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-09 20:58 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-09 20:58 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-09 20:58 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-09 20:58 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-09 20:58 . 2010-12-09 20:58 -------- d-----w- c:\program files\Alwil Software
2010-12-09 17:59 . 2010-12-09 17:59 -------- d-----w- c:\documents and settings\Ales\Local Settings\Data aplikací\{3248F0A6-6813-11D6-A77B-00B0D0150000}
2010-12-09 17:43 . 2010-12-09 17:43 -------- d-----w- c:\program files\WinASO
2010-12-09 17:15 . 2010-12-09 17:16 -------- dc-h--w- c:\windows\ie8
2010-12-05 16:38 . 2010-12-14 18:36 -------- d-----w- c:\program files\DiaryOne
2010-12-05 16:26 . 2010-12-05 16:26 -------- d-----w- c:\documents and settings\Ales\Data aplikací\TrayCalendar
2010-12-05 16:23 . 2010-12-05 16:23 -------- d-----w- c:\documents and settings\Ales\Data aplikací\Chaos Software
2010-12-05 16:23 . 2010-12-05 16:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Chaos Software
2010-12-05 14:34 . 2010-12-05 14:34 -------- d-----w- c:\documents and settings\Ales\Data aplikací\Konrad Papala
2010-12-05 13:00 . 2010-12-05 13:00 -------- d-----w- c:\documents and settings\Ales\Data aplikací\ZJSoftware
2010-12-05 12:33 . 2010-12-05 12:33 -------- d-----w- c:\documents and settings\Ales\Data aplikací\XemiComputers
2010-12-05 10:55 . 2010-12-05 10:55 -------- d-----w- c:\documents and settings\Ales\Data aplikací\ERGOM
2010-12-05 10:54 . 2010-12-05 10:54 -------- d-----w- c:\program files\Business Objects
2010-11-28 09:15 . 1999-09-10 11:06 5600 ----a-w- c:\windows\system\WINASPI.DLL
2010-11-28 09:15 . 1999-09-10 11:06 4672 ----a-w- c:\windows\system\WOWPOST.EXE
2010-11-27 13:18 . 2010-11-27 13:18 -------- d-----w- c:\documents and settings\Ales\Local Settings\Data aplikací\Electronic Arts
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 01:36 . 2009-11-05 15:13 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-12-12 01:36 . 2009-11-05 15:13 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-12-12 01:36 . 2009-03-01 19:00 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-12-11 23:28 . 2009-11-05 15:13 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-03 18:46 . 2009-06-01 21:01 475136 ------w- c:\windows\Setup1.exe
2010-12-03 18:46 . 2009-06-01 21:01 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-11-27 10:04 . 2009-11-05 15:13 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-10-23 21:42 . 2010-10-23 21:31 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-19 20:37 . 2008-10-04 12:12 22328 ----a-w- c:\documents and settings\Ales\Data aplikací\PnkBstrK.sys
2010-09-19 20:37 . 2010-05-27 18:38 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2010-09-18 10:23 . 2004-08-17 13:49 974848 ------w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-17 13:49 974848 ------w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2001-10-25 14:00 954368 ------w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2001-10-25 14:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 139264]
"OEXPRESS"="c:\windows\OETRN.EXE" [2009-11-09 26624]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-25 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-02 98304]
"AMTDeviceService"="c:\program files\AMT Media Manager\AMTDeviceService.exe" [2009-01-21 184320]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-17 44544]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
BDARemote.lnk - c:\program files\USB TV\EM28XX\BDARemote.exe [2009-10-28 81997]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"e:\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"e:\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.10.2010 22:31 691696]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.12.2010 21:59 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.12.2010 21:59 17744]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [28.10.2009 16:35 9446]
