Re: Viry neodstraněné Avastem
Napsal: 08 srp 2012 10:58
Po restartu Combofixem se ale opět aktivoval avast!, během vytváření logu vyhodil několikrát hlášku, že nějaké aplikace (PV.3XE a ještě něco) se snaží o změny v registru, tak jsem to odsouhlasil...snad jsem nic nezoral! Tady je tedy ještě log Combofixu.
ComboFix 12-08-07.03 - Trash 08.08.2012 11:27:05.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.548 [GMT 2:00]
Spuštěný z: c:\documents and settings\Trash\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Trash\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll"
"c:\windows\tasks\Ad-Aware Update (Weekly).job"
"c:\windows\tasks\avast! Emergency Update.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-08 do 2012-08-08 )))))))))))))))))))))))))))))))
.
.
2012-08-07 00:00 . 2012-08-07 11:50 -------- dc----w- c:\documents and settings\All Users\Data aplikací\CPA_VA
2012-08-06 23:45 . 2012-08-06 23:59 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Comodo
2012-08-06 23:45 . 2012-08-06 23:47 -------- d-----w- c:\program files\COMODO
2012-08-06 17:23 . 2012-07-03 16:21 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-06 17:23 . 2012-07-03 16:21 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-06 17:22 . 2012-07-03 16:21 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-06 17:22 . 2012-07-03 16:21 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-06 17:22 . 2012-07-03 16:21 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-06 17:22 . 2012-07-03 16:21 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-06 17:22 . 2012-07-03 16:21 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-06 17:22 . 2012-07-03 16:21 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-06 17:21 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
2012-08-06 17:21 . 2012-07-03 16:21 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-06 17:20 . 2012-08-06 17:20 -------- dc----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-08-06 17:20 . 2012-08-06 17:20 -------- d-----w- c:\program files\AVAST Software
2012-08-06 14:15 . 2012-08-06 14:15 -------- dc----w- c:\documents and settings\Trash\Data aplikací\Kaspersky_Key_Finder_(KKF
2012-08-06 13:45 . 2009-09-15 02:15 162320 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
2012-08-06 13:42 . 2012-08-06 17:02 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Kaspersky Lab
2012-08-06 12:46 . 2012-08-06 17:03 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2012-08-05 01:14 . 2012-08-05 01:14 -------- d-----w- c:\documents and settings\Trash\Local Settings\Data aplikací\Opera
2012-08-05 01:14 . 2012-08-05 01:14 26403 ----a-w- c:\windows\system32\epfwdata.bin
2012-08-05 01:13 . 2012-08-05 01:14 -------- d-----w- c:\program files\Opera
2012-08-02 16:23 . 2012-08-02 16:23 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\IObit
2012-08-02 13:52 . 2012-08-02 13:52 -------- d-----w- c:\windows\ServicePackFiles
2012-08-02 13:44 . 2009-06-22 11:48 91776 ----a-w- c:\windows\system32\drivers\SET1A6A.tmp
2012-08-02 13:26 . 2009-02-09 10:22 473088 ----a-w- c:\windows\system32\wbem\SET18C3.tmp
2012-08-02 13:26 . 2009-02-06 16:39 227840 ----a-w- c:\windows\system32\wbem\SET18C1.tmp
2012-08-02 13:26 . 2009-02-09 10:22 453120 ----a-w- c:\windows\system32\wbem\SET18C2.tmp
2012-08-02 13:24 . 2008-04-21 21:28 216576 ----a-w- c:\program files\Windows NT\Accessories\SET1873.tmp
2012-08-02 13:11 . 2008-06-20 17:42 247296 -c--a-w- c:\windows\system32\dllcache\SET1730.tmp
2012-08-02 13:11 . 2008-06-20 10:45 360320 -c--a-w- c:\windows\system32\dllcache\SET172F.tmp
2012-08-02 13:05 . 2006-10-11 16:26 104960 -c--a-w- c:\windows\system32\dllcache\SET1635.tmp
2012-08-02 13:05 . 2006-10-11 16:26 313344 -c--a-w- c:\windows\system32\dllcache\SET1634.tmp
2012-08-02 13:05 . 2006-10-11 16:26 116224 -c--a-w- c:\windows\system32\dllcache\SET1632.tmp
2012-08-02 13:05 . 2006-10-11 16:26 153088 -c--a-w- c:\windows\system32\dllcache\SET1636.tmp
2012-08-02 13:05 . 2006-10-11 16:26 58880 -c--a-w- c:\windows\system32\dllcache\SET1630.tmp
2012-08-02 13:04 . 2012-05-24 08:48 21376 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-08-02 12:05 . 2012-08-02 12:05 -------- d-----w- c:\documents and settings\Trash\Local Settings\Data aplikací\ESET
2012-07-27 11:50 . 2012-07-27 11:50 -------- dc----w- c:\documents and settings\LocalService\Dokumenty
2012-07-26 17:05 . 2012-07-26 17:05 -------- dc----w- c:\documents and settings\Trash\Data aplikací\Telefónica Móviles
2012-07-26 17:04 . 2009-12-15 12:05 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-07-26 17:04 . 2009-12-15 12:05 113280 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-07-26 17:04 . 2009-12-15 12:05 102528 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-07-26 17:04 . 2009-12-15 12:05 100736 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2012-07-26 17:04 . 2012-07-26 17:04 -------- d-----w- c:\program files\O2
