Re: Svchost a USB no function
Napsal: 11 bře 2011 18:48
ComboFix 11-03-10.04 - pc 11.03.2011 18:26:08.3.1 - x86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.420.1029.18.1023.685 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Dokumenty\Stažené soubory\ComboFix.exe
.
/wow section - STAGE 10
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\winnt\system\winspool.drv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-11 do 2011-03-11 )))))))))))))))))))))))))))))))
.
.
2011-03-11 07:20 . 2011-03-11 07:41 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Deployment
2011-03-10 19:38 . 2003-06-19 11:05 90384 ----a-w- c:\winnt\system32\CRYPTDLG.DLL
2011-03-10 19:38 . 2003-06-19 11:05 380957 ------w- c:\winnt\system32\expsrv.dll
2011-03-10 19:38 . 2003-06-19 11:05 30749 ------w- c:\winnt\system32\vbajet32.dll
2011-03-09 20:54 . 2003-02-01 11:08 192512 -c--a-w- c:\winnt\system32\dllcache\unregmp2.exe
2011-03-09 20:54 . 2002-12-12 18:45 301712 -c--a-w- c:\winnt\system32\dllcache\drmclien.dll
2011-03-09 20:54 . 2002-12-12 00:34 9728 -c--a-w- c:\winnt\system32\dllcache\npwmsdrm.dll
2011-03-09 20:54 . 2002-12-12 00:34 9728 ----a-w- c:\program files\Windows Media Player\npwmsdrm.dll
2011-03-09 20:54 . 2002-12-12 00:34 82432 -c--a-w- c:\winnt\system32\dllcache\drmstor.dll
2011-03-09 20:54 . 2002-12-12 00:34 82432 ----a-w- c:\winnt\system32\drmstor.dll
2011-03-09 20:53 . 2002-10-04 01:05 831488 ----a-w- c:\program files\Windows Media Player\Roxio\wmburn.exe
2011-03-09 20:53 . 2002-10-04 01:05 180224 ----a-w- c:\program files\Windows Media Player\Roxio\rsl.dll
2011-03-09 17:49 . 2011-03-09 17:49 -------- d-----w- c:\program files\SimBin
2011-03-09 17:37 . 2010-11-03 19:08 237568 ----a-w- c:\winnt\system32\yv12vfw.dll
2011-03-09 17:37 . 2010-01-17 16:18 151552 ----a-w- c:\winnt\system32\ac3acm.acm
2011-03-09 17:37 . 2009-07-03 14:13 121344 ----a-w- c:\winnt\system32\lagarith.dll
2011-03-09 17:37 . 2008-09-24 19:41 839680 ----a-w- c:\winnt\system32\lameACM.acm
2011-03-09 17:37 . 2006-04-02 13:47 630784 ----a-w- c:\winnt\system32\vp7vfw.dll
2011-03-09 17:37 . 2011-01-28 08:00 80896 ----a-w- c:\winnt\system32\ff_vfw.dll
2011-03-09 17:37 . 2010-12-07 18:40 183808 ----a-w- c:\winnt\system32\xvidvfw.dll
2011-03-09 17:37 . 2010-12-07 18:22 810496 ----a-w- c:\winnt\system32\xvidcore.dll
2011-03-09 17:37 . 2011-03-09 21:00 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-09 16:47 . 2011-03-09 16:47 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\ATI
2011-03-09 16:47 . 2011-03-09 16:47 -------- d-----w- c:\documents and settings\pc\Data aplikací\ATI
2011-03-09 16:40 . 2005-05-03 20:05 516096 ------w- c:\winnt\system32\ati2sgag.exe
2011-03-09 16:39 . 2011-03-09 16:41 -------- d-----w- c:\program files\ATI Technologies
2011-03-09 16:38 . 2005-05-03 20:05 212992 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2011-03-09 16:33 . 2004-05-02 08:47 23040 ----a-r- c:\winnt\system32\drivers\GVCplDrv.sys
2011-03-09 16:31 . 2003-06-19 11:05 21008 -c--a-w- c:\winnt\system32\dllcache\agp440.sys
2011-03-09 16:31 . 2003-06-19 11:05 21008 ----a-w- c:\winnt\system32\drivers\AGP440.SYS