R3 WFLR6654;WinFast TV2000 XP Global/Global TV (Video);c:\windows\system32\drivers\wfeaglxt.sys [2.10.2008 21:51 405632]
S2 gupdate;Služba Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;e:\dragon age\bin_ship\daupdatersvc.service.exe [26.12.2009 9:01 25832]
S3 DIGIRPS;Ovladač Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [28.11.2009 19:33 42432]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [29.5.2010 11:04 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [29.5.2010 11:04 8320]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.idnes.cz/
IE: DiaryOne: Save full text - c:\program files\DiaryOne\Script\fullcatcher.htm
IE: DiaryOne: Save selected text - c:\program files\DiaryOne\Script\catcher.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-15 21:27
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0CFCE647-8B7D-FDC9-CAAA-30D2BBB939F8}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:16,14,7e,3e,f9,c1,ad,28,5d,8b,e1,53,15,00,07,91,b8,4b,cd,53,e9,a0,a5,
b6,5f,87,78,1e,17,e1,97,73,16,56,99,33,0a,26,34,8b,ca,16,8c,8d,37,6b,47,00,\
"??"=hex:25,37,22,6c,20,3a,78,8f,8b,c0,d1,01,fd,51,a6,28
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:0d,dd,55,5a,51,74,64,ed,b7,45,88,a9,d0,ad,e7,6f,26,80,8a,e0,f0,
fd,12,76,51,75,fb,5c,91,0a,5f,a1,dc,b4,f1,51,58,65,b6,70,e4,dd,5b,75,96,5a,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'explorer.exe'(1112)
c:\windows\TrnOEH.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-12-15 21:31:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-15 20:31
Před spuštěním: Volných bajtů: 10 139 172 864
Po spuštění: Volných bajtů: 10 103 054 336
- - End Of File - - CC50449A061092ADFFC5BE8EB1E33AC7
Nevím, jak jste myslela ty linky, ale prostě jsem to jen zkopíroval do poz. bloku, snad to bude stačit. Mimoch. ComboFix se chtěl aktualizovat, dal jsem ne a použil jsem ho s "originálním" názvem, ne jako žížala.com
WINASPI.DLL
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: WINASPI.DLL
Submission date: 2010-12-15 21:07:07 (UTC)
Current status: queued (#10) queued analysing finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2010.12.15.02 2010.12.15 -
AntiVir 7.11.0.45 2010.12.15 -
Antiy-AVL 2.0.3.7 2010.12.15 -
Avast 4.8.1351.0 2010.12.15 -
Avast5 5.0.677.0 2010.12.15 -
AVG 9.0.0.851 2010.12.15 -
BitDefender 7.2 2010.12.15 -
CAT-QuickHeal 11.00 2010.12.15 -
ClamAV 0.96.4.0 2010.12.15 -
Command 5.2.11.5 2010.12.15 -
Comodo 7072 2010.12.15 -
DrWeb 5.0.2.03300 2010.12.15 -
Emsisoft 5.1.0.1 2010.12.15 -
eSafe 7.0.17.0 2010.12.15 -
eTrust-Vet 36.1.8043 2010.12.15 -
F-Prot 4.6.2.117 2010.12.15 -
F-Secure 9.0.16160.0 2010.12.15 -
Fortinet 4.2.254.0 2010.12.15 -
GData 21 2010.12.15 -
Ikarus T3.1.1.90.0 2010.12.15 -
Jiangmin 13.0.900 2010.12.15 -
K7AntiVirus 9.73.3258 2010.12.15 -
Kaspersky 7.0.0.125 2010.12.15 -
McAfee 5.400.0.1158 2010.12.15 -
McAfee-GW-Edition 2010.1C 2010.12.15 -
Microsoft 1.6402 2010.12.15 -
NOD32 5706 2010.12.15 -
Norman 6.06.12 2010.12.15 -
nProtect 2010-12-15.02 2010.12.15 -
Panda 10.0.2.7 2010.12.15 -
PCTools 7.0.3.5 2010.12.15 -
Prevx 3.0 2010.12.15 -
Rising 22.78.01.04 2010.12.15 -
Sophos 4.60.0 2010.12.15 -
SUPERAntiSpyware 4.40.0.1006 2010.12.15 -
Symantec 20101.3.0.103 2010.12.15 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.15 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.15 -
VBA32 3.12.14.2 2010.12.14 -
VIPRE 7666 2010.12.15 -
ViRobot 2010.12.15.4202 2010.12.15 -
VirusBuster 13.6.96.0 2010.12.15 -
WOWPOST.EXE
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: WOWPOST.EXE
Submission date: 2010-12-15 21:00:22 (UTC)
Current status: queued (#3) queued (#3) analysing finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2010.12.15.02 2010.12.15 -
AntiVir 7.11.0.45 2010.12.15 -