2012-07-24 12:01 . 2012-07-24 12:01 1409 ----a-w- c:\windows\QTFont.for
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-21 22:46 . 2012-06-21 22:46 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2012-06-21 22:46 . 2012-06-21 22:46 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2012-07-29 10:58 . 2012-06-08 12:14 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-07_19.23.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-08 09:42 . 2012-08-08 09:42 16384 c:\windows\temp\Perflib_Perfdata_3a4.dat
+ 2007-10-31 18:06 . 2012-08-08 09:45 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-31 18:06 . 2012-08-07 17:30 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-31 18:06 . 2012-08-08 09:45 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-31 18:06 . 2012-08-07 17:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-08-08 09:07 . 2012-08-08 09:45 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2012-08-06 23:59 . 2012-08-07 17:30 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 69632]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-30 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Soulseek-Test\\slsk.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Documents and Settings\\Trash\\Plocha\\utorrent-portable\\utorrent.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Documents and Settings\\Trash\\Data aplikací\\GameRanger\\GameRanger\\GameRanger.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.10.2007 21:34 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [6.8.2012 19:22 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.8.2012 19:23 353688]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [11.3.2012 21:13 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [11.3.2012 21:13 31704]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 11:51 19200]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.8.2012 19:23 21256]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [23.11.2011 12:27 1052472]
R2 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [1.12.2007 18:54 8192]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [5.7.2012 18:41 3048136]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29.2.2012 9:50 158856]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [26.7.2012 19:04 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [26.7.2012 19:04 100736]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.5.2012 13:57 113120]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2.5.2010 2:34 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2.5.2010 2:35 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2.5.2010 2:35 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2.5.2010 2:36 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2.5.2010 2:36 25704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 -c--a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-08 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-08-06 16:21]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-06 17:23]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-06 17:23]
.
.
------- Doplňkový sken -------
.
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\documents and settings\Trash\Data aplikací\Mozilla\Firefox\Profiles\sm04586p.default\
FF - user.js: extensions.installedDistroAddon.testpilot@labs.mozilla.com - true
FF - user.js: extensions.jqs@sun.com.install-event-fired - true
FF - user.js: extensions.kosa.anonymousId - 047b792e0c7c5e971952c209f392b325
FF - user.js: extensions.kosa.bgCount - 261
FF - user.js: extensions.kosa.bundles - +1$fvd
FF - user.js: extensions.kosa.config - +fvd
FF - user.js: extensions.kosa.enabled - true
FF - user.js: extensions.kosa.install - fvd
FF - user.js: extensions.kosa.prefix - fvd
FF - user.js: extensions.kosa.settingsPrefix - fvd
FF - user.js: extensions.kosa.smspHideAds - false
FF - user.js: extensions.kosa.smspMaxPerPage - 10
FF - user.js: extensions.kosa.userId - c9929576-5e09-454f-80ca-9dd101fbac71
FF - user.js: extensions.kosa.vercheck - hxxp://init.kallout.com/versioncheck.js
FF - user.js: extensions.kosa.version - 2.2.3
FF - user.js: extensions.lastAppVersion - 14.0.1
FF - user.js: extensions.lastPlatformVersion - 14.0.1
FF - user.js: extensions.pendingOperations - false
