Re: Ani po odvireni NB nejde Facebook
Napsal: 17 lis 2011 18:12
Tak tu to je..
ComboFix 11-11-17.03 - Janka 17.11.2011 17:48:52.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2039.1598 [GMT 1:00]
Running from: c:\documents and settings\Janka\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\18F
c:\documents and settings\All Users\Application Data\18F\{2C2E9D9D-EC15-44E5-B74A-D10376EE7848}.swf
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Janka\Application Data\Desktopicon
c:\documents and settings\Janka\Application Data\Desktopicon\config.ini
c:\documents and settings\Janka\WINDOWS
c:\windows\$NtUninstallKB16995$
c:\windows\$NtUninstallKB16995$\786010949\@
c:\windows\$NtUninstallKB16995$\786010949\L\acummful
c:\windows\$NtUninstallKB16995$\786010949\loader.tlb
c:\windows\$NtUninstallKB16995$\786010949\U\@00000001
c:\windows\$NtUninstallKB16995$\786010949\U\@000000c0
c:\windows\$NtUninstallKB16995$\786010949\U\@000000cb
c:\windows\$NtUninstallKB16995$\786010949\U\@000000cf
c:\windows\$NtUninstallKB16995$\786010949\U\@80000000
c:\windows\$NtUninstallKB16995$\786010949\U\@800000c0
c:\windows\$NtUninstallKB16995$\786010949\U\@800000cb
c:\windows\$NtUninstallKB16995$\786010949\U\@800000cf
c:\windows\$NtUninstallKB16995$\887770884
c:\windows\av_ico
c:\windows\av_ico\ico_avira_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.tray-8-0-lnk
c:\windows\update.tray-8-0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-10-17 to 2011-11-17 )))))))))))))))))))))))))))))))
.
.
2011-11-17 10:28 . 2011-11-17 10:30 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2011-11-17 10:27 . 2011-11-17 10:27 -------- d-----w- C:\RK_Quarantine
2011-11-15 14:55 . 2011-11-15 14:55 -------- d-----w- c:\documents and settings\Janka\Application Data\Malwarebytes
2011-11-15 14:55 . 2011-11-15 14:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-15 14:55 . 2011-11-15 14:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-15 14:55 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-14 19:55 . 2011-11-16 09:17 -------- d-----w- c:\program files\trend micro
2011-11-14 19:55 . 2011-11-14 19:55 -------- d-----w- C:\rsit
2011-11-13 10:42 . 2011-11-13 10:44 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-11-13 10:42 . 2011-11-13 10:44 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-11-13 10:42 . 2011-11-13 10:44 801752 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-11-13 10:42 . 2011-11-13 10:44 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-11-13 10:42 . 2011-11-13 10:44 1989592 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-11-13 10:42 . 2011-11-13 10:44 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-11-13 10:42 . 2011-09-29 00:26 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-11-13 10:42 . 2011-09-29 00:26 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-11-13 10:16 . 2011-11-13 10:16 -------- d-----w- c:\program files\Yamicsoft
2011-11-13 10:14 . 2011-11-13 10:15 -------- d-----w- c:\program files\SpywareBlaster
2011-11-12 21:47 . 2011-11-12 21:47 -------- d-----w- c:\documents and settings\Janka\Application Data\IObit
2011-11-12 21:36 . 2011-11-12 21:36 -------- d-----w- c:\program files\EMCO
2011-11-12 21:32 . 2011-11-17 10:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-11-12 21:16 . 2011-11-12 21:16 -------- d-----w- c:\documents and settings\Janka\Application Data\Avira
2011-11-12 21:15 . 2011-09-18 07:39 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-12 21:15 . 2011-09-15 22:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-12 21:15 . 2011-09-15 22:55 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-12 21:14 . 2011-11-12 21:14 -------- d-----w- c:\program files\Avira
2011-11-12 21:14 . 2011-11-12 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-11-08 20:17 . 2011-11-12 15:21 -------- d-sh--w- c:\documents and settings\LocalService\Local Settings\Application Data\2ed99345
2011-11-03 10:15 . 2011-11-03 10:15 -------- d-----w- c:\documents and settings\Janka\Local Settings\Application Data\S2PC
2011-11-03 10:15 . 2009-09-18 16:40 523264 ------w- c:\windows\system32\dsmgr.cpl
2011-11-03 10:12 . 2009-12-23 06:30 484592 ----a-w- c:\windows\SSndii.exe
2011-11-03 10:12 . 2009-09-18 09:32 21776 ----a-w- c:\windows\system32\msxml2a.dll
2011-11-03 10:12 . 2011-11-03 10:12 -------- d-----w- c:\windows\Dell