2011-03-03 18:58 . 2011-03-03 18:58 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-03-03 18:37 . 2011-03-03 18:37 -------- d-----w- c:\documents and settings\pc\Data aplikací\GlarySoft
2011-03-03 18:30 . 2011-03-03 18:30 -------- d-----w- c:\program files\Glary Utilities
2011-03-01 18:06 . 2011-03-01 18:06 -------- d-----w- c:\program files\Defraggler
2011-02-27 15:10 . 2011-03-09 17:45 -------- d-----w- c:\documents and settings\pc\Data aplikací\Media Player Classic
2011-02-22 20:02 . 2011-02-22 20:00 13951112 ----a-w- c:\program files\Windows Media Player\Installer\winmediaplayer9.exe
2011-02-22 20:02 . 2002-07-06 17:01 54688 ----a-w- c:\program files\Windows Media Player\1033\dwintl.dll
2011-02-22 20:02 . 2002-12-12 18:45 301712 ----a-w- c:\winnt\system32\drmclien.dll
2011-02-21 19:24 . 2011-02-21 20:10 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-02-21 17:32 . 2011-03-05 10:35 25048 ----a-w- c:\program files\Mozilla Firefox\components\browserdirprovider.dll
2011-02-21 17:32 . 2011-03-05 10:35 140248 ----a-w- c:\program files\Mozilla Firefox\components\brwsrcmp.dll
2011-02-20 20:38 . 2002-12-12 00:34 208896 ----a-w- c:\winnt\system32\wmpns.dll
2011-02-20 20:04 . 2011-02-20 20:04 -------- d-----w- c:\program files\Common Files\Java
2011-02-18 16:56 . 2011-02-22 20:15 -------- d-----w- C:\Adresář
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\Malwarebytes
2011-02-18 16:38 . 2010-12-20 17:09 38224 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-18 16:38 . 2010-12-20 17:08 19288 ----a-w- c:\winnt\system32\drivers\mbam.sys
2011-02-10 19:14 . 2011-02-10 19:14 -------- d-----w- c:\documents and settings\pc\Data aplikací\Sony Ericsson
2011-02-10 19:04 . 2011-02-10 19:04 -------- dc----w- c:\winnt\system32\DRVSTORE
2011-02-10 19:03 . 2011-02-10 19:14 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
2011-02-10 19:03 . 2011-02-10 19:14 -------- d-----w- c:\program files\Common Files\Teleca Shared
2011-02-10 19:03 . 2011-02-10 19:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Teleca
2011-02-10 19:03 . 2011-02-10 19:03 -------- d-----w- c:\winnt\Downloaded Installations
2011-02-10 19:01 . 2011-02-10 19:01 1409 ----a-w- c:\winnt\QTFont.for
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-27 15:01 . 2010-12-19 10:36 737280 ----a-w- c:\winnt\iun6002.exe
2011-02-02 20:40 . 2011-01-25 14:19 472808 ----a-w- c:\winnt\system32\deployJava1.dll
2011-02-02 18:19 . 2011-01-25 14:19 73728 ----a-w- c:\winnt\system32\javacpl.cpl
2011-01-09 16:38 . 2011-01-09 16:38 717296 ------w- c:\winnt\system32\drivers\sptd.sys
2010-12-17 11:51 . 2010-12-17 11:51 73216 ------w- c:\winnt\ST6UNST.EXE
2010-12-17 11:12 . 2010-12-17 11:12 58000 ------w- c:\winnt\system32\drivers\cdr4_2K.sys
2010-12-17 11:12 . 2010-12-17 11:12 57344 ------w- c:\winnt\uneng.exe
2010-12-17 11:12 . 2010-12-17 11:12 49152 ------w- c:\winnt\system32\cdrtc.dll
2010-12-17 11:12 . 2010-12-17 11:12 45056 ------w- c:\winnt\system32\cdral.dll
2010-12-17 11:12 . 2010-12-17 11:12 23420 ------w- c:\winnt\system32\drivers\cdralw2k.sys
2010-12-13 08:08 . 2011-01-27 07:28 132800 ----a-w- c:\winnt\system32\drivers\avipbb.sys
2010-12-13 07:40 . 2011-01-27 07:28 73584 ----a-w- c:\winnt\system32\drivers\avgntflt.sys
.