FF - user.js: extensions.register@pgport.com.data - {ef522540-89f5-46b9-b6fe-1829e2b572c6},0,9999,999.999.999,9999,|{c50ca3c4-5656-43c2-a061-13e717f73fc8},5300,5300,4.0.1,5300,fvd|fvd@kallout.com,5200,5200,4.0.1,5200,fvd|fbg@pgport.com,0,5100,0.0.0,4600,|kosa@kallout.com,5000,5000,2.0.1,5000,sm|ytvdh@pgport.com,0,4800,1.1.3,4800,|ytvdw@pgport.com,0,4700,1.1.3,4700,|btpersonas@brandthunder.com,0,4600,0.0.0.,4600,|lifetimesavings@pgport.com,0,1002,0.0.0.,1002,|afhack@pgport.com,0,1001,0.0.0.,1001,|afext@pgport.com,0,1000,0.0.0.,1000,
FF - user.js: extensions.register@pgport.com.version - 1017
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extensions.skype_toolbar.version - 5.10.0.9560
FF - user.js: extensions.testpilot.alreadyCustomizedToolbar - true
FF - user.js: extensions.testpilot@labs.mozilla.com.install-event-fired - true
FF - user.js: extensions.ui.dictionary.hidden - true
FF - user.js: extensions.ui.lastCategory - addons://list/extension
FF - user.js: extensions.ui.locale.hidden - true
FF - user.js: extensions.update.notifyUser - false
FF - user.js: extensions.{20a82645-c095-46ed-80e3-08825760534b}.install-event-fired - true
FF - user.js: extensions.{23fcfd51-4958-4f00-80a3-ae97e717ed8b}.install-event-fired - true
FF - user.js: extensions.{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.install-event-fired - true
FF - user.js: extensions.{E2883E8F-472F-4fb0-9522-AC9BF37916A7}.install-event-fired - true
FF - user.js: extensions.{c50ca3c4-5656-43c2-a061-13e717f73fc8}.install-event-fired - true
FF - user.js: extensions.{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.install-event-fired - true
FF - user.js: extensions.{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}.install-event-fired - true
FF - user.js: font.internaluseonly.changed - true
FF - user.js: fvd.first_time_use - false
FF - user.js: gfx.blacklist.suggested-driver-version - 257.21
FF - user.js: icqtoolbar.allowSendURL - false
FF - user.js: icqtoolbar.engineVerified - true
FF - user.js: icqtoolbar.geolastmodified - 1271677352
FF - user.js: icqtoolbar.hiddenElements - itb_options
FF - user.js: icqtoolbar.history - Super.8.2011.DVDSCR.XViD-EVO%20torrent||Super.8.2011.DVDSCR.XviD.AC3-ViSiON%20torrent||Ringu%200%3A%20Basudei%20torrent||isohunt%20Ring.0.Birthday.2000.iNTERNAL.DVDRip.XviD-iLS%20torrent||Ring.0.Birthday.2000.iNTERNAL.DVDRip.XviD-iLS%20torrent||piratebay%20Smiley.Face.LIMITED.DVDRip.XviD-iMBT%20torrent||isohunt%20Smiley.Face.Festival.DVDSCR.XviD-XanaX%20torrent||Smiley.Face.Festival.DVDSCR.XviD-XanaX%20torrent||Smiley.Face.LIMITED.DVDRip.XviD-iMBT%20torrent||how.i.met.your.mother.s07e05.hdtv.xvid-lol%20torrent||menza%20jednota||abz%20slovn%C3%ADk||isifa%2Fgetty%20images||Shelter.LiMiTED.DVDRip.XviD-ALLiANCE||how.i.met.your.mother.s07e04.hdtv.xvid-lol
FF - user.js: icqtoolbar.icqgeo - 42
FF - user.js: icqtoolbar.installTime - 1270415208
FF - user.js: icqtoolbar.newtab_state - 1
FF - user.js: icqtoolbar.numberOfSearches - 0
FF - user.js: icqtoolbar.previousFFVersion - 3.6.23
FF - user.js: icqtoolbar.skip_default_search - no
FF - user.js: icqtoolbar.suggestions - false
FF - user.js: icqtoolbar.uninstStatSent - true
FF - user.js: icqtoolbar.uniqueID - 122881625112288168511228899951121
FF - user.js: icqtoolbar.usageStatstTimestamp - 1318699420
FF - user.js: icqtoolbar.xmlEnableSuggestions - false
FF - user.js: icqtoolbar.xmlLanguage - cs
FF - user.js: idle.lastDailyNotification - 1343689907
FF - user.js: intl.charsetmenu.browser.cache - ISO-8859-1, windows-1250, windows-1251, ISO-8859-2, UTF-8
FF - user.js: network.cookie.prefsMigrated - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: oldKeyword - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60327&qkw=
FF - user.js: places.database.lastMaintenance - 1343689912
FF - user.js: places.history.expiration.transient_current_max_pages - 26830
FF - user.js: places.last_vacuum - 1331515232
FF - user.js: plugin.expose_full_path - true
FF - user.js: pref.advanced.javascript.disable_button.advanced - false
FF - user.js: pref.browser.homepage.disable_button.current_page - false
FF - user.js: pref.browser.homepage.disable_button.restore_default - false
FF - user.js: pref.privacy.disable_button.view_cookies - false
FF - user.js: print.print_bgcolor - false
FF - user.js: print.print_bgimages - false
FF - user.js: print.print_command -
FF - user.js: print.print_downloadfonts - true
FF - user.js: print.print_evenpages - true
FF - user.js: print.print_in_color - true
FF - user.js: print.print_margin_bottom - 0.5
FF - user.js: print.print_margin_left - 0.5
FF - user.js: print.print_margin_right - 0.5
FF - user.js: print.print_margin_top - 0.5
FF - user.js: print.print_oddpages - true
FF - user.js: print.print_orientation - 0
FF - user.js: print.print_pagedelay - 500
FF - user.js: print.print_paper_data - 0
FF - user.js: print.print_paper_height - 11,00
FF - user.js: print.print_paper_size - 7209061