Antiy-AVL 2.0.3.7 2010.12.15 -
Avast 4.8.1351.0 2010.12.15 -
Avast5 5.0.677.0 2010.12.15 -
AVG 9.0.0.851 2010.12.15 -
BitDefender 7.2 2010.12.15 -
CAT-QuickHeal 11.00 2010.12.15 -
ClamAV 0.96.4.0 2010.12.15 -
Command 5.2.11.5 2010.12.15 -
Comodo 7072 2010.12.15 -
DrWeb 5.0.2.03300 2010.12.15 -
Emsisoft 5.1.0.1 2010.12.15 -
eSafe 7.0.17.0 2010.12.15 -
eTrust-Vet 36.1.8043 2010.12.15 -
F-Prot 4.6.2.117 2010.12.15 -
F-Secure 9.0.16160.0 2010.12.15 -
Fortinet 4.2.254.0 2010.12.15 -
GData 21 2010.12.15 -
Ikarus T3.1.1.90.0 2010.12.15 -
Jiangmin 13.0.900 2010.12.15 -
K7AntiVirus 9.73.3258 2010.12.15 -
Kaspersky 7.0.0.125 2010.12.15 -
McAfee 5.400.0.1158 2010.12.15 -
McAfee-GW-Edition 2010.1C 2010.12.15 -
Microsoft 1.6402 2010.12.15 -
NOD32 5706 2010.12.15 -
Norman 6.06.12 2010.12.15 -
nProtect 2010-12-15.02 2010.12.15 -
Panda 10.0.2.7 2010.12.15 -
PCTools 7.0.3.5 2010.12.15 -
Prevx 3.0 2010.12.15 -
Rising 22.78.01.04 2010.12.15 -
Sophos 4.60.0 2010.12.15 -
SUPERAntiSpyware 4.40.0.1006 2010.12.15 -
Symantec 20101.3.0.103 2010.12.15 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.15 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.15 -
VBA32 3.12.14.2 2010.12.14 -
VIPRE 7666 2010.12.15 -
ViRobot 2010.12.15.4202 2010.12.15 -
VirusBuster 13.6.96.0 2010.12.15 -
ComboFix 10-12-15.03 - Ales 15.12.2010 21:21:02.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2831 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ales\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Ales\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA281
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-15 do 2010-12-15 )))))))))))))))))))))))))))))))
.
2010-12-14 19:46 . 2010-12-14 19:57 -------- d-----w- C:\UsbFix
2010-12-14 18:09 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-14 18:09 . 2010-12-14 18:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-14 18:09 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 17:29 . 2010-12-14 17:29 -------- d-----w- C:\_OTL
2010-12-12 15:56 . 2010-12-12 15:56 -------- d-----w- c:\program files\PopCap Games
2010-12-12 14:27 . 2010-12-12 14:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PopCap Games
2010-12-09 21:00 . 2010-12-12 19:58 -------- d-----w- c:\program files\CCleaner
2010-12-09 20:59 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-09 20:59 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-09 20:59 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-09 20:58 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-09 20:58 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-09 20:58 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-09 20:58 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-09 20:58 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-09 20:58 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-09 20:58 . 2010-12-09 20:58 -------- d-----w- c:\program files\Alwil Software
2010-12-09 17:59 . 2010-12-09 17:59 -------- d-----w- c:\documents and settings\Ales\Local Settings\Data aplikací\{3248F0A6-6813-11D6-A77B-00B0D0150000}
2010-12-09 17:43 . 2010-12-09 17:43 -------- d-----w- c:\program files\WinASO
2010-12-09 17:15 . 2010-12-09 17:16 -------- dc-h--w- c:\windows\ie8
2010-12-05 16:38 . 2010-12-14 18:36 -------- d-----w- c:\program files\DiaryOne
2010-12-05 16:26 . 2010-12-05 16:26 -------- d-----w- c:\documents and settings\Ales\Data aplikací\TrayCalendar
2010-12-05 16:23 . 2010-12-05 16:23 -------- d-----w- c:\documents and settings\Ales\Data aplikací\Chaos Software
2010-12-05 16:23 . 2010-12-05 16:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Chaos Software
2010-12-05 14:34 . 2010-12-05 14:34 -------- d-----w- c:\documents and settings\Ales\Data aplikací\Konrad Papala
2010-12-05 13:00 . 2010-12-05 13:00 -------- d-----w- c:\documents and settings\Ales\Data aplikací\ZJSoftware
2010-12-05 12:33 . 2010-12-05 12:33 -------- d-----w- c:\documents and settings\Ales\Data aplikací\XemiComputers