2011-11-03 10:10 . 1997-05-26 13:55 23040 ----a-w- c:\windows\system32\irisco32.dll
2011-11-03 10:09 . 2011-11-03 10:10 -------- d-----w- c:\program files\Readiris10
2011-11-03 10:09 . 2011-11-03 10:11 -------- d-----w- c:\program files\SmarThru 4
2011-11-03 10:08 . 2009-12-23 05:06 115952 ----a-r- c:\windows\Wiainst.exe
2011-11-03 10:06 . 2009-09-17 01:38 26624 ----a-w- c:\windows\system32\sdo1ml3.dll
2011-11-03 10:06 . 2009-09-17 01:38 19968 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\sdo1mpc.dll
2011-11-03 10:06 . 2009-09-17 01:38 151552 ----a-w- c:\windows\system32\sdo1mci.exe
2011-11-03 10:06 . 2009-09-17 01:38 65536 ----a-w- c:\windows\system32\sdo1mci.dll
2011-11-03 10:05 . 2011-11-03 10:05 -------- d-----w- c:\program files\Dell
2011-10-31 13:40 . 2011-11-13 10:23 -------- d-----w- C:\reports
2011-10-31 13:40 . 2011-08-14 14:23 -------- d-----w- C:\lib
2011-10-31 13:40 . 2011-08-14 14:23 -------- d-----w- C:\ProductDB
2011-10-31 13:40 . 2009-06-03 13:39 825 ----a-w- C:\jr.cmd
2011-10-31 13:40 . 2009-05-05 20:13 147 ----a-w- C:\Projekcie.cmd
2011-10-31 09:58 . 2011-11-16 07:15 -------- d-----w- c:\windows\ufa
2011-10-30 20:24 . 2011-11-14 18:42 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-28 08:05 . 2011-10-31 09:58 246272 ----a-w- c:\windows\unrar.exe
2011-10-28 07:51 . 2011-11-12 16:15 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-10-28 07:51 . 2011-11-12 16:15 -------- d--h--w- c:\windows\update.tray-9-0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 10:35 . 2009-08-10 09:06 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2011-09-26 09:41 . 2008-07-29 17:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2007-07-27 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 09:41 . 2007-07-27 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2007-07-27 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2007-07-27 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2007-07-27 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2007-07-27 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2007-07-27 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2007-07-27 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-13 10:44 . 2011-11-13 10:42 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lotus iNotes Sync Manager"="c:\notes\LOTUSI~1\nDOLMgr.exe" [2008-08-08 409600]
"1133 Scan2PC"="c:\windows\twain_32\Dell\DELL1133\Scan2Pc.exe" [2009-12-24 1978880]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"LXDBCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Deutscher Ring\\Calculator SK\\Deutscher Ring Calculator SK.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Deutscher Ring\\Accident Calculator SK\\Deutscher Ring Accident Calculator SK.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\DELL1133\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\DELL1133\\Sscan2io.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\ScanMgr.exe"=
"c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Program Files\\Ask.com\\UpdateTask.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
"c:\\Documents and Settings\\Janka\\Desktop\\KALKULACKY OVB\\run.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [12.11.2011 22:15 36000]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [19.3.2010 16:40 51072]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12.11.2011 22:15 86224]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [15.11.2011 15:55 366152]
R3 FlrnUSB;Leadtek USB Network Interface;c:\windows\system32\drivers\LtkUSB.sys [13.8.2009 19:36 41907]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [15.11.2011 15:55 22216]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; [x]
S2 FMMService;FMMService; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28.10.2009 19:49 133104]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; [x]
S2 ICQ Service;ICQ Service; [x]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [9.8.2009 20:32 193840]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [28.10.2009 19:49 133104]
S3 lxdb_device;lxdb_device; [x]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service; [x]
S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [17.11.2011 11:28 111872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 10:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-28 18:49]
.