FF - user.js: print.print_paper_size_type - 1
FF - user.js: print.print_paper_size_unit - 0
FF - user.js: print.print_paper_width - 8,50
FF - user.js: print.print_printer - Adobe PDF
FF - user.js: print.print_reversed - false
FF - user.js: print.print_scaling - 1,00
FF - user.js: print.print_shrink_to_fit - true
FF - user.js: print.print_to_file - false
FF - user.js: print.print_to_filename -
FF - user.js: print.print_unwriteable_margin_bottom - 0
FF - user.js: print.print_unwriteable_margin_left - 0
FF - user.js: print.print_unwriteable_margin_right - 0
FF - user.js: print.print_unwriteable_margin_top - 0
FF - user.js: print.printer_Adobe_PDF.print_bgcolor - false
FF - user.js: print.printer_Adobe_PDF.print_bgimages - false
FF - user.js: print.printer_Adobe_PDF.print_command -
FF - user.js: print.printer_Adobe_PDF.print_downloadfonts - true
FF - user.js: print.printer_Adobe_PDF.print_edge_bottom - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_left - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_right - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_top - 0
FF - user.js: print.printer_Adobe_PDF.print_evenpages - true
FF - user.js: print.printer_Adobe_PDF.print_footercenter -
FF - user.js: print.printer_Adobe_PDF.print_footerleft - &PT
FF - user.js: print.printer_Adobe_PDF.print_footerright - &D
FF - user.js: print.printer_Adobe_PDF.print_headercenter -
FF - user.js: print.printer_Adobe_PDF.print_headerleft - &T
FF - user.js: print.printer_Adobe_PDF.print_headerright - &U
FF - user.js: print.printer_Adobe_PDF.print_in_color - true
FF - user.js: print.printer_Adobe_PDF.print_margin_bottom - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_left - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_right - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_top - 0.5
FF - user.js: print.printer_Adobe_PDF.print_oddpages - true
FF - user.js: print.printer_Adobe_PDF.print_orientation - 0
FF - user.js: print.printer_Adobe_PDF.print_pagedelay - 500
FF - user.js: print.printer_Adobe_PDF.print_paper_data - 0
FF - user.js: print.printer_Adobe_PDF.print_paper_height - 11,00
FF - user.js: print.printer_Adobe_PDF.print_paper_size_type - 0
FF - user.js: print.printer_Adobe_PDF.print_paper_size_unit - 1
FF - user.js: print.printer_Adobe_PDF.print_paper_width - 8,50
FF - user.js: print.printer_Adobe_PDF.print_reversed - false
FF - user.js: print.printer_Adobe_PDF.print_scaling - 1,00
FF - user.js: print.printer_Adobe_PDF.print_shrink_to_fit - true
FF - user.js: print.printer_Adobe_PDF.print_to_file - false
FF - user.js: print.printer_Adobe_PDF.print_to_filename -
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_bottom - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_left - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_right - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_top - 0
FF - user.js: privacy.sanitize.migrateFx3Prefs - true
FF - user.js: privacy.sanitize.timeSpan - 3
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: storage.vacuum.last.index - 1
FF - user.js: storage.vacuum.last.places.sqlite - 1343506873
FF - user.js: toolkit.startup.last_success - 1343924707
FF - user.js: toolkit.telemetry.prompted - 2
FF - user.js: toolkit.telemetry.rejected - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: urlclassifier.keyupdatetime.hxxps://sb-ssl.google.com/safebrowsing/newkey - 1345980394
FF - user.js: urlclassifier.tableversion.goog-black-enchash - 1.53228
FF - user.js: urlclassifier.tableversion.goog-black-url - 1.22331
FF - user.js: urlclassifier.tableversion.goog-white-domain - 1.480
FF - user.js: urlclassifier.tableversion.goog-white-url - 1.371
FF - user.js: useragentswitcher.import.overwrite - false
FF - user.js: useragentswitcher.menu.hide - false
FF - user.js: useragentswitcher.version - 0.73
FF - user.js: xpinstall.whitelist.add -
FF - user.js: xpinstall.whitelist.add.103 -
FF - user.js: xpinstall.whitelist.add.36 -
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: browser.blink_allowed - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-08 11:43
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(1048)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(3948)
c:\windows\system32\guard32.dll
c:\windows\system32\MSCTF.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\MPR.dll
.
- - - - - - - > 'csrss.exe'(964)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\COMODO\COMODO GeekBuddy\CLPS.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Celkový čas: 2012-08-08 11:53:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-08 09:53
ComboFix2.txt 2012-08-07 19:27
ComboFix3.txt 2009-12-19 19:16
ComboFix4.txt 2009-04-21 20:39
.
Před spuštěním: 2 579 877 888
Po spuštění: 2 561 179 648
.