.
------- Sigcheck -------
.
[-] 2004-05-13 23:19 . 1F51839ECCF908FD86558198909262E4 . 792064 . . [ERROR: 0x0] . . c:\winnt\system32\comres.dll
.
[-] 2003-02-01 11:09 . 9E1381B2DE2A23F8E4C22E814D55F475 . 52224 . . [ERROR: 0x0] . . c:\winnt\system32\mspmsnsv.dll
.
[-] 2004-07-09 03:27 . 0E51BD586D186F61A9E4453DB8AEC774 . 1703936 . . [ERROR: 0x0] . . c:\winnt\system32\d3d9.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2003-06-19 111888]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2005-06-21 126976]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-05-03 32768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 188688]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Hlavnˇ panel ATI CATALYST.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-5-4 32768]
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2006-6-26 610304]
.
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.1.lnk]
backup=c:\winnt\pss\OpenOffice.org 2.1.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^Yahoo! Widgets.lnk]
backup=c:\winnt\pss\Yahoo! Widgets.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cobian Backup 8]
2007-09-27 11:37 501248 ------w- c:\program files\Cobian Backup 8\Cobian.exe
.
R0 sptd;sptd;c:\winnt\system32\drivers\sptd.sys [9.1.2011 17:38 717296]
R1 SandBox;SandBox;c:\winnt\system32\drivers\SandBox.sys [27.1.2011 8:38 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [27.1.2011 8:36 1195008]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27.1.2011 8:28 135336]
R3 afw;Agnitum firewall driver;c:\winnt\system32\drivers\afw.sys [27.1.2011 8:36 31256]
R3 afwcore;afwcore;c:\winnt\system32\drivers\afwcore.sys [27.1.2011 8:37 256920]
R3 usbhub20;Podpora kořenového rozbočovač rozbočovače sběrnice USB 2.0;c:\winnt\system32\drivers\usbhub20.sys [16.12.2010 17:44 49776]
R3 ZD1211BU(Atheros);Atheros ZD1211B IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\winnt\system32\drivers\ZD1211BU.sys [11.4.2008 20:51 720896]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-11 c:\winnt\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-03-03 10:28]
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\system32\blank.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\fwegmscf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: mediaplayerconnectivity: {84b24861-62f6-364b-eba5-2e5e2061d7e6} - %profile%\extensions\{84b24861-62f6-364b-eba5-2e5e2061d7e6}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-11 18:35
Windows 5.0.2195 Service Pack 4 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\winnt\system32\Perflib_Perfdata_370.dat 16384 bytes
c:\winnt\system32\Perflib_Perfdata_5e4.dat 16384 bytes
c:\winnt\system32\Perflib_Perfdata_5e8.dat 16384 bytes
.
sken byl úspešně dokončen
skryté soubory: 3
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(236)
c:\winnt\system32\Ati2evxx.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
- - - - - - - > 'explorer.exe'(1616)
c:\winnt\system32\SHDOCVW.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\winnt\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\winnt\system32\regsvc.exe
c:\winnt\system32\MSTask.exe
c:\winnt\System32\WBEM\WinMgmt.exe
c:\winnt\system32\Ati2evxx.exe
c:\winnt\system32\internat.exe
.
**************************************************************************
.
Celkový čas: 2011-03-11 18:47:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-11 17:47
.
Před spuštěním: Volných bajtů: 110 410 764 288
Po spuštění: Volných bajtů: 110 389 428 224
.