2011-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-28 18:49]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://gmail.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: SmarThru4 Capture Selection - c:\program files\SmarThru 4\WebCapture.dll2.htm
IE: SmarThru4 Save as HTML - c:\program files\SmarThru 4\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - c:\program files\SmarThru 4\WebCapture.dll.htm
IE: SmarThru4 Web Capture - c:\program files\SmarThru 4\WebCapture.dll
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 195.91.0.17 194.154.227.17
FF - ProfilePath - c:\documents and settings\Janka\Application Data\Mozilla\Firefox\Profiles\6lk4fek8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-17 18:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Lotus iNotes Sync Manager = c:\notes\LOTUSI~1\nDOLMgr.exe -minimize?????????????P7m?t?????B~????????????&?B~????P7m???T?P???T?????????D~0?B~????&?B~?xB~?????????xB~???????? ???????(???s??|????0???????????Q?stA?B~????????????T????a???????????????????Ep??Ip???????????C~?????Ep??Ip????
LXDBCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2968)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2011-11-17 18:09:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-17 17:09
.
Pre-Run: 97 189 552 128 bytes free
Post-Run: 25 adresárov, 97 453 187 072 voľných bajtov
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - FF9F71AA173EBC41F4CA84E56A9E2812
ComboFix 11-11-17.03 - Janka 17.11.2011 17:48:52.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2039.1598 [GMT 1:00]
Running from: c:\documents and settings\Janka\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\18F
c:\documents and settings\All Users\Application Data\18F\{2C2E9D9D-EC15-44E5-B74A-D10376EE7848}.swf
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Janka\Application Data\Desktopicon
c:\documents and settings\Janka\Application Data\Desktopicon\config.ini
c:\documents and settings\Janka\WINDOWS
c:\windows\$NtUninstallKB16995$
c:\windows\$NtUninstallKB16995$\786010949\@
c:\windows\$NtUninstallKB16995$\786010949\L\acummful
c:\windows\$NtUninstallKB16995$\786010949\loader.tlb
c:\windows\$NtUninstallKB16995$\786010949\U\@00000001
c:\windows\$NtUninstallKB16995$\786010949\U\@000000c0
c:\windows\$NtUninstallKB16995$\786010949\U\@000000cb
c:\windows\$NtUninstallKB16995$\786010949\U\@000000cf
c:\windows\$NtUninstallKB16995$\786010949\U\@80000000
c:\windows\$NtUninstallKB16995$\786010949\U\@800000c0
c:\windows\$NtUninstallKB16995$\786010949\U\@800000cb
c:\windows\$NtUninstallKB16995$\786010949\U\@800000cf
c:\windows\$NtUninstallKB16995$\887770884
c:\windows\av_ico
c:\windows\av_ico\ico_avira_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.tray-8-0-lnk
c:\windows\update.tray-8-0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-10-17 to 2011-11-17 )))))))))))))))))))))))))))))))
.
.