- - End Of File - - 9BCFA5E62D160819B26C4AFE2D1EE6E7
ComboFix 12-08-07.03 - Trash 08.08.2012 11:27:05.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.548 [GMT 2:00]
Spuštěný z: c:\documents and settings\Trash\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Trash\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll"
"c:\windows\tasks\Ad-Aware Update (Weekly).job"
"c:\windows\tasks\avast! Emergency Update.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-08 do 2012-08-08 )))))))))))))))))))))))))))))))
.
.
2012-08-07 00:00 . 2012-08-07 11:50 -------- dc----w- c:\documents and settings\All Users\Data aplikací\CPA_VA
2012-08-06 23:45 . 2012-08-06 23:59 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Comodo
2012-08-06 23:45 . 2012-08-06 23:47 -------- d-----w- c:\program files\COMODO
2012-08-06 17:23 . 2012-07-03 16:21 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-06 17:23 . 2012-07-03 16:21 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-06 17:22 . 2012-07-03 16:21 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-06 17:22 . 2012-07-03 16:21 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-06 17:22 . 2012-07-03 16:21 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-06 17:22 . 2012-07-03 16:21 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-06 17:22 . 2012-07-03 16:21 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-06 17:22 . 2012-07-03 16:21 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-06 17:21 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
2012-08-06 17:21 . 2012-07-03 16:21 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-06 17:20 . 2012-08-06 17:20 -------- dc----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-08-06 17:20 . 2012-08-06 17:20 -------- d-----w- c:\program files\AVAST Software
2012-08-06 14:15 . 2012-08-06 14:15 -------- dc----w- c:\documents and settings\Trash\Data aplikací\Kaspersky_Key_Finder_(KKF
2012-08-06 13:45 . 2009-09-15 02:15 162320 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
2012-08-06 13:42 . 2012-08-06 17:02 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Kaspersky Lab
2012-08-06 12:46 . 2012-08-06 17:03 -------- dc----w- c:\documents and settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2012-08-05 01:14 . 2012-08-05 01:14 -------- d-----w- c:\documents and settings\Trash\Local Settings\Data aplikací\Opera
2012-08-05 01:14 . 2012-08-05 01:14 26403 ----a-w- c:\windows\system32\epfwdata.bin
2012-08-05 01:13 . 2012-08-05 01:14 -------- d-----w- c:\program files\Opera
2012-08-02 16:23 . 2012-08-02 16:23 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\IObit
2012-08-02 13:52 . 2012-08-02 13:52 -------- d-----w- c:\windows\ServicePackFiles
2012-08-02 13:44 . 2009-06-22 11:48 91776 ----a-w- c:\windows\system32\drivers\SET1A6A.tmp
2012-08-02 13:26 . 2009-02-09 10:22 473088 ----a-w- c:\windows\system32\wbem\SET18C3.tmp
2012-08-02 13:26 . 2009-02-06 16:39 227840 ----a-w- c:\windows\system32\wbem\SET18C1.tmp
2012-08-02 13:26 . 2009-02-09 10:22 453120 ----a-w- c:\windows\system32\wbem\SET18C2.tmp
2012-08-02 13:24 . 2008-04-21 21:28 216576 ----a-w- c:\program files\Windows NT\Accessories\SET1873.tmp
2012-08-02 13:11 . 2008-06-20 17:42 247296 -c--a-w- c:\windows\system32\dllcache\SET1730.tmp
2012-08-02 13:11 . 2008-06-20 10:45 360320 -c--a-w- c:\windows\system32\dllcache\SET172F.tmp
2012-08-02 13:05 . 2006-10-11 16:26 104960 -c--a-w- c:\windows\system32\dllcache\SET1635.tmp
2012-08-02 13:05 . 2006-10-11 16:26 313344 -c--a-w- c:\windows\system32\dllcache\SET1634.tmp
2012-08-02 13:05 . 2006-10-11 16:26 116224 -c--a-w- c:\windows\system32\dllcache\SET1632.tmp
2012-08-02 13:05 . 2006-10-11 16:26 153088 -c--a-w- c:\windows\system32\dllcache\SET1636.tmp
2012-08-02 13:05 . 2006-10-11 16:26 58880 -c--a-w- c:\windows\system32\dllcache\SET1630.tmp
2012-08-02 13:04 . 2012-05-24 08:48 21376 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-08-02 12:05 . 2012-08-02 12:05 -------- d-----w- c:\documents and settings\Trash\Local Settings\Data aplikací\ESET
2012-07-27 11:50 . 2012-07-27 11:50 -------- dc----w- c:\documents and settings\LocalService\Dokumenty
2012-07-26 17:05 . 2012-07-26 17:05 -------- dc----w- c:\documents and settings\Trash\Data aplikací\Telefónica Móviles
2012-07-26 17:04 . 2009-12-15 12:05 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-07-26 17:04 . 2009-12-15 12:05 113280 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-07-26 17:04 . 2009-12-15 12:05 102528 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-07-26 17:04 . 2009-12-15 12:05 100736 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2012-07-26 17:04 . 2012-07-26 17:04 -------- d-----w- c:\program files\O2