- - End Of File - - DD3E1546789F6F6096CEF3B118C248DF
Microsoft Windows 2000 Professional 5.0.2195.4.1250.420.1029.18.1023.685 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Dokumenty\Stažené soubory\ComboFix.exe
.
/wow section - STAGE 10
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\winnt\system\winspool.drv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-11 do 2011-03-11 )))))))))))))))))))))))))))))))
.
.
2011-03-11 07:20 . 2011-03-11 07:41 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Deployment
2011-03-10 19:38 . 2003-06-19 11:05 90384 ----a-w- c:\winnt\system32\CRYPTDLG.DLL
2011-03-10 19:38 . 2003-06-19 11:05 380957 ------w- c:\winnt\system32\expsrv.dll
2011-03-10 19:38 . 2003-06-19 11:05 30749 ------w- c:\winnt\system32\vbajet32.dll
2011-03-09 20:54 . 2003-02-01 11:08 192512 -c--a-w- c:\winnt\system32\dllcache\unregmp2.exe
2011-03-09 20:54 . 2002-12-12 18:45 301712 -c--a-w- c:\winnt\system32\dllcache\drmclien.dll
2011-03-09 20:54 . 2002-12-12 00:34 9728 -c--a-w- c:\winnt\system32\dllcache\npwmsdrm.dll
2011-03-09 20:54 . 2002-12-12 00:34 9728 ----a-w- c:\program files\Windows Media Player\npwmsdrm.dll
2011-03-09 20:54 . 2002-12-12 00:34 82432 -c--a-w- c:\winnt\system32\dllcache\drmstor.dll
2011-03-09 20:54 . 2002-12-12 00:34 82432 ----a-w- c:\winnt\system32\drmstor.dll
2011-03-09 20:53 . 2002-10-04 01:05 831488 ----a-w- c:\program files\Windows Media Player\Roxio\wmburn.exe
2011-03-09 20:53 . 2002-10-04 01:05 180224 ----a-w- c:\program files\Windows Media Player\Roxio\rsl.dll
2011-03-09 17:49 . 2011-03-09 17:49 -------- d-----w- c:\program files\SimBin
2011-03-09 17:37 . 2010-11-03 19:08 237568 ----a-w- c:\winnt\system32\yv12vfw.dll
2011-03-09 17:37 . 2010-01-17 16:18 151552 ----a-w- c:\winnt\system32\ac3acm.acm
2011-03-09 17:37 . 2009-07-03 14:13 121344 ----a-w- c:\winnt\system32\lagarith.dll
2011-03-09 17:37 . 2008-09-24 19:41 839680 ----a-w- c:\winnt\system32\lameACM.acm
2011-03-09 17:37 . 2006-04-02 13:47 630784 ----a-w- c:\winnt\system32\vp7vfw.dll
2011-03-09 17:37 . 2011-01-28 08:00 80896 ----a-w- c:\winnt\system32\ff_vfw.dll
2011-03-09 17:37 . 2010-12-07 18:40 183808 ----a-w- c:\winnt\system32\xvidvfw.dll
2011-03-09 17:37 . 2010-12-07 18:22 810496 ----a-w- c:\winnt\system32\xvidcore.dll
2011-03-09 17:37 . 2011-03-09 21:00 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-09 16:47 . 2011-03-09 16:47 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\ATI
2011-03-09 16:47 . 2011-03-09 16:47 -------- d-----w- c:\documents and settings\pc\Data aplikací\ATI
2011-03-09 16:40 . 2005-05-03 20:05 516096 ------w- c:\winnt\system32\ati2sgag.exe
2011-03-09 16:39 . 2011-03-09 16:41 -------- d-----w- c:\program files\ATI Technologies
2011-03-09 16:38 . 2005-05-03 20:05 212992 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2011-03-09 16:33 . 2004-05-02 08:47 23040 ----a-r- c:\winnt\system32\drivers\GVCplDrv.sys
2011-03-09 16:31 . 2003-06-19 11:05 21008 -c--a-w- c:\winnt\system32\dllcache\agp440.sys
2011-03-09 16:31 . 2003-06-19 11:05 21008 ----a-w- c:\winnt\system32\drivers\AGP440.SYS
2011-03-03 18:58 . 2011-03-03 18:58 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-03-03 18:37 . 2011-03-03 18:37 -------- d-----w- c:\documents and settings\pc\Data aplikací\GlarySoft
