Nezničitelnej Worm
Napsal: 30 zář 2010 01:17
Ahoj mám podeření na nakou skrytou mrchu viz, combo ( boužel se mě nepodařilo přijít kde je "zdroj" ) Přišel sem z prace a pořád padal net... nasledoval restart wifi . Pak istalace ZA výpadky už nebyli takové časté ... po 7,5 minutě spadne na 10 sec net a takhle pořád dokola . UPM neřeklo naprosto nic , rsit take ne ( proletel sem log možná tam něco bylo ) a sory za edits .
ComboFix 10-09-29.01 - HackHell 29.09.2010 23:20:31.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2838 [GMT 2:00]
Spuštěný z: c:\documents and settings\HackHell\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
FW: Avira FireWall *enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HackHell\Data aplikací\BITS
c:\documents and settings\HackHell\Data aplikací\BITS\BITS.ini
c:\documents and settings\HackHell\Data aplikací\BITS\DHTTable.dat
c:\documents and settings\HackHell\Data aplikací\BITS\ProxyList.ini
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\FlashGetBHO3.dll
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\FlashGetHook.dll
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetAllUrl.htm
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetUrl.htm
c:\program files\FlashGet Network
c:\windows\libem.INI
c:\windows\regedit.com
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\secustat.dat
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-08-28 do 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-29 21:13 . 2010-09-29 21:13 -------- d-----w- c:\windows\LastGood
2010-09-29 21:10 . 2010-09-29 21:10 388096 ----a-r- c:\documents and settings\HackHell\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-29 20:57 . 2010-09-29 20:57 3895888 ----a-w- c:\windows\REGBK03.ZIP
2010-09-29 20:52 . 2010-09-29 20:52 -------- d---a-w- c:\windows\rundll16.exe
2010-09-29 20:52 . 2010-09-29 20:52 -------- d---a-w- c:\windows\logo1_.exe
2010-09-20 01:06 . 2010-09-20 01:06 -------- d-----w- c:\program files\Avira
2010-09-20 01:06 . 2010-03-01 08:06 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-20 01:06 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-20 01:06 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-20 01:06 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-20 00:20 . 2009-03-25 09:05 34216 ----a-w- c:\windows\system32\drivers\mferkdk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-29 21:06 . 2010-06-03 14:49 -------- d-----w- c:\program files\Realtek
2010-09-29 19:58 . 2010-06-03 14:57 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-28 21:55 . 2010-06-30 16:44 -------- d-----w- c:\program files\Trillian
2010-09-23 00:42 . 2010-07-13 08:22 -------- d-----w- c:\program files\UPM
2010-09-21 13:03 . 2010-08-27 16:49 -------- d-----w- c:\program files\Clip2Net
2010-09-12 20:42 . 2010-06-26 01:07 -------- d-----w- c:\program files\CCleaner
2010-08-29 16:31 . 2010-06-03 16:04 -------- d-----w- c:\program files\Xfire
2010-08-20 15:06 . 2010-08-20 15:06 3907208 ----a-w- c:\windows\REGBK02.ZIP
2010-08-17 13:17 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-14 00:59 . 2010-06-17 21:08 -------- d-----w- c:\program files\Teamspeak2_RC2
2010-08-13 22:01 . 2010-06-18 18:46 -------- d-----w- c:\program files\AIMP2
2010-08-13 01:36 . 2010-08-13 01:36 2826192 ----a-w- c:\documents and settings\HackHell\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-08-07 19:22 . 2010-08-07 19:21 3920986 ----a-w- c:\windows\REGBK01.ZIP
2010-08-06 16:38 . 2010-08-06 16:38 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-26 20:30 . 2010-08-06 16:48 65536 ----a-w- c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}\components\Engine.dll
2010-07-22 15:46 . 2006-03-02 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-13 06:44 . 2010-07-13 06:44 3815533 ----a-w- c:\windows\REGBK00.ZIP
2010-07-13 02:53 . 2010-07-13 02:53 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-07-13 02:53 . 2010-07-13 02:53 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-07-13 02:53 . 2010-07-13 02:53 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-07-12 20:07 . 2010-06-03 16:09 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-07-09 19:00 . 2010-07-09 19:00 41872 ----a-w- c:\windows\system32\xfcodec.dll
.
------- Sigcheck -------
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2006-03-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-02-18 357448]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-02-18 1573448]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-02-18 3203144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [20.9.2010 3:06 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.9.2010 3:06 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [20.9.2010 3:06 405672]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [23.11.2009 17:37 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [3.6.2010 18:00 14856]
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [3.6.2010 17:37 13225]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3.6.2010 18:43 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
2010-07-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Stahnou vse FlashGet3 - c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetAllUrl.htm
IE: Stahnout FlashGet3 - c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetUrl.htm
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - http://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}\components\Engine.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-29 23:23
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(820)
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
Celkový čas: 2010-09-29 23:24:01
ComboFix-quarantined-files.txt 2010-09-29 21:23
Před spuštěním: Volných bajtů: 156 399 845 376
Po spuštění: Volných bajtů: 156 973 969 408
- - End Of File - - DC23850BADC9222F2EF930644441CF9C
BTW : není FlashGet torent downloader ? neco takového sem měl v pc 5-6 let zpatky ( takže pár winu pozadu ) vubec netuším jak se neco takového dostalo do pc .