2011-11-17 10:28 . 2011-11-17 10:30 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2011-11-17 10:27 . 2011-11-17 10:27 -------- d-----w- C:\RK_Quarantine
2011-11-15 14:55 . 2011-11-15 14:55 -------- d-----w- c:\documents and settings\Janka\Application Data\Malwarebytes
2011-11-15 14:55 . 2011-11-15 14:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-15 14:55 . 2011-11-15 14:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-15 14:55 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-14 19:55 . 2011-11-16 09:17 -------- d-----w- c:\program files\trend micro
2011-11-14 19:55 . 2011-11-14 19:55 -------- d-----w- C:\rsit
2011-11-13 10:42 . 2011-11-13 10:44 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-11-13 10:42 . 2011-11-13 10:44 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-11-13 10:42 . 2011-11-13 10:44 801752 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-11-13 10:42 . 2011-11-13 10:44 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-11-13 10:42 . 2011-11-13 10:44 1989592 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-11-13 10:42 . 2011-11-13 10:44 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-11-13 10:42 . 2011-09-29 00:26 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-11-13 10:42 . 2011-09-29 00:26 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-11-13 10:16 . 2011-11-13 10:16 -------- d-----w- c:\program files\Yamicsoft
2011-11-13 10:14 . 2011-11-13 10:15 -------- d-----w- c:\program files\SpywareBlaster
2011-11-12 21:47 . 2011-11-12 21:47 -------- d-----w- c:\documents and settings\Janka\Application Data\IObit
2011-11-12 21:36 . 2011-11-12 21:36 -------- d-----w- c:\program files\EMCO
2011-11-12 21:32 . 2011-11-17 10:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-11-12 21:16 . 2011-11-12 21:16 -------- d-----w- c:\documents and settings\Janka\Application Data\Avira
2011-11-12 21:15 . 2011-09-18 07:39 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-12 21:15 . 2011-09-15 22:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-12 21:15 . 2011-09-15 22:55 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-12 21:14 . 2011-11-12 21:14 -------- d-----w- c:\program files\Avira
2011-11-12 21:14 . 2011-11-12 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-11-08 20:17 . 2011-11-12 15:21 -------- d-sh--w- c:\documents and settings\LocalService\Local Settings\Application Data\2ed99345
2011-11-03 10:15 . 2011-11-03 10:15 -------- d-----w- c:\documents and settings\Janka\Local Settings\Application Data\S2PC
2011-11-03 10:15 . 2009-09-18 16:40 523264 ------w- c:\windows\system32\dsmgr.cpl
2011-11-03 10:12 . 2009-12-23 06:30 484592 ----a-w- c:\windows\SSndii.exe
2011-11-03 10:12 . 2009-09-18 09:32 21776 ----a-w- c:\windows\system32\msxml2a.dll
2011-11-03 10:12 . 2011-11-03 10:12 -------- d-----w- c:\windows\Dell
2011-11-03 10:10 . 1997-05-26 13:55 23040 ----a-w- c:\windows\system32\irisco32.dll
2011-11-03 10:09 . 2011-11-03 10:10 -------- d-----w- c:\program files\Readiris10
2011-11-03 10:09 . 2011-11-03 10:11 -------- d-----w- c:\program files\SmarThru 4
2011-11-03 10:08 . 2009-12-23 05:06 115952 ----a-r- c:\windows\Wiainst.exe
2011-11-03 10:06 . 2009-09-17 01:38 26624 ----a-w- c:\windows\system32\sdo1ml3.dll
2011-11-03 10:06 . 2009-09-17 01:38 19968 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\sdo1mpc.dll
2011-11-03 10:06 . 2009-09-17 01:38 151552 ----a-w- c:\windows\system32\sdo1mci.exe
2011-11-03 10:06 . 2009-09-17 01:38 65536 ----a-w- c:\windows\system32\sdo1mci.dll
2011-11-03 10:05 . 2011-11-03 10:05 -------- d-----w- c:\program files\Dell
2011-10-31 13:40 . 2011-11-13 10:23 -------- d-----w- C:\reports
2011-10-31 13:40 . 2011-08-14 14:23 -------- d-----w- C:\lib
2011-10-31 13:40 . 2011-08-14 14:23 -------- d-----w- C:\ProductDB
2011-10-31 13:40 . 2009-06-03 13:39 825 ----a-w- C:\jr.cmd
2011-10-31 13:40 . 2009-05-05 20:13 147 ----a-w- C:\Projekcie.cmd
2011-10-31 09:58 . 2011-11-16 07:15 -------- d-----w- c:\windows\ufa
2011-10-30 20:24 . 2011-11-14 18:42 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-28 08:05 . 2011-10-31 09:58 246272 ----a-w- c:\windows\unrar.exe