2011-03-03 18:30 . 2011-03-03 18:30 -------- d-----w- c:\program files\Glary Utilities
2011-03-01 18:06 . 2011-03-01 18:06 -------- d-----w- c:\program files\Defraggler
2011-02-27 15:10 . 2011-03-09 17:45 -------- d-----w- c:\documents and settings\pc\Data aplikací\Media Player Classic
2011-02-22 20:02 . 2011-02-22 20:00 13951112 ----a-w- c:\program files\Windows Media Player\Installer\winmediaplayer9.exe
2011-02-22 20:02 . 2002-07-06 17:01 54688 ----a-w- c:\program files\Windows Media Player\1033\dwintl.dll
2011-02-22 20:02 . 2002-12-12 18:45 301712 ----a-w- c:\winnt\system32\drmclien.dll
2011-02-21 19:24 . 2011-02-21 20:10 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-02-21 17:32 . 2011-03-05 10:35 25048 ----a-w- c:\program files\Mozilla Firefox\components\browserdirprovider.dll
2011-02-21 17:32 . 2011-03-05 10:35 140248 ----a-w- c:\program files\Mozilla Firefox\components\brwsrcmp.dll
2011-02-20 20:38 . 2002-12-12 00:34 208896 ----a-w- c:\winnt\system32\wmpns.dll
2011-02-20 20:04 . 2011-02-20 20:04 -------- d-----w- c:\program files\Common Files\Java
2011-02-18 16:56 . 2011-02-22 20:15 -------- d-----w- C:\Adresář
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\documents and settings\pc\Data aplikací\Malwarebytes
2011-02-18 16:38 . 2010-12-20 17:09 38224 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-18 16:38 . 2011-02-18 16:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-18 16:38 . 2010-12-20 17:08 19288 ----a-w- c:\winnt\system32\drivers\mbam.sys
2011-02-10 19:14 . 2011-02-10 19:14 -------- d-----w- c:\documents and settings\pc\Data aplikací\Sony Ericsson
2011-02-10 19:04 . 2011-02-10 19:04 -------- dc----w- c:\winnt\system32\DRVSTORE
2011-02-10 19:03 . 2011-02-10 19:14 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
2011-02-10 19:03 . 2011-02-10 19:14 -------- d-----w- c:\program files\Common Files\Teleca Shared
2011-02-10 19:03 . 2011-02-10 19:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Teleca
2011-02-10 19:03 . 2011-02-10 19:03 -------- d-----w- c:\winnt\Downloaded Installations
2011-02-10 19:01 . 2011-02-10 19:01 1409 ----a-w- c:\winnt\QTFont.for
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-27 15:01 . 2010-12-19 10:36 737280 ----a-w- c:\winnt\iun6002.exe
2011-02-02 20:40 . 2011-01-25 14:19 472808 ----a-w- c:\winnt\system32\deployJava1.dll
2011-02-02 18:19 . 2011-01-25 14:19 73728 ----a-w- c:\winnt\system32\javacpl.cpl
2011-01-09 16:38 . 2011-01-09 16:38 717296 ------w- c:\winnt\system32\drivers\sptd.sys
2010-12-17 11:51 . 2010-12-17 11:51 73216 ------w- c:\winnt\ST6UNST.EXE
2010-12-17 11:12 . 2010-12-17 11:12 58000 ------w- c:\winnt\system32\drivers\cdr4_2K.sys
2010-12-17 11:12 . 2010-12-17 11:12 57344 ------w- c:\winnt\uneng.exe
2010-12-17 11:12 . 2010-12-17 11:12 49152 ------w- c:\winnt\system32\cdrtc.dll
2010-12-17 11:12 . 2010-12-17 11:12 45056 ------w- c:\winnt\system32\cdral.dll
2010-12-17 11:12 . 2010-12-17 11:12 23420 ------w- c:\winnt\system32\drivers\cdralw2k.sys
2010-12-13 08:08 . 2011-01-27 07:28 132800 ----a-w- c:\winnt\system32\drivers\avipbb.sys
2010-12-13 07:40 . 2011-01-27 07:28 73584 ----a-w- c:\winnt\system32\drivers\avgntflt.sys
.