ComboFix 10-09-29.01 - HackHell 29.09.2010 23:20:31.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2838 [GMT 2:00]
Spuštěný z: c:\documents and settings\HackHell\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
FW: Avira FireWall *enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HackHell\Data aplikací\BITS
c:\documents and settings\HackHell\Data aplikací\BITS\BITS.ini
c:\documents and settings\HackHell\Data aplikací\BITS\DHTTable.dat
c:\documents and settings\HackHell\Data aplikací\BITS\ProxyList.ini
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\FlashGetBHO3.dll
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\FlashGetHook.dll
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetAllUrl.htm
c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetUrl.htm
c:\program files\FlashGet Network
c:\windows\libem.INI
c:\windows\regedit.com
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\secustat.dat
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-08-28 do 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-29 21:13 . 2010-09-29 21:13 -------- d-----w- c:\windows\LastGood
2010-09-29 21:10 . 2010-09-29 21:10 388096 ----a-r- c:\documents and settings\HackHell\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-29 20:57 . 2010-09-29 20:57 3895888 ----a-w- c:\windows\REGBK03.ZIP
2010-09-29 20:52 . 2010-09-29 20:52 -------- d---a-w- c:\windows\rundll16.exe
2010-09-29 20:52 . 2010-09-29 20:52 -------- d---a-w- c:\windows\logo1_.exe
2010-09-20 01:06 . 2010-09-20 01:06 -------- d-----w- c:\program files\Avira
2010-09-20 01:06 . 2010-03-01 08:06 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-20 01:06 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-20 01:06 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-20 01:06 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-20 00:20 . 2009-03-25 09:05 34216 ----a-w- c:\windows\system32\drivers\mferkdk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-29 21:06 . 2010-06-03 14:49 -------- d-----w- c:\program files\Realtek
2010-09-29 19:58 . 2010-06-03 14:57 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-28 21:55 . 2010-06-30 16:44 -------- d-----w- c:\program files\Trillian
2010-09-23 00:42 . 2010-07-13 08:22 -------- d-----w- c:\program files\UPM
2010-09-21 13:03 . 2010-08-27 16:49 -------- d-----w- c:\program files\Clip2Net
2010-09-12 20:42 . 2010-06-26 01:07 -------- d-----w- c:\program files\CCleaner
2010-08-29 16:31 . 2010-06-03 16:04 -------- d-----w- c:\program files\Xfire
2010-08-20 15:06 . 2010-08-20 15:06 3907208 ----a-w- c:\windows\REGBK02.ZIP
2010-08-17 13:17 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-14 00:59 . 2010-06-17 21:08 -------- d-----w- c:\program files\Teamspeak2_RC2
2010-08-13 22:01 . 2010-06-18 18:46 -------- d-----w- c:\program files\AIMP2
2010-08-13 01:36 . 2010-08-13 01:36 2826192 ----a-w- c:\documents and settings\HackHell\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-08-07 19:22 . 2010-08-07 19:21 3920986 ----a-w- c:\windows\REGBK01.ZIP
2010-08-06 16:38 . 2010-08-06 16:38 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-26 20:30 . 2010-08-06 16:48 65536 ----a-w- c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}\components\Engine.dll
2010-07-22 15:46 . 2006-03-02 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-13 06:44 . 2010-07-13 06:44 3815533 ----a-w- c:\windows\REGBK00.ZIP
2010-07-13 02:53 . 2010-07-13 02:53 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-07-13 02:53 . 2010-07-13 02:53 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-07-13 02:53 . 2010-07-13 02:53 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-07-12 20:07 . 2010-06-03 16:09 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-07-09 19:00 . 2010-07-09 19:00 41872 ----a-w- c:\windows\system32\xfcodec.dll
.
------- Sigcheck -------
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2006-03-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-02-18 357448]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-02-18 1573448]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-02-18 3203144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [20.9.2010 3:06 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.9.2010 3:06 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [20.9.2010 3:06 405672]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [23.11.2009 17:37 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [3.6.2010 18:00 14856]
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [3.6.2010 17:37 13225]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3.6.2010 18:43 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
2010-07-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Stahnou vse FlashGet3 - c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetAllUrl.htm
IE: Stahnout FlashGet3 - c:\documents and settings\HackHell\Data aplikací\FlashGetBHO\GetUrl.htm
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - http://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\documents and settings\HackHell\Data aplikací\Mozilla\Firefox\Profiles\5ab0itn4.default\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}\components\Engine.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-29 23:23
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(820)
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
Celkový čas: 2010-09-29 23:24:01
ComboFix-quarantined-files.txt 2010-09-29 21:23
Před spuštěním: Volných bajtů: 156 399 845 376
Po spuštění: Volných bajtů: 156 973 969 408
- - End Of File - - DC23850BADC9222F2EF930644441CF9C
BTW : není FlashGet torent downloader ? neco takového sem měl v pc 5-6 let zpatky ( takže pár winu pozadu ) vubec netuším jak se neco takového dostalo do pc .