2012-07-24 12:01 . 2012-07-24 12:01 1409 ----a-w- c:\windows\QTFont.for
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-21 22:46 . 2012-06-21 22:46 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2012-06-21 22:46 . 2012-06-21 22:46 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2012-07-29 10:58 . 2012-06-08 12:14 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-07_19.23.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-08 09:42 . 2012-08-08 09:42 16384 c:\windows\temp\Perflib_Perfdata_3a4.dat
+ 2007-10-31 18:06 . 2012-08-08 09:45 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-31 18:06 . 2012-08-07 17:30 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-31 18:06 . 2012-08-08 09:45 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-31 18:06 . 2012-08-07 17:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-08-08 09:07 . 2012-08-08 09:45 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2012-08-06 23:59 . 2012-08-07 17:30 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 69632]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-30 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Soulseek-Test\\slsk.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Documents and Settings\\Trash\\Plocha\\utorrent-portable\\utorrent.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Documents and Settings\\Trash\\Data aplikací\\GameRanger\\GameRanger\\GameRanger.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.10.2007 21:34 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [6.8.2012 19:22 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.8.2012 19:23 353688]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [11.3.2012 21:13 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [11.3.2012 21:13 31704]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 11:51 19200]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.8.2012 19:23 21256]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [23.11.2011 12:27 1052472]
R2 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [1.12.2007 18:54 8192]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [5.7.2012 18:41 3048136]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29.2.2012 9:50 158856]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [26.7.2012 19:04 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [26.7.2012 19:04 100736]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.5.2012 13:57 113120]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2.5.2010 2:34 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2.5.2010 2:35 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2.5.2010 2:35 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2.5.2010 2:36 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2.5.2010 2:36 25704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 -c--a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-08 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-08-06 16:21]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-06 17:23]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-06 17:23]
.
.
------- Doplňkový sken -------
.
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\documents and settings\Trash\Data aplikací\Mozilla\Firefox\Profiles\sm04586p.default\
FF - user.js: extensions.installedDistroAddon.testpilot@labs.mozilla.com - true
FF - user.js: extensions.jqs@sun.com.install-event-fired - true
FF - user.js: extensions.kosa.anonymousId - 047b792e0c7c5e971952c209f392b325
FF - user.js: extensions.kosa.bgCount - 261
FF - user.js: extensions.kosa.bundles - +1$fvd
FF - user.js: extensions.kosa.config - +fvd
FF - user.js: extensions.kosa.enabled - true
FF - user.js: extensions.kosa.install - fvd
FF - user.js: extensions.kosa.prefix - fvd
FF - user.js: extensions.kosa.settingsPrefix - fvd
FF - user.js: extensions.kosa.smspHideAds - false
FF - user.js: extensions.kosa.smspMaxPerPage - 10
FF - user.js: extensions.kosa.userId - c9929576-5e09-454f-80ca-9dd101fbac71
FF - user.js: extensions.kosa.vercheck - hxxp://init.kallout.com/versioncheck.js
FF - user.js: extensions.kosa.version - 2.2.3
FF - user.js: extensions.lastAppVersion - 14.0.1
FF - user.js: extensions.lastPlatformVersion - 14.0.1
FF - user.js: extensions.pendingOperations - false
FF - user.js: extensions.register@pgport.com.data - {ef522540-89f5-46b9-b6fe-1829e2b572c6},0,9999,999.999.999,9999,|{c50ca3c4-5656-43c2-a061-13e717f73fc8},5300,5300,4.0.1,5300,fvd|fvd@kallout.com,5200,5200,4.0.1,5200,fvd|fbg@pgport.com,0,5100,0.0.0,4600,|kosa@kallout.com,5000,5000,2.0.1,5000,sm|ytvdh@pgport.com,0,4800,1.1.3,4800,|ytvdw@pgport.com,0,4700,1.1.3,4700,|btpersonas@brandthunder.com,0,4600,0.0.0.,4600,|lifetimesavings@pgport.com,0,1002,0.0.0.,1002,|afhack@pgport.com,0,1001,0.0.0.,1001,|afext@pgport.com,0,1000,0.0.0.,1000,
