ComboFix 10-07-12.03 - Administrator 2010-07-13 13:47:36.15.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.110 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt.txt
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FILE ::
"c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk"
"c:\documents and settings\Lucia Rusnakova\Start Menu\Programs\Startup\WKCALREM.LNK"
"c:\windows\Tasks\Spybot - Search & Destroy.job"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\jtrsovksp
c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\urrunaiwe
c:\documents and settings\Lucia Rusnakova\Start Menu\Programs\Startup\WKCALREM.LNK
c:\windows\Tasks\Spybot - Search & Destroy.job
.
--------------- FCopy ---------------
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\system32\user32.dll
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\$NtServicePackUninstall$\user32.dll
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\$NtUninstallKB925902$\user32.dll
c:\windows\$NtUninstallKB890859$\user32.dll --> c:\windows\ServicePackFiles\i386\user32.dll
c:\windows\$NtUninstallKB884883$\explorer.exe --> c:\windows\$NtUninstallKB938828$\explorer.exe
c:\windows\$NtUninstallKB884883$\explorer.exe --> c:\windows\ServicePackFiles\i386\explorer.exe
c:\windows\$NtUninstallKB884883$\explorer.exe --> c:\windows\$NtServicePackUninstall$\explorer.exe
c:\windows\$NtUninstallKB884883$\explorer.exe --> c:\windows\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2010-06-13 to 2010-07-13 )))))))))))))))))))))))))))))))
.
2010-08-11 17:29 . 2010-08-11 17:30 26682864 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\rp\RealPlayerSPGold.exe
2010-08-11 17:29 . 2010-08-11 17:29 220272 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-08-11 17:29 . 2010-08-11 17:29 149000 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\chr_helper\LaunchHelper.exe
2010-08-11 17:29 . 2010-08-11 17:29 13407072 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\chr\ChromeInstaller.exe
2010-08-11 17:28 . 2010-08-11 17:28 79368 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\RUP\vista.exe
2010-08-11 17:28 . 2010-08-11 17:28 73344 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\RUP\inst_config\gtapi_v6.dll
2010-08-11 17:28 . 2010-08-11 17:28 64000 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\RUP\inst_config\gcapi_dll.dll
2010-08-11 17:28 . 2010-08-11 17:28 52288 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\RUP\inst_config\gtapi.dll
2010-08-11 17:28 . 2010-08-11 17:28 122880 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\RUP\inst_config\compat.dll
2010-08-08 07:12 . 2010-08-08 07:12 452104 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.12\setup.exe
2010-07-13 08:47 . 2010-07-13 08:47 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-07-04 08:09 . 2010-07-04 08:09 439816 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Real\Update\setup3.10\setup.exe
2010-06-14 20:45 . 2010-06-14 20:45 503808 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6cc70812-n\msvcp71.dll
2010-06-14 20:45 . 2010-06-14 20:45 499712 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6cc70812-n\jmc.dll
2010-06-14 20:45 . 2010-06-14 20:45 348160 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-6cc70812-n\msvcr71.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-13 12:59 . 2006-04-21 23:26 -------- d-----w- c:\documents and settings\Lucia Rusnakova\Application Data\Skype
2010-07-13 12:58 . 2008-09-24 22:53 -------- d-----w- c:\documents and settings\Lucia Rusnakova\Application Data\skypePM
2010-07-13 07:36 . 2008-12-25 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-04 20:22 . 2006-07-08 23:12 1660 ----a-w- c:\documents and settings\Lucia Rusnakova\Application Data\wklnhst.dat
2010-06-01 19:34 . 2009-10-12 19:41 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-05-10 08:27 . 2006-04-20 20:17 55680 ----a-w- c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-29 14:39 . 2008-12-25 12:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2008-12-25 12:37 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-08-25 08:50 . 2008-08-25 08:50 16 ---ha-w- c:\program files\mxfilerelatedcache.mxc2
2009-07-07 00:14 . 2009-07-05 07:55 28565536 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"DeskSpace"="c:\documents and settings\Lucia Rusnakova\Desktop\3D_Cube_DeskSpace_v1.5.1\DeskSpace v1.5.1\deskspace.exe" [2007-09-18 1066496]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-04-06 26102056]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-10-14 53248]
"VTTrayp"="VTtrayp.exe" [2005-10-14 167936]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-17 729178]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
"OlStatusMon"="c:\program files\Olivetti\ANY_WAY\olDvcStatus.exe" [2006-06-28 106496]
"Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-03 1848648]
"WireLessMouse "="c:\program files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 503808]
"WireLessKeyboard "="c:\program files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2004-07-01 233472]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-23 185896]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2006-05-31 108160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprecovr \SystemRoot\sprecovr.txt
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2007-12-08 685816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7acc5102-c738-11de-a7ee-00c0a8b00f43}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-26 c:\windows\Tasks\avast! Antivirus.job
- c:\progra~1\ALWILS~1\Avast4\ashAvast.exe [2010-04-17 09:59]
2010-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-01 08:40]
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-01 08:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.centrum.sk/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5577
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {7876E4A5-78B7-4020-B08F-C960A1ED54C9} - hxxp://213.151.230.2:2222/Ctl/WinWebPush.cab
DPF: {CE40C3F1-3DF5-4461-A521-810923235628} - hxxp://
www.joj.sk/fileadmin/joj_player/JOJ_Explorer_Player.cab
FF - ProfilePath - c:\documents and settings\Lucia Rusnakova\Application Data\Mozilla\Firefox\Profiles\51uh23wh.default\
FF - component: c:\documents and settings\Lucia Rusnakova\Application Data\Mozilla\Firefox\Profiles\51uh23wh.default\extensions\
LAILoader@liveblockauctions.com\components\np_laiLoader.dll
FF - plugin: c:\documents and settings\Lucia Rusnakova\Application Data\Mozilla\Firefox\Profiles\51uh23wh.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\TV JOJ Media Player\npplugin_netscape.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-yxomgxfu - c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\urrunaiwe\uwkerpdtssd.exe
HKCU-Run-bwmavmnf - c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\jtrsovksp\uddxsnqtssd.exe
HKLM-Run-yxomgxfu - c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\urrunaiwe\uwkerpdtssd.exe
HKLM-Run-bwmavmnf - c:\documents and settings\Lucia Rusnakova\Local Settings\Application Data\jtrsovksp\uddxsnqtssd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-13 13:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2292)
c:\documents and settings\Lucia Rusnakova\Desktop\3D_Cube_DeskSpace_v1.5.1\DeskSpace v1.5.1\deskspace151.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Olivetti\ANY_WAY\olMntrService.exe
c:\windows\system32\slmdmsr.exe
c:\windows\system32\VTTimer.exe
Dufam, ze to bude O K. spravila som vsetko podla navodu a musela som ist prec na par minut. PC sa asi restartoval a spustil sa v normalnom rezime. este pred tym ako dopracoval Combofix sa vsak spustilo niekolko programov ako napr. skype
c:\windows\system32\VTtrayp.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Skype\Phone\Skype.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2010-07-13 14:06:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-13 13:06
ComboFix2.txt 2010-07-13 09:05
Pre-Run: 25,234,935,808 bytes free
Post-Run: 24,739,397,632 bytes free
- - End Of File - - 590740D7FFD409E22E5D893FC3DFE9F0