2010-12-05 10:55 . 2010-12-05 10:55 -------- d-----w- c:\documents and settings\Ales\Data aplikací\ERGOM
2010-12-05 10:54 . 2010-12-05 10:54 -------- d-----w- c:\program files\Business Objects
2010-11-28 09:15 . 1999-09-10 11:06 5600 ----a-w- c:\windows\system\WINASPI.DLL
2010-11-28 09:15 . 1999-09-10 11:06 4672 ----a-w- c:\windows\system\WOWPOST.EXE
2010-11-27 13:18 . 2010-11-27 13:18 -------- d-----w- c:\documents and settings\Ales\Local Settings\Data aplikací\Electronic Arts
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 01:36 . 2009-11-05 15:13 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-12-12 01:36 . 2009-11-05 15:13 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-12-12 01:36 . 2009-03-01 19:00 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-12-11 23:28 . 2009-11-05 15:13 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-03 18:46 . 2009-06-01 21:01 475136 ------w- c:\windows\Setup1.exe
2010-12-03 18:46 . 2009-06-01 21:01 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-11-27 10:04 . 2009-11-05 15:13 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-10-23 21:42 . 2010-10-23 21:31 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-19 20:37 . 2008-10-04 12:12 22328 ----a-w- c:\documents and settings\Ales\Data aplikací\PnkBstrK.sys
2010-09-19 20:37 . 2010-05-27 18:38 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2010-09-18 10:23 . 2004-08-17 13:49 974848 ------w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-17 13:49 974848 ------w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2001-10-25 14:00 954368 ------w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2001-10-25 14:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 139264]
"OEXPRESS"="c:\windows\OETRN.EXE" [2009-11-09 26624]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-25 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-02 98304]
"AMTDeviceService"="c:\program files\AMT Media Manager\AMTDeviceService.exe" [2009-01-21 184320]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-17 44544]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
BDARemote.lnk - c:\program files\USB TV\EM28XX\BDARemote.exe [2009-10-28 81997]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"e:\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"e:\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.10.2010 22:31 691696]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.12.2010 21:59 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.12.2010 21:59 17744]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [28.10.2009 16:35 9446]
R3 WFLR6654;WinFast TV2000 XP Global/Global TV (Video);c:\windows\system32\drivers\wfeaglxt.sys [2.10.2008 21:51 405632]
S2 gupdate;Služba Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;e:\dragon age\bin_ship\daupdatersvc.service.exe [26.12.2009 9:01 25832]
S3 DIGIRPS;Ovladač Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [28.11.2009 19:33 42432]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [29.5.2010 11:04 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [29.5.2010 11:04 8320]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.idnes.cz/
IE: DiaryOne: Save full text - c:\program files\DiaryOne\Script\fullcatcher.htm
IE: DiaryOne: Save selected text - c:\program files\DiaryOne\Script\catcher.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-15 21:27
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0CFCE647-8B7D-FDC9-CAAA-30D2BBB939F8}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:16,14,7e,3e,f9,c1,ad,28,5d,8b,e1,53,15,00,07,91,b8,4b,cd,53,e9,a0,a5,
b6,5f,87,78,1e,17,e1,97,73,16,56,99,33,0a,26,34,8b,ca,16,8c,8d,37,6b,47,00,\
"??"=hex:25,37,22,6c,20,3a,78,8f,8b,c0,d1,01,fd,51,a6,28
[HKEY_USERS\S-1-5-21-746137067-1292428093-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:0d,dd,55,5a,51,74,64,ed,b7,45,88,a9,d0,ad,e7,6f,26,80,8a,e0,f0,
