tady je obsah textaku
ComboFix 10-02-19.04 - NB - Fujitsu 20.02.2010 11:56:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.420.1029.18.2038.1120 [GMT 1:00]
Spuštěný z: c:\users\NB - Fujitsu\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\NB - Fujitsu\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100219-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1368 [VPS 100219-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-20 do 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-20 11:06 . 2010-02-20 11:07 -------- d-----w- c:\users\NB - Fujitsu\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-20 11:06 . 2010-02-20 11:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-19 22:03 . 2010-02-19 22:03 -------- d-----w- C:\_OTL
2010-02-19 19:32 . 2010-02-19 19:32 -------- d-----w- c:\program files\trend micro
2010-02-19 19:32 . 2010-02-19 19:33 -------- d-----w- C:\rsit
2010-02-10 18:16 . 2009-12-11 12:01 307200 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-10 18:16 . 2009-12-11 12:01 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-10 18:16 . 2009-12-08 22:29 3503704 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-10 18:16 . 2009-12-08 22:29 3469912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-10 18:16 . 2009-12-08 17:45 816640 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-10 18:16 . 2009-12-08 22:29 214104 ----a-w- c:\windows\system32\drivers\netio.sys
2010-02-10 18:16 . 2009-12-08 19:58 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2010-02-10 18:16 . 2009-12-08 19:58 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2010-02-10 18:16 . 2009-12-08 19:56 317440 ----a-w- c:\windows\system32\BFE.DLL
2010-02-10 18:16 . 2009-12-08 17:44 85504 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2010-02-10 18:16 . 2009-12-08 20:03 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-02-10 18:16 . 2009-12-08 17:44 22016 ----a-w- c:\windows\system32\netiougc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 19:52 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 19:29 . 2007-10-09 09:06 81404 ----a-w- c:\windows\system32\perfc005.dat
2010-02-10 19:29 . 2007-10-09 09:06 473598 ----a-w- c:\windows\system32\perfh005.dat
2010-01-21 21:29 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\Skype
2010-01-21 15:43 . 2008-08-29 09:35 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\skypePM
2010-01-14 10:12 . 2009-10-03 21:11 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-30 21:08 . 2009-12-30 17:57 -------- d-----w- c:\program files\Bacardi
2009-12-28 17:18 . 2009-12-28 17:18 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\U3
2009-12-28 17:12 . 2008-09-19 23:48 -------- d-----w- c:\users\NB - Fujitsu\AppData\Roaming\dvdcss
2009-12-28 12:36 . 2010-02-10 18:15 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 18:15 1327616 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:34 . 2010-02-10 18:15 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:34 . 2010-02-10 18:15 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:34 . 2010-02-10 18:15 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:34 . 2010-02-10 18:15 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:33 . 2010-02-10 18:15 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:32 . 2010-02-10 18:15 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:30 . 2010-02-10 18:15 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:30 . 2010-02-10 18:15 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-19 21:12 . 2009-12-19 21:12 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-18 12:52 . 2010-01-21 21:17 832512 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-21 21:17 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-21 21:17 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-21 21:17 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-21 21:17 72704 ----a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-21 21:17 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-21 21:17 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-12-04 16:14 . 2010-02-10 18:15 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:14 . 2010-02-10 18:15 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-12-04 16:14 . 2010-02-10 18:15 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-24 23:54 . 2009-07-13 07:50 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-07-13 07:50 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-07-13 07:50 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-07-13 07:50 97480 ----a-w- c:\windows\system32\AvastSS.scr
2007-11-04 01:23 . 2007-11-04 00:40 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-12-16 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"ares"="d:\ares\Ares.exe" [2007-12-31 962560]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-13 3276288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-11-03 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-04 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-04 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-04 133912]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-13 4399104]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-27 2658304]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [13.7.2009 8:50 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [13.7.2009 8:50 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [13.7.2009 8:50 53328]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.3.2009 16:47 222456]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [18.10.2008 11:26 685816]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\System32\drivers\Gt51Ip.sys [18.2.2008 16:14 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\System32\drivers\gt72ubus.sys [8.2.2008 12:00 59648]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-19 c:\windows\Tasks\User_Feed_Synchronization-{DC217D56-CBE3-45DB-81A7-2449F2D9D9D8}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {B1FF332D-D34D-4D07-8E6B-BFE75C78E8D3} = 10.154.86.1,10.154.96.6
FF - ProfilePath - c:\users\NB - Fujitsu\AppData\Roaming\Mozilla\Firefox\Profiles\b4rmqx4a.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-20 12:07
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2010-02-20 12:10:54
ComboFix-quarantined-files.txt 2010-02-20 11:10
ComboFix2.txt 2010-02-20 10:32
Před spuštěním: Volných bajtů: 100 664 860 672
Po spuštění: Volných bajtů: 100 679 233 536
- - End Of File - - 26B47B5A483907030EF454E767E5AF27
musela jsem to zase na flesce prenest z infikovaneho do neinfikovaneho protoze mi na infikovanem nejde zpustit ani mozilla ani internet explorer - oba hazou hlasku "Pokus použít neplatnou operaci na klíč registru, který je označen pro odstranění"