Tak tady to je..
ComboFix 11-02-19.02 - Doma 20.02.2011 15:36:14.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3071.2455 [GMT 1:00]
Spuštěný z: c:\documents and settings\Doma\Plocha\žížala.com.exe
Použité ovládací přepínače :: c:\documents and settings\Doma\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\niqilad.sys
.
--------------- FCopy ---------------
c:\proquota.exe --> c:\windows\system32\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_lwpjk
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-20 do 2011-02-20 )))))))))))))))))))))))))))))))
.
2011-02-20 14:36 . 2009-08-17 14:26 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2011-02-20 14:36 . 2009-08-17 14:26 50176 ----a-w- c:\windows\system32\proquota.exe
2011-02-20 14:31 . 2009-08-17 14:26 50176 ------w- C:\proquota.exe
2011-02-20 13:42 . 2011-02-20 13:42 -------- d-----w- c:\documents and settings\Doma\Data aplikací\Malwarebytes
2011-02-20 13:42 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-20 13:42 . 2011-02-20 13:42 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-20 13:42 . 2011-02-20 13:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-20 13:42 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-20 12:28 . 2011-02-20 12:41 -------- d-----w- C:\žížala.com
2011-02-20 10:40 . 2011-02-20 10:40 388096 ----a-r- c:\documents and settings\Doma\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-20 10:40 . 2011-02-20 10:40 -------- d-----w- c:\program files\Trend Micro
2011-02-20 08:24 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-20 08:24 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-20 08:24 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-20 08:24 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-20 08:24 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-20 08:24 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-20 08:24 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-20 08:24 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-20 08:24 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-20 08:24 . 2011-02-20 08:24 -------- d-----w- c:\program files\Alwil Software
2011-02-20 08:24 . 2011-02-20 08:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2011-02-14 13:55 . 2011-02-14 13:55 -------- d-----w- c:\documents and settings\Doma\Local Settings\Data aplikací\IVASystem
2011-02-14 13:55 . 2011-02-14 13:55 -------- d-----w- c:\program files\IVA_Client
2011-02-08 11:30 . 2011-02-08 11:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NovaTech Network
2011-02-08 11:28 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-02-08 11:28 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-02-08 11:28 . 2011-02-08 11:28 -------- d-----w- c:\windows\Logs
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
------- Sigcheck -------
[-] 2008-09-26 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2011-02-20_12.38.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-20 14:40 . 2011-02-20 14:40 16384 c:\windows\temp\Perflib_Perfdata_fc0.dat
+ 2011-02-20 14:39 . 2011-02-20 14:39 16384 c:\windows\temp\Perflib_Perfdata_858.dat
+ 2008-07-18 20:10 . 2009-08-06 18:24 44768 c:\windows\system32\wups2.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 35552 c:\windows\system32\wups.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 53472 c:\windows\system32\wuauclt.exe
+ 2011-02-20 12:40 . 2009-08-06 18:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2011-02-20 12:40 . 2009-08-06 18:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2008-04-14 06:51 . 2009-08-06 18:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2008-04-14 06:51 . 2009-08-06 18:24 96480 c:\windows\system32\cdm.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 209632 c:\windows\system32\wuweb.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 327896 c:\windows\system32\wucltui.dll
+ 2008-09-29 18:50 . 2009-08-06 18:23 575704 c:\windows\system32\wuapi.dll
+ 2008-07-18 20:07 . 2009-08-06 18:23 215920 c:\windows\system32\muweb.dll
+ 2008-09-02 16:38 . 2009-08-06 18:23 274288 c:\windows\system32\mucltui.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2008-09-29 18:50 . 2009-08-06 18:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2008-09-29 18:50 . 2009-08-06 18:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2008-09-29 18:50 . 2009-08-06 18:23 1929952 c:\windows\system32\wuaueng.dll
+ 2008-09-29 18:50 . 2009-08-06 18:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-09-02 13351304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-02 149280]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-03-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Doma\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-3-16 393216]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\~Disabled
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2010-1-2 57344]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Metin2_CZ\\metin2client.bin"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\TopCD\\Cossacks\\Cossacks - Napoleonic Wars\\Data\\engine.exe"=
"c:\\Program Files\\TrackMania Nations ESWC Special Edition\\TmNationsESWC.exe"=
"c:\\Program Files\\IVA_Client\\Client_IVA.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.2.2011 9:24 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.2.2011 9:24 17744]
R2 iva_control;iva_control;c:\program files\IVA_Client\iva_control.exe [19.3.2010 13:00 36864]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6.7.2010 15:17 136176]
S3 uvnc_service;uvnc_service;c:\program files\IVA_Client\VNC\winvnc.exe [5.12.2009 16:00 1581512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2011-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 14:17]
2011-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 14:17]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Doma\Data aplikací\Mozilla\Firefox\Profiles\govoovn8.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-02-20 15:40
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3216)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\windows\RTHDCPL.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Skype\Phone\Skype.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.BIN
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2011-02-20 15:42:41 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-20 14:42
ComboFix2.txt 2011-02-20 13:24
ComboFix3.txt 2011-02-20 12:41
ComboFix4.txt 2009-06-04 20:27
ComboFix5.txt 2011-02-20 14:35
Před spuštěním: Volných bajtů: 80 306 577 408
Po spuštění: Volných bajtů: 80 290 930 688
- - End Of File - - DFFEB751633215B7D2453D7922630AB4