.
------- Sigcheck -------
.
[-] 2004-05-13 23:19 . 1F51839ECCF908FD86558198909262E4 . 792064 . . [ERROR: 0x0] . . c:\winnt\system32\comres.dll
.
[-] 2003-02-01 11:09 . 9E1381B2DE2A23F8E4C22E814D55F475 . 52224 . . [ERROR: 0x0] . . c:\winnt\system32\mspmsnsv.dll
.
[-] 2004-07-09 03:27 . 0E51BD586D186F61A9E4453DB8AEC774 . 1703936 . . [ERROR: 0x0] . . c:\winnt\system32\d3d9.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2003-06-19 111888]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2005-06-21 126976]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-05-03 32768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [2002-08-25 20752]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 188688]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Hlavnˇ panel ATI CATALYST.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-5-4 32768]
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2006-6-26 610304]
.
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.1.lnk]
backup=c:\winnt\pss\OpenOffice.org 2.1.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^pc^Nabídka Start^Programy^Po spuštění^Yahoo! Widgets.lnk]
backup=c:\winnt\pss\Yahoo! Widgets.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cobian Backup 8]
2007-09-27 11:37 501248 ------w- c:\program files\Cobian Backup 8\Cobian.exe
.
R0 sptd;sptd;c:\winnt\system32\drivers\sptd.sys [9.1.2011 17:38 717296]
R1 SandBox;SandBox;c:\winnt\system32\drivers\SandBox.sys [27.1.2011 8:38 704384]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [27.1.2011 8:36 1195008]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27.1.2011 8:28 135336]
R3 afw;Agnitum firewall driver;c:\winnt\system32\drivers\afw.sys [27.1.2011 8:36 31256]
R3 afwcore;afwcore;c:\winnt\system32\drivers\afwcore.sys [27.1.2011 8:37 256920]
R3 usbhub20;Podpora kořenového rozbočovač rozbočovače sběrnice USB 2.0;c:\winnt\system32\drivers\usbhub20.sys [16.12.2010 17:44 49776]
R3 ZD1211BU(Atheros);Atheros ZD1211B IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\winnt\system32\drivers\ZD1211BU.sys [11.4.2008 20:51 720896]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-11 c:\winnt\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-03-03 10:28]
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\system32\blank.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\fwegmscf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: mediaplayerconnectivity: {84b24861-62f6-364b-eba5-2e5e2061d7e6} - %profile%\extensions\{84b24861-62f6-364b-eba5-2e5e2061d7e6}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-11 18:35
Windows 5.0.2195 Service Pack 4 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\winnt\system32\Perflib_Perfdata_370.dat 16384 bytes
c:\winnt\system32\Perflib_Perfdata_5e4.dat 16384 bytes
c:\winnt\system32\Perflib_Perfdata_5e8.dat 16384 bytes
.
sken byl úspešně dokončen
skryté soubory: 3
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(236)
c:\winnt\system32\Ati2evxx.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
- - - - - - - > 'explorer.exe'(1616)
c:\winnt\system32\SHDOCVW.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\winnt\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\winnt\system32\regsvc.exe
c:\winnt\system32\MSTask.exe
c:\winnt\System32\WBEM\WinMgmt.exe
c:\winnt\system32\Ati2evxx.exe
c:\winnt\system32\internat.exe
.
**************************************************************************
.
Celkový čas: 2011-03-11 18:47:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-11 17:47
.
Před spuštěním: Volných bajtů: 110 410 764 288
Po spuštění: Volných bajtů: 110 389 428 224
.
- - End Of File - - DD3E1546789F6F6096CEF3B118C248DF