fd,12,76,51,75,fb,5c,91,0a,5f,a1,dc,b4,f1,51,58,65,b6,70,e4,dd,5b,75,96,5a,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'explorer.exe'(1112)
c:\windows\TrnOEH.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-12-15 21:31:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-15 20:31
Před spuštěním: Volných bajtů: 10 139 172 864
Po spuštění: Volných bajtů: 10 103 054 336
- - End Of File - - CC50449A061092ADFFC5BE8EB1E33AC7
Nevím, jak jste myslela ty linky, ale prostě jsem to jen zkopíroval do poz. bloku, snad to bude stačit. Mimoch. ComboFix se chtěl aktualizovat, dal jsem ne a použil jsem ho s "originálním" názvem, ne jako žížala.com
WINASPI.DLL
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: WINASPI.DLL
Submission date: 2010-12-15 21:07:07 (UTC)
Current status: queued (#10) queued analysing finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2010.12.15.02 2010.12.15 -
AntiVir 7.11.0.45 2010.12.15 -
Antiy-AVL 2.0.3.7 2010.12.15 -
Avast 4.8.1351.0 2010.12.15 -
Avast5 5.0.677.0 2010.12.15 -
AVG 9.0.0.851 2010.12.15 -
BitDefender 7.2 2010.12.15 -
CAT-QuickHeal 11.00 2010.12.15 -
ClamAV 0.96.4.0 2010.12.15 -
Command 5.2.11.5 2010.12.15 -
Comodo 7072 2010.12.15 -
DrWeb 5.0.2.03300 2010.12.15 -
Emsisoft 5.1.0.1 2010.12.15 -
eSafe 7.0.17.0 2010.12.15 -
eTrust-Vet 36.1.8043 2010.12.15 -
F-Prot 4.6.2.117 2010.12.15 -
F-Secure 9.0.16160.0 2010.12.15 -
Fortinet 4.2.254.0 2010.12.15 -
GData 21 2010.12.15 -
Ikarus T3.1.1.90.0 2010.12.15 -
Jiangmin 13.0.900 2010.12.15 -
K7AntiVirus 9.73.3258 2010.12.15 -
Kaspersky 7.0.0.125 2010.12.15 -
McAfee 5.400.0.1158 2010.12.15 -
McAfee-GW-Edition 2010.1C 2010.12.15 -
Microsoft 1.6402 2010.12.15 -
NOD32 5706 2010.12.15 -
Norman 6.06.12 2010.12.15 -
nProtect 2010-12-15.02 2010.12.15 -
Panda 10.0.2.7 2010.12.15 -
PCTools 7.0.3.5 2010.12.15 -
Prevx 3.0 2010.12.15 -
Rising 22.78.01.04 2010.12.15 -
Sophos 4.60.0 2010.12.15 -
SUPERAntiSpyware 4.40.0.1006 2010.12.15 -
Symantec 20101.3.0.103 2010.12.15 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.15 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.15 -
VBA32 3.12.14.2 2010.12.14 -
VIPRE 7666 2010.12.15 -
ViRobot 2010.12.15.4202 2010.12.15 -
VirusBuster 13.6.96.0 2010.12.15 -
WOWPOST.EXE
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: WOWPOST.EXE
Submission date: 2010-12-15 21:00:22 (UTC)
Current status: queued (#3) queued (#3) analysing finished
Result: 0/ 43 (0.0%)
VT Community
not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2010.12.15.02 2010.12.15 -
AntiVir 7.11.0.45 2010.12.15 -
Antiy-AVL 2.0.3.7 2010.12.15 -
Avast 4.8.1351.0 2010.12.15 -
Avast5 5.0.677.0 2010.12.15 -
AVG 9.0.0.851 2010.12.15 -
BitDefender 7.2 2010.12.15 -
CAT-QuickHeal 11.00 2010.12.15 -
ClamAV 0.96.4.0 2010.12.15 -
Command 5.2.11.5 2010.12.15 -
Comodo 7072 2010.12.15 -
DrWeb 5.0.2.03300 2010.12.15 -
Emsisoft 5.1.0.1 2010.12.15 -
eSafe 7.0.17.0 2010.12.15 -
eTrust-Vet 36.1.8043 2010.12.15 -
F-Prot 4.6.2.117 2010.12.15 -
F-Secure 9.0.16160.0 2010.12.15 -
Fortinet 4.2.254.0 2010.12.15 -
GData 21 2010.12.15 -
Ikarus T3.1.1.90.0 2010.12.15 -
Jiangmin 13.0.900 2010.12.15 -
K7AntiVirus 9.73.3258 2010.12.15 -
Kaspersky 7.0.0.125 2010.12.15 -
McAfee 5.400.0.1158 2010.12.15 -
McAfee-GW-Edition 2010.1C 2010.12.15 -
Microsoft 1.6402 2010.12.15 -
NOD32 5706 2010.12.15 -
Norman 6.06.12 2010.12.15 -
nProtect 2010-12-15.02 2010.12.15 -
Panda 10.0.2.7 2010.12.15 -
PCTools 7.0.3.5 2010.12.15 -
Prevx 3.0 2010.12.15 -
Rising 22.78.01.04 2010.12.15 -
Sophos 4.60.0 2010.12.15 -
SUPERAntiSpyware 4.40.0.1006 2010.12.15 -
Symantec 20101.3.0.103 2010.12.15 -
TheHacker 6.7.0.1.101 2010.12.15 -
TrendMicro 9.120.0.1004 2010.12.15 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.15 -
VBA32 3.12.14.2 2010.12.14 -
VIPRE 7666 2010.12.15 -
ViRobot 2010.12.15.4202 2010.12.15 -
VirusBuster 13.6.96.0 2010.12.15 -