FF - user.js: extensions.register@pgport.com.version - 1017
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extensions.skype_toolbar.version - 5.10.0.9560
FF - user.js: extensions.testpilot.alreadyCustomizedToolbar - true
FF - user.js: extensions.testpilot@labs.mozilla.com.install-event-fired - true
FF - user.js: extensions.ui.dictionary.hidden - true
FF - user.js: extensions.ui.lastCategory - addons://list/extension
FF - user.js: extensions.ui.locale.hidden - true
FF - user.js: extensions.update.notifyUser - false
FF - user.js: extensions.{20a82645-c095-46ed-80e3-08825760534b}.install-event-fired - true
FF - user.js: extensions.{23fcfd51-4958-4f00-80a3-ae97e717ed8b}.install-event-fired - true
FF - user.js: extensions.{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.install-event-fired - true
FF - user.js: extensions.{E2883E8F-472F-4fb0-9522-AC9BF37916A7}.install-event-fired - true
FF - user.js: extensions.{c50ca3c4-5656-43c2-a061-13e717f73fc8}.install-event-fired - true
FF - user.js: extensions.{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.install-event-fired - true
FF - user.js: extensions.{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}.install-event-fired - true
FF - user.js: font.internaluseonly.changed - true
FF - user.js: fvd.first_time_use - false
FF - user.js: gfx.blacklist.suggested-driver-version - 257.21
FF - user.js: icqtoolbar.allowSendURL - false
FF - user.js: icqtoolbar.engineVerified - true
FF - user.js: icqtoolbar.geolastmodified - 1271677352
FF - user.js: icqtoolbar.hiddenElements - itb_options
FF - user.js: icqtoolbar.history - Super.8.2011.DVDSCR.XViD-EVO%20torrent||Super.8.2011.DVDSCR.XviD.AC3-ViSiON%20torrent||Ringu%200%3A%20Basudei%20torrent||isohunt%20Ring.0.Birthday.2000.iNTERNAL.DVDRip.XviD-iLS%20torrent||Ring.0.Birthday.2000.iNTERNAL.DVDRip.XviD-iLS%20torrent||piratebay%20Smiley.Face.LIMITED.DVDRip.XviD-iMBT%20torrent||isohunt%20Smiley.Face.Festival.DVDSCR.XviD-XanaX%20torrent||Smiley.Face.Festival.DVDSCR.XviD-XanaX%20torrent||Smiley.Face.LIMITED.DVDRip.XviD-iMBT%20torrent||how.i.met.your.mother.s07e05.hdtv.xvid-lol%20torrent||menza%20jednota||abz%20slovn%C3%ADk||isifa%2Fgetty%20images||Shelter.LiMiTED.DVDRip.XviD-ALLiANCE||how.i.met.your.mother.s07e04.hdtv.xvid-lol
FF - user.js: icqtoolbar.icqgeo - 42
FF - user.js: icqtoolbar.installTime - 1270415208
FF - user.js: icqtoolbar.newtab_state - 1
FF - user.js: icqtoolbar.numberOfSearches - 0
FF - user.js: icqtoolbar.previousFFVersion - 3.6.23
FF - user.js: icqtoolbar.skip_default_search - no
FF - user.js: icqtoolbar.suggestions - false
FF - user.js: icqtoolbar.uninstStatSent - true
FF - user.js: icqtoolbar.uniqueID - 122881625112288168511228899951121
FF - user.js: icqtoolbar.usageStatstTimestamp - 1318699420
FF - user.js: icqtoolbar.xmlEnableSuggestions - false
FF - user.js: icqtoolbar.xmlLanguage - cs
FF - user.js: idle.lastDailyNotification - 1343689907
FF - user.js: intl.charsetmenu.browser.cache - ISO-8859-1, windows-1250, windows-1251, ISO-8859-2, UTF-8
FF - user.js: network.cookie.prefsMigrated - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: oldKeyword - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60327&qkw=
FF - user.js: places.database.lastMaintenance - 1343689912
FF - user.js: places.history.expiration.transient_current_max_pages - 26830
FF - user.js: places.last_vacuum - 1331515232
FF - user.js: plugin.expose_full_path - true
FF - user.js: pref.advanced.javascript.disable_button.advanced - false
FF - user.js: pref.browser.homepage.disable_button.current_page - false
FF - user.js: pref.browser.homepage.disable_button.restore_default - false
FF - user.js: pref.privacy.disable_button.view_cookies - false
FF - user.js: print.print_bgcolor - false
FF - user.js: print.print_bgimages - false
FF - user.js: print.print_command -
FF - user.js: print.print_downloadfonts - true
FF - user.js: print.print_evenpages - true
FF - user.js: print.print_in_color - true
FF - user.js: print.print_margin_bottom - 0.5
FF - user.js: print.print_margin_left - 0.5
FF - user.js: print.print_margin_right - 0.5
FF - user.js: print.print_margin_top - 0.5
FF - user.js: print.print_oddpages - true
FF - user.js: print.print_orientation - 0
FF - user.js: print.print_pagedelay - 500
FF - user.js: print.print_paper_data - 0
FF - user.js: print.print_paper_height - 11,00
FF - user.js: print.print_paper_size - 7209061
FF - user.js: print.print_paper_size_type - 1
FF - user.js: print.print_paper_size_unit - 0
FF - user.js: print.print_paper_width - 8,50