2011-10-28 07:51 . 2011-11-12 16:15 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-10-28 07:51 . 2011-11-12 16:15 -------- d--h--w- c:\windows\update.tray-9-0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 10:35 . 2009-08-10 09:06 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2011-09-26 09:41 . 2008-07-29 17:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2007-07-27 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 09:41 . 2007-07-27 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2007-07-27 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2007-07-27 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2007-07-27 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2007-07-27 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2007-07-27 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2007-07-27 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-13 10:44 . 2011-11-13 10:42 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lotus iNotes Sync Manager"="c:\notes\LOTUSI~1\nDOLMgr.exe" [2008-08-08 409600]
"1133 Scan2PC"="c:\windows\twain_32\Dell\DELL1133\Scan2Pc.exe" [2009-12-24 1978880]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"LXDBCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Deutscher Ring\\Calculator SK\\Deutscher Ring Calculator SK.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Deutscher Ring\\Accident Calculator SK\\Deutscher Ring Accident Calculator SK.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\DELL1133\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\DELL1133\\Sscan2io.exe"=
"c:\\WINDOWS\\twain_32\\Dell\\ScanMgr.exe"=
"c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Program Files\\Ask.com\\UpdateTask.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
"c:\\Documents and Settings\\Janka\\Desktop\\KALKULACKY OVB\\run.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [12.11.2011 22:15 36000]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [19.3.2010 16:40 51072]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12.11.2011 22:15 86224]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [15.11.2011 15:55 366152]
R3 FlrnUSB;Leadtek USB Network Interface;c:\windows\system32\drivers\LtkUSB.sys [13.8.2009 19:36 41907]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [15.11.2011 15:55 22216]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; [x]
S2 FMMService;FMMService; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28.10.2009 19:49 133104]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; [x]
S2 ICQ Service;ICQ Service; [x]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [9.8.2009 20:32 193840]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [28.10.2009 19:49 133104]
S3 lxdb_device;lxdb_device; [x]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service; [x]
S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [17.11.2011 11:28 111872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 10:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-28 18:49]
.
2011-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-28 18:49]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://gmail.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: SmarThru4 Capture Selection - c:\program files\SmarThru 4\WebCapture.dll2.htm
IE: SmarThru4 Save as HTML - c:\program files\SmarThru 4\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - c:\program files\SmarThru 4\WebCapture.dll.htm
IE: SmarThru4 Web Capture - c:\program files\SmarThru 4\WebCapture.dll
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 195.91.0.17 194.154.227.17
FF - ProfilePath - c:\documents and settings\Janka\Application Data\Mozilla\Firefox\Profiles\6lk4fek8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-17 18:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Lotus iNotes Sync Manager = c:\notes\LOTUSI~1\nDOLMgr.exe -minimize?????????????P7m?t?????B~????????????&?B~????P7m???T?P???T?????????D~0?B~????&?B~?xB~?????????xB~???????? ???????(???s??|????0???????????Q?stA?B~????????????T????a???????????????????Ep??Ip???????????C~?????Ep??Ip????
LXDBCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2968)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2011-11-17 18:09:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-17 17:09
.
Pre-Run: 97 189 552 128 bytes free
Post-Run: 25 adresárov, 97 453 187 072 voľných bajtov
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - FF9F71AA173EBC41F4CA84E56A9E2812