FF - user.js: print.print_printer - Adobe PDF
FF - user.js: print.print_reversed - false
FF - user.js: print.print_scaling - 1,00
FF - user.js: print.print_shrink_to_fit - true
FF - user.js: print.print_to_file - false
FF - user.js: print.print_to_filename -
FF - user.js: print.print_unwriteable_margin_bottom - 0
FF - user.js: print.print_unwriteable_margin_left - 0
FF - user.js: print.print_unwriteable_margin_right - 0
FF - user.js: print.print_unwriteable_margin_top - 0
FF - user.js: print.printer_Adobe_PDF.print_bgcolor - false
FF - user.js: print.printer_Adobe_PDF.print_bgimages - false
FF - user.js: print.printer_Adobe_PDF.print_command -
FF - user.js: print.printer_Adobe_PDF.print_downloadfonts - true
FF - user.js: print.printer_Adobe_PDF.print_edge_bottom - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_left - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_right - 0
FF - user.js: print.printer_Adobe_PDF.print_edge_top - 0
FF - user.js: print.printer_Adobe_PDF.print_evenpages - true
FF - user.js: print.printer_Adobe_PDF.print_footercenter -
FF - user.js: print.printer_Adobe_PDF.print_footerleft - &PT
FF - user.js: print.printer_Adobe_PDF.print_footerright - &D
FF - user.js: print.printer_Adobe_PDF.print_headercenter -
FF - user.js: print.printer_Adobe_PDF.print_headerleft - &T
FF - user.js: print.printer_Adobe_PDF.print_headerright - &U
FF - user.js: print.printer_Adobe_PDF.print_in_color - true
FF - user.js: print.printer_Adobe_PDF.print_margin_bottom - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_left - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_right - 0.5
FF - user.js: print.printer_Adobe_PDF.print_margin_top - 0.5
FF - user.js: print.printer_Adobe_PDF.print_oddpages - true
FF - user.js: print.printer_Adobe_PDF.print_orientation - 0
FF - user.js: print.printer_Adobe_PDF.print_pagedelay - 500
FF - user.js: print.printer_Adobe_PDF.print_paper_data - 0
FF - user.js: print.printer_Adobe_PDF.print_paper_height - 11,00
FF - user.js: print.printer_Adobe_PDF.print_paper_size_type - 0
FF - user.js: print.printer_Adobe_PDF.print_paper_size_unit - 1
FF - user.js: print.printer_Adobe_PDF.print_paper_width - 8,50
FF - user.js: print.printer_Adobe_PDF.print_reversed - false
FF - user.js: print.printer_Adobe_PDF.print_scaling - 1,00
FF - user.js: print.printer_Adobe_PDF.print_shrink_to_fit - true
FF - user.js: print.printer_Adobe_PDF.print_to_file - false
FF - user.js: print.printer_Adobe_PDF.print_to_filename -
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_bottom - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_left - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_right - 0
FF - user.js: print.printer_Adobe_PDF.print_unwriteable_margin_top - 0
FF - user.js: privacy.sanitize.migrateFx3Prefs - true
FF - user.js: privacy.sanitize.timeSpan - 3
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: storage.vacuum.last.index - 1
FF - user.js: storage.vacuum.last.places.sqlite - 1343506873
FF - user.js: toolkit.startup.last_success - 1343924707
FF - user.js: toolkit.telemetry.prompted - 2
FF - user.js: toolkit.telemetry.rejected - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: urlclassifier.keyupdatetime.hxxps://sb-ssl.google.com/safebrowsing/newkey - 1345980394
FF - user.js: urlclassifier.tableversion.goog-black-enchash - 1.53228
FF - user.js: urlclassifier.tableversion.goog-black-url - 1.22331
FF - user.js: urlclassifier.tableversion.goog-white-domain - 1.480
FF - user.js: urlclassifier.tableversion.goog-white-url - 1.371
FF - user.js: useragentswitcher.import.overwrite - false
FF - user.js: useragentswitcher.menu.hide - false
FF - user.js: useragentswitcher.version - 0.73
FF - user.js: xpinstall.whitelist.add -
FF - user.js: xpinstall.whitelist.add.103 -
FF - user.js: xpinstall.whitelist.add.36 -
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: browser.blink_allowed - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-08 11:43
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(1048)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(3948)
c:\windows\system32\guard32.dll
c:\windows\system32\MSCTF.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\MPR.dll
.
- - - - - - - > 'csrss.exe'(964)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\COMODO\COMODO GeekBuddy\CLPS.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Celkový čas: 2012-08-08 11:53:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-08 09:53
ComboFix2.txt 2012-08-07 19:27
ComboFix3.txt 2009-12-19 19:16
ComboFix4.txt 2009-04-21 20:39
.
Před spuštěním: 2 579 877 888
Po spuštění: 2 561 179 648
.
- - End Of File - - 9BCFA5E62D160819B26C4AFE2D1EE6E7